SHEET 006 · IDENTITY POLICY · WHAT WE ASK / WHAT WE NEVER ASK · REV. B
A no-KYC VPS, and the short list of what we do ask for.
One email address and a crypto payment. That is the entire onboarding. Everything else on this page is the rest of the answer: what we keep, how long we keep it, and why 'no KYC' is not 'no rules'.
01 — The lists
What we ask for, and what we never will
Two lists, both complete. If it is not on the first one, we do not ask for it. If it is on the second one, we never will.
What we ask for
01An email address
Credentials, invoices and the six-digit sign-in code go there. One inbox, everything about your account, yours to delete on the way out.
02Cryptocurrency, settled in minutes
The payment proves ability to pay without proving identity. Twenty-four assets, quoted in euros, rate locked 60 minutes.
What we never ask for
- Government identity documents
- Selfies or liveness checks
- Utility bills or proof of address
- Phone number verification
- A card on file or a billing name
- Social accounts or referrals
02 — The retention table
Everything we store, and for how long
A complete inventory of customer data. If it is not in this table, we do not have it — there is no 'other' column, no analytics bucket, no data lake with your name in it.
| What | How long | Why it exists |
|---|---|---|
| Email address | Until the account closes, then deleted within 24 h | Sign-in and delivery of credentials and invoices. |
| Invoices | 10 years | Estonian accounting law requires it. No payment identity is attached to them. |
| Server configuration | Until the instance is destroyed | So your server survives restarts, moves and our mistakes. |
| NetFlow metadata | 72 hours | Abuse investigations only. No payloads are stored, ever. |
| Support tickets | 24 months | So the engineer who helped you in March remembers it in May. |
| Payment identity | Never collected | Payments are handled by a processor; we see a chain, not a person. |
| ID documents | Never collected | Documents that do not exist cannot be leaked, subpoenaed or lost. |
| Phone number | Never collected | Nothing on this service needs a phone. Neither do you. |
Account closure starts a deletion sweep: servers, snapshots, backups, sessions and metadata are destroyed within 24 hours. The email address goes when you ask; invoices stay because the law outranks the delete button.
03 — Where the line sits
No KYC is not no rules
Privacy is a product decision. Abuse is a safety decision. The two never met on this page, and they will not meet on your invoice either.
✓Phishing, spam, malware, botnet command-and-control and CSAM are terminated immediately, without refund and without appeal — privacy is not a licence to harm people.
✓Sanctions and law-enforcement requests are answered the same way everywhere: we have almost nothing to hand over, we publish what we did hand over, and we never had the documents other companies keep 'just in case'.
✓The acceptable use policy is two pages long, written in the same plain language as this one, and it is part of the contract you sign with an email address and a transaction.
04 — Questions
Asked often, answered in writing
The eight questions closest to being asked every day — answered in writing, so the answer outlives the conversation.
Do I really not need to verify my identity?
How does an email address open an account?
What about anti-money-laundering rules?
Why crypto instead of cash or a bank transfer?
Do you respond to data requests from authorities?
Is Monero accepted, and can I pay over Tor?
What happens to my data when I close the account?
No KYC — so anything goes?
The whole identity section of checkout
One email field. Everything else on this page is the fine print, and it is all here so you never have to read fine print again.