Skip to content
Kuro

Transparency

Draft pending legal review. Values in [brackets] are being finalised.

What authorities have asked Kuro VPN for, what we could give them, and a signed statement we renew every month.

Requests for user data

| Period | Requests received | Requests where data was provided | |---|---|---| | Since launch | 0 | 0 |

We update this table every quarter. Requests we can't legally mention are counted in the canary below, not here.

What an order could get

Only what exists. Because Kuro VPN doesn't log connections, DNS queries or the sites you visit, there is no activity history to hand over. What does exist:

| What we hold | What it shows | |---|---| | Your account number and plan | That an account exists and whether it pays | | Country at sign-up | One country, recorded once | | Your devices | Names we generated (such as "Brave Otter"), platform, app version, the date each was last used | | Recovery email, if you added one | That address | | Payment records at Paddle, Google Play or the App Store | Billing details those companies hold, not your activity | | While a device is connected: its IP address, in the VPN server's memory | Where that device is connecting from right now; forgotten 3 minutes after it goes quiet |

The full list, with how long each item is kept, is in our privacy policy.

Warrant canary

No statement has been published yet. The first one goes out when Kuro VPN launches, and then every month.

Each month someone at [COMPANY_LEGAL_NAME] checks this statement and signs it again. If it stops being renewed, or disappears, take that as a signal.

To check a signature yourself: the signed data is the canonical JSON (RFC 8785) of {"type":"kuro-canary-v1","statement":…,"issued_on":…}, the signature is Ed25519, and the public key is the one with the same kid in /.well-known/kuro-keys.json. The raw statement is at /.well-known/kuro-canary.json.

Security

To report a vulnerability, see our security policy.