Privacy Policy

Last Updated: August 20, 2026CCPA & GDPR Compliant

Table of Contents

1. Information We Collect

PuriFi LLC (“PuriFi,” “we,” “us,” or “our”) collects the following categories of information when you use our products and services.

1a. Account Information

When you create a PuriFi account, we collect your email address, name, phone number, and profile photo (if you choose to upload one).

1b. Authentication and Session Data

We collect OAuth tokens used for Google and Apple Sign-In authentication, session information (including refresh tokens and session identifiers), and security audit logs recording authentication events and account actions.

1c. Device Information

For each PuriFi device registered to your account, we collect device identifiers (serial number, MAC address, VPN IP address), firmware version, device health metrics (CPU usage, memory, temperature, disk usage), and current service status for the PuriFi system components running on the device.

1d. Network and DNS Information

We collect aggregate DNS statistics reported by your device as integer counts only (for example: total queries processed, queries blocked, queries forwarded). We do not log individual DNS queries or the hostnames you look up. On the device itself, your PuriFi keeps a short local log of DNS activity (a rolling 24-hour window) to power the stats screen and the Recently Blocked list; that log lives only on hardware you own and is never uploaded to us. You can turn query logging off entirely in the app's Privacy settings — your PuriFi then records nothing at all, and the history already stored on the device is permanently deleted. Blocking keeps working either way. We also collect network topology information necessary to maintain your VPN connection (gateway IP, LAN IP, and DNS server addresses) and any DNS policy configuration you set within the PuriFi app. Your device also reports its public IP address, which we use in the moment to look up your approximate state or region and then discard — we do not store your public IP address. We do not store your router's hardware (MAC) address, and we do not store GPS or street-level coordinates for your home.

If you turn on home-network auto-pause — which stops the VPN automatically when your phone is on your own WiFi — we store the name of the network or networks you select, so the setting follows your account and applies to anyone you have shared the device with. This is the network name only; your WiFi password is never sent to us. You can remove it at any time by turning the feature off.

1e. Location Information

We derive an approximate geographic location from your IP address using an offline MaxMind database, and we keep only the resulting state or region and country — for example, “FL, US”. The IP address itself is used for that lookup and is not stored. We do not collect precise GPS location, and your IP address is not shared with MaxMind or any external service for geolocation purposes.

1f. Order, Shipping, and Payment

When you purchase a PuriFi device, we collect your order details, shipping address, and order tracking information. Payment processing is handled by Stripe (or a similar provider). PuriFi never stores your card number, CVV, or full payment credentials. We retain only the payment token, billing name, and billing address provided by our payment processor.

1g. VPN Remote Access

To enable secure remote management of your device, we store WireGuard public keys associated with your account and maintain relay session mapping records that allow your client application to reach your device over the VPN mesh. We do not inspect or log the content of VPN traffic.

1h. Automatically Collected Information

Our servers automatically receive your IP address and user agent string when you use the PuriFi app or visit our website. We maintain standard server-side access and error logs. If you enable push notifications in the PuriFi mobile app, we store a push notification token issued by Expo for your device, along with the device label and platform (iOS or Android), so that we can send you alerts about your own PuriFi device — for example, when it goes offline or comes back online. You can revoke this at any time by disabling notifications for PuriFi in your phone's system settings. The mobile application sends crash reports and error diagnostics as described in Section 4. In future releases, we may also collect functional cookies (to maintain your login session).

1i. Marketing & Newsletter Communications

If you opt in to receive launch updates, product news, or our newsletter — either by submitting your email on our website, or by clicking the “Yes — keep me posted” link in an invite email — we store your email address and first name (when provided) in a separate marketing audience for the purpose of sending you these messages. Marketing communications are kept strictly separate from transactional communications (such as email verification or password reset), and you can unsubscribe at any time using the one-click link in any marketing email or by emailing privacy@purifi.io. We do not sell or rent this list, and apart from the hashed ad-measurement events described in Section 6 we do not share it with third parties.

