Identity documents
None are requested at any point — not at signup, not at payment, not at cancellation.
A privacy policy is worth exactly what its inventory is worth. This one is short enough to read in full, which is the only claim it makes.
The inventory
Each row exists because the service cannot be delivered or lawfully invoiced without it. Nothing here was kept because it might be useful later — the no-KYC page walks the same ground from the signup end, stage by stage.
| What | Kept for | Status | Why it exists |
|---|---|---|---|
| Email address | While the account exists | Held | The only way to reach you. Never verified against anything, and a forwarding alias is fine. |
| Invoice records | 5 years | Held | Moldovan accounting law requires it. Amount, coin, date. No name is attached, because none was ever given. |
| Connection metadata | 24 hours | Held | Source address and timestamp of panel and API logins, kept to stop credential stuffing. Rotated out, not archived. |
| Support tickets | 90 days after closing | Held | So a follow-up has context. Purged on schedule, and earlier if you ask. |
| Service inventory | While the service exists | Held | Which machine, which plan, which address. The minimum needed to run it and to bill it. |
Retention is counted from the event, not from the end of the month or the quarter. The 24-hour window on connection metadata has been shortened twice since we opened and has never been lengthened.
Never created
A promise to delete quickly survives nothing. A statement that the data was never created survives a court order, which is the only test that matters.
Identity documents
None are requested at any point — not at signup, not at payment, not at cancellation.
A payment identity
Crypto only. No processor holds a legal name for your account, and no card network can be asked for one.
Traffic content
We do not inspect, mirror, sample or index what crosses your port. No DPI is deployed, and none is planned.
Disk contents
Encrypted or not, we do not read them. There is no backup you did not order and pay for.
A phone number
Never collected, so never disclosed. SMS is not used for anything, including recovery.
Browsing or usage profiles
No analytics, no third-party scripts, no cookies beyond the session that keeps you logged in.
This page, right now
Everything else on this page you have to take on trust until a court tests it. This part you can verify before you finish reading the sentence.
No analytics, first or third party
No Google Analytics, no Plausible, no self-hosted Matomo. We do not know how many people read this page, and we have decided we can live without knowing.
No third-party requests at all
Fonts, styles, scripts and images are served from this domain. Nothing on this page contacts another host, so nothing on this page tells another host you were here.
One cookie, and only once you log in
A session cookie for the customer panel. No consent banner, because there is nothing to consent to — the reason those banners exist is the tracking we do not do.
No web server access logs
nginx writes them to /dev/null on the public site. There is no file to subpoena, no file to leak, and no file to forget to rotate.
The operative text. Written to be read rather than to be defensible, which is why it names the law it operates under instead of gesturing at “applicable regulations”.
VPSOffshore SRL, Chișinău, Republic of Moldova. Registered in the Republic of Moldova. We are the controller for everything described here, and there is no processor behind us: the hardware is ours, the building sells us space and power only, and no part of the platform is subcontracted.
Privacy questions and access requests are raised from the customer panel, which is also where you upload a public key so that every reply is encrypted to it. Ours is published on the canary page.
Processing is governed by the personal-data law of the Republic of Moldova: Law No. 133/2011 until 22 August 2026, and Law No. 195/2024 from 23 August 2026, which repeals it and aligns Moldovan law closely with the GDPR. Moldova is also a party to the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (ETS 108).
We are not established in the European Union and do not target the Union, so the GDPR does not apply to us of its own force. We nevertheless answer access, correction and deletion requests to the same standard, because refusing would be a worse look than the effort is worth.
There is no data-retention mandate in Moldovan law obliging a host to keep traffic or subscriber records. The 24-hour figure below is our own choice, not a floor set by a statute, which means we are free to shorten it and have done so twice.
Five categories, listed in full in the table above this document. In summary: an email address for as long as the account exists; invoice records for five years because Moldovan accounting law requires it; connection metadata for 24 hours; support tickets for 90 days after closing; and the service inventory needed to run and bill what you ordered.
