Privacy and loggingSeven records exist. Here is every one of them.

Not a policy about how carefully we guard your data — an inventory of how little of it was ever created. A promise to protect a record can be overridden by an order. A record that does not exist cannot be.

access logs24 hours

The inventory

No identity documents · No IP history · No netflow

What exists

The whole schema, and the clock on each row.

This is the same list your client area shows you and the same one we hand a court. If those three ever differ, one of them is a story — so there is only one of them.

Email addressYou may use any address, including a disposable or onion-hosted one. It is never verified against anything except itself. The only way we can reach you Life of the account
Password hashHashed, never the password. A disclosure request for it produces a hash, which is what it is designed to be worth. So you can sign in Life of the account
Balance and ledgerAmounts and dates. Cryptocurrency payments reference a transaction you chose to make on a public chain; we add nothing to it that was not already public. Accounting: what you paid, what you spent Life of the account
Service configurationRegion, specification, operating system image. Not the contents of the disk, which we cannot read and do not hold a key to. To build and run what you bought Life of the service, then 7 days
HTTP access logsRotated and destroyed on a timer, not on request. A request arriving on Thursday for a Monday cannot be met by anyone, including us. Debugging and stopping attacks in progress 24 hours, then destroyed
Support correspondenceWhatever you chose to put in a message. We recommend saying less than feels natural. Continuity across a conversation 90 days after it closes
Interface countersBits per second on a port. Deliberately not netflow: nothing at a resolution that could reconstruct who talked to whom. Capacity planning 13 months, aggregate only

Never created

The list that does the actual work.

Every item here is a category the systems were built not to produce, rather than one we delete when asked. The difference is the whole of it: deletion is a policy somebody can be ordered to reverse, and absence is a fact about the schema.

  • Government identity documents, of any kind, at any tier
  • Your legal name, address, country or telephone number
  • Payment-card details, bank details or any KYC file
  • A record of the addresses you sign in from
  • IP history, session history or device fingerprints
  • Netflow detailed enough to reconstruct who talked to whom
  • Contents of your disks, memory, databases or backups
  • Encryption keys, console keystrokes or screen captures
  • DNS query logs for resolvers we operate

Decisions behind the schema

Each of these costs us something operationally. They are listed with the cost, because a privacy decision that was free is a privacy decision nobody had to make.

No sign-up identity
An email address, and nothing else Costs us the ability to recover an account for somebody who has lost both their password and their email. That is a real support burden and we accept it.
Access logs on a 24-hour timer
Rotated and destroyed, not archived Costs us the ability to investigate anything more than a day old. Every host that keeps ninety days keeps them for exactly this convenience.
Counters, never netflow
Bits per second, not who to whom Costs us fine-grained attack forensics. We can see a port saturated; we deliberately cannot reconstruct a conversation.
No sign-in address history
Not even for your own security Costs you the “new device” alert other services offer. That feature is a location history of you, held by us, and we would rather not hold it.
No analytics, no third parties
No tag manager, no pixel, no CDN font Costs us knowing which pages convert. Every asset on this site is served from this site; nothing you load here tells anybody else you were here.
Cookies only when you act
A session, and a CSRF token on forms Reading the brochure sets nothing at all. There is no consent banner here because there is nothing to consent to.

Getting rid of it

Closing the account erases the account. There is no soft delete.

  1. 01

    Immediately

    The row goes, and the hashes with it

    Email address, password hash, ledger and service records are deleted in one transaction. Not flagged inactive — deleted.

  2. 02

    Within 24 hours

    Any access log mentioning you expires anyway

    On the same timer it always was. Closing the account does not accelerate it and nothing accelerates it, which is the property that makes it worth having.

  3. 03

    Within 30 days

    Backups roll past you

    Encrypted backups cycle out on their own schedule. This is the one place a deleted record briefly persists, and pretending otherwise would be dishonest.

  4. 04

    Permanently

    Nothing is kept for a rainy day

    No shadow copy, no anonymised analytics record, no marketing list. A closed account leaves nothing behind that could be joined back to a person.

Where a statutory retention obligation applies to a particular entity — accounting records, in some of the eight jurisdictions — the minimum kept is an amount and a date with no counterparty. Those obligations bind ledgers, not the identity of who paid, and the identity was never collected in the first place.

The awkward questions.

Can you read my disk?

A hypervisor operator can technically copy the disk of a guest it runs, and any provider claiming otherwise is either misunderstanding their own stack or lying. What we do not do is hold a key to a disk you encrypted, and we do not have contents in the storage tier for the same reason. Encrypt at rest with a key we never see, and the technical answer becomes as strong as the policy one.

Do you keep IP addresses?

They appear in HTTP access logs for 24 hours and then the log file is destroyed by a timer. There is no separate IP history, no sign-in location record and no device fingerprint. Nothing anywhere in the system joins an address to an account after that day has passed.

What about the cryptocurrency payments?

A blockchain is a public ledger and we cannot make it private. What we record is that a payment of a given amount arrived on a given date. We do not cluster addresses, we do not run chain analysis and we add nothing to the public record that was not already in it. Choosing a privacy-preserving asset is a decision you can make on our payments page, and it is the strongest one available to you.

Is there a consent banner because of the GDPR?

No, because there is nothing to consent to. No analytics, no advertising identifiers, no third-party requests of any kind, and cookies are set only when you sign in or submit a form. A banner asking permission to do nothing is theatre, and this industry has enough of it.

What data does support see?

Whatever you put in the message, plus the same account record you can see yourself. Correspondence is kept for 90 days after a conversation closes and then deleted. Our standing advice is to say less in a support ticket than feels natural — it is the one place customers routinely create a record that did not need to exist.

Who else has access?

No third-party processor, no analytics vendor, no CDN in front of the account area, and no support outsourcer. The infrastructure is operated by the entities that own it, which is also the assertion the warrant canary renews every quarter.

How do I verify any of this?

Some of it you can check directly: open the developer tools and confirm that no request leaves this domain, and that the brochure pages set no cookie at all. The retention timers you cannot check from outside, which is why the transparency report publishes what requests produced, and why the canary is signed rather than asserted.

The one thing this site sends elsewhere

Added 29 July 2026

Every page loads one first-party script that posts to /api/h.php on this domain. That endpoint forwards, from our server rather than from your browser, to a counter shared with the other sites this company operates. It is what makes a live visitor count possible, and it is the only thing on this site that leaves it.

What goes: your address, hashed at the far end and never stored raw; the country it resolves to; the user-agent string your browser sends anyway; and the page you are on. What does not: a cookie of any kind, an identifier that survives the visit, your account, or anything you typed.

It returns immediately and does nothing at all if your browser sends Do Not Track. Turning that on in your browser is the switch, and we would rather point at it than bury it.