개인정보 처리방침

최종 업데이트 2026-09-17

이 문서는 저희 팀이 작성하고 법률 자문이 검토 중인 초안입니다. 서비스가 어떻게 동작하도록 설계되었는지 설명합니다.

The short version

Kaza VPN is built so that there is nothing to hand over about what you do online. We keep no record of the sites you visit, the apps you use, the addresses you connect from, or how much data you move. We keep what is needed to run your account and bill you, and nothing more. This page lists all of it.

What our servers do not keep

  • No browsing history, DNS queries, or destination addresses.
  • No record of which VPN server you used at what time, and no history of connections.
  • No bandwidth or traffic volume per person.
  • No IP address of yours in any log. Our request logs contain the method, path and status of a request only.

VPN servers run with logging switched off and their temporary memory is cleared on restart. While a device is connected, the server necessarily holds its public key and the address it is talking to in memory; that information disappears when the device disconnects.

What we store about your account

  • Email address and a salted hash of your password (we cannot see the password itself).
  • Devices you add: the name you give them, the platform, and the public key each one uses to encrypt its tunnel.
  • Your plan and, if you pay, an identifier that links your account to your customer record at Stripe, our payment processor. Card details never reach us.
  • The current assignment of a connected device to a server (which server, which tunnel address, since when). It is deleted the moment you disconnect. There is no history of past assignments.

What we store about our network

Servers report their own health every few seconds: load, number of connected devices, packet loss. These figures are per server, never per person, and are kept for 7 days.

Session tokens and rate limits

When you sign in, the app receives a session token; we keep a hash of it that expires when it is idle. To protect the service from abuse we keep short-lived counters keyed by network address for sign-in attempts; they are deleted ten minutes after the last request.

Payments

Payments are handled by Stripe. Stripe's privacy policy applies to the payment itself. We receive confirmation that a subscription is active, past due or cancelled, and nothing about your card.

Backups

Backups of the account database are encrypted before they leave our server, with a key that is not stored on any server, and are kept for 30 days. They contain exactly what the database contains: the account data listed above.

Requests from authorities

Because of how the service is built, a valid legal request can only produce: whether an email address has an account, its plan and billing history, its device public keys and, if a device is connected at that moment, which server it is on. It cannot produce who used a given server address at a given time in the past, because that is never written down. We respond only to valid process in our jurisdiction and publish a count of requests received each quarter.

Retention and deletion

  • Account data: until you delete your account (write to [email protected]; we complete it within 30 days).
  • Device assignment: until disconnect.
  • Server health figures: 7 days.
  • Backups: 30 days.

Cookies and analytics on this website

This website sets no tracking cookies and uses no third-party analytics. Signing in on the account page stores a session token in your browser for that tab only.

Contact

Questions about privacy: [email protected].