Privacy Policy
Last Updated: September 13, 2026
1. Information We Collect
PuriFi LLC (“PuriFi,” “we,” “us,” or “our”) collects the following categories of information when you use our products and services.
1a. Account Information
When you create a PuriFi account, we collect your email address, name, phone number, and profile photo (if you choose to upload one).
1b. Authentication and Session Data
We collect OAuth tokens used for Google and Apple Sign-In authentication, session information (including refresh tokens and session identifiers), and security audit logs recording authentication events and account actions.
1c. Device Information
For each PuriFi device registered to your account, we collect device identifiers (serial number, MAC address, VPN IP address), firmware version, device health metrics (CPU usage, memory, temperature, disk usage), and current service status for the PuriFi system components running on the device.
1d. Network and DNS Information
We collect aggregate DNS statistics reported by your device as integer counts only (for example: total queries processed, queries blocked, queries forwarded). We do not log individual DNS queries or the hostnames you look up, with the opt-in exception for AI Fleet Intelligence described at the end of this section. On the device itself, your PuriFi keeps a short local log of DNS activity (a rolling 24-hour window by default) to power the stats screen and the Recently Blocked list; that log lives only on hardware you own and is never uploaded to us. If you turn on the blocked-traffic log in the app, your PuriFi also keeps a longer history of the requests it blocked — only blocked requests, only on the device, up to the storage size you choose (100 MB to 2 GB), dropping the oldest entries when that space is full. It is off unless you turn it on, and turning it off deletes that history. You can turn query logging off entirely in the app's Privacy settings — your PuriFi then records nothing at all, and the history already stored on the device — including any blocked-traffic log — is permanently deleted. Blocking keeps working either way. We also collect network topology information necessary to maintain your VPN connection (gateway IP, LAN IP, and DNS server addresses), any DNS policy configuration you set within the PuriFi app, and, for the devices on your home network, the identity they announce about themselves on that network so the app can label them — a device's own name, model and room (for example a speaker's room name), its manufacturer, and the kind of device its network requests suggest. These are labels a device already broadcasts to everything on your Wi-Fi; they never include what a device looked up or visited. Your device also reports its public IP address — at most once a day, and once each time it restarts — which we use in the moment to look up your approximate state or region and then discard — we do not store your public IP address. We do not store your router's hardware (MAC) address, and we do not store GPS or street-level coordinates for your home.
One exception, and only if you switch it on. AI Fleet Intelligence is off unless you turn it on in the app's Advanced Security settings. With it on, your PuriFi sends us a small number of individual domain names — never your query log, and never your ordinary browsing. A domain is eligible only if your device has never seen it before, it is not among the world's hundred thousand most-visited sites, it is not on your own allowed list, and a model running on your PuriFi scores it as suspicious. Each report contains that domain, the score, the numeric features behind the score, and when your device first saw it. Before we store it, we replace your device identifier with a code that changes every day, so the stored reports are not attached to your account and cannot be joined up across days. The report reaches us over your device’s own VPN connection, so the tunnel it arrives on identifies the device until that substitution happens. We keep these reports for 30 days and use them only to identify new threats for the whole fleet. Turn the setting off and it stops, and our servers reject reports from any device that is not opted in.
Devices on your home network. If you use Household profiles — the feature that lets you name the devices in your home and give each one its own rules — your PuriFi reports the devices it can see on your local network so the app can list them. For each one we store its hardware (MAC) address, the name the device broadcasts, its manufacturer (looked up from the MAC against a public registry), its local IP address, and when it was first and last seen. We do not store anything about what those devices do: no browsing history, no DNS queries, no traffic. A device you have not seen in 30 days is hidden from the app, and its record is deleted after 180 days. Your router is listed too, so you can recognise it, but — as above — we look up its manufacturer and then discard its hardware address rather than storing it.
Wi-Fi discovery, and only if you switch it on. In the standard wired setup your PuriFi cannot see individual devices, so the app offers an optional unlock: connecting your PuriFi to your Wi-Fi network so it can discover the devices on it. If you turn it on, your Wi-Fi password travels from your phone to the device over Bluetooth and stays on the device — it is never sent to us. The device then finds your other devices by briefly probing your network, and what it reports about each one is exactly the household inventory described above — hardware address, broadcast name, manufacturer, local IP, first and last seen — and nothing more: no traffic, no browsing history, and your router's hardware address is still never stored. Turn the feature off in the app and the device disconnects from your Wi-Fi, forgets the password, stops discovering, and the devices it had found are removed.
