Ir para o conteúdo
FortiSafe VPN

Privacy Policy

Version 1.2 · Effective

In short

  • We don't sell your data and we don't use advertising trackers.
  • VPN traffic doesn't pass through our systems: the app connects straight to the network's servers. That's why we have no record of the sites you visit.
  • We keep what we need to run the service — your email, your devices and your subscription — each with a deadline for deletion.
  • The VPN servers are operated by an infrastructure partner that is contractually bound not to log what you access or where you connect from.
  • You can ask for a copy, correction or deletion of your data at [email protected].

1. Who we are

FortiSafe VPN is provided by Tascom Global Network LLC, a limited liability company registered in the State of Florida, United States (No. L17000240494), located at 13057 Gabor Ave, Orlando, FL 32827. We are the controller of the data described here.

Privacy contact and data protection officer channel: [email protected].

2. What we keep, why and for how long

DataWhyLegal basisHow long
Email, name (if you provide it) and languageCreate and maintain your account, send your sign-in code and subscription noticesContractWhile the account exists
Sign-in code and the IP address that requested itProtect sign-in against repeated attempts. The code is stored only as a one-way hashLegitimate interest (security)30 days
Sessions: device type and start, last-use and expiry datesKeep you signed inContractUp to 30 days after the session ends (each session lasts at most 90 days)
Devices: the name you give them, the operating system, dates and the VPN technical credential, stored encryptedDeliver the VPN configuration to each deviceContractWhile the device is on the account. Once removed, its network account is deleted immediately and the record is erased after 12 months
Subscription: plan, where it was bought, the purchase ID at the store or payment provider, start and endKnow whether you can connect; charge, renew and refundContract and legal obligationWhile the subscription exists and up to 5 years afterwards, for tax obligations and to handle any dispute
API technical logs: IP address, time and the endpoint calledSecurity and troubleshootingLegitimate interestUp to 7 days, deleted automatically by Cloudflare
Messages you send usReply and keep a support recordContract and legitimate interestUp to 2 years after the last message

Card details never reach us: they go to the store (App Store, Google Play, Amazon) or the payment provider, which only tells us the result of the purchase.

3. What never reaches our systems

Once your device has its configuration, the app connects straight to the network's servers — our systems take no part in the connection. So we don't receive or keep:

  • the sites, apps and services you use;
  • the content of what you send and receive;
  • your DNS queries;
  • the IP address you connect to the VPN from, or your connection and disconnection times;
  • how much data you use.

A device's “last use”, mentioned above, is the last time the app requested its configuration from your account — not the last VPN connection.

4. The network and its provider

The VPN servers are operated by a specialized network infrastructure partner we contract, in data centers across 45 countries.

For each device we create a technical account on the network, identified by a random code — without your name or email.

Under its contract with us, this partner is bound not to log anything about your VPN activity: not your traffic or the sites you visit, not connection data (your real IP address, connection and disconnection times, session length or data volume), and not your DNS queries — and not to write any of this to disk, even temporarily.

Putting both sides together, neither we nor our partner keep a record of what you do on the VPN. What we do keep is listed in “What we keep”. API technical logs (up to 7 days) show when the app talked to our API — not when you were connected to the VPN or what you accessed.

5. Who we share with

We don't sell or rent your data, and we don't use it for advertising.

We share only with the companies that help us run the service, each limited to what it needs. The full list, with each company's country, is at Who processes your data.

When you buy through the App Store, Google Play or Amazon, the store handles your payment data under its own rules, as an independent controller.

6. Requests from authorities

We only disclose data in response to a legally valid order or request, reviewed case by case, and only what was requested and exists — at most, what is listed in the table above. Where the law allows, we tell you first. We publish how many requests we receive in our transparency report.

7. Where the data is stored

We are a US company, and your data is mainly stored there: the database is in Ohio, and the website and API run on Cloudflare's network. Sign-in emails are sent from São Paulo, Brazil. The VPN network is operated by a partner based outside Brazil and the European Union, with servers in many countries.

If you live in Brazil, the European Union or the United Kingdom, international transfers rely on the standard contractual clauses offered by our providers, where available, and on being necessary to provide the service you signed up for (LGPD, art. 33; GDPR, arts. 46 and 49).

8. Your rights

At any time and free of charge, you can:

  • confirm whether we process your data and get a copy of it;
  • correct incomplete or inaccurate data;
  • ask us to delete your data;
  • receive your data in a format another service can read (portability);
  • object to processing based on legitimate interest;
  • find out who we share your data with;
  • withdraw any consent you have given.

Write to [email protected] from your account email. We reply within 15 days. To protect you, we may ask you to confirm the request with a code sent to that address.

When you delete your account, we disconnect your devices, delete their technical accounts on the network and erase your data — except the subscription records the law requires us to keep, for the period shown in the table.

If our answer doesn't resolve it, you can complain to the data protection authority in your country.

9. Cookies

The website uses only two cookies, both strictly necessary for it to work, so we don't ask for consent to them:

CookieWhyDuration
fs_idiomaRemember the language you chose1 year
fs_sessaoKeep you signed in. Page scripts cannot read itUp to 90 days, or until you sign out

We don't use analytics, advertising or social media cookies, and the website serves its own fonts. If we ever use anything beyond this, we will ask for your permission first, with declining as easy as accepting.

10. Security and incidents

All communication with the website, the API and the network is encrypted (TLS 1.2 or higher, and WireGuard). Device technical credentials are encrypted with AES-256, sign-in codes are stored only as hashes, and administrative access is restricted to authorized people.

If a security incident could put you at risk, we notify the competent authority and the people affected within the legal deadlines — within 72 hours in Europe and 3 business days in Brazil — explaining what happened, what was affected and what to do.

11. Minors

FortiSafe is intended for people aged 18 and over. We don't knowingly collect data from minors; if we learn that we have, we delete it.

12. Regional rules

Brazil (LGPD)

  • Controller: Tascom Global Network LLC, with the details in “Who we are”.
  • Data protection officer channel: [email protected].
  • Legal bases: performance of a contract (art. 7, V), compliance with a legal obligation (art. 7, II), regular exercise of rights (art. 7, VI) and legitimate interest (art. 7, IX).
  • Your rights are set out in art. 18 of the LGPD, and you may petition the ANPD.
  • As a consumer, you keep your rights under Brazil's Consumer Protection Code.

European Union and United Kingdom (GDPR and UK GDPR)

  • Legal bases: performance of a contract (art. 6(1)(b)), legal obligation (art. 6(1)(c)) and legitimate interest (art. 6(1)(f)) — namely, the security of your account and of the service.
  • You have the rights in arts. 15 to 22, including restriction of processing, and you may lodge a complaint with the supervisory authority in your country.
  • We don't make automated decisions that produce legal effects concerning you.

California (CCPA/CPRA)

  • Categories collected in the last 12 months: identifiers (email and IP address), commercial information (subscription) and technical usage data, for the purposes in the table above.
  • We don't sell or share personal information for cross-context behavioral advertising, and we don't use sensitive personal information.
  • You can request to know, correct and delete your information, and we won't discriminate against you for doing so.

13. Changes to this policy

When we change something material, we'll email you at least 30 days before the new version takes effect. This page always shows the version and its effective date.