Privacy Policy

Last updated: August 8, 2026

This Privacy Policy describes how Sezi LLC, doing business as Hourly VPN ("we", "us", "our") collects, uses, and protects your personal information when you use our website and service at https://hourlyvpn.com (the "Service"). The Service lets you use a remote web browser running on our infrastructure in a city you choose. We keep the data we hold to what we actually need to operate the session, bill you, keep abuse in check, and (when ads are running) measure campaign performance.

1. Information We Collect

1.1 Email Address

To start a session you sign in with email plus a one-click magic link. We store your email so we can identify your account, recognize you when you come back, and send you receipts and the occasional service message. We do not use this address for marketing.

1.2 Account & Balance

We store your prepaid hourly credit balance, any active daily or weekly passes, the city each pass is locked to, and the bandwidth used against each pass. Hourly credits are valid for 12 months from your last top-up.

1.3 Session Records

For each session we record the city you picked, when it started and ended, total active minutes billed, total cents charged, and total egress bytes. We do not record what you typed inside the remote browser, the URLs you visited (only hostnames; see 1.5), or any screen contents.

1.4 Payment Information

Payment is processed by Stripe. We do not store your credit card number, CVC, or full billing address. We only store a Stripe Payment Intent ID so we can reconcile a charge against the credits or pass it bought you. Stripe’s privacy policy is available at stripe.com/privacy.

1.5 Hostname Egress Log

For each session we record the hostnames the remote browser connected to (e.g.example.com, news.bbc.co.uk), the approximate bytes transferred per hostname, and the timestamp. We do not log full URLs, query strings, request bodies, response contents, form input, screen frames, or keystrokes. The hostname log is the only behavior signal we keep, and only so we can investigate Acceptable-Use Policy reports. It is automatically deleted after 30 days.

1.6 Technical & Server Data

We collect standard server logs and request metadata for security and debugging:

  • IP address: stored on each session row and short-lived rate-limit buckets, used for rate limiting, abuse detection, and security
  • Request method, path, status code, response time: standard application logs (no request body, no user-agent persisted by us)
  • CDN logs: Cloudflare records standard CDN request data (IP, user agent, path) on its side; see Section 4

1.7 Browser Storage

The homepage remembers the city, plan, and acceptable-use checkbox you selected in your browser’s sessionStorage so a page refresh doesn’t lose your selection. We set a strictly necessary first-party cookie (hvpn_acct) on api.hourlyvpn.com after you redeem a magic link, so we know you’re signed in. We also set a single first-party analytics cookie (ph_*_posthog, set by PostHog on the apex hourlyvpn.com); see Section 1.8 below and our Cookie Policy for the full list.

1.8 Web Analytics & Session Replay

We use PostHog on hourlyvpn.com to understand how people use the site so we can fix friction points and improve the Service. PostHog runs on every page of our SPA , the homepage, sign-in, checkout, account, the in-session control surface (top bar, buttons, status alerts), and the legal pages. PostHog records:

  • Page views: which pages you visit on hourlyvpn.com, the page’s URL and title, referrer, browser language, screen size, approximate location (country / region from IP, never street-level)
  • Click events: which buttons or links you interact with on this site
  • Session recordings: a "video-like" replay of your interactions with our UI (mouse movements, scrolls, clicks). Every form input is masked by default, so the email you type at sign-in, the city you pick, and any other typed content are not captured in the recording. Recordings are retained for ~30 days and then deleted by PostHog
  • An anonymous visitor ID: a random identifier stored in a first-party cookie (ph_*_posthog, set on the apex hourlyvpn.com) and mirrored in localStorage so PostHog can link the page views in a single session together and across subdomain hops. Once you sign in, we identify you to PostHog via a one-way SHA-256 hash of your email (so cross-product analysis can match you to your other Sezi-product sessions if any). Not shared with any third party. See our Cookie Policy for the full list of browser storage we use and how to opt out.

The remote browser itself is excluded from session recording. When a session is open, our UI embeds the remote Chromium browser inside a cross-origin iframe. That iframe is explicitly blocked from PostHog’s replay capture (data-ph-no-capture), so recordings show our control surface, the top bar, buttons, alerts, the iframe’s position and size, but never the URLs you visit, never the page contents, never the iframe’s own URL or its embedded session token. What you do inside the remote browser stays between you and the sites you visit, the same as it would in your local browser.

PostHog data is processed by PostHog Inc. under our Data Processing Agreement, hosted in the United States. We do not share PostHog product data with advertisers, do not share it with other third parties for their marketing, and do not sell it. We honor two browser-level opt-out signals: Do Not Track (DNT) and Global Privacy Control (GPC). If either is set, PostHog never initializes for your visit (no cookie set, no events fired). Either signal is the legal opt-out path; the dismissible cookie notice at the bottom of the page is disclosure only and does not gate collection.

1.9 Advertising measurement

When we run Google Ads campaigns for Hourly VPN, we load Google's advertising tag (gtag) to measure campaign clicks and conversions such as signup and purchase. That tag may set Google advertising cookies. We do not sell personal data. See the Cookie Policy for the cookie list; Do Not Track and Global Privacy Control both suppress the ads tag.

The hostname egress log described in Section 1.5 is a separate, server-side mechanism governed by the AUP. PostHog does not have access to it, and the egress log is not used for analytics.

