Skip to content
← All posts

29 July 2026

Paying for a VPN without telling it who you are

Every VPN sells the same promise: your traffic stops being readable by the network you're sitting on. Then most of them open the signup form and ask for your email address and a card number.

Think about what that record is. Your legal name, a billing address, the last four digits of a card that a bank can tie to everything else you buy, and a mailbox you use for password resets. It sits in a payments database next to a timestamped list of which VPN account it belongs to. The encryption starts working after that.

This is the part of the threat model people skip, and it's the part I'd worry about first if I were a US reader shopping for a VPN. Not because your provider is definitely evil. Because databases get sold, subpoenaed, and dumped, and the one holding your identity is usually not the one you were told to evaluate.

The identity record is the weak link, not the tunnel

Two things happen to customer databases with boring regularity.

The first is commercial. Location and behavioral data about Americans moves through a broker market that operates almost entirely out of view. In January 2024 the FTC issued an order against the data broker X-Mode Social and its successor Outlogic prohibiting the sale of sensitive location data, after finding that data collected through ordinary apps ended up with buyers the users never heard of (FTC press release). That's one enforcement action against one broker. The market it sits in is enormous, and EFF has spent years documenting how ordinary consumer records feed it (EFF on privacy).

The second is failure. VPN providers, including several with tens of millions of installs, have had user records exposed. When those stories break, the headline is almost never "encryption defeated". It's customer emails and payment details. The tunnel held. The signup form didn't.

So the honest question when you evaluate a VPN isn't only "what does it log". It's "what did it make me hand over before it did anything for me at all".

The anonymous path

Pangea has two ways to pay, and from a privacy point of view they are genuinely different products.

Start with the interesting one. You can pay in crypto, Monero included. No email address. No KYC. Nothing that ties the account back to a bank. You don't create an identity with us, because there's no field to put one in. If a court, a buyer, or an attacker comes to us for the personal details behind that account, the answer is that there aren't any to give. Not as a policy we promise to honor. As a consequence of never collecting them.

That's also why we don't keep traffic or connection logs on the two boxes. Data you never wrote down can't be handed over later.

The other path is the normal one, and it behaves normally. Monthly £5.49, annual £54.99, and the payment processor knows what payment processors know. The 3-day trial asks for card details up front, because that's what stops it being farmed. I'd rather say that here than let you discover it at the checkout.

The parts you should hold against us

I run a small VPN, so let me put the limits in the same document as the pitch.

There are two servers, in London and Amsterdam. They're rented VPSes. We don't own the metal, and I'm not going to pretend otherwise, because plenty of providers selling you "our own global network" are renting too and decline to mention it. What we control completely is the software and configuration on those boxes, and what they're set up to remember about you.

If you're in the US, both of those servers are an ocean away. Your latency will show it. I'm not going to sell you speed I can't deliver; the reasons to use us from Texas are the identity story above, the open source client, and the fact that your ISP's view of your browsing collapses into one encrypted flow to Europe. If your priority is the lowest possible ping for gaming, buy something with a server in your state.

We have not been audited by a third party. That costs money we don't have yet, and plenty of the industry's audits are narrower than the marketing built on top of them.

What we have instead is the code. The desktop app is GPLv3 and open source, it generates your keys on the device, and the encryption is 256-bit using WireGuard's ChaCha20. Don't take my word for any of that. Read it, and if I'm lying, the diff is public.

Desktop first, by the way: Windows and macOS, iOS through Shadowrocket, no Android app yet.

The short version

A VPN that holds your name, your card, and your email has a copy of you sitting in a database, and that copy is the thing most likely to end up somewhere you didn't expect. The fix isn't a better privacy policy. It's not being asked in the first place.

If that's the version you want, the crypto path is right there: see pricing.