If you turn on home-network auto-pause — which stops the VPN automatically when your phone is on your own WiFi — we store the name of the network or networks you select, so the setting follows your account and applies to anyone you have shared the device with. This is the network name only; your WiFi password is never sent to us. You can remove it at any time by turning the feature off.
1e. Location Information
We derive an approximate geographic location from your IP address using an offline MaxMind database, and we keep only the resulting state or region and country — for example, “FL, US”. The IP address itself is used for that lookup and is not stored. We do not collect precise GPS location, and your IP address is not shared with MaxMind or any external service for geolocation purposes.
So that your PuriFi can show a local clock and weather almanac on its own screen, we also hand the device the time zone and an approximate point (latitude and longitude rounded to one decimal place, about 10 km) that the same lookup produced. That point is stored only on the device you own — not on our servers — and is erased by a factory reset. The device uses it to fetch weather, tides and the tropical outlook directly from the US government sources listed in Section 4.
1f. Order, Shipping, and Payment
When you purchase a PuriFi device, we collect your order details, shipping address, and order tracking information. Payment processing is handled by Stripe (or a similar provider). PuriFi never stores your card number, CVV, or full payment credentials. We retain only the payment token, billing name, and billing address provided by our payment processor.
1g. VPN Remote Access
To enable secure remote management of your device, we store WireGuard public keys associated with your account and maintain relay session mapping records that allow your client application to reach your device over the VPN mesh. We do not inspect or log the content of VPN traffic.
IP Shield. Off unless you turn it on. Some tracking endpoints cannot be blocked without breaking the apps they are built into. With IP Shield on, connections to a curated list of those endpoints leave through a PuriFi-operated server instead of directly from your home, so those trackers see an address shared by many households rather than your home IP address. For that traffic — and only that traffic — PuriFi is in the network path: the server carries the connection and can see the address it is going to. It does not decrypt the connection, and it keeps no record of the traffic it carries. Everything else on your network continues to connect directly and is unaffected, and turning the setting off returns that traffic to a direct connection.
1h. Automatically Collected Information
Our servers automatically receive your IP address and user agent string when you use the PuriFi app or visit our website. We maintain standard server-side access and error logs. If you enable push notifications in the PuriFi mobile app, we store a push notification token issued by Expo for your device, along with the device label and platform (iOS or Android), so that we can send you alerts about your own PuriFi device — for example, when it goes offline or comes back online. You can revoke this at any time by disabling notifications for PuriFi in your phone's system settings. The mobile application sends crash reports and error diagnostics as described in Section 4. In future releases, we may also collect functional cookies (to maintain your login session).
1i. Marketing & Newsletter Communications
If you opt in to receive launch updates, product news, or our newsletter — either by submitting your email on our website, or by clicking the “Yes — keep me posted” link in an invite email — we store your email address and first name (when provided) in a separate marketing audience for the purpose of sending you these messages. Marketing communications are kept strictly separate from transactional communications (such as email verification or password reset), and you can unsubscribe at any time using the one-click link in any marketing email or by emailing privacy@purifi.io. We do not sell or rent this list, and apart from the hashed ad-measurement events described in Section 7 we do not share it with third parties.
We also maintain a permanent internal log of every email we send to you (transactional or marketing) recording the message subject, template used, send timestamp, and delivery status. This log is used for support troubleshooting and compliance reporting and is included in any data export request you make.
Our marketing and newsletter emails include a small tracking pixel (a 1×1 transparent image) and rewritten link URLs (routed through links.hello.purifi.io) so we can measure open and click rates. The data captured is limited to the message you interacted with, your approximate IP address, your browser/device (user-agent), and the timestamp. Mail apps with privacy features (Apple Mail’s Mail Privacy Protection, Gmail’s image proxy) may pre-load the tracking pixel automatically, which can inflate our open counts — we treat open rates as a directional signal, not an exact one. Transactional emails may include the same tracking so we can diagnose deliverability issues. Unsubscribing stops all future marketing tracking; transactional emails continue for account-related actions.
1j. Pre-Launch Waitlist, Reservations, and Website Analytics
We run a launch-updates list on this website. If you ask to be notified about our launch, we store your email address and which page or campaign you signed up from. Before our campaign opened we also ran a VIP reservation programme; if you placed a reservation while it was open, we still hold your email address together with the Stripe checkout and payment references for that reservation, plus the amount and its status — card details are handled entirely by Stripe and never reach our servers. That programme has now closed and we no longer take reservations on this website.
