ORA VPN
Login
Back to Home
Legal & Privacy Center

Privacy Policy & Legal Notices

Last updated: July 25, 2026. Your privacy and security are the foundation of our peer-to-peer network architecture.

Strict Zero-Logs Policy

We never track, store, log, or sell your online activity, DNS queries, IP addresses, or traffic content.

Direct P2P Encryption

Traffic routes directly between peers using Noise protocol and X25519 cryptography with zero central inspection.

Ephemeral Coordination

Coordination servers only broker peer discovery handshakes and discard metadata immediately upon connection establishment.

1. Overview & Commitment

At ORA VPN, we believe that privacy is a fundamental human right. Unlike traditional VPN providers that operate monolithic proxy clusters capable of inspecting your traffic, ORA VPN utilizes a decentralized, peer-to-peer (P2P) mesh architecture.

This document explains how our platform handles data, what minimal information is required to maintain your active service subscription, and how our cryptographically verified architecture ensures absolute privacy.

2. Information We Collect (and What We Don't)

No Activity Logs: We do NOT collect or store browsing history, visited URLs, data payloads, bandwidth usage, or outgoing IP addresses.
Account Data: When creating an account, we collect only your email address and payment state to manage account authentication and active plan access.
Payment Processing: Financial transactions are securely processed by merchant partners (e.g. Stripe/PayPal). We do not store raw credit card details on our servers.

3. Peer-to-Peer Encryption Architecture

ORA VPN uses modern cryptographic primitives (ChaCha20-Poly1305 and Noise Protocol IK/XX patterns) to build end-to-end encrypted tunnels between participating nodes.

Our coordination infrastructure only facilitates initial peer discovery and connection handshakes. Once a peer connection is established, all data travels directly between client endpoints. Coordination servers have zero ability to decrypt or intercept tunneled packets.

4. Cookies & Website Analytics

Our marketing website uses privacy-focused, anonymized web metrics strictly to analyze page loading speeds and aggregated traffic patterns. We do not use cross-site tracking cookies, third-party advertising identifiers, or invasive telemetry scripts.

5. Data Protection Rights

Depending on your jurisdiction (such as under GDPR or CCPA), you have the right to request access to your account data, request deletion of your account record, or request data portability. To exercise these rights, please contact our privacy compliance team.

6. Contacting Legal & Privacy

If you have any questions, concerns, or legal inquiries regarding our privacy policy or network architecture, please reach out to us at:

Legal & Compliance Department

Email: [email protected]

Support Hours: 10:00 AM – 5:00 PM IST (Mon – Fri)