General information

  1. Controller

    Armin Šupuk is the controller for Šupuk’s processing of personal data:

    Armin Šupuk
    Bankstrasse 2
    6280 Hochdorf
    Switzerland
    armin@supuk.ch

    Šupuk processes personal data under the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR).

  2. Šupuk processes personal data to:

    • deliver and secure the website, APIs, software, and licensing infrastructure;
    • handle requested pre-purchase steps and perform software-license agreements, including license delivery, activation, validation, recovery, and management;
    • administer the Creem-hosted affiliate program, review referrals and commissions, prevent affiliate abuse, and handle participant questions;
    • provide VPN Leak Guard update checks, downloads, support, and responses to requests;
    • prevent fraud, misuse, and security incidents, enforce activation limits, and handle refunds, disputes, and legal claims;
    • comply with tax, accounting, consumer-protection, and other legal obligations; and
    • conduct optional VPN Leak Guard NAT-T security research with the user’s consent.

    Where the GDPR applies, the legal grounds are performance of a contract or requested pre-contract steps, compliance with legal obligations, and Šupuk’s legitimate interests in reliable and secure service operation, administering the affiliate program, and preventing abuse. Consent is the legal ground for optional VPN Leak Guard NAT-T security research.

  3. Retention and security

    Support correspondence and records needed for a dispute or legal obligation are retained until the request and any applicable limitation or mandatory retention period end. Other personal data is deleted or anonymised when its purpose and any mandatory retention period end. Technical backup copies follow their scheduled deletion cycles.

    Šupuk uses encrypted transport, restricted administrative access, validation of fixed request formats, and application logs that omit sensitive fields. Device entitlement records are encrypted with an Android Keystore-protected key, and browser-receipt tokens expire after short fixed periods.

  4. Your rights and complaints

    Under applicable law, you may request information about and access to your personal data, correction of inaccurate data, deletion, restriction of or objection to processing, and delivery or transfer of data where portability applies. You may withdraw consent for future processing without affecting earlier lawful processing.

    Send requests to armin@supuk.ch, name the relevant service, and provide only the information needed to locate and verify the record. A CDN-log request may include the relevant host, approximate UTC time, requested path or identifier, user agent, and anonymised network range. Do not send a license key, payment callback signature, or other secret by ordinary email. Šupuk may request additional proof to prevent access to or deletion of another person’s data. A legal retention duty or the need to establish, exercise, or defend a legal claim may limit access, objection, restriction, or deletion.

    Send requests about data controlled by Creem, Bunny, GrapheneOS, or Google directly to that provider under its privacy notice.

    You may complain to the Swiss Federal Data Protection and Information Commissioner or, where the GDPR applies, to the competent data-protection authority in the EU or EEA state of your habitual residence, place of work, or alleged infringement.

Specific processing information

  1. Recipients and international transfers

    Šupuk discloses personal data only to operate and secure the services, deliver transactional messages, administer the affiliate program, answer requests, and meet legal obligations. Recipients are Bunny for infrastructure, Lettermint for transactional email, Tuta Mail for correspondence, Creem for hosted checkout and affiliate-program operations, professional-service providers for support and legal obligations, and competent authorities when disclosure is required by law. Service providers processing personal data for Šupuk are bound by applicable contractual and confidentiality obligations.

    Bunny, operated by BunnyWay d.o.o. in Slovenia, provides the CDN, edge application, database, and storage infrastructure. Frankfurt, Germany, is the primary region for Šupuk’s database and main file storage. Enabled replication locations may hold replicas. CDN edge processing is geographically separate: Bunny selects an edge location for each request through its global network. Personal data may therefore be processed in Slovenia, Germany, an enabled replication country, or the country of the selected CDN edge. Bunny lists its current subprocessors.

    Tuta Mail, operated by Tutao GmbH in Germany, processes messages sent to the published email address. Tuta receives the sender and recipient addresses, delivery metadata, and the message content and attachments supplied by the sender.

    Creem, operated by Armitage Labs OÜ in Estonia, is the independent controller, merchant of record, and contractual reseller for checkout and payment processing. Creem also hosts affiliate enrollment, accounts, referral tracking, commission reporting, and payouts. Creem may use providers or process data outside the European Economic Area under its Privacy Notice.

    Lettermint, operated in the Netherlands, delivers transactional checkout and license-recovery messages for Šupuk.

    VPN Leak Guard requests public trust metadata directly from GrapheneOS and Google. Their infrastructure may process these requests in Canada, the United States, European countries, or another server location selected for the request.

    For a transfer to a country without an applicable adequacy decision, the responsible provider or Šupuk uses an available legal safeguard, including recognised standard contractual clauses, or a statutory transfer exception.

  2. Website and API CDN logs

    The website is static HTML and CSS and has no first-party browser JavaScript, analytics scripts, tracking pixels, client-side tracking, or contact form.

    Bunny CDN delivers the website and the APIs at api.supuk.ch and processes connection and request data through its edge network.

