The complete list. Not a summary.
Most privacy policies are written to preserve options. Ours is written to close them. Below is every field our systems hold and every field they deliberately do not, with the reason for each — 8 collected, 23 deliberately absent.
If a field is not on this page, we do not have it. If you find one that is missing from this list, that is a bug in the page or a bug in our systems, and we want to hear about it either way.
What does VPSDEN actually log?
Identity
Who you are — or rather, the systematic absence of it.
| Field | Held? | Detail |
|---|---|---|
| Legal name | no | No field exists in the schema. There never has been one. |
| Billing address | no | Not requested. Crypto settlement needs no address. |
| Phone number | no | Not requested at any point, including for support. |
| Government identity document | no | Never requested, never accepted. Do not send us one. |
| Date of birth | no | Not requested. |
| Company or VAT number | no | Not requested. We do not charge VAT. |
| Email address | no | Optional. Stored as a salted hash unless you ask to be contacted. |
| Access key hash | yes | HMAC-SHA256 of your access key with a server-side pepper. This is your entire identity to us. |
Network & web
What our infrastructure observes about your connections.
| Field | Held? | Detail |
|---|---|---|
| IP address at signup | no | Not written to any log. The web tier is configured with access logging disabled, not truncated. |
| Panel session IP addresses | no | Not recorded. Most sessions arrive over our onion service and have no meaningful source address anyway. |
| API request source addresses | no | Not recorded. |
| Browser user agent | no | Not recorded. |
| Referrer headers | no | Not recorded. We also send Referrer-Policy: no-referrer so your browser does not leak ours. |
| Cookies for tracking | no | None. The site sets one session cookie in the panel and nothing else. No analytics, no tag manager, no third-party script anywhere on this domain. |
| Per-instance bandwidth samples | no | Disabled at the hypervisor by metadata-free mode, which is on by default. The sampling job does not run. |
| DNS queries made by your instance | no | Our resolvers run with query logging off and answer from memory. You are free to use your own. |
| NetFlow / sFlow per customer | no | Not exported. Aggregate per-region counters only. |
| Deep packet inspection | no | Not performed. No IDS on customer traffic, no protocol shaping. |
| Aggregate regional bandwidth | yes | 15-minute resolution, per region, no per-customer attribution. Needed to know when to buy more transit. |
Instance
What we know about the machine you are running.
| Field | Held? | Detail |
|---|---|---|
| Contents of your volume | no | Encrypted with a key we never receive, on every disk-backed plan by default. On GHOST there is no volume. |
| Snapshot contents | no | Client-side encrypted before leaving your instance. We hold ciphertext and a byte count. |
| Console / VNC session recordings | no | Disabled at the hypervisor. Console sessions are proxied, not recorded. |
| Process lists, memory contents, running services | no | Not collected. No agent is installed in your instance unless you install one. |
| Instance specification and region | yes | We need to know what machine to run and where. |
| Instance power state | yes | Current state only — running or stopped. No history is retained. |
| Support tickets you write | yes | Retained for 90 days after closure, then deleted. Encrypted at rest. Write nothing sensitive in them. |
Billing
What settlement leaves behind.
| Field | Held? | Detail |
|---|---|---|
| Card or bank details | no | We do not accept cards or bank transfers, so there is nothing to store. |
| Payment origin address | yes | Held only between payment and settlement, and for as long as an in-window refund takes to pay out. Nothing about the origin survives the 72-hour refund window. It is on this list as collected because for that period it exists. |
| Transaction hashes | no | Not retained after settlement confirms. |
| Payment amount and status | yes | We need to know whether the machine is paid for. |
| Invoice reference (OxaPay track ID) | yes | Retained for 90 days for reconciliation, then deleted. |
Logging questions
What does VPSDEN log?
A salted hash of your access key, the specification and region of each instance, the current power state, the amount and status of each payment, the OxaPay invoice reference for 90 days, support tickets for 90 days after closure, and a 15-minute-resolution aggregate of per-region bandwidth with no per-customer attribution. That is the complete list.
Does VPSDEN log IP addresses?
No. Not at signup, not for panel sessions, not for API requests, and not per instance. The web tier runs with access logging disabled rather than truncated, and per-instance bandwidth sampling is turned off at the hypervisor by metadata-free mode, which is enabled by default.
Nothing to log, nothing to leak, nothing to hand over.
From €4.40 a month. Metadata-free mode and zero-knowledge LUKS are free and on by default.
No email · No KYC · Pay in Monero · Deployed in under a minute