Lord Owl crest

Security & Privacy

How OwlGate keeps your connection under owl-eye.

This page is maintained by Lord Owl Ltd to answer common security and privacy questions about OwlGate. It describes our own practices and the platform controls we rely on. It is not a certification, audit report, or legal advice.

No-logs policy

OwlGate is designed not to log the contents of your VPN traffic. We do not record the sites you visit, the searches you make, the files you download, or the DNS queries you send through our tunnels.

  • We do not store connection timestamps or session durations tied to your identity.
  • We do not store originating IP addresses after a session ends.
  • We keep short-term, aggregate bandwidth counters only for capacity planning and network health.
  • These counters are not linked to individual accounts and are erased automatically.

Encryption & protocols

OwlGate uses modern, widely-reviewed cryptography. Our Android client is built around the WireGuard protocol where the device supports it, with fallback to OpenVPN-style transports on older hardware.

Data in transit

WireGuard: ChaCha20-Poly1305 for data and Curve25519 for key exchange. Legacy fallback uses AES-256-GCM.

Data at rest

Auth and profile data is held in Lovable Cloud databases with platform-managed encryption at rest.

What we collect — and what we do not

We collect the minimum data needed to run the service and support you. We do not sell personal data, show ads, or build profiles for marketing.

DataWhy we need itHow long it stays
Email address & OAuth nameAuthentication and account recovery via Google OAuth.Until you delete your account.
Active perch & favouritesTo remember your preferred VPN location in the app.Stored locally on your device; cleared when you clear app data.
Support email detailsTo reply to your questions. Sent via your email client; not stored by us unless you ask us to keep a record.Only for the duration of the conversation, then deleted.
Optional diagnosticsTo troubleshoot connection issues. Sent only when you choose to include them.Deleted after the ticket is closed.

Authentication

OwlGate uses passwordless sign-in with Google OAuth through Lovable Cloud. We never store your Google password. Session tokens are issued and rotated by the backend; you can sign out from any device at any time.

Keep your Google account secure with two-factor authentication and a strong password. That is the single most important step you can take to protect your OwlGate account.

Cookies, analytics & local data

We do not use third-party advertising or analytics cookies. The site uses only the cookies and local storage needed for authentication and basic UI preferences.

  • Auth session cookie from Lovable Cloud to keep you signed in.
  • Local storage for your active perch and favourite watchtowers in the Locations page.
  • No tracking pixels, fingerprinting, or behavioural analytics.

Subprocessors & hosting

OwlGate runs on Lovable Cloud, which provides hosting, database, authentication, and edge routing. Google OAuth is used for identity verification. We do not share your data with any other third parties for processing.

Lovable Cloud manages the underlying infrastructure, encryption at rest, and access logging for the platform. We configure our own Row-Level Security policies and restrict database access to the minimum required for the app.

Retention & deletion

You can request deletion of your account and associated profile data at any time by emailing privacy@owlgate.co. We aim to complete deletion requests within 30 days.

  • Support emails are deleted after the issue is resolved.
  • Local device data is under your control and can be cleared in your browser or app settings.
  • Aggregate bandwidth counters are automatically rotated and cannot be tied back to you.

Shared responsibility

Security is a shared effort. OwlGate protects the tunnel between your device and our watchtowers, but you are responsible for the device that sits in front of it.

  • Keep your operating system, browser, and OwlGate app up to date.
  • Only install the APK from this official website or a verified app store listing.
  • Do not share your OwlGate session or Google account with others.
  • Review app permissions before granting access to your device.

Contact & vulnerability reporting

Found a security issue or have a privacy question? Email us directly. We read every report and aim to respond within 72 hours.

Last updated: 29 July 2026.