All systems operational 6 offshore regions No-KYC checkout
SP·09 — LEGAL

Privacy policy

Last revised 2026-06-10 Applies to servprivacy.io SP-LEGAL/PRIV

The legal version of our no-KYC page: an exact inventory of what we hold — because "we value your privacy" is not an inventory.

1. The principle

We sell compute, not your identity. The cheapest way to protect customer data is to never hold it, so this policy enumerates the little we do hold, why, and for how long. Where EU law applies to a region we operate in, processing rests on necessity for the contract (GDPR art. 6(1)(b)) — not on consent banners, of which this site has none, because there is nothing to consent to.

2. What we never collect

  • Name, postal address, or government identification of any kind.
  • Phone number.
  • Payment cards or bank details — no rail for them exists here.
  • Analytics, fingerprinting, advertising pixels or third-party scripts. Every byte of this site is served from our own origin.
  • Email — unless you choose an email address as your handle or as your reply channel, there is no field for one.

3. What we hold, exactly

  • Account — your handle and a hash of it used as the account key; an argon2id password hash; sha256 hashes of your recovery codes; a TOTP secret if you enabled two-factor; timestamps for account creation and password changes.
  • Money — your balance and a ledger of balance movements: timestamp, amount, reason, order reference.
  • Orders — plan, location, OS, period, addons, optional hostname, status timestamps; for top-ups, the payment metadata the payment rail returns (coin, deposit address, amounts, transaction hashes); and the IP address that created the order, kept for fraud defence.
  • Operations — web server access logs, rotated every 14 days; contact-form rate-limit counters keyed by a hash of the sender IP, expiring within the hour.

4. Payment privacy

Payments are crypto-only and flow through our payment orchestrator — the one third party in the pipeline, and it learns an invoice, not an identity. No card processor, no bank, no payment KYC. Whatever a public blockchain records is beyond anyone's power of deletion, ours included; if transaction-graph privacy matters to you, pay in Monero — it is a first-class option here, not a grudging one.

Refunds leave the same way money arrived: as crypto, to an address you give us at refund time. We do not store payout addresses between uses.

5. Cookies

One cookie exists: the session cookie (sp_sess), set when you sign in and at no point earlier. It is Secure, HttpOnly and SameSite=Lax, and it identifies a session, not a person. Browsing the site signed out sets nothing at all. Fonts, styles and scripts are first-party static files — there is no CDN to log your visit on our behalf.

6. Retention and deletion

  • Access logs: 14 days, then gone.
  • Orders never paid: purged after 48 hours.
  • Account file and ledger: kept while the account is open. Ask us to close it through the panel or the contact form and both are deleted within 30 days — except records that are evidence in an active dispute or that hosting-jurisdiction law requires us to keep.

7. Disclosure

We do not sell, rent, share or "enrich" customer data; there is no marketing department to feed. Disclosure happens in exactly one case: a verified order from a court of competent jurisdiction over the relevant operation. What such an order can obtain is limited to the inventory in section 3 — which is the point of section 2.

8. Your controls

From the panel: change your password, rotate recovery codes, enable or disable TOTP. Through the contact form: export or deletion requests for your account data. We answer on the channel you leave — we could not email you unprompted even if we wanted to.

Other legal documents

Questions about a clause?

Ask through the contact form — a human operator answers on the channel you leave, not an auto-responder.

Contact us