We record page views and interaction events on our own servers. These carry no name, email, or account identifier. We store a truncated IP address — the last part removed, so it identifies a network rather than a device — along with your browser type, screen size, and the campaign or referring site you arrived from. These records are deleted after 90 days.
If you reached us from a Meta (Facebook or Instagram) ad, we record the advertising click and browser identifiers Meta sets and send Meta a conversion event so it can measure that ad. We honour Do Not Track and Global Privacy Control signals when reconstructing click identifiers. These advertising identifiers are deleted within 24 hours of the reservation being processed.
1k. Device Sharing and Guest Invitations
PuriFi lets you share a device you own with other people in your household. If you invite someone, we store the email address you enter, a hashed invitation token, an expiry time for that invitation, the access role you assigned (VPN-only, viewer, or administrator), and the status of the invitation. We send an invitation email to that address on your behalf.
If you are the person being invited: your email address was provided to us by the PuriFi device owner who invited you, not collected from you directly. We use it only to deliver and validate that one invitation. If you accept, your existing PuriFi account is linked to that device with the role the owner assigned; if you decline, if the owner revokes the invitation, or if it expires unused, the invitation record is closed and the associated email address is deleted along with it when the device or the owner's account is deleted. We do not add invited addresses to any marketing audience, and we do not use them to contact you for any purpose other than that invitation.
A device owner can revoke a guest's access at any time, and a guest can leave a shared device at any time, from the PuriFi mobile app. Guests can see the status of the device they were given access to; guests never receive access to the owner's account details, order history, or payment information.
2. Information We Do NOT Collect
PuriFi is built with privacy as a core design principle. We explicitly do not collect:
- DNS query logs or your browsing history — the domains you visit are never recorded on our servers. When you open the stats screen, your device classifies its own blocked activity and sends only the company, category and counts behind it — the hostnames themselves stay on the device. There is no field in our systems that stores them. The live blocking feed relays individual blocked names to your phone as they happen, held in memory only for the moment it takes to pass them on and never written to our database. The same applies to three things you can ask for on demand — the list of dangerous sites your device stopped, a text export of your blocked-traffic log, and how many lookups each of your devices made today (a count per device, never which sites): all are read from your PuriFi and relayed straight to your phone through our server, which never stores or logs them. The single exception is AI Fleet Intelligence, which is off unless you turn it on — Section 1d describes exactly what it sends
- VPN traffic content — we do not inspect, log, or retain the content of any traffic passing through your PuriFi device's VPN connection
- WiFi passwords — your WiFi credentials are provisioned directly to the device during setup and are never stored on PuriFi servers
- Router credentials — PuriFi does not require or store access credentials to your router or home network equipment
- Precise location — we do not access GPS coordinates or any precise location signal from your device or phone
- Behavioral profiles — we do not build advertising profiles or sell data to advertisers. We do share limited conversion events with Meta for ad measurement on our marketing pages — a launch-updates signup, which is hashed, or the fact that someone followed a link from our site to our crowdfunding campaign, which carries no email address at all — Section 7 describes exactly what is shared, and you can opt out on our Your Privacy Choices page
3. How We Use Your Information
| Purpose | Data Used |
|---|---|
| Provide and maintain the Services | Account info, device identifiers, network config, DNS stats, health metrics |
| Show and manage the devices on your home network | Household device inventory (MAC address, device name, manufacturer, local IP, first/last seen) |
| Authenticate your identity | Email, password hash, OAuth credentials, phone number (SMS verification) |
| Fulfill orders and provide support | Shipping address, order details, tracking information, email |
| Enable remote device access | VPN client records, relay session mapping |
| Monitor device health | Health metrics, service status, firmware version |
| Detect and prevent fraud | Audit logs, IP addresses, session data |
| Improve our Services | Aggregated health metrics, DNS statistics (integers only), crash reports (mobile app) |
| Communicate with you | Email address (service updates, security alerts, support responses) |
| Alert you about your device | Push notification token and device nickname; phone number where you have enabled text alerts — used to tell you when your device goes offline or comes back online |
| Comply with legal obligations | As required by applicable law |
5. SMS / Text Messaging and Mobile Information
When you provide your phone number in the PuriFi customer portal or mobile app, we use it to send you one-time verification passcodes (OTP) and, once your number is verified and if you choose to enable text alerts, infrequent operational alerts about your own PuriFi device — for example, when your device goes offline, when it comes back online, or when its protection status changes. SMS consent is collected directly by us at the moment you enter your phone number and request a verification code. Device alert texts are optional: you can turn them on or off at any time in your PuriFi account settings without affecting your ability to use your device or receive verification codes. We never purchase, rent, or import phone numbers, and providing a phone number is not a condition of purchasing any PuriFi product.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with, or sold to, any third party. The sharing described elsewhere in this policy excludes this information in all cases. Your phone number is disclosed only to our SMS delivery provider (Twilio), acting on our behalf as a service provider, solely to deliver the messages described above.
