Delete your Suphuzi VPN account

Applies to the Suphuzi VPN app (Android package com.suphuzivpn.app, iOS com.suphuzivpn.app), published on Google Play by İmzahub Teknoloji Ltd. Şti. and on the Apple App Store by Cheetah Tech Lab Yazılım Elektronik Mobil ve Danışmanlık Hizmetleri Ticaret Limited Şirketi, an affiliated company. İmzahub Teknoloji Ltd. Şti. is the data controller in both cases and handles every deletion request described here. Last updated 2 September 2026.

You can delete your Suphuzi VPN account and the data attached to it at any time, for any reason, without explaining yourself. This page tells you how, exactly what disappears, what does not, and how long it takes. You do not need an account on this website and you do not need to be signed in anywhere to read or use it.


Option 1 — delete it yourself, in the app

This is the fastest route and it is immediate. It requires no message to us and no waiting.

1

Open Suphuzi VPN on your device.

2

Go to Settings.

3

Scroll to the account section and choose Delete account.

4

Confirm. Your tunnel is disconnected, your server-side account record is deleted, the Android RevenueCat session is signed out where configured, and both the ordinary secure-storage copy and the operating-system copy used to restore the same account after reinstall are cleared. This does not cancel Google Play billing.

Deleting the app on its own does not delete your account, because the account lives on our server. On supported devices, reinstalling may restore the same account and remaining allowance. Use the step above, or send us the request below.

Option 2 — ask us, without the app

If you have already uninstalled the app, lost the device, or simply prefer that we do it, email us. This route works with no app installed and no login.

Send a message to privacy@suphuzivpn.com

Subject: Account deletion request

Include:

There is no email login, email OTP recovery or cross-device account. On Android, a Google Play receipt may help investigate a billing issue, but it is not a substitute for the Suphuzi account ID when you ask us to delete the app account.

If you cannot supply any of those

We would have to guess, and we will not guess — deleting a stranger's account on an unverified request would be a worse privacy failure than the one you are trying to fix. If you no longer have the account ID, use Option 1 while the app still has access to the account. If you have lost access entirely, tell us what you do know and we will help determine whether a record exists that we can lawfully act on.

What deletion removes

When the deletion runs, the following are erased from the live database immediately. They are also inside the rolling database backups, which take up to 35 days to age out — see Backups below.

DataDeleted?Notes
Your account record — random account ID, current service state, subscription tier/expiry, last RevenueCat event metadata and the HMAC mapping used to recognise the same Android installation after reinstallYes, immediatelyThe account ceases to exist; raw ANDROID_ID was never sent or stored
The current-device record — random device ID, platform, coarse label, creation and last-seen datesYes, immediatelyThe device can no longer authenticate
Any active VPN sessionYes, immediatelyThe current tunnel lease is revoked and the peer is removed from the exit server
Your lifetime allowance balance and recent daily ad countersYes, immediatelyBytes granted, bytes used and rewarded ads credited
The identity stored on your deviceYes, if you use Option 1Account ID, device ID, device secret and local counters are erased from secure storage and reinstall-recovery storage

There is nothing else about you in our account database. We do not hold browsing history, DNS queries, connection history, a list of servers you used, your real IP address, your name, your phone number or any raw hardware identifier. Android's reinstall-continuity value is transformed on-device and HMACed again by the server; the resulting mapping is deleted with the account. The Privacy Policy lists every field we do hold.

What is retained, and why

A few records can outlive deletion for the limited reasons and periods below. They are not used to rebuild a deleted account or create a behaviour profile.

DataKept forWhy
Tunnel lease records — a random token, the public half of a WireGuard key, and a private in-tunnel address such as 10.66.21.105 Deleted with your session. Any record not tied to a live session expires automatically within 48 hours. These contain no account field and no real IP address. They exist only to keep the tunnel working. This table has no backups, so nothing restorable outlives the 48 hours.
A copy of your account record inside the backups of the account database Up to 35 days, then it ages out on its own The backups exist so a database failure cannot wipe out account, allowance and server-verified entitlement state. Nothing is read out of them to look you up. See below.
Rewarded-ad transaction IDs 7 days, then deleted automatically Prevents the same ad reward being claimed twice. It is a Google transaction number, not a record of you.
Request idempotency keys 24 hours, then deleted automatically Stops a retried network request being counted twice.
A recent daily rewarded-ad counter 3 days from creation, then deleted automatically Reward count and byte totals only; no content, no destinations.
Server-side application logs 7 days They record only server-health errors and counters. They contain no IP address, no account ID and no key, so there is nothing in them to erase.
Ad-request data already received by Google AdMob Under Google's policy Use Google's own My Ad Center privacy controls. Suphuzi cannot erase records controlled by Google.
Android purchase, renewal, cancellation and refund records held by Google Play and RevenueCat Under their policies, contractual obligations and applicable accounting law Deleting the Suphuzi account does not erase transaction records that a store or purchase processor must retain. Contact us to request processor-side erasure where it is legally permitted.
The deletion-request email you sent Until the request is resolved and for any further period needed to demonstrate compliance or respond to a dispute The privacy@ alias routes through Cloudflare Email Routing to an access-controlled Google Gmail mailbox. Ask us to delete the correspondence where the law permits.

Backups — the 35-day window

The database that holds accounts has continuous backups (point-in-time recovery) with a 35-day window. We keep them because losing that table would destroy account, allowance and entitlement state, and there would be no reliable way to rebuild it.

What that means for you, stated plainly: deleting your account removes it from the live database at once and it stops existing as far as the service is concerned — you cannot sign in with it, it grants nothing, and no part of Suphuzi reads it again. A copy of it nevertheless sits inside the rolling backups until it ages out, which takes up to 35 days. We do not restore individual accounts from those backups, and we will not restore yours after a deletion; they exist only to bring the whole table back after a failure.

The tunnel lease table has no such window — backups are switched off there on purpose, so tunnel data really does end at 48 hours.

How long it takes

Android subscription and account deletion are separate

Deleting your Suphuzi account does not cancel an Android subscription. Google Play controls recurring billing, not the Suphuzi account-deletion endpoint.

  1. Open Google Play and tap your profile.
  2. Choose Payments & subscriptions → Subscriptions → Suphuzi VPN.
  3. Cancel there if you do not want the monthly or yearly plan to renew.

Cancellation normally leaves Pro active until the end of the period already paid. Restore purchases in the Android app asks Google Play and RevenueCat for the active entitlement. iOS 1.0.5 has no subscription or in-app purchase to cancel.

Other data rights

Deletion is not your only option. You can also ask for a copy of everything we hold about your account, in machine-readable form, or ask us to correct or restrict it. Write to privacy@suphuzivpn.com with what you want, and see section 15 of the Privacy Policy for the full list.

Contact

İmzahub Teknoloji Ltd. Şti.
Beştepe Mahallesi, 32. Cadde No: 1/97, Yenimahalle, Ankara, Türkiye
Deletion requests and data rights: privacy@suphuzivpn.com
General support: support@suphuzivpn.com
Telephone: +90 553 688 13 56

Read the Privacy Policy Read the Terms