Privacy Policy
Last updated: September 15, 2026
1. Introduction
This policy describes how Zend2 handles information when you use zend2.com and Zend2 Private Browser. It is written from current product and backend behavior. It is not a claim of zero data collection, anonymity, or “no logs.”
2. Services covered
- The zend2.com website, including privacy tools, VPN Finder, Learn content, contact forms, and support pages
- Zend2 Private Browser for Android (package com.zend2.browser)
- Zend2 VPN for Android, which has a separate privacy policy at https://zend2.com/legal/vpn/privacy/2026-09-09
- Zend2 Plus, when purchased through Google Play
3. Zend2 website data
The website does not require an account for privacy tools or VPN Finder.
- Contact and deletion requests: If you submit a form or email us, we receive the information you send (such as name, email, and message) so we can respond.
- Privacy tools: Tools such as IP Check, DNS leak test, WebRTC leak test, and similar checks need network information to work. That typically includes your public IP address for the duration of the test. Zend2 does not use these tools to build a browsing-history profile of you.
- VPN Finder: Preferences used to rank providers are processed in the browser where the current finder works that way. Affiliate clicks go to third-party VPN sites.
- Server logs: Web servers typically record request metadata such as IP address, URL path, user agent, and time. Exact log retention on zend2.com hosting has not been independently verified in this update and may differ from older “30 days” wording.
The main site header does not load Google Analytics. Some older article templates include optional analytics hooks that only run if a tracking library is already present. CDN providers (currently jsDelivr for Bootstrap) may process requests for static assets under their own policies.
4. Zend2 Private Browser data
The Android app signs you in to a Zend2 account and uses Zend2 services to authorize protected browsing. Zend2’s account/control-plane service (Borsa) stores account, device, legal-acceptance, subscription, and private-connection session records as described below.
Based on current backend design:
- Zend2 does not store browsing history, visited URLs, domains, search queries, or page content with your account.
- Grant tokens used to start a protected connection are signed and returned; they are not stored as browsing history.
- When Zend2 Private Browser issues a private-connection grant, we may record the public IP address observed by our backend at that time. The connection record may also include the associated account or device identifier, grant or session identifier, timestamps, selected location or region, app or platform metadata, and other technical service information needed to operate and secure the service.
We use this connection information for service operation, security, abuse and fraud prevention, enforcement of our terms, and responding to valid legal requests where required or permitted.
These connection records are not browsing-history records. This source-IP capture does not record URLs, search queries, webpage contents, page titles, DNS query history, HTTP or packet contents, browsing history, or destination IP addresses or destination ports.
The protected connection applies to browsing inside Zend2 Private Browser. It is not a system-wide VPN for other apps.
Zend2 VPN is a separate product. When a VPN session is created, Borsa may record a public source IP on that VPN session row. That behavior, and how VPN session rows are deleted, is described in the Zend2 VPN Privacy Policy.
5. Google Sign-In / account data
Zend2 account access uses Google Sign-In. Zend2 verifies a Google ID token and does not store that ID token after verification.
Account records can include:
- Google subject identifier
- Email, display name, and profile photo URL provided by Google
- Account status and last login time
- Device install identifier, platform, app version, and optional push token if the app sends them
- Session tokens (stored as hashes, not as reusable plaintext after issue)
- Records of which Terms and Privacy versions you accepted, with time, app version, and platform
6. Protected browsing / Zend2 Edge
While protection is active, browser traffic is routed through Zend2 Edge toward a selected upstream browsing region. Zend2 authorizes this connection. Destination websites you open in the browser are not sent to the Zend2 account API as URL fields. Edge and upstream operators necessarily see traffic needed to deliver the connection, as with any network path. Zend2 does not claim that this makes you anonymous or untraceable.
7. Subscription and Google Play data
If you buy Zend2 Plus, Google Play processes payment. Zend2 stores subscription/entitlement state needed to know whether Plus is active (for example plan, status, product identifiers, expiry, and a purchase token used for Google verification). Zend2 does not collect card numbers through the website or app. Google’s privacy policy applies to Play billing.
8. Operational / security diagnostics
Zend2 uses operational error monitoring (GlitchTip, Sentry-compatible) with default PII sending disabled and additional sanitizing. Unexpected errors can still include technical diagnostics. Web server and application logs may include IP addresses and API paths. Zend2 does not present this as a “no logs” service.
9. Cookies / analytics on the website
The website may use cookies or local storage required for basic function of tools and forms. Zend2 does not currently advertise a marketing pixel or Google Analytics tag on the shared site header. Third-party CDNs and linked sites have their own cookies.
10. Affiliate links / third-party websites
VPN Finder and some Learn pages include affiliate links to third-party VPN providers. Those companies have their own privacy policies. See the Affiliate Disclosure.
11. Data retention
Contact emails are kept as needed to respond and for ordinary business records.
For Zend2 Private Browser accounts, current deletion behavior is described on Delete your Zend2 account. In summary, identity fields are anonymized, API sessions and devices are removed, and some non-identity records are retained. Retained records include legal acceptances, cancelled subscription rows, and private-connection session rows (including the public source IP recorded when a grant is issued). Product code does not enforce a fixed retention period for those private-connection rows.
Zend2 VPN session rows, including any public source IP recorded when a VPN session is created, are removed by the current account-deletion flow. That is different from Private Browser private-connection records. See the Zend2 VPN Privacy Policy.
Hosting access-log retention should be confirmed by the operator.
12. Account deletion
You can delete a Zend2 Private Browser account in the app (Settings → Account → Delete Account) or at zend2.com/account-deletion. Deleting a Zend2 account does not cancel a Google Play subscription. See also subscription support.
13. Security
Zend2 uses standard transport encryption for the website and API, hashed API tokens, and server-side checks for Plus. No method of transmission or storage is perfectly secure.
14. Children’s privacy
These services are not directed to children under 13. Zend2 does not knowingly collect information from children under 13. If you believe a child has created an account, contact hello@zend2.com.
15. International processing
Zend2 may process data on servers in more than one country. A specific legal entity, postal address, and hosting-region list are not stated here because they are not confirmed in the public site repository. If you need this for a legal request, email hello@zend2.com.
16. Changes
We may update this policy. The “Last updated” date will change when we do. Continued use after an update means you should review the new policy. The Android app may also require acknowledgement of a new privacy version before you continue.
17. Contact
Questions: hello@zend2.com or the Contact page. Account deletion: Delete your Zend2 account.