    Bunny CDN access logs are Šupuk’s only visitor or audience measurement. Šupuk uses them to identify technical problems, missing pages, abuse patterns, and cache behaviour, and to measure rough aggregate audiences. Šupuk does not use the logs to profile individual visitors or build advertising audiences.

    Archived Plain-format entries contain the standard cache status, HTTP status code, UTC timestamp, bytes sent, Pull Zone ID, anonymised remote IP address, referrer, complete requested URL, edge location, user agent, request ID, and country code. A complete URL contains its path and any query string sent by the browser, application, or payment provider. It may contain opaque website receipt identifiers and payment-related API callback parameters, including order, checkout, customer, product, request, or subscription identifiers and a callback signature. Standard CDN entries do not contain request bodies.

    The two source Pull Zones retain these existing logging settings:

    • api-supuk, serving api.supuk.ch: IP anonymisation enabled with “Remove last octet”, Plain log format, and Extended Logging disabled.
    • the Pull Zone serving supuk.ch: IP anonymisation enabled with “Remove last octet”, Plain log format, and Extended Logging disabled.

    Bunny’s logging documentation states that “Remove last octet” masks IPv4 addresses to a /24 range, for example 163.172.53.0, and IPv6 addresses to a /64 range, for example 2001:7d0:700d:db04::. Full-IP logging is disabled. Extended Logging is disabled, so the additional body-byte, range, and Authorization-header fields are not recorded.

    Ordinary Bunny access logs remain available for three days. Šupuk uses Bunny Permanent Log Storage to archive logs from both source Pull Zones in a private, dedicated Edge Storage zone. The archive uses Standard storage with Frankfurt, Germany, as the primary region and Stockholm, Sweden, as the replication region.

    Archived access logs are retained indefinitely.

    When a visitor follows an affiliate, referral, or sponsored link, the destination receives the browser’s request information and processes it under its own privacy policy.

    Creem checkout and customer pages apply Creem’s privacy and cookie practices.

    When a prospective buyer follows a participant’s personal affiliate link, Creem receives the request and referral identifier and manages attribution for up to 180 days under its privacy and cookie practices. The Šupuk website does not set affiliate-tracking cookies, collect affiliate applications, or proxy the affiliate join link; affiliate enrollment links lead directly to Creem.

  3. Payments and software licensing

    Creem checkout and payment processing

    Creem collects the buyer’s name, email address, billing address, payment details, order information, IP address, device or log data, and tax information. Creem uses this data for checkout, payment collection, invoicing, indirect-tax handling, fraud prevention, customer support, disputes, and legal compliance.

    Creem’s Privacy Notice currently states that contractual data is generally retained for three and a half years after the contract ends and accounting data for seven years. Creem controls the payment-card data and buyer account or checkout records that it collects; Šupuk’s payment and licensing systems and VPN Leak Guard do not receive or store payment-card data.

    Creem-hosted affiliate program

    People who join the affiliate program use Creem’s hosted enrollment page and account tools. Creem processes the enrollment and account information they submit, personal referral links, referral and attribution records, qualifying purchases, refunds and reversals, commission balances, and the identity, tax, and payment information needed to manage payouts. Creem supplies the personal referral link, applies the 180-day attribution period, reports referral and commission status, and manages payouts under its own privacy notice and platform terms.

    Šupuk may access the affiliate identity and contact information, account status, referral and qualifying-purchase reports, commission records, and payout status that Creem makes available. Šupuk uses that information to administer the program, answer participant questions, prevent and investigate fraud or misuse, resolve attribution or commission disputes, and meet accounting, tax, and other legal obligations. Affiliate administration records are retained while needed for those purposes and any applicable limitation or mandatory retention period. Requests about tracking, payout, tax, or account data controlled by Creem should be sent directly to Creem.

    Šupuk payment and license records

    Šupuk’s payment and licensing systems store:

    • the payment gateway, Creem order identifier, and normalized checkout email address;
    • the internal offering identifier and payment-verification timestamp;
    • the Lettermint acceptance time and opaque message identifier for the checkout email;
    • the generated license key, license status, activation limit, and any optional expiry; and
    • an opaque, temporary browser-receipt token.

    The Šupuk payment and licensing database does not store buyer names or billing addresses.

    After a verified payment, Šupuk sends Lettermint the checkout email address, application name, license key, payment-verification time, and generated plain-text and HTML message content for delivery. Lettermint does not receive the payment gateway, Creem order ID, buyer name, or billing address. Open and click tracking are disabled. Lettermint retains the full message content and delivery information for up to 28 days.

    Šupuk records the time when Lettermint accepts a checkout message and its opaque message identifier; acceptance records submission for delivery, not receipt by the recipient’s mailbox. A browser receipt displays the license key, and its temporary token normally expires after ten minutes.

    If the receipt or email is unavailable, the buyer can use the manual license-recovery form and select the payment gateway. For Creem, the lookup value is the checkout email address, and an exact Creem order ID may locate the same stored purchase. Recovery searches only identities stored for the selected gateway and environment. When matching purchases share one stored email address, Šupuk sends all matching license details to that address. The submitted value cannot redirect delivery, and the browser shows the same generic email-success page whether a purchase matched or not. If the selected gateway stores no email identity, recovery returns a short-lived browser receipt. The form does not request a buyer name or billing address.

