We publish this annually because a no-KYC host that never talks about legal process is either lying or has not been asked yet. We have been asked.
| Year | Requests | Complied | Refused | Data produced |
|---|---|---|---|---|
| 2025 | 14 | 6 | 8 | Email address, invoices, 72 h NetFlow |
| 2024 | 11 | 5 | 6 | Email address, invoices |
| 2023 | 9 | 4 | 5 | Email address, invoices, 72 h NetFlow |
The test we apply
We respond to an order that is valid in the jurisdiction where the server physically sits. Not where the company is registered, not where the requester is, not where the complainant would prefer. An American subpoena for a machine in Chișinău gets a polite letter explaining the correct route.
Why the answers are short
Because we hold almost nothing. An email address the customer chose, invoices with a company name we never verified, the configuration of the instance, and seventy-two hours of NetFlow-level metadata. No identity documents, no payment identity, no phone number, no address. Several requests have been withdrawn once the requesting authority understood how little there was to collect.
Notification
We tell the customer when a request touches their account, unless a court explicitly bars us. In 2025 that applied to two of the six we complied with; the other four customers were notified within 48 hours.
The strongest privacy guarantee is not a promise. It is an empty directory.