You can opt out of text messages at any time by replying STOP to any message we send, or by removing your phone number from your profile in the PuriFi app. For assistance, reply HELP to any message or contact support@purifi.io. Message frequency varies, and message and data rates may apply. Full program terms are described in the SMS / Text Messaging Program section of our Terms of Service.
6. Data Security
We implement the following security measures to protect your information:
Encryption at Rest
- Passwords are hashed using bcrypt with a cost factor of 12 rounds and are never stored in plaintext
- Sensitive fields are encrypted using AES-256-GCM before storage
- Claim tokens and verification codes are stored as SHA-256 hashes
Encryption in Transit
- All API communication between the PuriFi app and our servers uses TLS
- Device-to-server communication is secured using WireGuard, a modern VPN protocol with strong cryptographic guarantees
Secure Mobile Storage
- Authentication tokens on iOS are stored in the iOS Keychain
- Authentication tokens on Android are stored in the Android Keystore
Additional Measures
- Rate limiting is applied to authentication and sensitive API endpoints to protect against brute-force attacks
- Session management enforces a 7-day refresh token expiry, after which re-authentication is required
No method of transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially reasonable means to protect your personal information, we cannot guarantee absolute security.
8. Data Retention and Deletion
| Data | Retention Period |
|---|---|
| Active account data | Until you delete your account |
| Session / refresh tokens | 7 days from last use, not from when you signed in — each time the app refreshes your session the clock restarts, so a session you keep using stays active until you sign out or revoke it. Once a session goes 7 days unused it expires, and expired sessions are deleted automatically each night. The IP address stored with a session is the one you signed in from and is not updated afterwards. |
| Email verification tokens | 24 hours |
| Password reset tokens | 1 hour |
| Phone verification codes | 10 minutes |
| Device health (current snapshot) | Overwritten approximately every 60 seconds |
| Device health (hourly history) | Retained for performance insights; you may request deletion |
| On-device DNS query log | Rolling 24 hours by default, stored only on your PuriFi device and never uploaded to our servers — the one exception is AI Fleet Intelligence, described in Section 1d, which is off unless you turn it on — or nothing at all if you turn query logging off in the app's Privacy settings (turning it off permanently deletes the history already on the device). If you turn on the blocked-traffic log, blocked requests are kept on the device up to the storage size you choose (100 MB to 2 GB), oldest dropped first; turning it off deletes them |
| Daily DNS statistics (counts only, no hostnames) | Daily totals are kept for as long as you have the device, so the app can show lifetime figures. The hour-by-hour breakdown behind your Daily Recap is erased after 90 days, leaving only the totals. |
| AI Fleet Intelligence threat reports (only if you turn the feature on) | 30 days, after which each report is deleted. A domain confirmed as a threat stays in our block list, which is not linked to any device or account. |
| Security audit logs | The record of the action, its outcome, and when it happened is retained so we can investigate unauthorised access and meet legal obligations. The IP address and browser user agent recorded alongside each entry are deleted after 180 days. Some records may be retained where required by law even after a deletion request. |
| Push notification tokens | Until you disable notifications, sign out, or uninstall the app; tokens rejected as invalid by Expo are deactivated automatically |
| Guest invitations (device sharing) | Invitation links expire on the date shown in the invite; invitation records are removed when the shared device or the inviting account is deleted |
| Website analytics (page views and events) | 90 days |
| Advertising attribution identifiers | Deleted within 24 hours of the reservation being processed |
| Waitlist and reservation records | Until launch is complete or you ask us to remove them |
| Profile photos (after account deletion) | Deleted within 30 days |
| Orders and shipping data | Retained for tax / legal obligations; you may request deletion of non-essential data |
When you delete your account, we initiate deletion of your personal data within 30 days, subject to the exceptions noted above for legal obligations, security audit logs, and order records required for tax compliance.
