Privacy policy
Last updated: 21 August 2026
The short version: we store what is needed to bill you and keep the account secure, and nothing about what you do online.
1. What we collect
Three categories, all of them strictly needed to run the service:
- —Account details: your email, a hashed password, the IP you registered from and the IP of your last sign-in (used for abuse prevention).
- —Usage data: the start time, end time and total number of bytes for each connection. This does NOT include the sites, domains or URLs you visited, or the contents of your traffic.
- —Payment data: order amount, payment method, and the cryptocurrency transaction hash we use to confirm a payment arrived. We do not store card or bank account numbers.
2. What we do not collect
- —The sites, domains or IP addresses you visit
- —Your DNS queries
- —The contents of your traffic, in either direction
- —Device fingerprints, IMEI or advertising identifiers
- —Your location
Technically: our servers forward traffic and nothing more. No deep packet inspection, no connection logs, no request caching. Our service quality comes from what we spend on infrastructure, not from anything we learn about you.
3. How we use it
- —Billing — deducting from your data allowance and telling you when a plan is about to expire
- —Payment confirmation — activating your plan once a crypto payment is confirmed
- —Service email — password resets and expiry notices, sent to the address you gave us
- —Abuse prevention — detecting unusual sign-ins, bulk registration and API abuse
4. How long we keep it
- —Basic account details: for as long as the account exists
- —Sign-in logs (IP and timestamp): deleted after 90 days
- —Traffic statistics: individual records are aggregated and deleted on the last day of each month; only monthly totals are kept, for billing history
- —After you delete your account, all personal data is permanently erased within 30 days
5. Who we share it with
We do not sell, rent or disclose your personal data to anyone. It is shared only in these cases:
- —Payment providers — the minimum needed to process an order
- —Our email provider — your address and the message contents, nothing else
- —Legal compulsion — only on receipt of a legally valid demand, and only within its stated scope
6. Security
- —Passwords are stored as salted Argon2id hashes and never in plain text
- —All API traffic runs over HTTPS with TLS 1.3
- —Databases are backed up encrypted, on a schedule
- —Two-factor authentication is available on every account
7. Your rights
- —See it — your account data and usage records are visible in your dashboard
- —Export it — request a full export of your account data as JSON
- —Correct it — change your email or password at any time
- —Delete it — close your account at any time; everything is erased within 30 days
8. Cookies and local storage
We use local storage only to hold your sign-in tokens, so you stay signed in as you move between pages. There are no third-party cookies, no advertising trackers, and no analytics tools such as Google Analytics.
9. Children
This service is not intended for anyone under 13. If we find an account belonging to a child, we close it and delete the data.
10. Changes to this policy
If we make a significant change we will email you 30 days beforehand. Continuing to use the service counts as accepting the new version.
11. Contact
For privacy questions, or to request a data export or deletion, email [email protected]. We respond within 7 business days.