Ir para o conteúdo
FortiSafe VPN

Privacy Policy

Version 1.4 · Effective

In short

  • We don't sell your data and we don't use advertising trackers.
  • VPN traffic doesn't pass through our systems: the app connects straight to the network's servers. That's why we have no record of the sites you visit.
  • We keep what we need to run the service — your email, your devices and your subscription — each with a deadline for deletion. Under Brazilian law, we also keep access logs for our systems for 6 months.
  • The VPN servers are operated by an infrastructure partner that is contractually bound not to log what you access or where you connect from.
  • You can ask for a copy, correction or deletion of your data at [email protected].

1. Who we are

FortiSafe VPN is provided by Tascom Global Network LLC, a limited liability company registered in the State of Florida, United States (No. L17000240494), located at 13057 Gabor Ave, Orlando, FL 32827. We are the controller of the data described here.

Privacy contact and data protection officer channel: [email protected].

2. What we keep, why and for how long

DataWhyLegal basisHow long
Email, name (if you provide it) and languageCreate and maintain your account, send your sign-in code and subscription noticesContractWhile the account exists
Sign-in code and the IP address that requested itProtect sign-in against repeated attempts. The code is stored only as a one-way hashLegitimate interest (security)30 days
Sessions: device type and start, last-use and expiry datesKeep you signed inContractUp to 30 days after the session ends (each session lasts at most 90 days)
Devices: the name you give them, the operating system, dates and the VPN technical credential, stored encryptedDeliver the VPN configuration to each deviceContractWhile the device is on the account. Once removed, its network account is deleted immediately and the record is erased after 12 months
Subscription: plan, where it was bought, the purchase ID at the store or payment provider, start and endKnow whether you can connect; charge, renew and refundContract and legal obligationWhile the subscription exists and up to 5 years afterwards, for tax obligations and to handle any dispute
API technical logs: IP address, time and the endpoint calledSecurity and troubleshootingLegitimate interestUp to 7 days, deleted automatically by Cloudflare
Access logs for our systems: date and time, IP address and source port, and the account when identifiedMeet the legal obligation to keep access logs (Brazil's Marco Civil da Internet, art. 15) and protect the account. Applies to access from Brazil and to Brazil accountsLegal obligation6 months, unless a legal preservation obligation applies
Messages you send usReply and keep a support recordContract and legitimate interestUp to 2 years after the last message

Card details never reach us: they go to the store (App Store, Google Play, Amazon) or the payment provider, which only tells us the result of the purchase.

3. What never reaches our systems

Once your device has its configuration, the app connects straight to the network's servers — our systems take no part in the connection. So we don't receive or keep:

  • the sites, apps and services you use;
  • the content of what you send and receive;
  • your DNS queries;
  • the IP address you connect to the VPN from, or your connection and disconnection times;
  • how much data you use.

A device's “last use”, mentioned above, is the last time the app requested its configuration from your account — not the last VPN connection.

The access logs in the table cover access to our systems — the app requesting its configuration, signing in, the account area. They are not logs of your browsing through the VPN, which we don't log.

DNS queries — which turn a site's name into an address — are answered by an external DNS resolution service, at the protection level you choose for each device: no filter, scams and malware, or scams, malware and adult content. Queries reach that service through the VPN server, with the server's address, not with your real IP address, your name or your email.

4. The network and its provider

The VPN servers are operated by a specialized network infrastructure partner we contract, in data centers across 45 countries.

For each device we create a technical account on the network, identified by a random code — without your name or email.

Under its contract with us, this partner is bound not to log anything about your VPN activity: not your traffic or the sites you visit, not connection data (your real IP address, connection and disconnection times, session length or data volume), and not your DNS queries — and not to write any of this to disk, even temporarily.

The DNS resolution service is not the network partner and has no data processing agreement with us: it receives the queries coming from the VPN server and handles them under its own privacy terms.

Putting both sides together, neither we nor our partner keep a record of what you do on the VPN; DNS queries go to the DNS resolution service, as explained above. What we do keep is listed in “What we keep”. API technical logs (up to 7 days) show when the app talked to our API — not when you were connected to the VPN or what you accessed.

5. Who we share with

We don't sell or rent your data, and we don't use it for advertising.

We share only with the companies that help us run the service, each limited to what it needs. The full list, with each company's country, is at Who processes your data.

When you buy through the App Store, Google Play or Amazon, the store handles your payment data under its own rules, as an independent controller.

