Skip to content
Kuro

No-logs policy

Draft pending legal review. Values in [brackets] are being finalised.

"No logs" is easy to claim. This page describes how Kuro VPN is built so that the data isn't there in the first place. An independent audit of these claims is planned.

On our VPN servers

  • System logs live in memory only. The servers' journal is configured as volatile and capped at 64 MB. There is no syslog daemon and no log file on disk, so nothing survives a reboot.
  • Our DNS resolver logs nothing. It runs with query logging, reply logging and cumulative statistics off.
  • The firewall never logs packets. Our build process rejects any firewall rule that logs.
  • No packet capture tools are installed.
  • Our server software logs only state words ("connected", "updated"), never your public key, IP address or tunnel address. Its debug mode, used only for hands-on troubleshooting, is switched off afterwards.
  • Peer data is never written to disk. A server knows your device's public key and tunnel address only while you're registered on it. That list is kept in memory and in a RAM-only directory, and is deleted after 24 hours without use.
  • Per-user byte counts exist only on free servers, to enforce the monthly allowance. Paid servers don't read or report per-user traffic, only totals for the whole server.

If a server were seized, it would hold its own private key, plus the public keys and tunnel addresses of devices currently registered on it, which are removed after 24 hours of inactivity. No history and no traffic.

On our API and website

  • Request logs record only the route, the status code, the timing and a random request ID. A test in our build fails if a log line contains anything that looks like an IP address, a key or an account number.
  • Rate limiting uses salted hashes of IP addresses that expire within an hour.
  • The country you sign up from is looked up once and stored; your IP address is not.
  • We record when a device was last used as a date only, not a time. There is no "last connected" timestamp anywhere.
  • Our control plane knows which server each device is currently registered on, and when that registration was created, only for as long as the registration exists.

In our apps

No analytics SDKs. Crash reporting is off unless you turn it on, and reports are scrubbed of IP addresses, keys, account numbers and URLs. Your WireGuard private key is generated on your device and never leaves it.

What we do keep

Your account, devices, subscription status and (free plan) monthly byte totals. See the privacy policy for the full list and how long each item is kept.