Security & no-logs

What the tunnel covers, and where it stops.

A VPN is a good tool with clear edges. This page explains the path your traffic takes, what our no-logs design actually means, and — the part most VPN sites leave out — the list of things a VPN cannot do for you.

Tunnel Encrypted end to server Activity logs None Third-party sharing None declared

The path your traffic takes

Four stages, and one of them is the important one.

Knowing where the encrypted section begins and ends is the whole basis for judging whether a VPN helps you in a given situation.

  1. 1 — Your device

    Your app or browser produces ordinary traffic. Lumo Veil encrypts it here, on the phone, before it is handed to the network hardware. Everything from this point until it reaches our server is enclosed.

    Encryption begins
  2. 2 — The local network and your ISP

    The café router, the hotel access point, the mobile carrier, and everything between them carries your traffic without being able to read it. They can see that you are connected to a Lumo Veil server, and how much data is moving. They cannot see which sites you opened or what you sent.

    Unreadable in transit
  3. 3 — The Lumo Veil server

    Your traffic arrives, is decrypted, and is passed on to its destination. This is the point where the tunnel ends, and the reason a VPN provider's logging policy matters more than its marketing. We do not record what passes through here, where it came from, or when.

    Tunnel ends here
  4. 4 — The site or service you are using

    From here on, your traffic behaves like any other traffic on the internet, protected by whatever the destination itself uses — usually HTTPS. The service sees the Lumo Veil server's IP address rather than yours. It does not see your home or mobile address.

    Ordinary internet
How it is protected

The parts worth stating precisely.

Strong, standard encryption

The tunnel between your device and our servers is protected with AES-256, the same class of encryption used for banking and government traffic. We use established, published algorithms rather than anything of our own invention — in cryptography, novelty is a warning sign.

Access controls on our side

Server access is restricted and monitored, systems are patched, and infrastructure sits in data centres with physical and logical access controls. This is table stakes rather than a differentiator, but it is worth saying we do it.

No store means no leak

The strongest control on this page is not technical. If browsing records are never written, a breach of our systems, a rogue employee, or a legal order cannot produce them. Most of our privacy work went into not building the database.

What we do not claim

We have not published an independent third-party security audit, and we will not imply that we have. When one is completed, it will be linked from this page with its date and its findings. Until then, judge us on what is verifiable: the Google Play Data safety declaration, this site, and the app itself.

Threat model

What a VPN does for you. And what it doesn't.

A VPN is one layer. Sold as a cloak, it becomes dangerous — people take risks believing they are covered. Here is the boundary, drawn honestly.

SituationDoes Lumo Veil help?Why
Someone on the same Wi-Fi trying to read your traffic Yes Your traffic crosses that network encrypted.
A network operator or ISP logging which sites you visit Yes They see an encrypted connection to a Lumo Veil server, not your destinations.
A website recording the IP address you arrived from Yes It records the server's address instead of yours.
A service you have logged into knowing who you are No You told it. A VPN does not undo a sign-in.
Cookies, ad IDs, and browser fingerprinting No These live inside your browser and apps, on the far side of the tunnel.
Malware already installed on your phone No It runs on your device, before anything is encrypted.
Phishing pages, scam messages, and fake apps No The tunnel carries a phishing page as faithfully as any other.
Someone holding your unlocked phone No Nothing on the network layer helps here. Use a screen lock.
Making restricted or illegal activity permissible No It does not, and our acceptable use policy prohibits it.

If you need protection beyond this boundary — from a state adversary, for instance, or for journalism in a hostile environment — a commercial VPN alone is not the right tool, and we would rather tell you that than take the install.

No-logs, in practice

What "we don't log that" has to mean to be worth anything.

Never written

Browsing history, traffic content, DNS queries, your original IP address, the VPN IP you are assigned, connection timestamps, and session duration. None of these are recorded, so none of them can be produced later — by us, by a court order, or by an attacker.

Exists only while a session runs

Routing a live connection requires the system to know where packets are going, for as long as they are going there. This is true of every network on earth. That state is not written to a log and does not outlive your session.

Held deliberately

Device identifiers, anonymised crash and performance data, and anything you send us in a support email. Each has a stated purpose and a stated retention period in the privacy policy.

Requests we could not fulfil
"Which sites did this user visit?"No record exists
"What was in their traffic?"No record exists
"What did they resolve in DNS?"No record exists
"What is their real IP address?"No record exists
"When were they connected, and for how long?"No record exists

We comply with valid legal process. Compliance simply produces very little, because the records being asked for were never created. This is covered in section 6.2 of the privacy policy.

Responsible disclosure

Found something? Tell us before you tell the internet.

If you have found a vulnerability in the Lumo Veil app, our servers, or this website, we want to hear about it, and we will not respond to a good-faith report with a lawyer.

How to report

Email buivandong298523@gmail.com with "Security" in the subject line. Include what you found, how to reproduce it, and what you think the impact is. If you would like to encrypt the report, say so and we will arrange a key.

What we commit to

We will acknowledge your report within five business days, keep you updated while we work on it, credit you if you would like to be credited, and take no legal action over research conducted in good faith that does not degrade the service or access other people's data.

We do not currently run a paid bug bounty programme, and we will not pretend otherwise. What we offer is a fast answer from the people who wrote the code.

The short version

Encrypted where it counts. Recorded nowhere.

If that is the trade you want, the app is free and takes a minute to set up.