Privacy Policy

What we collect, why, and for how long.

Updated 18 August 2026

Data controller: Liberna Labs Sp. z o.o., with its registered office at Grzybowska 87, 00-844 Warsaw, Poland (KRS 0001254470, NIP 5273228302, REGON 545310572). References to “Meander,” “we,” “us,” or “our” mean Liberna Labs Sp. z o.o.

Contact: [email protected] for questions about this policy or to exercise the rights described below.

Supervisory authority: You have the right to lodge a complaint with the Polish data protection authority, Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl, or with the supervisory authority in your EU/EEA country of residence.


1. Our starting position

Meander is built so that using the VPN itself requires as little personal data as possible. You can create an account without providing an email address or other identifying information; we generate a random login ID for you. We do not need to know who you are to provide a VPN connection, and we have designed the product accordingly.

This policy explains what we do collect. Some data is unavoidable to run a paid service: an account must exist, a subscription must be billed, and a WireGuard tunnel must know which key to route to.

2. What we collect

Category What it includes Why
Account data Your login ID, whether self-chosen or randomly generated, and password hash Authenticate you and let you sign in on multiple devices
Device data Device name, WireGuard public key, currently assigned VPN IP address, and device type Route traffic and let you view or revoke devices
Billing data Subscription plan, order and payment status, amount, currency, and payment provider reference Process payments, maintain accounting records, and handle refunds
Connection state Which device currently has, or recently had, an active tunnel and its assigned IP Route traffic while connected; stale entries are automatically purged
Support communications Information you provide when contacting us Answer and manage your request
Website data Basic hosting logs and aggregated analytics collected using our self-hosted Umami installation; this data is kept separate from VPN accounts Secure and operate the website and understand its use

What we do not do

We do not log the websites or servers you connect to while using the VPN, your DNS queries, the content of your traffic, or a history of connection timestamps tied to your identity. Our gateways route encrypted WireGuard traffic; they are not designed to inspect or record it.

We do not sell your personal data.

Being precise about “no logs”

We do not log your activity: what you did while connected. We necessarily hold a small amount of account and technical state for as long as required to run the service. References to “no logs” mean that we do not keep logs of your VPN activity; they do not mean that no technical state exists while providing the service.

Under Article 6 of the GDPR, we rely on:

  • Performance of a contract for account creation, authentication, VPN provisioning, and billing.
  • Legal obligation for invoices and payment records required by Polish accounting and tax law.
  • Legitimate interests for support, service security, abuse prevention, basic hosting logs, and self-hosted aggregated website analytics.
  • Consent where requested separately, such as for an optional marketing mailing list. No marketing mailing list is currently offered.

4. Retention

Data Retention period
Account records While the account is active; deleted or anonymised within 30 days after closure
Device records While the device is registered; deleted when the device is revoked or within 30 days after account closure
Backups Removed through the normal backup rotation within 30 days
Billing and invoice records Five years, calculated from the beginning of the year following the financial year concerned, or longer where required by applicable Polish tax or accounting law
Connection state Purged automatically within 24 hours after the connection becomes inactive and not retained as a historical log
Support communications Twelve months after the request is closed, unless longer retention is necessary for an unresolved complaint, a legal obligation, or the establishment, exercise, or defence of legal claims
Website hosting logs Cloudflare Workers request logs are retained for up to three days. Cloudflare Pages Functions logs are viewed in real time and are not stored. We do not export either for longer-term retention
Aggregated website analytics Retained in our self-hosted Umami installation for twelve months

5. Service providers

We use a limited number of service providers for the parts of the service they support:

  • Card payment processing: Stripe Payments Europe, Limited and Stripe Technology Europe, Limited.
  • Cryptocurrency payment processing: UAB “Decentralized”, trading as CoinGate.
  • Infrastructure hosting: DigitalOcean, LLC, using infrastructure in Frankfurt, the United Kingdom, and Canada.
  • Website hosting: Cloudflare, Inc., through Cloudflare Workers Static Assets and Cloudflare Pages.

Each provider receives only the data needed for its role and is subject to applicable contractual and data-protection obligations.

6. International data transfers

Our gateway fleet includes locations in the EU, the United Kingdom, and Canada. Cloudflare, DigitalOcean, Stripe, and their subprocessors may also process data outside the EU/EEA as described in their applicable data-processing terms.

  • Transfers to the United Kingdom and to qualifying commercial organizations in Canada rely on the applicable European Commission adequacy decisions.
  • Eligible transfers to participating organizations in the United States rely on the EU-U.S. Data Privacy Framework.
  • Where an adequacy decision does not apply, transfers are protected by the European Commission’s Standard Contractual Clauses or another lawful transfer mechanism.

7. Your rights

Under the GDPR, you may have the right to:

  • Access personal data we hold about you.
  • Correct inaccurate data.
  • Request erasure, subject to legal retention obligations.
  • Restrict processing.
  • Receive portable data in a structured format.
  • Object to processing based on legitimate interests.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with UODO or another competent supervisory authority.

If you registered without providing identifying information and lose your login ID, we may have no way to verify that you are the account holder. This is a consequence of the privacy-preserving account model. Contact [email protected] to exercise your rights.

8. Automated decision-making

We do not use personal data for automated decision-making or profiling that produces legal or similarly significant effects.

9. Children

The service is intended only for people aged 18 or older. We do not knowingly collect personal data from anyone under 18. If you believe that a person under 18 has provided personal data to us, contact [email protected], and we will take appropriate steps to delete it.

10. Changes to this policy

We will announce material changes before they take effect through the website or, where available, account communications. This page will show the latest revision date.

11. Contact

Liberna Labs Sp. z o.o.
Grzybowska 87, 00-844 Warsaw, Poland
[email protected]