Privacy Policy
Last updated: July 15, 2026
AEGIS-SIGMA ("we", "our", "us") operates the AEGIS-SHIELD mobile application and the aegis-sigma.com website. This policy explains how we collect, use, and protect your data.
1. Data We Collect
- Account data: Email address, license key, subscription tier
- Network data: IP address, connection timestamps, WireGuard public key, VPN client IP assignment
- Device data: User agent, Android version, device model (for troubleshooting)
- Security events: Blocked threat attempts, anonymized attack patterns
2. How We Use Your Data
- Providing and maintaining your VPN connection
- Processing payments via Stripe (we never store card details)
- Threat detection and service security
- License key verification and subscription management
- Customer support and troubleshooting
3. No-Logging Policy
AEGIS-SIGMA operates a strict no-logging policy for VPN traffic. We do not monitor, log, or store your browsing activity, DNS queries, or data transmitted through the VPN tunnel. Security events (blocked threats, connection metadata) are retained for 7 days for operational security and then purged.
4. Data Sharing
We do not sell your data. We share only with:
- Stripe, Inc. — Payment processing (their privacy policy applies to your payment data)
- WireGuard — The VPN protocol is open source; no data is sent to WireGuard developers
- Law enforcement: Only if required by valid legal process
5. Data Storage & Retention
- Account data: Retained for the duration of your subscription plus 30 days
- License keys: Stored indefinitely to verify access
- Security logs: Retained for 7 days
- Connection metadata: Deleted immediately upon tunnel termination
6. Your Rights
You may request deletion of your account and associated data at any time by emailing admin@aegis-sigma.com. Data subject to ongoing legal holds will be retained as required by law.
7. Security
All data is encrypted in transit via WireGuard (Curve25519/ChaCha20Poly1305) and TLS. Servers are hosted in secure data centers with physical access controls.
8. Proxy & Reverse Proxy Transparency
We cannot read your data. Our reverse proxy is a pure pass-through with security header injection. Zero content logging. Zero body inspection. Zero storage.
- No Content Access — Traffic is proxied at the TLS layer. We inject security headers only — we never read, log, or store request bodies or responses. The config is open for your audit at any time.
- Transparent Config — Our entire nginx proxy config is 20 lines. You can inspect it yourself. No hidden logging, no data collection, no third-party services. What you see is what runs.
- Contract-Backed — Our service agreement contractually prohibits accessing, logging, or storing client origin data. The proxy is limited to TLS termination and security header injection. Period.
9. Meeting Scheduling & Booking (cal.aegis-sigma.com)
When you book a meeting through our scheduling service at cal.aegis-sigma.com, we collect the following solely to arrange and hold your call:
- Name and email address — used to create your meeting invitation and confirm the booking
- Requested meeting slot — the date and time you select
- Phone number — collected only when you choose a phone-call meeting, so we can reach you
- Google Calendar event — with your consent, we create a meeting event on our host's calendar and send you an invitation. For Google Meet meetings, a live video link is auto-generated and attached to your invite.
We do not use booking data for any purpose other than scheduling and holding the requested meeting. We do not sell, share, or retain booking data beyond what is required to service the booking. Meeting invitations are delivered by Google Calendar; Google's privacy policy applies to your Google account data.
10. Contact
Privacy inquiries: admin@aegis-sigma.com