    License activation

    License activation and device management process the license key, a random installation identifier, a server-generated activation identifier, the application identifier, activation status and timestamps, and the following Android device and build metadata:

    • manufacturer, brand, model, device, product, board, and hardware values;
    • Android release, SDK and full SDK versions, base OS, and security-patch level;
    • build ID, display, incremental version, fingerprint, and radio version; and
    • the installed application version.

    Šupuk uses this data to confirm entitlement, enforce the activation limit, show and manage activated devices, replace a deactivated device, prevent abuse, and investigate license problems.

    Verified payment records, licenses, activations, and associated device metadata are retained while needed to deliver and recover licenses, enforce activation limits, handle refunds or disputes, prevent abuse, establish or defend legal claims, and meet legal obligations. These records have purpose-based retention with no automatic fixed deletion period.

    Šupuk’s application logs for payment and licensing operations exclude payment identifiers, license keys, activation identifiers, and request payloads.

  4. VPN Leak Guard

    Processing on the Android device

    VPN Leak Guard processes the following information on the Android device to assess protection, explain findings, operate its protection service, manage a license, and provide diagnostics:

    • network and interface state, logical networks, physical transports, and VPN state;
    • local and source addresses, default-gateway and other route information, and socket and local-port state;
    • Android device, version, build, and application details;
    • protection state, findings, diagnostic state, and service timing; and
    • permissions, settings, and other application preferences.

    VPN Leak Guard does not access Creem checkout records or buyer contact and billing data.

    The application encrypts its on-device entitlement record with a key protected by Android Keystore. The record contains the random installation identifier, license key, activation identifier, signed entitlement, most recent validation time, and cached device inventory used for license management. Android backup and device-transfer backup are disabled for the application.

    Public trust metadata

    For local hardware-attestation checks, VPN Leak Guard downloads signed public trust metadata from GrapheneOS and Google. These HTTPS requests disclose the source IP address, timing, and request headers to the relevant provider and network infrastructure. The downloaded material is public trust data. Hardware-attestation evidence and results remain on the device and are not uploaded to GrapheneOS, Google, or Šupuk.

    Optional update checks

    VPN Leak Guard’s update checks are enabled by default and can be disabled at any time in Settings.

    While NAT-T protection is active and update checks are enabled, the application requests the public https://supuk.ch/software/vpn-leak-guard/version.txt file immediately and about once per hour. The request is an unauthenticated HTTPS GET with no request body. VPN Leak Guard does not add a device, installation, activation, license, payment, or telemetry identifier to it. The response contains only the current release marker, which is compared locally with the installed canonical application version. A different non-empty value can produce a local notification linking to the public APK download.

    Bunny CDN processes the source IP address, timing, requested file, and request headers to return the version file and records the request under its configured access-log settings. VPN Leak Guard does not send the update result to the NAT-T observation service and does not maintain a server-side update-check profile. Turning update checks off stops future scheduled requests while protection runs.

    Optional NAT-T security research

    Optional NAT-T research reporting is off by default and begins only when the user explicitly consents in VPN Leak Guard’s Settings; where the GDPR applies, consent is the legal ground. The user may withdraw consent there at any time for future processing without affecting earlier lawful processing. This consent choice does not change update checks, purchases, or ordinary license management.

    When enabled, a report transmits:

    • the license key and activation identifier used as the activation credential;
    • the application identifier and production or test environment;
    • device manufacturer, brand, and model, together with model-level device, product, board, and hardware identifiers;
    • Android version and exact build metadata, including SDK values, base OS, security-patch level, build ID, display, incremental version, fingerprint, and radio version;
    • application version;
    • physical transport category; and
    • the highest NAT-T slot count observed for that transport.

    The server keeps one aggregated row for each activation, UTC day, and physical transport. The row contains the permitted application, environment, device, build, and application-version fields, the highest and latest counts, the first and last report timestamps, and the report count.

    While protection is running, VPN Leak Guard evaluates whether a report is due about once an hour. It submits after a meaningful change in the permitted device, build, application, or transport-count fields, or once per UTC day.

    Reports intentionally exclude:

    • Wi-Fi or network names, SSID, and BSSID;
    • interface names;
    • IP, gateway, or DNS addresses;
    • local or remote ports;
    • carrier or SIM information;
    • Android ID, advertising ID, and serial number;
    • location;
    • raw network snapshots;
    • payment or buyer data; and
    • arbitrary metadata outside the fixed report format.

    Bunny edge infrastructure processes the request’s source IP address to handle the connection. The NAT-T observation worker stores the address in neither the research table nor Šupuk application logs.

    Withdrawing consent stops future submissions and clears the application’s local comparison state. Withdrawal does not delete observations already accepted by the server. Accepted research rows are retained indefinitely to study and validate the relevant security behaviour and have no automatic expiry.

    To request access to or deletion of accepted rows, contact armin@supuk.ch. Include enough information to locate and authenticate the relevant activation without sending the license key by ordinary email.

Last updated: 29 July 2026.