The plain-English version of our Privacy Policy - what we actually log, what we don't, and how the system is built underneath. Nothing here overrides the Privacy Policy; this just explains it without the legal phrasing.
The actual, unmodified WireGuard protocol - not a proprietary or "WireGuard-inspired" tunnel. Open, audited cryptography, not something we rolled ourselves.
We never log or inspect which sites you visit, the content of your traffic, or your DNS queries - technically not possible to disclose what was never recorded.
Connect/disconnect timestamps, which server, and billed duration - enough to bill accurately and investigate abuse, nothing about what you did while connected.
We don't sell or share your data with advertisers or data brokers, ever - free tier is ad-supported by third-party ad networks shown to you, not by selling your browsing data.
Your device encrypts traffic locally with WireGuard, sends it to whichever server you picked, and that server forwards it to the internet under its own exit IP. The server never decrypts or inspects the contents of that traffic to log it - it just routes packets. DNS-level ad/tracker/malware blocking (on paid tiers) works the same way: a resolver checks each domain lookup against a blocklist and returns nothing for a match, without recording which domains you queried.
Full detail, retention periods, and your rights are in the Privacy Policy.
Don't take our word for the "no leaks" part - run our own WebRTC leak test or an independent one (ipleak.net, browserleaks.com) while connected. Check current uptime on the status page, and see our standing legal-request disclosure on the transparency page.