GhostMesh
DownloadServersSRSPFAQPricingBlog
Login
GhostMesh

© 2026 SRS Conglomerate. All rights reserved.

Service StatusDocumentationSecurityTerms & ConditionsTransparency reportPrivacy policy

Privacy Policy

Your privacy is our priority. Learn how we protect your data and maintain your anonymity.

Last updated: June 11, 2026

Privacy Overview

At GhostMesh VPN, we are committed to protecting your privacy and maintaining the confidentiality of your personal information.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our VPN service.

We maintain a strict no-logs policy, meaning we do not monitor, record, or store your online activities or browsing history.

Data Controller

Data Controller: Individual Entrepreneur Mishagin Vyacheslav Vladimirovich (Tax ID/INN: 390609456123, OGRNIP: 324390000046940).

Contact Information: For data subject requests, contact us at info@srs-ghostmesh.com or through the contact form on our website.

For EU/EEA Users: Your rights are additionally governed by the GDPR. Please see the EU/EEA Addendum section for detailed information.

Information We Collect

Account Information: E-mail, username, and password for account creation and management.

Payment Information: Billing details processed securely through third-party payment processors.

Technical Data: Per-account upload and download byte counters, totalled by calendar day, plus the server locations you use. These are not linked to individual sessions, connection times, or destinations.

Support Data: Information you provide when contacting our customer support team.

Children's Privacy

GhostMesh VPN is not directed to children under 13 and is not designed for use by children without parental or guardian supervision.

We do not knowingly collect personal information from children under 13. If we learn that we have collected such information without appropriate consent, we will delete it or take the legally required steps as soon as reasonably possible.

Parents or guardians who believe that a child has provided personal information to GhostMesh may contact us at info@srs-ghostmesh.com to request review or deletion.

Purposes of Personal Data Processing

VPN Service Provision: Processing account and technical data to ensure service operation.

Payment Processing: Transferring payment information to third-party payment processors for payment processing.

Customer Support: Processing support data to respond to inquiries and resolve issues.

Security and Abuse Prevention: Using aggregated technical data to ensure service stability and prevent abuse.

Legal Compliance: Storing data in accordance with applicable legal requirements.

Legal Basis for Processing

Contract Performance: Processing account and payment information is necessary to provide VPN services under the subscription agreement.

Legitimate Interests: Processing technical data for security and abuse prevention is based on the operator's legitimate interests.

Consent: Some additional services (e.g., marketing communications) may require your explicit consent.

Legal Obligations: Processing data to comply with legal requirements (e.g., tax legislation).

How We Use Your Information

Service Provision: To provide, maintain, and improve our VPN services.

Account Management: To manage your account, process payments, and provide customer support.

Security: To protect against fraud, abuse, and security threats.

Communication: To send important service updates, security notifications, and support responses.

Traffic Counters and Abuse Prevention

GhostMesh does not store VPN traffic content or a browsing-history list of websites visited through the tunnel.

For billing, reliability, dashboards, fair-use enforcement, and abuse prevention, GhostMesh may process account identifiers, device/session data, selected server, app version, error reports, aggregate upload/download counters, and current-calendar-month usage totals.

Data Protection Measures

Encryption: All data transmission is encrypted using modern cryptographic protocols. Connections use the GhostMesh SRSP transport with REALITY over TLS 1.3. The exact parameters depend on the server and connection mode you choose.

Secure Servers: Our servers are located in privacy-friendly jurisdictions with strict data protection laws.

Access Controls: Limited access to personal data on a need-to-know basis for authorized personnel only.

Infrastructure Security: We apply industry-standard security practices to protect our infrastructure and regularly update security measures.

Information Sharing

We do not sell, trade, or rent your personal information to third parties.

We may share information only in the following limited circumstances:

• Legal Requirements: When required by law or to protect our rights and safety.

• Service Providers: With trusted third-party service providers who assist in operating our service.

• Business Transfers: In the event of a merger, acquisition, or sale of assets.

Data Recipients and Processors

Payment Processors: We use third-party payment processors (Robokassa, cryptocurrency payments, etc.) to process payments. Payment information is processed by them according to their privacy policies.

Analytics Providers: With your consent we use Google Analytics / Google Tag Manager (Google) and Microsoft Clarity (Microsoft) on our website. Microsoft Clarity records how you interact with pages, including a replay of clicks, scrolling and mouse movement. These tools run only after you accept cookies, and never inside the VPN app or the tunnel.

Hosting Providers: Our servers are hosted with hosting providers who may have access to infrastructure but not to traffic content due to encryption.

Support Team: Support data may be processed by support staff to respond to your inquiries.

Legal Requirements: We may disclose data to third parties if required by law or court order.

Cross-Border Data Transfers

Data Storage: Account data is stored on servers in the Russian Federation. Some VPN servers may be located in other countries to ensure global service availability.

Payment Processors: Payment information may be processed by payment processors in various jurisdictions according to their policies.

Data Protection: We apply appropriate security measures to protect data during cross-border transfers, including encryption and compliance with data protection standards.

Data Retention

Account Information: Retained for the duration of your account plus a reasonable period for legal compliance.

Payment Information: Processed by third-party payment processors and not stored on our servers.

Technical Data: Aggregated account statistics are updated in real-time and not linked to specific sessions. Connection logs or session timestamps are not stored.

Support Data: Retained for up to 3 years for quality assurance and legal compliance purposes.

Data Retention Periods by Category

Account Information: Retained for the duration of the account plus 3 years after account termination for legal compliance.

Payment Information: Not stored on our servers, processed by payment processors according to their policies (typically 7 years for tax purposes).

Technical Data: Aggregated account statistics are retained for the duration of the account. Connection logs or session timestamps are not stored.

Support Data: Retained for up to 3 years from the last contact for quality assurance and legal compliance.

Your Privacy Rights

Access: You have the right to request access to personal information we hold about you. To submit a request, contact us at info@srs-ghostmesh.com with 'Data Access Request' in the subject line.

Correction: You have the right to request correction of inaccurate or incomplete personal information. Requests can be submitted through our support team.

Deletion: You have the right to request deletion of your personal information (subject to legal and operational requirements). Note that data deletion may result in service termination.

Portability: You have the right to request a copy of your personal information in a structured, machine-readable format (JSON, CSV).

Objection: You have the right to object to processing of your personal information for certain purposes (e.g., marketing).

Restriction of Processing: You have the right to request restriction of processing of your data in certain cases.

Withdrawal of Consent: If processing is based on consent, you have the right to withdraw consent at any time. Processing of data before consent withdrawal remains lawful.

Right to Lodge a Complaint with Supervisory Authority

For EU/EEA Users: If you believe that processing of your personal data violates the GDPR, you have the right to lodge a complaint with a data protection supervisory authority in your country or the country where the alleged violation occurred.

For UK Users: You may lodge a complaint with the Information Commissioner's Office (ICO) at https://ico.org.uk/make-a-complaint/.

EU Supervisory Authorities List: A complete list is available on the European Commission website. We recommend first contacting us through support to attempt to resolve the matter directly.

For Users from Other Countries: Contact the relevant data protection supervisory authority in your jurisdiction.

Questions About Your Privacy?

If you have any questions about this Privacy Policy or want to exercise your privacy rights, please contact us.

Terms of Service