We also maintain a permanent internal log of every email we send to you (transactional or marketing) recording the message subject, template used, send timestamp, and delivery status. This log is used for support troubleshooting and compliance reporting and is included in any data export request you make.

Our marketing and newsletter emails include a small tracking pixel (a 1×1 transparent image) and rewritten link URLs (routed through links.hello.purifi.io) so we can measure open and click rates. The data captured is limited to the message you interacted with, your approximate IP address, your browser/device (user-agent), and the timestamp. Mail apps with privacy features (Apple Mail’s Mail Privacy Protection, Gmail’s image proxy) may pre-load the tracking pixel automatically, which can inflate our open counts — we treat open rates as a directional signal, not an exact one. Transactional emails may include the same tracking so we can diagnose deliverability issues. Unsubscribing stops all future marketing tracking; transactional emails continue for account-related actions.

1j. Pre-Launch Waitlist, Reservations, and Website Analytics

Before our public launch we run a waitlist and a reservation programme on this website. If you ask to be notified about our launch, we store your email address and which page or campaign you signed up from. If you place a VIP reservation, we store your email address together with the Stripe checkout and payment references for that reservation, plus the amount and its status — card details are handled entirely by Stripe and never reach our servers.

We record page views and interaction events on our own servers. These carry no name, email, or account identifier. We store a truncated IP address — the last part removed, so it identifies a network rather than a device — along with your browser type, screen size, and the campaign or referring site you arrived from. These records are deleted after 90 days.

If you reached us from a Meta (Facebook or Instagram) ad, we record the advertising click and browser identifiers Meta sets and send Meta a conversion event so it can measure that ad. We honour Do Not Track and Global Privacy Control signals when reconstructing click identifiers. These advertising identifiers are deleted within 24 hours of the reservation being processed.

1k. Device Sharing and Guest Invitations

PuriFi lets you share a device you own with other people in your household. If you invite someone, we store the email address you enter, a hashed invitation token, an expiry time for that invitation, the access role you assigned (VPN-only, viewer, or administrator), and the status of the invitation. We send an invitation email to that address on your behalf.

If you are the person being invited: your email address was provided to us by the PuriFi device owner who invited you, not collected from you directly. We use it only to deliver and validate that one invitation. If you accept, your existing PuriFi account is linked to that device with the role the owner assigned; if you decline, if the owner revokes the invitation, or if it expires unused, the invitation record is closed and the associated email address is deleted along with it when the device or the owner's account is deleted. We do not add invited addresses to any marketing audience, and we do not use them to contact you for any purpose other than that invitation.

A device owner can revoke a guest's access at any time, and a guest can leave a shared device at any time, from the PuriFi mobile app. Guests can see the status of the device they were given access to; guests never receive access to the owner's account details, order history, or payment information.

2. Information We Do NOT Collect

PuriFi is built with privacy as a core design principle. We explicitly do not collect:

  • DNS query logs or your browsing history — the domains you successfully visit are never recorded on our servers. When you open the stats screen, your device sends the list of domains it blocked that day so we can show it to you; that list is held in memory only for the moment it takes to answer your request and is never written to our database. There is no field in our systems that stores it
  • VPN traffic content — we do not inspect, log, or retain the content of any traffic passing through your PuriFi device's VPN connection
  • WiFi passwords — your WiFi credentials are provisioned directly to the device during setup and are never stored on PuriFi servers
  • Router credentials — PuriFi does not require or store access credentials to your router or home network equipment
  • Precise location — we do not access GPS coordinates or any precise location signal from your device or phone
  • Behavioral profiles — we do not build advertising profiles or sell data to advertisers. During our pre-launch campaign we do share limited, hashed conversion events (a launch-updates signup or a $1 VIP reservation) with Meta for ad measurement on our marketing pages — Section 6 describes exactly what is shared