6. Requests from authorities

We check the authenticity, authority, legal basis and scope of every request, and disclose only available data covered by a legally applicable order or request — at most, what is listed in the table above. Specific data may be preserved beyond the usual retention periods when a legal obligation applies; preserving is not disclosing. Where legally permitted, we tell you before disclosing; if a temporary restriction applies, we reassess notice once it ends. We publish how many requests we receive in our transparency report.

Requests from authorities should be sent to [email protected].

7. Where the data is stored

We are a US company, and your data is mainly stored there: the database is in Ohio, and the website and API run on Cloudflare's network. Sign-in emails are sent from São Paulo, Brazil. The VPN network is operated by a partner based outside Brazil and the European Union, with servers in many countries.

If you live in Brazil, the European Union or the United Kingdom, international transfers rely on the standard contractual clauses offered by our providers, where available, and on being necessary to provide the service you signed up for (LGPD, art. 33; GDPR, arts. 46 and 49).

8. Your rights

At any time and free of charge, you can:

  • confirm whether we process your data and get a copy of it;
  • correct incomplete or inaccurate data;
  • ask us to delete your data;
  • receive your data in a format another service can read (portability);
  • object to processing based on legitimate interest;
  • find out who we share your data with;
  • withdraw any consent you have given.

Write to [email protected] from your account email. We reply within 15 days. To protect you, we may ask you to confirm the request with a code sent to that address.

When you delete your account, we disconnect your devices, delete their technical accounts on the network and erase your data — except the subscription records the law requires us to keep, for the period shown in the table.

If our answer doesn't resolve it, you can complain to the data protection authority in your country.

9. Cookies

The website uses only two cookies, both strictly necessary for it to work, so we don't ask for consent to them:

CookieWhyDuration
fs_idiomaRemember the language you chose1 year
fs_sessaoKeep you signed in. Page scripts cannot read itUp to 90 days, or until you sign out

We don't use analytics, advertising or social media cookies, and the website serves its own fonts. If we ever use anything beyond this, we will ask for your permission first, with declining as easy as accepting.

10. Security and incidents

All communication with the website, the API and the network is encrypted (TLS 1.2 or higher, and WireGuard). Device technical credentials are encrypted with AES-256, sign-in codes are stored only as hashes, and administrative access is restricted to authorized people.

If a security incident could put you at risk, we notify the competent authority and the people affected within the legal deadlines — within 72 hours in Europe and 3 business days in Brazil — explaining what happened, what was affected and what to do.

11. Minors

FortiSafe is intended for people aged 18 and over. We don't knowingly collect data from minors; if we learn that we have, we delete it.

12. Regional rules

Brazil (LGPD)

  • Controller: Tascom Global Network LLC, with the details in “Who we are”.
  • Data protection officer channel: [email protected].
  • Legal bases: performance of a contract (art. 7, V), compliance with a legal obligation (art. 7, II), regular exercise of rights (art. 7, VI) and legitimate interest (art. 7, IX).
  • Your rights are set out in art. 18 of the LGPD, and you may petition the ANPD.
  • As a consumer, you keep your rights under Brazil's Consumer Protection Code.

European Union and United Kingdom (GDPR and UK GDPR)

  • Legal bases: performance of a contract (art. 6(1)(b)), legal obligation (art. 6(1)(c)) and legitimate interest (art. 6(1)(f)) — namely, the security of your account and of the service.
  • You have the rights in arts. 15 to 22, including restriction of processing, and you may lodge a complaint with the supervisory authority in your country.
  • We don't make automated decisions that produce legal effects concerning you.

California (CCPA/CPRA)

  • Categories collected in the last 12 months: identifiers (email and IP address), commercial information (subscription) and technical usage data, for the purposes in the table above.
  • We don't sell or share personal information for cross-context behavioral advertising, and we don't use sensitive personal information.
  • You can request to know, correct and delete your information, and we won't discriminate against you for doing so.

13. Changes to this policy

When we change something material, we'll email you at least 30 days before the new version takes effect. This page always shows the version and its effective date.

Version 1.3: adds access logs for our systems kept for 6 months as required by Brazilian law, and details how we handle requests from authorities. Retention started before this date because it is a legal obligation; notice was emailed 30 days in advance.

Version 1.4: explains that DNS queries are answered by an external DNS resolution service, at the protection level chosen for each device. The technical change was made before this date; notice was emailed 30 days in advance.