Our no-logs policy
Every provider claims no logs. Here is what that means for us, item by item.
Every provider claims no logs, so the phrase has stopped meaning much. Instead of the claim, here is the list of what exists in our systems and what does not.
Never recorded
- Websites, applications and services you connect to.
- DNS queries made through the tunnel.
- Source IP addresses paired with timestamps.
- Session start and end times for individual users.
- Any identity data, because we never ask for it.
Stored, because the service cannot run without it
- The key identifier and its expiry date.
- Aggregate traffic volume per key, reset monthly, used only to detect abuse.
- The Telegram id the key was issued to.
- Payment confirmations, kept as long as accounting law requires.
Why our server locations matter
The CERT-In directive requires providers operating inside India to keep customer records for five years. A provider with Indian servers either complies or withdraws them, and most privacy-focused services withdrew. We run no Indian servers, which is what makes this policy possible. A provider that kept them cannot honestly publish the same list.
What happens if someone asks
A lawful request can only be answered with what exists: that a key was issued and when it expires. There is no browsing history to produce, because it is never written.
How to sanity-check any no-logs claim
- Does the provider require an email? If yes, there is an identity to link to activity.
- Does it offer account recovery? If yes, an account exists to be seized.
- Where are its servers? Jurisdiction determines what it can be compelled to keep.
- Does the policy list retention periods, or just say no logs?
We cannot prove a negative to you, and nobody can. What we can do is build the service so that there is very little to collect, and then publish exactly what that little is.