3. How We Use Your Information

PurposeData Used
Provide and maintain the ServicesAccount info, device identifiers, network config, DNS stats, health metrics
Authenticate your identityEmail, password hash, OAuth credentials, phone number (SMS verification)
Fulfill orders and provide supportShipping address, order details, tracking information, email
Enable remote device accessVPN client records, relay session mapping
Monitor device healthHealth metrics, service status, firmware version
Detect and prevent fraudAudit logs, IP addresses, session data
Improve our ServicesAggregated health metrics, DNS statistics (integers only), crash reports (mobile app)
Communicate with youEmail address (service updates, security alerts, support responses)
Alert you about your devicePush notification token and device nickname; phone number where you have enabled text alerts — used to tell you when your device goes offline or comes back online
Comply with legal obligationsAs required by applicable law

4. How We Share Your Information

We do not sell your personal information. We share information only with the service providers listed below and only to the extent necessary to operate the Services.

Current Service Providers

Service ProviderInformation SharedPurpose
ResendEmail address, first name, subscriber preferencesTransactional emails (verification, password reset, account notifications) and, where you have opted in, marketing emails / newsletter via Resend Audiences. Resend also records email opens (via a tracking pixel) and link clicks (via URL rewriting through links.hello.purifi.io) so we can measure engagement and improve deliverability.
TwilioPhone number, message contentSMS delivery — one-time verification codes and, where you have enabled them, device status alerts
Meta PlatformsHashed email, advertising click/browser identifiers, IP address and browser user agent, and the conversion event (waitlist signup or reservation)Measuring the performance of our own ads. Applies only to pre-launch website visitors who arrived from a Meta ad — never to PuriFi device data, DNS activity, or customer accounts.
StripeEmail address, payment method and billing details you enter on Stripe's checkout pageProcessing VIP reservation payments. Card numbers are handled entirely by Stripe and never reach our servers.
ExpoPush notification token, device label and platform, notification content (alert title, message, and the nickname you gave your device)Delivering push notifications to the PuriFi mobile app on iOS and Android. Expo relays notifications to Apple Push Notification Service and Firebase Cloud Messaging on our behalf. Notification content is limited to your device's status — it never contains DNS queries, browsing history, or account credentials.
GoogleOAuth token verificationGoogle Sign-In authentication
AppleOAuth token verificationApple Sign-In authentication
Amazon Web Services (S3)Profile photos, firmware binariesCloud file storage
USPSRecipient name, shipping addressShipping label generation
SentryCrash reports and error diagnostics from the mobile app — stack traces, device model, OS version, in-app interaction breadcrumbs, and sampled performance data — linked to your customer account ID (never your email, name, or IP address)Mobile app error tracking and crash reporting

Geolocation is performed locally on our servers using an offline MaxMind database. Your IP address is not transmitted to MaxMind or any external party for this purpose.

Crash reports from the mobile app are relayed through our own server (api.purifi.io) before reaching Sentry, because PuriFi's DNS filtering blocks Sentry's ingest domains. Our server forwards these reports without reading them and never logs their contents.

We may also disclose your information if required to do so by law, court order, or valid governmental request; to protect the rights, property, or safety of PuriFi, our users, or the public; or in connection with a merger, acquisition, or sale of all or substantially all of our assets, in which case we will notify you before your information is transferred and becomes subject to a different privacy policy.

5. SMS / Text Messaging and Mobile Information

When you provide your phone number in the PuriFi customer portal or mobile app, we use it to send you one-time verification passcodes (OTP) and, once your number is verified and if you choose to enable text alerts, infrequent operational alerts about your own PuriFi device — for example, when your device goes offline, when it comes back online, or when its protection status changes. SMS consent is collected directly by us at the moment you enter your phone number and request a verification code. Device alert texts are optional: you can turn them on or off at any time in your PuriFi account settings without affecting your ability to use your device or receive verification codes. We never purchase, rent, or import phone numbers, and providing a phone number is not a condition of purchasing any PuriFi product.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with, or sold to, any third party. The sharing described elsewhere in this policy excludes this information in all cases. Your phone number is disclosed only to our SMS delivery provider (Twilio), acting on our behalf as a service provider, solely to deliver the messages described above.

You can opt out of text messages at any time by replying STOP to any message we send, or by removing your phone number from your profile in the PuriFi app. For assistance, reply HELP to any message or contact support@purifi.io. Message frequency varies, and message and data rates may apply. Full program terms are described in the SMS / Text Messaging Program section of our Terms of Service.

