POLICY / CONTROLLED BETA / UPDATED 2 AUGUST 2026

Privacy means stating exactly what exists.

This policy describes the current NullSec controlled beta, the public website and the contact channel. It separates VPN activity from the limited operational data needed to issue Account Codes and WireGuard configurations.

Current scope: NullSec is a working beta, not yet a generally available paid service. This policy is an operational draft based on the deployed architecture. Legal entity details, final commercial terms and an independent legal review must be completed before a public paid launch.

1. Controller and contact

The current controller is the NullSec VPN project. Privacy, deletion and security requests can be sent to nullsecvpn@proton.me. Do not include browsing history, Account Codes or private WireGuard keys in email.

2. What “no activity logs” means

NullSec does not intentionally create or retain records of browsing traffic, DNS queries, visited destinations, traffic contents, connection start or end times, session duration, source IP addresses or per-user bandwidth history in its application database.

This does not mean invisibility. A VPN changes which network can see your traffic; websites, devices, payment networks and infrastructure providers may still process data under their own policies.

3. Account Codes

NullSec does not require a name, email address or password to activate the VPN beta. The control plane stores only a keyed hash of the Account Code, its creation and expiry dates, status and device limit. The plaintext Account Code is returned once and is not recoverable by NullSec.

4. WireGuard devices

For each authorized device, the control plane stores the WireGuard public key, platform type, assigned private tunnel address, selected node, provisioning state, creation date and a keyed hash of the device token. Private WireGuard keys remain on the device and must never be sent to NullSec.

WireGuard necessarily keeps current peer endpoints, handshakes and byte counters in server memory while the peer exists. NullSec does not copy those values into its application database or an activity-history system. Expired and revoked peers are removed automatically by the reconciliation worker.

5. Website, waitlist and contact channel

The public site has no advertising tracker or analytics SDK. Vercel hosts the site and may process ordinary web-request metadata under its own policy. The public site sets no visitor account cookie. The private administration area uses one strictly necessary, signed session cookie.

If you join the waitlist, NullSec stores your name or pseudonym, email, main platform, region and stated level of launch interest in Supabase. These details are used to plan beta capacity, send essential beta or launch updates and manage invitations. If you submit the separate contact form, NullSec also stores the selected contact category, support level and message. FormSubmit may transmit a notification to the project mailbox hosted by Proton. Records can be permanently deleted from the private admin inbox, and you may request deletion by email.

6. Support payments and benefit delivery

Voluntary development support is currently accepted through Ko-fi and the connected PayPal account. Ko-fi shares the supporter's display name and email with NullSec, and PayPal may share payment-account details under its own policy. NullSec uses the supporter email to record the contribution, communicate about it and deliver any eligible supporter benefit. A privacy email alias may be used, but it must match the email used on the waitlist if automatic matching is expected.

Ko-fi support is separate from the future VPN subscription. The planned self-hosted crypto subscription flow remains disabled. When enabled, it is designed to use a temporary random payment token instead of sending the Account Code to the invoice provider. Blockchain transactions are public and cryptocurrency is not automatically anonymous.

7. Infrastructure providers and limits

The beta currently relies on Hostinger for the gateway, Vercel for the website, Supabase for contact management, FormSubmit for notification delivery and Proton for email. Those providers can process infrastructure metadata under their own policies. NullSec cannot truthfully promise that third-party network operators retain nothing; the goal is to minimize what NullSec itself creates and to reduce provider dependence over time.

8. Security, retention and disclosure

Operational secrets are stored outside source code, administrative access is authenticated, database backups are encrypted, and expired or revoked peers are reconciled without recording traffic history. Account and device records remain while needed to operate or revoke access. Contact records remain until handled or deleted. If NullSec receives a valid legal request, it can disclose only data that actually exists.

9. Changes

Material changes will be dated on this page. NullSec will not silently redefine “no activity logs” to include traffic, DNS or destination histories. Before the public paid launch, this draft requires professional legal review and complete controller information.