What FortiSafe logs — and what it doesn't
FortiSafe doesn't log what you do on the VPN: the sites you visit, the content, DNS queries, your connection IP address, timestamps or data volume. We keep only what the account and subscription need, each with a deadline for deletion, and, under Brazilian law, access logs for our systems for 6 months. The partner that runs the servers is contractually bound not to log it either.
Based on the Privacy Policy version 1.4, effective October 14, 2026.
What we don't log
Once your device has its configuration, the app connects straight to the network's servers — our systems take no part in the connection. So we don't receive or keep:
- the sites, apps and services you use;
- the content of what you send and receive;
- your DNS queries;
- the IP address you connect to the VPN from, or your connection and disconnection times;
- how much data you use.
What about the partner that runs the servers?
Under its contract with us, this partner is bound not to log anything about your VPN activity: not your traffic or the sites you visit, not connection data (your real IP address, connection and disconnection times, session length or data volume), and not your DNS queries — and not to write any of this to disk, even temporarily.
For each device we create a technical account on the network, identified by a random code — without your name or email.
The DNS resolution service is not the network partner and has no data processing agreement with us: it receives the queries coming from the VPN server and handles them under its own privacy terms.
What we keep, why and for how long
| Data | Why | How long |
|---|---|---|
| Email, name (if you provide it) and language | Create and maintain your account, send your sign-in code and subscription notices | While the account exists |
| Sign-in code and the IP address that requested it | Protect sign-in against repeated attempts. The code is stored only as a one-way hash | 30 days |
| Sessions: device type and start, last-use and expiry dates | Keep you signed in | Up to 30 days after the session ends (each session lasts at most 90 days) |
| Devices: the name you give them, the operating system, dates and the VPN technical credential, stored encrypted | Deliver the VPN configuration to each device | While the device is on the account. Once removed, its network account is deleted immediately and the record is erased after 12 months |
| Subscription: plan, where it was bought, the purchase ID at the store or payment provider, start and end | Know whether you can connect; charge, renew and refund | While the subscription exists and up to 5 years afterwards, for tax obligations and to handle any dispute |
| API technical logs: IP address, time and the endpoint called | Security and troubleshooting | Up to 7 days, deleted automatically by Cloudflare |
| Access logs for our systems: date and time, IP address and source port, and the account when identified | Meet the legal obligation to keep access logs (Brazil's Marco Civil da Internet, art. 15) and protect the account. Applies to access from Brazil and to Brazil accounts | 6 months, unless a legal preservation obligation applies |
| Messages you send us | Reply and keep a support record | Up to 2 years after the last message |
A device's “last use”, mentioned above, is the last time the app requested its configuration from your account — not the last VPN connection.
How the deadlines are enforced
- An automatic routine runs every day and deletes sign-in codes, ended sessions, removed devices, access logs older than 6 months and records of subscriptions that ended more than 5 years ago when each deadline passes. Only a legal preservation request suspends that deletion, and only within its scope.
- In the same daily routine, messages older than 2 years are deleted along with their attachments.
- Our infrastructure partner's commitment is contractual. We haven't published an independent audit yet.
Requests from authorities
We check the authenticity, authority, legal basis and scope of every request, and disclose only available data covered by a legally applicable order or request — at most, what is listed in the table above. Specific data may be preserved beyond the usual retention periods when a legal obligation applies; preserving is not disclosing. Where legally permitted, we tell you before disclosing; if a temporary restriction applies, we reassess notice once it ends. We publish how many requests we receive in our transparency report.
What this doesn't mean
- A VPN doesn't make anyone anonymous: wherever you sign in, the service still knows who you are.
- The sites and apps you use still log whatever they log themselves.
- Anyone who buys the fixed IP (under construction) will have that address tied to their account. That will be in the policy before the service exists.
Questions
Does FortiSafe keep the sites I visit?
No. VPN traffic doesn't go through our systems, and our infrastructure partner is contractually bound not to log sites, DNS queries or connection data. DNS queries are answered by an external DNS resolution service, which receives them through the VPN server, without your real IP address or account data, and handles them under its own privacy terms.
What does FortiSafe keep about me?
Your account email, devices, subscription, sessions and sign-in codes for a short time, access logs for our systems for 6 months, and the messages you send us — each with the deadline shown in the table on this page.
Does FortiSafe hand data to authorities?
Only in response to a legally applicable order or request, after checking authenticity, authority and scope, and only what exists: at most, the data in the table on this page. Preserving data at an authority's request is not disclosing it. Requests received are listed in the transparency report.