6. Data Security

We implement the following security measures to protect your information:

Encryption at Rest

  • Passwords are hashed using bcrypt with a cost factor of 12 rounds and are never stored in plaintext
  • Sensitive fields are encrypted using AES-256-GCM before storage
  • Claim tokens and verification codes are stored as SHA-256 hashes

Encryption in Transit

  • All API communication between the PuriFi app and our servers uses TLS
  • Device-to-server communication is secured using WireGuard, a modern VPN protocol with strong cryptographic guarantees

Secure Mobile Storage

  • Authentication tokens on iOS are stored in the iOS Keychain
  • Authentication tokens on Android are stored in the Android Keystore

Additional Measures

  • Rate limiting is applied to authentication and sensitive API endpoints to protect against brute-force attacks
  • Session management enforces a 7-day refresh token expiry, after which re-authentication is required

No method of transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially reasonable means to protect your personal information, we cannot guarantee absolute security.

7. Cookies and Similar Technologies

Current Usage

The PuriFi Services currently use minimal cookie and local storage technologies. We set a single HTTP-only authentication cookie to maintain your logged-in session in the web application. This cookie contains only a session identifier and does not contain your personal data.

Advertising Measurement (Pre-Launch)

During our pre-launch campaign, our marketing funnel pages — the homepage, the VIP reservation pages, and our published research reports (such as our smart-TV privacy report) — load the Meta Pixel and Google Analytics. The Meta Pixel may set the _fbp and _fbc cookies, and when you sign up for launch updates or complete a $1 VIP reservation we send Meta a conversion event containing your email address in one-way hashed (SHA-256) form — the same hash also serves as an anonymous match identifier — along with your IP address, browser user agent, and, when you arrived from a Meta ad, the ad-click identifier carried in the page URL. The pixel itself may include the hashed email with its events (Meta hashes it in your browser before it is sent). Meta can use the hash to match the event to an account it already knows — it cannot learn your email address from us — and we use these events solely to measure and improve our advertising. We honor the Do Not Track browser signal: with DNT enabled, the pixel never loads and no Meta cookies are set, and we do not attach ad-click identifiers for visitors sending Do Not Track or Global Privacy Control. These pixels run only on the marketing pages listed above; the web application and device services remain tracker-free.

What We Will Not Do

  • We will not sell your personal information to advertisers or data brokers
  • We will not place advertising or tracking cookies beyond the marketing funnel pages disclosed above
  • We will not use fingerprinting or similar techniques to identify you across sessions

8. Data Retention and Deletion

DataRetention Period
Active account dataUntil you delete your account
Session / refresh tokens7 days from last use, not from when you signed in — each time the app refreshes your session the clock restarts, so a session you keep using stays active until you sign out or revoke it. Once a session goes 7 days unused it expires, and expired sessions are deleted automatically each night. The IP address stored with a session is the one you signed in from and is not updated afterwards.
Email verification tokens24 hours
Password reset tokens1 hour
Phone verification codes10 minutes
Device health (current snapshot)Overwritten approximately every 60 seconds
Device health (hourly history)Retained for performance insights; you may request deletion
On-device DNS query logRolling 24 hours, stored only on your PuriFi device and never uploaded to our servers — or nothing at all if you turn query logging off in the app's Privacy settings (turning it off permanently deletes the history already on the device)
Security audit logsThe record of the action, its outcome, and when it happened is retained so we can investigate unauthorised access and meet legal obligations. The IP address and browser user agent recorded alongside each entry are deleted after 180 days. Some records may be retained where required by law even after a deletion request.
Push notification tokensUntil you disable notifications, sign out, or uninstall the app; tokens rejected as invalid by Expo are deactivated automatically
Guest invitations (device sharing)Invitation links expire on the date shown in the invite; invitation records are removed when the shared device or the inviting account is deleted
Website analytics (page views and events)90 days
Advertising attribution identifiersDeleted within 24 hours of the reservation being processed
Waitlist and reservation recordsUntil launch is complete or you ask us to remove them
Profile photos (after account deletion)Deleted within 30 days
Orders and shipping dataRetained for tax / legal obligations; you may request deletion of non-essential data

When you delete your account, we initiate deletion of your personal data within 30 days, subject to the exceptions noted above for legal obligations, security audit logs, and order records required for tax compliance.

