Transparency

What we keep, where, and for how long. This table is generated from the same source as our admin console.

What is stored where

What is stored where
DataStoredWhereRetention
Account id, login identifier (email or number), plan, payment referencesYesAccount DBAccount lifetime + legal minimum
Device list (name, platform, app version)YesAccount DBWhile device active
Per-account daily token counterCounter onlyValkey (counter only)48 h
WireGuard public key ↔ accountNo— (dedicated-IP leases excepted, disclosed)—
Register / session events per userNo——
Source IP at token issuanceNo——
Source IP at register (connect)No——
Node-level counters (peers, bytes, registers, rejects)AggregatedVictoriaMetrics90 days
Spent-token hashesHash onlyRegional NATS KV48 h
Destination IPs / DNS queriesNo——
Admin actionsYesaudit_events, hash-chained + WORM2 years

Warrant canary

Oct 1, 2026

As of the date below, FlymeVPN has not received any national security letter, gag order or warrant requiring us to hand over user data or to modify our systems.

Last updated: 2026-10-01 · Signed canary text is published here quarterly (placeholder).

Transparency report

Twice a year we publish how many legal requests we received and how many we could answer. Because we do not hold activity data, the answer is always: none.

H2 2026 report — to be published (placeholder).

Independent audit

P4

An independent no-logs audit is scheduled before the public launch of Privacy mode.