Privacy Policy

Last updated: 15 September 2026

This policy covers two things we do: security consulting and the VPN service. They handle data very differently, so they are described separately.

If you only want to know what the VPN records, the short answer is on what we log. This page is the fuller statement.

1. Who we are

The service and this website are operated by:

YMRTECH LLC
30 N Gould St Ste R
Sheridan, WY 82801
United States

2. Consulting and enquiries

If you email us or use the contact form, we receive your message and your email address. We hold that only to reply and to keep a record of our own work. We do not sell it, and we do not add you to a mailing list.

Website analytics: this site sets no advertising or tracking cookies and embeds no third-party analytics.

3. The VPN service

3.1 What we collect

Data Purpose Retention
Email address, password hash Account access, service notices Life of the account
Subscription state, Stripe customer identifier Billing and entitlement Life of the account
Device records: device name, tier, assigned tunnel IP, public key Provisioning, revocation, support Life of the account
Aggregate data-volume counters (bytes only) Fair use and abuse prevention Up to 1 year

Card details are entered directly with Stripe and never reach our systems. We do not operate our own payment storage.

3.2 What we never collect

  • Which websites you visit
  • Which DNS names you resolve
  • The content of your traffic
  • Your ISP-assigned IP address, in connection with your account
  • Connection or session records — when you connected, or for how long
  • Your browsing history, in any derived or aggregated form

We cannot sell, leak, or be compelled to produce data we do not collect. See what we log for how this is tested rather than merely stated.

3.3 Service providers

We use a small number of processors. None of them receive your browsing data, because we do not have any to give:

Provider Role What they see
Stripe Payments Your payment details and email
Cloudflare (R2) Encrypted backups Our server state, encrypted at rest
SMTP2GO Transactional email Delivery of service emails
Oracle Cloud Server hosting Machine-level infrastructure
Quad9 Upstream DNS resolver for our resolvers The DNS query itself, from our servers — Quad9 is a non-profit resolver that does not retain personal data

We do not sell personal data and we do not share it for advertising.

3.4 Retention

We keep account data while your account exists, because we must be able to provision and revoke your access and to account for the subscription. When you close your account we delete the account record and its devices; encrypted backups roll off within 30 days.

Aggregate byte counters are kept for up to 1 year and then discarded.

3.5 Security

Passwords are stored as keyed hashes. Sessions are stored as keyed hashes so a database disclosure does not yield usable login tokens. Devices authenticate with their own cryptographic keys. Backups are encrypted at rest. Our servers are configured declaratively from version-controlled source, which means the running state of a machine can be reviewed and reproduced rather than trusted.

No system is perfect. If we ever suffer a breach that affects your personal information, we will notify you and the relevant authorities as required by Wyo. Stat. § 40-12-501 et seq., without unreasonable delay.

3.6 Your choices

Wyoming has no comprehensive consumer privacy statute; we extend these rights regardless:

  • Access — ask what we hold about you.
  • Correction — ask us to fix it.
  • Deletion — close your account and we delete your account data.
  • Portability — ask for a copy of your account data.

Email us and we will action a request within 30 days. Note the limit of what we can produce: if you ask for “everything you have on me”, the honest answer is the table in §3.1 — there is no browsing record to hand over.

California residents: because we may collect personal information from California residents, this policy is posted conspicuously and describes the categories collected, as required by the California Online Privacy Protection Act (CalOPPA).

3.7 Children

The service is not directed to children under 13 and we do not knowingly collect their personal information.

4. Changes

Material changes to this policy will be posted here with a new date. Changes to what the VPN collects are also visible in our public configuration history and are described on what we log. Where a change would alter the no-log invariants, it also has to survive the signed daily audit, which re-asserts those invariants on the host and publishes the result.

5. Contact

yannick@ymrtech.com

󰣨 ymrtech@ymrtech 󰖣 DARK | 󰌠 NixOS | 󰍢 UTF-8