Nothing in that list was chosen for its usefulness to us. Each entry exists because the service cannot be delivered or lawfully invoiced without it, and each has been shortened at least once since we opened.
No identity documents at any stage. No payment identity — payment is crypto only, so no processor holds a legal name for your account. No traffic content: no deep packet inspection is deployed, no mirror port exists, and nothing is sampled or indexed. No disk contents. No phone number. No behavioural profile.
These are not undertakings to delete things quickly. They are statements that the data is never created, which is the only version of the promise that survives a court order.
Performance of the contract you entered into, for the email address and the service inventory. A legal obligation, for invoice records. Our legitimate interest in keeping the platform reachable, for the 24 hours of connection metadata — narrowly, and it is the reason the window is 24 hours rather than 24 days.
Nothing is processed on the basis of consent, because nothing here is optional enough to need it. There is no marketing list, and no email you did not ask for.
Nobody. There is no analytics provider, no advertising network, no CRM, no error-reporting service, no email marketing platform and no customer-support SaaS. Tickets live on our own hardware, in the same racks as everything else.
The single exception is disclosure compelled by an order of a Moldovan court, which is described in the law enforcement policy and counted in the transparency report.
You may ask what we hold, ask for it to be corrected, ask for it to be erased, and object to processing. Raise it from the panel, signed in as the account holder, and you will get an answer within 30 days — in practice within a working day, because the answer is short.
Erasure is immediate for everything except invoice records, which the accounting obligation keeps for five years. Those contain an amount, a coin and a date, and no name.
Full-disk encryption on every machine that holds account data. Panel access over TLS 1.3 only. Ticket contents encrypted to your PGP key when you upload one. Administrative access limited to named engineers with hardware tokens, and logged.
We do not claim this makes a breach impossible. It makes the amount of interesting material in a breach very small, which is a more useful property and the one we optimise for.
A breach affecting customer data is announced on the status page and by email within 72 hours of us establishing it, whether or not any law requires the notice, and whether or not it reflects well on us. The notice says what was taken, when, and what we do not yet know.
Material changes are announced by email 30 days before they take effect, and the previous version stays reachable. A change that lengthens a retention period is material by definition.
If a sentence in this document is vaguer than it needs to be, say so from the panel and we will tighten it. Vagueness in a privacy policy is almost always deliberate, and we would rather not have any of ours be.
Version 1.3 · last substantive change 2026-07-01 · in force since 2026-07-22. Material changes are announced by email 30 days before they take effect, and the previous version stays reachable.
The honest edges
Every privacy claim has an edge. These are ours, stated rather than buried.
What happens under an orderOn a dedicated server, no — it is your hardware for the term and the disks are yours to encrypt. On a virtual server, an administrator with hypervisor access could technically read an unencrypted guest disk, and any provider claiming otherwise about a VPS is lying to you. That access is limited to named engineers with hardware tokens, it is logged, and it is used for hardware faults. If that residual risk matters to your threat model, encrypt the guest — we will not ask for the key, and we could not produce it.
No, and we do not use the phrase. Panel and API logins leave an address and a timestamp for 24 hours, because without that we cannot stop somebody brute-forcing your account. What does not exist is web server access logs on the public site, traffic logs of any kind, and any record of what crosses your port. “No logs” as a slogan usually means the second list; we would rather publish both.
That a service is at that address, in that building, in Chișinău — which is public and unavoidable for any host anywhere. It does not connect that address to you: the link between the address and an account exists only in our inventory, and getting it requires a Moldovan court order. If you want the address not to point at you at all, put a proxy in front; several customers run their own.
Disks are wiped when a service is reclaimed, before it is reissued. The account record and email address are erased on request immediately, and automatically 90 days after the last service ends. Invoice records remain for five years because accounting law requires them — an amount, a coin and a date, with no name attached, because none was ever given.
The same list, tested
The law enforcement page describes the process, and the canary states each week that nothing has come through it.