Skip to content
VPSDen
Legal

Privacy policy

This is short because there is very little to describe. For the field-by-field version, see the no-logs page — it is more detailed than this document and it is not written by lawyers.

Effective on acceptanceLast revised 2026-03-15Governed by the law of Panama

Summary

In plain terms
We hold a salted hash of your access key, what machine you bought, where it runs, and whether it is paid for. We do not hold your name, your address, your IP address, your browser fingerprint, or the contents of your disk. We have never sold data, we have never disclosed a customer record, and there is nothing here that would be worth buying in a bankruptcy.

1. What we collect

The complete list:

  • A salted hash of your access key. HMAC-SHA256 with a server-side pepper. This is your entire identity to us. We cannot reverse it and we cannot recover your key from it.
  • Instance specification and region. Cores, memory, storage, transfer, operating system, add-ons and location, so we know what machine to run.
  • Instance power state. Current state only. No history is retained.
  • Payment amount, currency and status. So we know whether the machine is paid for.
  • The payment provider's invoice reference. Retained 90 days for reconciliation, then deleted.
  • A contact address, if you volunteered one. Stored as a salted hash unless you have asked to be contacted, in which case it is stored encrypted. Optional at every stage.
  • Support tickets you write. Encrypted at rest, deleted 90 days after closure.
  • Aggregate per-region bandwidth. 15-minute resolution, no per-customer attribution, for capacity planning.

2. What we do not collect

No name, address, phone number, date of birth, government document, company number, card, or bank account. No IP address at signup, for panel sessions, or for API requests. No user agent, referrer, or tracking cookie. No per-instance bandwidth samples, DNS queries, NetFlow, console recordings, or disk contents.

The no-logs page lists every field individually with the reason for each. It is the authoritative version; this section is a summary.

3. Why we hold what we hold

Each item above exists for exactly one purpose: to deliver the service you bought. We do not process anything for marketing, analytics, profiling, product research, machine learning, or "improving our services." Where a legal basis is required, it is performance of a contract with you.

4. Retention

DataRetained
Access key hashUntil you close the account, then destroyed within 24 hours
Instance specificationUntil 30 days after the instance is destroyed
Payment records90 days, then reduced to an amount and a date
Invoice references90 days
Support tickets90 days after closure
Aggregate bandwidth13 months, no customer attribution at any point
Contact address hashUntil you remove it
In plain terms
Deletion is deletion. Rows are overwritten, not flagged, and our backups roll forward with a 35-day window rather than being kept indefinitely. There is no archive, no data warehouse, and no analytics copy.

5. Sharing

We share data with exactly one category of third party:

  • Our payment provider (OxaPay). They receive the amount, the currency, an order reference that is a random string, and a description of the machine specification. They do not receive your access key, your contact address, or anything identifying. They operate under their own privacy policy, which we do not control.

We do not use analytics providers, advertising networks, tag managers, session recorders, CDNs that terminate TLS, customer data platforms, or CRM systems. There is no third-party JavaScript on this website. You can verify that in your browser's network inspector, and we encourage you to.

Legal disclosure. We respond only to a valid, binding order from a court in the jurisdiction where the relevant hardware sits, and we produce only what is compelled. See the law enforcement guide and the transparency report.

In an acquisition or insolvency. Any acquirer or administrator receives what exists, which is a table of hashes and machine specifications. This is a deliberate structural protection, not a promise: there is nothing here that constitutes a saleable customer list.

6. This website

The web tier runs with access logging disabled — not truncated, not anonymised, disabled. There are no analytics of any kind. The only cookie set is a session cookie in the control panel, which is required for the panel to function and expires when your session ends.

No external fonts, scripts, images or stylesheets are loaded from any other domain. Every asset on this site is served by us, which means visiting this page does not tell anyone else that you visited it.

A mirror of this entire site, including the panel and the API, is available as a v3 onion service. We publish an Onion-Location header, so Tor Browser will offer it to you automatically.

7. Your rights

Data protection frameworks including the GDPR give you rights of access, rectification, erasure, restriction, portability and objection. We honour all of them for anyone who asks, regardless of where you live, because it costs us nothing to do so.

The practical difficulty is authentication. We cannot verify that you are the holder of an account without your access key, and we will not accept an identity document as an alternative — accepting one would create exactly the record we exist to avoid. Prove control of the access key and we will action any request within 72 hours.

In plain terms
Erasure is available at any time and takes about ten seconds: destroy your instances and close the account in the panel. There is no retention hold and no "we may keep some data for legitimate interests" clause.

8. Security

  • Everything encrypted in transit with TLS 1.3; HSTS with preload.
  • Databases encrypted at rest, keys held in hardware security modules.
  • Zero-knowledge LUKS on customer volumes by default, keyed by the customer.
  • Hypervisor access restricted to four named individuals, with two-person authorisation for console access.
  • Privileged actions logged to an append-only store in a separate jurisdiction.
  • Annual third-party penetration test; the summary is published on request.

Report vulnerabilities to the address in our security.txt. We pay bounties, we do not threaten researchers, and we credit findings publicly unless you ask us not to.

9. Changes

Material changes are announced at least 30 days in advance on the status feed and, for customers who have provided one, by their contact channel. We keep every prior version of this document and will publish the archive, with diffs, at /legal/privacy/archive. It is not up yet; ask us and we will send you any superseded version.

We will never introduce a change that adds a data collection category without a corresponding 30-day notice and the option to leave with a pro-rata refund.

Questions about any of this?

We answer legal questions from prospective customers, in writing, before you buy anything.

No email · No KYC · Pay in Monero · Deployed in under a minute