In short
Brix VPN does not log what you do online. We do not record the sites you visit, the DNS queries you make, the IP addresses you connect to, or the contents of your traffic. We cannot hand over records we do not keep.
We hold the minimum needed to run an account: a device identifier that serves as your account, your subscription status, and a running monthly byte total used only to enforce the free tier's 10 GB allowance. There is no email address and no password. We never see your payment card.
Brix VPN is operated from Canada by Petrichor Enchantment Inc. This summary is for orientation only; the sections below are the binding terms.
Who we are and what this covers
Brix VPN is operated by Petrichor Enchantment Inc., a corporation incorporated in Ontario, Canada, trading as LumiVeil. In this policy, "we", "us" and "Brix" mean Petrichor Enchantment Inc.
This policy covers the Brix VPN mobile applications for iOS and Android, our VPN server network, our account systems, and the website at brix.lumiveil.io. It does not cover third-party sites or services you reach while connected to Brix VPN.
For the purposes of the General Data Protection Regulation, Petrichor Enchantment Inc. is the data controller for personal data described here.
What we do not collect
We do not log your activity. Specifically, Brix VPN does not record, store or retain any of the following:
- Websites, domains or applications you access
- DNS queries you make while connected
- Destination IP addresses or ports you connect to
- The contents of your traffic, in any form, encrypted or otherwise
- Your originating IP address, once a session has ended
- Timestamps of individual connections or disconnections
- Per-session bandwidth figures tied to a destination or a time
- Which VPN server or exit location you selected on any given occasion
- Any record that links a point in time to an account and an activity
We have not built the systems that would make this collection possible. This is an architectural decision, not a policy we could quietly reverse. Where a change to this list becomes necessary, we will say so under Changes to this policy before it takes effect.
Because we do not hold this information, we cannot produce it — to a government, a litigant, a rights holder, or anyone else. See Government and law enforcement requests below.
What we do collect
| Data | Why we hold it | Tied to you? |
|---|---|---|
| Device identifier | Serves as your account; there is no login, email or password | Yes, to the device |
| Subscription status and plan | Entitlement to paid features; renewal date | Yes |
| Running monthly byte total | Enforcing the free tier's 10 GB allowance | Yes, as a single number |
| Platform store transaction identifier | Verifying and restoring purchases | Yes |
| Crash reports and diagnostics | Fixing faults in the app | Pseudonymous |
| Support correspondence, if you write to us | Answering your question | Only what you send |
On the device identifier. Your account is the device. We do not ask for your name, email address or phone number, and there is no password to set. We do not use your device's advertising identifier (IDFA on iOS, AAID on Android). If you reset or replace your device, your free-tier account does not carry over; a paid subscription can be restored through Apple or Google.
On the monthly byte total. To enforce the free tier we count bytes transferred and store one running figure per account, reset at the start of each billing month. It is a single number. It carries no destination, no timestamp, no session breakdown, and no indication of what the traffic was. Paid accounts have no allowance, and we do not meter them.
On crash reports. Diagnostics are limited to device model, operating system version, app version, and the technical details of the fault. They do not contain your browsing activity or the contents of your traffic.
We do not use advertising identifiers, third-party analytics SDKs, trackers, or fingerprinting. We do not sell, rent or trade personal information, and we do not share it for cross-context behavioural advertising.
How we use what we collect
We use the data above only to:
- Recognise your device as an account
- Determine whether you are on the free or paid tier and apply the right allowance
- Verify and restore purchases made through Apple or Google
- Show you service notices in the app: billing failures, security notices, material changes to this policy
- Diagnose and fix faults in the applications
- Answer support requests you choose to send
- Detect and prevent abuse of the free tier, fraud, and attacks on our infrastructure
- Meet legal obligations that apply to us in Canada
We do not use your data for advertising, profiling, or automated decision-making that produces legal or similarly significant effects. We do not send marketing email.
Legal bases for processing
If you are in the European Economic Area or the United Kingdom, we rely on these legal bases under the GDPR and UK GDPR:
| Purpose | Legal basis |
|---|---|
| Running your account and delivering the service | Performance of a contract, Art. 6(1)(b) |
| Verifying purchases and handling billing | Performance of a contract, Art. 6(1)(b) |
| Enforcing the free tier allowance | Performance of a contract, Art. 6(1)(b) |
| Security, fraud and abuse prevention | Legitimate interests, Art. 6(1)(f) |
| Crash diagnostics and service improvement | Legitimate interests, Art. 6(1)(f) |
| Service and security notices | Legitimate interests, Art. 6(1)(f) |
| Responding to lawful legal obligations | Legal obligation, Art. 6(1)(c) |
| Optional marketing, if you opt in | Consent, Art. 6(1)(a) |
Where we rely on legitimate interests, we have weighed those interests against your rights and concluded that the processing is limited, expected, and not overriding. You may object at any time using the contact details below.
Payments and billing
Brix VPN subscriptions are sold through the Apple App Store and Google Play. Those platforms act as the merchant of record: they take your payment, hold your payment details, and issue your receipt.
We never receive or store your card number, bank details, or billing address. What we receive is a transaction identifier and your entitlement status, which tell us that a subscription is active and when it renews.
Current prices, in Canadian dollars:
| Plan | Price | Effective monthly |
|---|---|---|
| Monthly | $4.99 | $4.99 |
| 6 months | $25.99 | $4.33 |
| 12 months | $45.99 | $3.83 |
Apple's and Google's own privacy policies govern how they handle your payment information. Refunds, cancellations and billing disputes are handled by the platform you purchased through, as set out in the Terms of Use.