9. Your Privacy Rights

All Users

Regardless of where you are located, you have the right to access the personal information we hold about you, correct inaccurate information, request deletion of your account and associated data, export a copy of your data in a machine-readable format, and opt out of non-essential communications. You can exercise the most common requests directly:

  • Export your data: signed-in users can download a JSON file containing all personal data we hold about them at any time. From the PuriFi mobile app, navigate to Settings → Account → Export My Data. The export is generated on demand and includes your profile, paired devices, orders, audit logs, and email send history (per GDPR Article 20).
  • Delete your account: signed-in users can delete their account from Settings → Account → Delete Account. We soft-delete immediately (your sessions are revoked and you can no longer log in) and permanently remove your data after a 30-day grace period during which the deletion can be reversed by contacting us.
  • Unsubscribe from marketing emails: click the “Unsubscribe” link in any marketing email, use the one-click unsubscribe button surfaced by Gmail/Apple Mail/Outlook (we support the List-Unsubscribe header), or email privacy@purifi.io. Unsubscribing from marketing does not affect transactional emails, which are required for your account to function.

For any other request, including corrections to information that you cannot edit yourself, contact us at privacy@purifi.io.

California Residents (CCPA / CPRA)

If you are a California resident, you have the right to know what personal information we collect and how it is used and disclosed, the right to delete personal information we hold about you, the right to opt out of the sale or sharing of your personal information (we do not sell or share your personal information as defined under the CCPA/CPRA), and the right not to be discriminated against for exercising any of these rights. We will respond to verifiable consumer requests within 45 days. To submit a request, contact us at privacy@purifi.io.

EEA, UK, and Switzerland Residents (GDPR)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, we process your personal information on the following legal bases: performance of a contract with you (providing the Services you have requested), our legitimate interests (fraud prevention, security, improving the Services) where those interests are not overridden by your rights, your consent (where we explicitly request it), and compliance with legal obligations.

In addition to the rights listed above, you have the right to data portability, the right to restrict processing, the right to object to processing based on legitimate interests, and the right to lodge a complaint with your local data protection authority.

Other Jurisdictions

Users in Brazil (LGPD), Canada (PIPEDA), and other jurisdictions with applicable privacy laws may have additional rights under those laws. We are committed to honoring privacy rights regardless of jurisdiction. Please contact us at privacy@purifi.io with any request, and we will respond in accordance with applicable law.

10. Children's Privacy

The PuriFi Services are not intended for use by individuals under the age of 13, and we do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected information from a child under 13, please contact us at privacy@purifi.io and we will promptly delete it.

PuriFi devices include parental content filtering controls. These devices are purchased and operated by adults; any content filtering applied to children in the household is configured and controlled by the adult account holder.

11. International Data Transfers

PuriFi LLC is based in the United States. Our primary infrastructure runs on Amazon Web Services in the US-East-1 region (Virginia). If you access the Services from outside the United States, your information will be transferred to and processed in the United States.

For users in the European Economic Area, the United Kingdom, and Switzerland, we rely on standard contractual clauses approved by the European Commission as the lawful mechanism for transferring personal data to the United States. A copy of the applicable clauses is available upon request by contacting privacy@purifi.io.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by sending an email to the address associated with your account before the changes take effect. The updated policy will also be posted on our website with a revised “Last Updated” date.

Your continued use of the PuriFi Services after a material change becomes effective constitutes your acceptance of the revised Privacy Policy. If you do not agree to the revised policy, please discontinue use of the Services and delete your account.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

PuriFi LLC

Email: privacy@purifi.io
Mail: PuriFi LLC
1100 Biscayne Blvd, Unit 4201
Miami, FL 33132
United States