Private beta: CloakiVPN is not yet open to the public — new sign-ups are by invitation only.

Privacy policy

CloakiVPN is built so there is as little about you to keep as possible. This page describes exactly what exists.

No identity

Signing up creates a random account number. We do not ask for an email address, a name, or a password. The number is stored only as a salted, keyed hash — a database leak alone cannot recover it.

No activity logs

We do not log source IP addresses, destinations, DNS queries, or any record of which location a device connects to. Relay servers keep their logs in memory only; they are erased on reboot and never written to disk.

What we store

Location unlinkability

Every device key is provisioned on every server, so the system has no record — and no way to determine — which location any device uses. This is structural, not a policy choice.

What a VPN cannot do

Everything above is about what we know. This is about what somebody else can work out regardless, and no VPN can fix it: an observer who can watch both the traffic entering a server and the traffic leaving it can match the two by their timing and size, without breaking any encryption and without our help. That means a network operator or anyone with that vantage point can potentially tell that a particular connection is yours.

Defending against an adversary that powerful takes routing through multiple servers in different jurisdictions, or sending decoy traffic to hide the pattern. We do neither today — CloakiVPN is a single-hop VPN. It moves your traffic away from your internet provider and hides your address from the sites you visit, which is what most people need it for. It is not designed to protect you from an adversary who is already watching the whole path.

Payments

You pay on pay.cloakivpn.net, a page that does nothing else. The card fields on it are Stripe's own secure fields, so card details go straight from your browser to Stripe. We never see or store them.

That page is the only place we load anyone else's code: Stripe's script, which Stripe requires to be loaded from their servers. It runs on its own address on purpose, so it can never reach your account session or the WireGuard keys your browser generates on the account page. While the payment form is open, Stripe's script also collects device and browsing signals from that page, which Stripe uses to detect fraud. Stripe asks for an email address for its receipt. Stripe's payment notification to our server includes that address, and we neither store it nor log it. We have turned off Stripe's "Link" wallet, which would remember your details across other shops.

Be clear-eyed about what paying by card means: Stripe and your bank know who you are, and nothing we do changes that. What we can control is whether our identifiers extend that link, so we keep them out of it. When you buy time we hand Stripe a single-use random reference — never your account number, never our internal account id, not even the duration. That reference is deleted the moment your payment is credited, so the copy Stripe keeps afterwards no longer resolves to anything here.

What remains is our refund record, which holds Stripe's payment identifier alongside your account for 180 days — the chargeback window. During that period, somebody holding both our records and Stripe's could connect a payment to an account. After 180 days the record is deleted and that link is gone for good.

We do not yet offer a payment method that avoids this entirely. Cash and cryptocurrency are the usual answers and we do not accept them today. If genuinely unlinkable payment matters to you, a card cannot provide it — and we would rather say so plainly than imply otherwise.

Contact

Questions about privacy? See the FAQ.