Infrastructure and service providers
We rent servers from commercial hosting providers to run our VPN relay and exit nodes. These providers supply physical hardware, network capacity and data-centre space. They do not operate the Brix VPN service and have no access to our account database.
Your traffic is encrypted between your device and the Brix exit node. A hosting provider can observe that encrypted traffic transits its network; it cannot read the contents, and it cannot associate that traffic with your Brix account, because the account database is not on those machines.
We use providers in several jurisdictions so the service keeps working when a route is blocked. Our relay and exit locations change as network conditions change.
We engage a small number of processors for functions we do not run ourselves, such as crash reporting. Each is bound by contract to process data only on our instructions. We do not engage processors that would receive VPN traffic.
How long we keep things
| Data | Retention |
|---|---|
| Device identifier and subscription status | While the account is active; deleted within 30 days of deletion, or after 12 months of inactivity on a free account |
| Monthly byte total | Overwritten each billing month; not archived |
| Store transaction identifiers | While the subscription is active, then as long as tax and accounting law requires |
| Crash reports and diagnostics | 90 days |
| Support correspondence | 24 months from the last message |
When you delete your account from the app, we delete the device identifier and its usage counter. Records we are required to keep for tax or accounting purposes are retained in a form that does not identify your activity.
Backups are rotated out within 30 days, so deleted data may persist in an encrypted backup for that period before it is overwritten.
When we disclose data
We disclose personal data only in these cases:
- To processors acting for us, under contract, for the functions named above.
- Where you ask us to, for example when you give consent for a specific disclosure.
- Where the law validly compels us, as described in the next section.
- In a corporate transaction, if Petrichor Enchantment Inc. is acquired or merged. You would be notified before your data became subject to a different privacy policy, and the acquirer would be bound by commitments no weaker than these.
We do not sell personal information. We do not disclose data to advertisers, data brokers, or analytics companies.
In every case the limit is the same: the only data we can disclose is the data listed under What we do collect. Your browsing activity is not on that list, and no order can compel us to produce it.
Government and law enforcement requests
We are a Canadian company and respond only to requests that are valid under Canadian law, or that reach us through a recognised mutual legal assistance process. We do not act on informal requests, foreign subpoenas served directly on us, or demands without legal force.
Our response to a valid order is bounded by what exists. We hold a device identifier, a subscription status, and a monthly byte count. We do not hold activity logs, and we cannot create them retroactively.
Where we are legally permitted to notify you of a request concerning your account, we will do so before responding, unless a court forbids it or there is an immediate risk to life.
International transfers
Our account systems are operated from Canada. Canada has been recognised by the European Commission as providing an adequate level of data protection for commercial organisations subject to PIPEDA, so transfers from the EEA to us rely on that adequacy decision.
Our VPN servers sit in many countries, by design: a censorship-resistant network cannot be confined to one jurisdiction. Those servers carry encrypted traffic and do not hold account data.
Where a processor operates outside Canada or the EEA, we put Standard Contractual Clauses or an equivalent transfer mechanism in place.
Your rights
Whatever your location, you may ask us to give you a copy of your data, correct it, delete it, or close your account. Write to the address under Contact us. We respond within 30 days and charge nothing.
Canada (PIPEDA). You may access and correct your personal information and challenge our handling of it. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada.
Quebec (Law 25). You additionally have the right to data portability and the right to be informed of automated decision-making. We do not carry out automated decision-making about you.
EEA and UK (GDPR). You have rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent where we rely on it. You may lodge a complaint with your national supervisory authority.
California (CCPA/CPRA). You have rights to know, delete, correct, and opt out of sale or sharing. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of. We will not discriminate against you for exercising a right.
Because there is no email or password, we verify a request by asking you to make it from within the app on the device concerned. We will not demand identity documents, and we cannot act on a request we cannot tie to a device.
Children
Brix VPN is not intended for children. You must be at least 13 years old to create an account, and at least 16 if you are in the European Economic Area or the United Kingdom, unless local law sets a lower age and a parent or guardian consents.
We do not knowingly collect personal data from anyone below these ages. If you believe a child has created an account, write to us and we will delete it.
Security
Traffic between your device and our servers is encrypted with modern protocols. We hold no passwords, because accounts have none. Account data is encrypted at rest, and access to production systems is restricted and authenticated.
We publish the source code of our client applications so that anyone can verify what the app does with your data.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant regulators within the periods the law requires — 72 hours to a supervisory authority under the GDPR, and as soon as feasible under PIPEDA where the breach poses a real risk of significant harm.
To report a vulnerability, write to us at [email protected]. We will not pursue legal action against researchers who act in good faith and give us reasonable time to fix what they find.
Changes to this policy
We may update this policy as the service changes or the law does. The effective date at the top always reflects the current version.
If a change would materially reduce your privacy — in particular, any change to the list under What we do not collect — we will give you at least 30 days' notice in the app and on our website before it takes effect. You may close your account during that period if you disagree.
Minor clarifications take effect when published. We keep previous versions available on request.
Contact us
Petrichor Enchantment Inc., trading as LumiVeil, Ontario, Canada
For privacy questions and rights requests, security and vulnerability reports, and general support, write to [email protected].
Our Privacy Officer, as required under PIPEDA, is reachable at [email protected].
If you are unsatisfied with how we handle a privacy matter, you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca, or, in the EEA or UK, to your national supervisory authority.