What we keep, what we don't, and for how long.
Written to be read, not to cover ourselves. If anything on this list changes, this page changes first.
Process errors, service starts and crashes
Count of active peers per node
Aggregate bandwidth per node and region
All aggregated per server: enough to run the network, not to watch you.
Client source IP
Domains or destinations visited
Per-user usage as a time series
Our metrics cannot answer "what did this user do?". By design.
Usage and billing
Your total usage does exist: it is a billing figure tied to your anonymous key, stored while your plan is active. It is not a time series and is never crossed with your activity.
Your "account"
An email and a password you choose. We ask for no name or phone; the password is stored only as a hash. If you pay by card, the payment processor knows your payment details — we only receive confirmation that your account is credited.
Legal requests
We can only hand over what we have: aggregate per-server metrics and the billing status of a key. We cannot link traffic to people, because that link is never recorded.
Changes
Any change to this policy is announced 90 days in advance and logged in the public history of this page.