9. Your Privacy Rights
All Users
Regardless of where you are located, you have the right to access the personal information we hold about you, correct inaccurate information, request deletion of your account and associated data, export a copy of your data in a machine-readable format, and opt out of non-essential communications. You can exercise the most common requests directly:
- Export your data: signed-in users can request a copy of all personal data we hold about them at any time. In the PuriFi mobile app, tap your avatar in the top-right of the dashboard to open Account, then choose Export My Data. We email the export to the address on your account as a JSON file, generated on demand, containing your profile, paired devices, orders, audit logs, and email send history (per GDPR Article 20). Records we can match to you only by email address, such as marketing messages sent before you created an account, are included once your email address is verified.
- Delete your account: signed-in users can delete their account from the Account screen in the PuriFi mobile app, reached by tapping your avatar in the top-right of the dashboard. We soft-delete immediately (your sessions are revoked and you can no longer log in) and permanently remove your data after a 30-day grace period during which the deletion can be reversed by contacting us.
- Unsubscribe from marketing emails: click the “Unsubscribe” link in any marketing email, use the one-click unsubscribe button surfaced by Gmail/Apple Mail/Outlook (we support the
List-Unsubscribeheader), or email privacy@purifi.io. Unsubscribing from marketing does not affect transactional emails, which are required for your account to function.
For any other request, including corrections to information that you cannot edit yourself, contact us at privacy@purifi.io.
California Residents (CCPA / CPRA)
If you are a California resident, you have the right to know what personal information we collect and how it is used and disclosed, the right to delete personal information we hold about you, the right to opt out of the sale or sharing of your personal information, and the right not to be discriminated against for exercising any of these rights. We do not sell your personal information. We do “share” it in one narrow respect as the CCPA/CPRA defines that term — the advertising-measurement events described in Section 7, which involve this website only and never your PuriFi device, its DNS activity, or your account. You can opt out of that at any time on our Your Privacy Choices page, and we honour the Global Privacy Control signal automatically. We will respond to verifiable consumer requests within 45 days. To submit a request, contact us at privacy@purifi.io.
EEA, UK, and Switzerland Residents (GDPR)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we process your personal information on the following legal bases: performance of a contract with you (providing the Services you have requested), our legitimate interests (fraud prevention, security, improving the Services) where those interests are not overridden by your rights, your consent (where we explicitly request it), and compliance with legal obligations.
In addition to the rights listed above, you have the right to data portability, the right to restrict processing, the right to object to processing based on legitimate interests, and the right to lodge a complaint with your local data protection authority.
PuriFi hardware is sold in the United States and Canada only. We honour the rights above for anyone who contacts us regardless of where they are, but we do not operate a cookie-consent banner: the advertising cookies described in Section 7 are governed by the opt-out on our Your Privacy Choices page and by the Global Privacy Control signal, which we honour automatically. If you are visiting from the EEA, the UK, or Switzerland and would prefer we process nothing for advertising measurement, use that page or send the signal and no pixel loads and no conversion event is sent.
Other Jurisdictions
Users in Brazil (LGPD), Canada (PIPEDA), and other jurisdictions with applicable privacy laws may have additional rights under those laws. We are committed to honoring privacy rights regardless of jurisdiction. Please contact us at privacy@purifi.io with any request, and we will respond in accordance with applicable law.
10. Children's Privacy
The PuriFi Services are not intended for use by individuals under the age of 13, and we do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected information from a child under 13, please contact us at privacy@purifi.io and we will promptly delete it.
PuriFi devices include parental content filtering controls. These devices are purchased and operated by adults; any content filtering applied to children in the household is configured and controlled by the adult account holder.
11. International Data Transfers
PuriFi LLC is based in the United States. Our primary infrastructure runs on Amazon Web Services in the US-East-1 region (Virginia). Our VPN relay servers and the IP Shield egress server run on dedicated servers hosted by Hetzner in the United States. If you access the Services from outside the United States, your information will be transferred to and processed in the United States.
For users in the European Economic Area, the United Kingdom, and Switzerland, we rely on standard contractual clauses approved by the European Commission as the lawful mechanism for transferring personal data to the United States. A copy of the applicable clauses is available upon request by contacting privacy@purifi.io.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by sending an email to the address associated with your account before the changes take effect. The updated policy will also be posted on our website with a revised “Last Updated” date.
Your continued use of the PuriFi Services after a material change becomes effective constitutes your acceptance of the revised Privacy Policy. If you do not agree to the revised policy, please discontinue use of the Services and delete your account.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
PuriFi LLC
Email: privacy@purifi.io
Mail: PuriFi LLC
1100 Biscayne Blvd, Unit 4201
Miami, FL 33132
United States