Privacy Policy

Last updated: 22 September 2026

This policy covers two things we do: security consulting and the VPN service. They handle data very differently, so they are described separately.

If you only want to know what the VPN records, the short answer is on what we log. This page is the fuller statement.

1. Who we are

The service and this website are operated by:

YMRTECH LLC
30 N Gould St Ste R
Sheridan, WY 82801
United States

2. Consulting and enquiries

If you email us or use the contact form, we receive your message and your email address. We hold that only to reply and to keep a record of our own work. We do not sell it, and we do not add you to a mailing list.

Website analytics: this site sets no advertising or tracking cookies and embeds no third-party analytics.

2.1 What the website measures, in detail

That sentence is the whole of it. The measurement is ours end to end: the code that does the measuring is served from this domain, it sends to a collector on this domain, and no third party is involved at any point in it.

These are not only statements. The measurement library is pinned by hash in our public repository, and every build re-checks that the served file is exactly the file we pinned, that the page sets no cookie and leaves nothing in your browser’s storage, and that it contacts nothing except our own collector.

3. The VPN service

3.1 What we collect

Data Purpose Retention
Email address, password hash Account access, service notices Life of the account
Subscription state, Stripe customer identifier Billing and entitlement Life of the account
Device records: device name, tier, assigned tunnel IP, public key Provisioning, revocation, support Life of the account
Aggregate data-volume counters (bytes only) Fair use and abuse prevention Up to 30 days

Card details are entered directly with Stripe and never reach our systems. We do not operate our own payment storage.

3.2 What we never collect

We cannot sell, leak, or be compelled to produce data we do not collect. See what we log for how this is tested rather than merely stated.

3.3 Service providers

We use a small number of processors. None of them receive your browsing data, because we do not have any to give:

Provider Role What they see
Stripe Payments Your payment details and email
Cloudflare (R2) Encrypted backups Our server state, encrypted at rest
SMTP2GO Transactional email Delivery of service emails
Oracle Cloud Server hosting Machine-level infrastructure
Quad9 Upstream DNS resolver for our resolvers The DNS query itself, from our servers — Quad9 is a non-profit resolver that does not retain personal data

We do not sell personal data and we do not share it for advertising.

3.4 Retention

We keep account data while your account exists, because we must be able to provision and revoke your access and to account for the subscription. When you close your account we delete the account record and its devices; encrypted backups roll off within 30 days.

Aggregate byte counters are kept for at most 30 days and then discarded.

3.5 Security

Passwords are stored as keyed hashes. Sessions are stored as keyed hashes so a database disclosure does not yield usable login tokens. Devices authenticate with their own cryptographic keys. Backups are encrypted at rest. Our servers are configured declaratively from version-controlled source, which means the running state of a machine can be reviewed and reproduced rather than trusted.

No system is perfect. If we ever suffer a breach that affects your personal information, we will notify you and the relevant authorities as required by Wyo. Stat. § 40-12-501 et seq., without unreasonable delay.

3.6 Your choices

Wyoming has no comprehensive consumer privacy statute; we extend these rights regardless:

Email us and we will action a request within 30 days. Note the limit of what we can produce: if you ask for “everything you have on me”, the answer is the table in §3.1 — there is no browsing record to hand over.

California residents: because we may collect personal information from California residents, this policy is posted conspicuously and describes the categories collected, as required by the California Online Privacy Protection Act (CalOPPA).

3.7 Children

The service is not directed to children under 13 and we do not knowingly collect their personal information.

4. Changes

Material changes to this policy will be posted here with a new date. Changes to what the VPN collects are also visible in our public configuration history and are described on what we log. Where a change would alter the no-log invariants, it also has to survive the signed daily audit, which re-asserts those invariants on the host and publishes the result.

5. Contact

yannick@ymrtech.com

󰣨 ymrtech@ymrtech | 󰌠 NixOS | 󰍢 UTF-8