Privacy
This page says what we collect, why, how long we keep it and who else sees it. It covers this website, our apps, our Telegram bot and the VPN and server products themselves.
The short version
- To open an account we need an e-mail address. Not a name, not a phone number, not an address.
- We never see your card number or your wallet keys. Payments are handled by our payment provider.
- Our servers record connection and usage data — including the IP address you connect from — because a metered service has to count traffic, enforce device limits and deal with abuse.
- Our DNS servers do not log the names you look up.
- We do not sell your data, and we run no advertising or analytics trackers.
Your account
An account needs one thing: an e-mail address. Your password is never stored — only an irreversible, individually-salted hash of it, which cannot be turned back into your password. If you turn on two-factor authentication, the secret is encrypted before it is written down. If you sign in with Google we keep the account identifier Google gives us, the address on it, and whether Google says that address is verified — nothing else from your Google account. If you use our Telegram bot, we keep the link between your Telegram user and your account.
There is no field anywhere in our system for your name, postal address, date of birth or phone number.
Connection and usage records
This is a metered service, so it has to count. When you connect, our servers record which account connected, when, the IP address the connection came from, the device model and app version reported by the client, and how many bytes you transferred. Depending on which protocol you choose, the server software for that protocol may also write the address a connection was made to into its own operational log.
We use this to bill and meter your plan, to enforce how many devices may be connected at once, to keep a server healthy, and to investigate abuse or a security incident.
In our database, your usage is stored as a running byte total per account — at the finest, one figure per day, kept for seven days. There is no table anywhere that stores a row per connection.
Security records
Security-relevant events on your account — signing in, a failed sign-in, changing your password, turning two-factor on or off, connecting or disconnecting Google — are written to an append-only audit log together with the IP address and browser user-agent that made the request. This is what lets us answer "was this really you?" after the fact, and it is deliberately tamper-evident and not editable.
Some things are deliberately stored only as one-way hashes and never in a readable form: every code we e-mail you, your recovery codes, the identifiers our rate limiter counts against, and the IP address recorded against a subscription link.
Payments
We never see, and never store, a card number, a wallet key or a private key. Payment is handled by our payment provider. When you buy something or top up a balance we send them the amount, your account reference and your e-mail address so they can issue and match the invoice; they send back the result. Cryptocurrency payments are settled on their public network, and the transaction hash you give us when reporting a payment stays on file so a payment cannot be credited twice.
Support
If you open a ticket we keep the conversation, any files you attach, and — if you wrote in through Telegram — the Telegram chat it came from, so a reply reaches you. Ticket history is kept so that a later conversation has context.
This website
We set three cookies, and none of them are for tracking. A session cookie keeps you signed in — it holds nothing but an opaque token, with everything else on our side; it lasts thirty days, or seven days without use. A short-lived cookie protects a Google sign-in while it is in progress and is deleted the moment it finishes. A cookie remembers your language for a year. Your browser also stores an invite code locally if you arrived from an invite link.
There are no advertising cookies, no analytics cookies and no third-party trackers on this site.
How long we keep things
Different records have different lives:
- Signed-in sessions expire after thirty days, or seven days without use.
- A code we e-mail you expires in minutes and can be used once.
- Daily usage figures are kept for seven days; your running totals live as long as the account.
- Records that we sent you a message are kept for ninety days. We do not keep the message body.
- Telegram conversation state is kept for thirty days.
- Your account, your orders and invoices, your entitlements, your tickets and the security audit log are kept for as long as the account exists. Some of these we are required to keep for accounting; the audit log is append-only by design and is not edited or trimmed.
Who else sees it
We do not sell data and we do not share it for advertising. Data reaches these parties, and only for the reason given:
- Our own VPN backend, which receives an internal account number — never your e-mail address — plus the settings your service needs.
- Our payment provider, which receives the amount, an account reference and your e-mail address so it can issue and match your invoice.
- Google, only if you choose to sign in with it, and only as part of that sign-in.
- Telegram, only if you use our bot, and only the messages you exchange with it.
- Our e-mail provider, which receives the address and the message so it can be delivered.
What you can do
- Change your e-mail address from your account page. We ask the new address to confirm itself, and tell the old one what happened so a change you did not make cannot go unnoticed.
- Turn two-factor authentication on or off, and regenerate your recovery codes.
- Connect or disconnect Google. You cannot disconnect it until you have set a password, because that would leave you with no way in.
- Sign out every other device from your account page.
- Ask us to close your account. Closing it blocks every way of signing in and using the service. Records tied to it — orders, invoices and the audit log — remain, because they are business records. If you want data erased beyond that, write to us and say so.
Children
This service is not intended for children, and we do not knowingly create accounts for them.
Changes
If this policy changes in a way that affects you, we will change the date at the top and, where the change is significant, tell you by e-mail.
Contact
Questions about anything on this page — including a request to see or delete what we hold — go to our support team, who will route them to the right person.