No-logs policy

The name is a joke. This page is not. Here is exactly what vpn.golf stores, what it doesn't, and why the architecture makes the difference.

What we do not store

What we do store (and why)

Why the architecture matters

Our control plane is physically separate from the exit nodes that carry your traffic. The exit nodes don't know who you are; the control plane doesn't see where you go. We'd rather under-promise: no independent audit yet (see the transparency page), and an external no-logs audit is on the roadmap as we grow.

Frequently asked questions

No. We keep no traffic logs, no DNS query logs, and no connection timestamps. We store only your account, your device public keys, and an aggregate byte counter for free-tier limits.

No. The exit nodes don't record destinations and run a no-log DNS resolver, and the control plane never carries your traffic. There is no browsing history for us to see or hand over.

Never. Your private key is generated on your device and is never transmitted to us. We only store the public key needed to register you on an exit node.

Not yet — we say so plainly. An external no-logs audit is on the roadmap as the service grows. Until then, our architecture (control plane separated from exit nodes, client-side keys) is designed so there's little to log in the first place.

Three things: your account email and authentication, the public keys of your devices, and an aggregate byte counter that resets each billing window. No destinations, no timestamps, no source IPs.

No. We do not record the IP you connect from or when you connect. There are no connection timestamps and no source-IP records tied to your sessions.

No. Each exit node runs its own DNS resolver with query logging disabled, so the lookups your device makes are resolved and discarded rather than recorded.

The only usage data we keep is an aggregate byte counter per account — a running total with no destinations and no timestamps. It tells us how much data moved, never where it went.

Very little: an account email and aggregate byte totals. Because there are no traffic, DNS, or connection logs, there is no browsing history to produce, even under a valid order.

No. Both tiers ride the same no-logs network. The only difference is that the free tier has a bandwidth cap tracked by the aggregate byte counter; neither tier records your activity.

We separate the control plane from the exit nodes and generate keys on your device, so there's structurally little to log. A claim is a promise; the architecture is the constraint.

Not with a third-party audit yet — we state that openly, and one is on the roadmap. What we can show today is the design: separated infrastructure, client-side keys, and resolvers with logging off.