2. How We Use Your Information

  • Provide the Service: start, suspend, and end your remote browser sessions; meter active minutes; track pass usage
  • Process payments: charge through Stripe and reconcile balance and passes against the orders that bought them
  • Authenticate you: recognize you across sessions via the magic-link cookie, without a password
  • Support you: respond to billing, session, and refund questions
  • Prevent abuse: apply rate limits, detect suspicious patterns, and investigate Acceptable-Use Policy violations using the hostname egress log
  • Improve the Service: measure aggregate volume, debug failure patterns, plan capacity per region, and analyze anonymous usage patterns on the marketing site to fix friction in checkout and sign-in (see Section 1.8)
  • Comply with law: respond to lawful requests and enforce our Terms of Service

We do not sell your data. We do not use your sessions or browsing behavior to train any generative model or to feed third-party advertising.

3. Legal Basis for Processing (GDPR)

If you are in the European Economic Area or UK, we process your data under:

  • Contract performance: to deliver the remote browser session you paid for
  • Legitimate interest: to improve the Service, prevent fraud, and ensure security
  • Consent: where required (e.g. the acceptable-use affirmation checkbox at sign-up)
  • Legal obligation: to comply with tax, accounting, and other applicable regulations

4. Data Sharing & Third Parties

We share your data only with the following service providers, strictly to operate the Service:

ProviderPurposeData Shared
StripePayment processingPayment details, billing email (handled by Stripe directly)
Fly.ioAPI hosting and per-region remote-browser containersIP, request metadata, and the egress traffic from your remote-browser session (Fly is the network operator for the city you picked)
NeonManaged PostgreSQL databaseAccount email, balance, pass records, session records, hostname egress log
CloudflareDNS for hourlyvpn.comStandard DNS query data on Cloudflare’s side
ResendTransactional email delivery (magic-link sign-in, receipts)Recipient email address, message content (sign-in link, receipt)
Google WorkspaceReceiving replies sent to support@hourlyvpn.comInbound email content when you contact us
SlackInternal failure and abuse-threshold alertsSession identifier, account identifier, region code, error details, and (for abuse alerts) the hostname and bytes that tripped the threshold
PostHogWeb analytics and session replay (the remote browser itself is excluded, see Section 1.8)Page views, click events, masked session recordings, anonymous visitor ID (replaced by a one-way SHA-256 hash of your email after sign-in), IP (used for approximate-location enrichment, then discarded)
Google AdsPaid-search advertising and conversion measurement when campaigns are activeCampaign click and conversion signals (signup, purchase). See Section 1.9 and the Cookie Policy.

We do not sell, rent, or trade your personal information. PostHog (Section 1.8) never sees inside the remote browser (the iframe is explicitly blocked from recording) and is operated under our Data Processing Agreement. Google Ads measurement (Section 1.9) is separate from PostHog and is only loaded when campaigns are configured.

5. Data Retention

  • Account & balance: retained as long as you have credit, an active pass, or any session activity within the last 12 months. After 12 months of inactivity we may purge inactive accounts; until then your balance remains usable
  • Session records: retained indefinitely so we can reconcile billing, answer support questions, and detect abuse patterns. You can ask us to delete a specific session at any time (see Section 6)
  • Hostname egress log: automatically deleted after 30 days
  • Server logs: retained for up to 90 days for security and debugging
  • Payment records: retained as long as required by tax, accounting, and Stripe’s own retention policies

6. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access: request a copy of the personal data tied to your account
  • Correction: request correction of inaccurate data
  • Deletion: request deletion of your account, your session history, or specific session records (note: doing so forfeits any remaining balance)
  • Portability: request your data in a machine-readable format
  • Objection: object to processing based on legitimate interest
  • Restriction: request restriction of processing in certain circumstances

6.1 For California Residents (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect, request deletion, request correction, and opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising. To exercise your rights, email privacy@hourlyvpn.com.

6.2 For EEA/UK Residents (GDPR)

You have the rights listed above under GDPR. You also have the right to lodge a complaint with your local data protection authority. To exercise your rights, email privacy@hourlyvpn.com.

To exercise any of these rights, email privacy@hourlyvpn.com from the address tied to your account so we can locate the right record. We will respond within 30 days.

7. Data Security

We implement appropriate technical and organizational measures to protect your data, including:

  • HTTPS encryption for all connections
  • The remote-browser stream connects directly between your device and the container in your chosen city; our API is not on the data path
  • Magic-link cookies marked HttpOnly, Secure, and SameSite=Lax so they can’t be read by client-side scripts
  • Per-region remote-browser containers are isolated VMs that we destroy when the session ends; nothing persists across sessions
  • Database, container orchestrator, and email services accessed over private credentials we rotate periodically
  • Rate limiting on API endpoints (per-IP and per-account)
  • Stripe-hosted Checkout (we never see your card details)

No system is perfectly secure. Please use a strong, unique password on your email account because the magic link is what proves you own the account.

8. International Transfers

Our control-plane servers are located in the United States. Per-region remote-browser containers are spun up in the city you select (which may be inside or outside the United States). When you use the Service from outside the US, your account and billing data are processed in the US; the browsing traffic itself is processed in the city you picked. Where required, we rely on our processors’ data processing agreements and the European Commission’s Standard Contractual Clauses or equivalent safeguards.

9. Children’s Privacy

Hourly VPN is not directed to children. Per our Terms of Service, you must be at least 13 years old (16 in the EEA/UK) to use the Service and at least 18 to make a purchase. We do not knowingly collect personal information from children under 13 (or under 16 in the EEA/UK). If we learn that we have collected data from a child below the applicable age, we will delete it promptly. If you believe a child has used the Service, contact us at privacy@hourlyvpn.com.

10. Changes to This Policy

We may update this Privacy Policy from time to time. The current version always lives at hourlyvpn.com/privacy. The "Last updated" date at the top of this page indicates when it was last revised. Material changes will be reflected in a new date.

11. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, contact:

Email: privacy@hourlyvpn.com
Entity: Sezi LLC (Hourly VPN)