Transparency
What we keep, where, and for how long. This table is generated from the same source as our admin console.
What is stored where
| Data | Stored | Where | Retention |
|---|---|---|---|
| Account id, login identifier (email or number), plan, payment references | Yes | Account DB | Account lifetime + legal minimum |
| Device list (name, platform, app version) | Yes | Account DB | While device active |
| Per-account daily token counter | Counter only | Valkey (counter only) | 48 h |
| WireGuard public key ↔ account | No | — (dedicated-IP leases excepted, disclosed) | — |
| Register / session events per user | No | — | — |
| Source IP at token issuance | No | — | — |
| Source IP at register (connect) | No | — | — |
| Node-level counters (peers, bytes, registers, rejects) | Aggregated | VictoriaMetrics | 90 days |
| Spent-token hashes | Hash only | Regional NATS KV | 48 h |
| Destination IPs / DNS queries | No | — | — |
| Admin actions | Yes | audit_events, hash-chained + WORM | 2 years |
Warrant canary
Oct 1, 2026As of the date below, FlymeVPN has not received any national security letter, gag order or warrant requiring us to hand over user data or to modify our systems.
Last updated: 2026-10-01 · Signed canary text is published here quarterly (placeholder).
Transparency report
Twice a year we publish how many legal requests we received and how many we could answer. Because we do not hold activity data, the answer is always: none.
H2 2026 report — to be published (placeholder).
Independent audit
P4An independent no-logs audit is scheduled before the public launch of Privacy mode.