What we log

This page states exactly what the VPN service records. It is deliberately short, specific, and written so that every claim in it can be checked against our infrastructure rather than taken on trust.

The claim, in one line: we keep no activity logs.

We do not record which websites you visit, which DNS names you look up, what you download, or who you talk to. We do not keep a record of when you connected.

We are equally precise about what we do hold, because “we keep no logs” is only meaningful when the exceptions are named.

What we do not keep

   
Your browsing history Not recorded.
The DNS names you resolve Not recorded — on any tier. The resolver that answers you runs with its query log disabled and its statistics disabled.
Your traffic content Encrypted end to end. We carry it; we cannot read it.
Your original IP address We do not store your ISP-assigned address in connection with your account.
Connection times / session records We do not keep a record of when you connected or disconnected.
Your device’s real network Not recorded.

What we do keep

Some data is unavoidable: you pay us, and you have an account.

Data Why it exists Retention
Email address, password hash Your account; you cannot log in without it Life of the account
Subscription and payment record Billing. Card details are handled by Stripe and never reach us Life of the account
Device records — device name, tier, the tunnel IP we assigned you, your public key Required to provision and revoke your access. This is configuration, not activity Life of the account
Aggregate data-volume counters Used to keep the service fast and fair (see fair use in our terms) and to stop abuse. These are byte counts only — they contain no destinations, no DNS and no browsing information Currently up to 1 year, per device

On the last row. The counters show how much you transferred, not what. A byte total cannot be turned back into a browsing history, and it is never combined with destination data because we do not have any. We disclose it here because a policy that hides a meter is worse than one that explains it.

Server logs

Our servers produce ordinary operating-system logs — service starts and stops, crashes, errors, deployment records. These are:

  • kept for 14 days;
  • never contain customer traffic or DNS data;
  • asserted to contain no client-tier addresses by the automated audit below.

How you can verify this

You do not have to take our word for it:

  1. Our infrastructure is declarative and its configuration is public. The servers are built from version-controlled source; the relevant parts are published at git.ymrtech.com. Nothing is hand-configured on a running machine.
  2. The no-log property is tested, not promised. The service continuously asserts its own behaviour: a real DNS query is sent through each resolver and then the system checks that nothing was written. If a log ever appears, the check fails and the change is rejected — it cannot reach production silently.
  3. We publish an audit. A scheduled job verifies the configuration of every resolver and reports the result. (This is being added; the signed report will be linked here.)

When we are forced to hand something over

We can only disclose what we hold, and we hold what is listed above. We cannot produce browsing history, DNS records, or connection logs, because they do not exist.

We will:

  • notify the affected account unless legally prohibited from doing so;
  • publish a warrant canary — a signed statement, periodically renewed, at a stable address — recording how many demands we have received.

(The canary is being added alongside the audit.)

What we cannot protect you from

Honesty matters here too. A VPN hides your traffic from your network provider. It does not protect you from:

  • malware on your own device;
  • logging in to an account that knows who you are;
  • a browser using its own DNS (DNS-over-HTTPS) in a way your device does not route through the tunnel — our privacy tier exists to prevent that, and the portal includes a leak test;
  • anything you do after you disconnect.

Changes

If this page ever changes in a way that expands what we collect, the change will be described here, in the public configuration history, and — where the change touches the no-log invariants themselves — it will show up as a change in the signed daily audit rather than only in prose. It will not be made quietly. The audit’s own generator is not public source; the boundary and what it costs you are described on the audit page.

Contact: yannick@ymrtech.com

󰣨 ymrtech@ymrtech 󰖣 DARK | 󰌠 NixOS | 󰍢 UTF-8