Privacy policy

Last updated: 2026-08-30

This page describes which personal data we process, why, on what legal basis, how long we keep it and what rights you have. The technical detail of what the network servers actually write is on a separate page, "What data we keep".

Data controller

The controller of your personal data is the operator of the Logrus service. A legal entity is being registered; its details will be published here once that is complete. For any question about data, including exercising the rights below, write to support@logrus.space. We have not appointed a separate data protection officer: the same mailbox handles these requests.

Purposes, legal bases and retention

We process the minimum set of data the service cannot run without. For each purpose below we state the legal basis under GDPR Art. 6 and how long the data is kept.

  • Providing access to the service: email or account number, password hash, subscription contents, list of bound devices. Basis — performance of a contract (Art. 6(1)(b)). Retention — while the account exists, plus 30 days after deletion.
  • Taking payments and accounting: amount, currency, payment method, the provider's payment identifier, invoice history. Basis — performance of a contract and legal obligation (Art. 6(1)(b), 6(1)(c)). Retention — 5 years from the transaction.
  • Running the network, diagnostics and anti-fraud: session records (account identifier, node, connecting IP address, start and end time, bytes transferred) and authentication events. Basis — legitimate interest in keeping the network working and protecting it from abuse (Art. 6(1)(f)). Retention — 90 days, then automatic deletion.
  • Support: chat and email correspondence. Basis — performance of a contract and legitimate interest (Art. 6(1)(b), 6(1)(f)). Retention — 12 months from the last message.
  • Product analytics and crash reports: de-identified usage telemetry and error stack traces. Basis — consent (Art. 6(1)(a)), requested through the banner; without consent no counters are loaded. Retention — 12 months.
  • Service email (subscription expiry, changes to these terms, payment receipts): email address. Basis — performance of a contract. Marketing email is sent only on separate consent, with one-click unsubscribe in every message.

What we store

  • Email or account number and a password hash — so you can sign in.
  • Subscription contents and the list of bound devices — so plan limits work.
  • Payment history: amount, date, method, the payment provider's identifier.
  • Operational session records: account, node, connecting IP, start and end time, bytes transferred — kept 90 days.
  • Support correspondence.
  • De-identified product telemetry — only with your consent.

What we do not store

  • The content of your traffic — we neither decrypt nor retain it.
  • The domains and addresses you reach through the tunnel.
  • Card details — those are entered on the payment provider's side and never reach us.
  • Identity documents — we do not ask for them.

Who we share data with

We do not sell data and do not pass it to third parties for their own purposes. The processors we use act under contract and only on our instructions:

  • Payment providers FreedomPay (cards, SBP), Cryptomus (crypto) and Stripe (international cards) — they receive the amount, the order identifier and whatever you enter directly with them.
  • Sentry — crash reporting for the apps and the website.
  • PostHog — product analytics, loaded only with your consent.
  • Chatwoot — the support chat on the website and in the app.
  • Hosting providers for network nodes and control-plane servers — they supply infrastructure and have no access to traffic content.
  • Government authorities — only under a legally binding request valid under applicable law, and only to the extent of the data we actually hold.

International transfers

Network nodes and some processors are located outside the European Economic Area. Transfers rely on the European Commission's Standard Contractual Clauses, or on adequacy decisions where these apply. You can request the list of countries in which your data is processed at support@logrus.space.

Your rights

If GDPR applies to you, you have the rights listed below. We respond within 30 days; identity is verified through the email address bound to the account.

  • Access to your data and a copy of it (Art. 15).
  • Rectification of inaccurate data (Art. 16).
  • Erasure of your account and associated data (Art. 17) — a button in your account; payment records are kept for the period tax law prescribes.
  • Restriction of processing, and objection to processing based on legitimate interest (Art. 18 and 21).
  • Portability of your data in a machine-readable format (Art. 20).
  • Withdrawal of analytics consent at any time, with no effect on your access to the service (Art. 7(3)).
  • Complaint to the supervisory authority where you live or work (Art. 77).

Users in Russia

If you are in Russia, processing of your data falls under Federal Law No. 152-FZ. We collect data with the consent you give at sign-up, process it as described above, and share it with no one beyond the processors listed. Account and payment data are stored on servers outside the Russian Federation — take that into account when deciding whether to register. You can withdraw consent and delete your account in your account settings or by writing to support@logrus.space.

Warrant canary

As of 2026-08-30 we have received no request from any government authority for user data, and no order prohibiting us from disclosing that such a request was made.

This statement is updated by hand and carries an explicit date — it does not print today's date by itself. If the date has not moved in a long time, treat that as the signal it is and do not rely on the statement.

Data questions

support@logrus.space — data subject requests, account deletion, data export, withdrawal of consent.