Skip to content

Every VPN says "no logs". Here's ours, itemised.

Pangea keeps no record of what you do online: no browsing history, no DNS queries, no connection times, no bandwidth figures, no IP addresses. What we do hold is short enough to fit on one page, so the whole of it is on this one. An email address if you signed up with one, payment dates, and a public key for each device. Fund an account with Monero and the first two never exist.

Last reviewed 14 August 2026

What we keep, and what we don't

Never recorded

What you do online
The sites you open, the DNS lookups that got you there, and everything inside the tunnel. None of it is inspected, counted, or written down.
Your sessions
When you connect, which server you picked, how long you stayed, how much you moved. Nothing writes any of it down, and there is no session table in the database to read it out of.
The address you connect from
While a tunnel is up the server has to know where to send your packets back, the same as any network. That lives in memory, never touches disk, and is gone when you disconnect.
Web server request logs
Access logging is switched off on our web servers, and our API records nothing beyond a path and a status code. Your IP is used to rate-limit the request in front of it, then dropped.
An activity trail on your account
No record of when you signed in, from where, or what you clicked in your dashboard. Nothing in the database has a column for it.

Stored, and why

Your email address
Only if you signed up with email or Google. It is how you sign back in, and how we reach you about the account. An account funded with Monero has no email at all.Kept: Until 30 days after you close the account
Payment records
By card: a Stripe customer reference and your plan dates. Card numbers never reach our servers. Stripe holds those. By crypto: the invoice amount, currency and date. No wallet address of yours is stored here.Kept: 7 years, as HMRC requires
One row per device
A public key, the tunnel address we route to it, the name you gave it, and the day you added it. The public key is what makes the tunnel work; the name is so you can tell your laptop from your phone.Kept: Until you remove the device
Anything you send us
Your name, email and message when you use the contact form, so there is something to reply to.Kept: 24 months
Anonymous page counts
On the public pages only, through analytics we host ourselves. No cookies, no stored IP, nothing tied to an account, and it does not run on your dashboard, at checkout, or on the sign-in page.Kept: Aggregate figures only

This is the plain-English version. The Privacy Policy is the binding one, and it lists the same data in legal language. Read the Privacy Policy

Why this isn't just a promise

A policy is a sentence, and sentences get rewritten. These three would take new code, a new release, and you agreeing to install it.

Your keys are made on your device

The app generates your encryption keys locally and sends us only the public half. The private key has never been on our side of the wire, so there is nothing on our side that could read your traffic even if someone insisted.

The servers never learn who you are

A VPN server receives a public key and a tunnel address. Not your email, not your account, not your name. We never send them, so a seized machine has nothing to give up but a list of keys.

There is nowhere to put it

No audit log, no provisioning log, and no timestamp anywhere for when a device last connected or an account was last set up. Recording any of that would mean adding the columns, writing the code that fills them, and shipping a release.

Read why a logging policy is worth less than the client's source

What could still reach you

A court order can compel what we hold
We are based in the United Kingdom. A valid order can require us to hand over the list above: an email address, billing dates, device public keys. It cannot produce browsing history that was never written.
We could be ordered to stay quiet about it
The UK has no blanket retention rule for VPNs, but under the Investigatory Powers Act a provider can be served a notice it is forbidden to discuss. We can't rule that out. What we can do is hold so little that such a notice reaches almost nothing, and publish a canary you can watch.
Stripe and Auth0 keep their own records
Pay by card and Stripe has your card; sign up by email and Auth0 has your address. Both under their own policies, whatever we do. Buying with Monero and an account number is the way around that, which is why we sell it.
Nobody independent has audited this yet
We are small and self-funded, and a real audit costs more than we currently take in. We would rather say that than imply otherwise. Until it changes, the client source, the canary and this page are what we can put in front of you.

Check us rather than trust us

Read what the app sends

The desktop client is open source under GPLv3. Every packet it puts on the wire is in that repository.

View the source

Watch the canary

A signed statement that no secret order has arrived, renewed monthly. Verify it against our key, and watch for it to stop.

See the warrant canary

Buy without telling us anything

Create an account number, fund it with Monero, sign in with the number. No email, no card and no name, so there is nothing to hand over later.

Pay with Monero

Ask for your data, or destroy it

Email us for a copy of everything we hold on you. Deleting your account erases the row, the Stripe customer and the sign-in identity together.

[email protected]

Questions people actually ask

Does Pangea keep any logs of what I do?
No. No browsing history, no DNS queries, no connection or disconnection times, no bandwidth records, no record of which server you used. The complete list of what we do store is on this page: an email address for email accounts, payment dates, one row per device, and contact messages.
Do you log my IP address?
No. While you are connected the server has to know where to send your packets back, exactly as any network does, but that lives in memory and is gone when the tunnel closes. Our web servers have access logging switched off, and the IP behind a request is used to rate-limit it and then dropped.
What would you hand over if the police asked?
Only what we hold: the email address on the account if it has one, subscription dates, and the public keys of registered devices. There are no traffic logs to give, because none are written. Where we are not legally barred from telling you, we will.
Can I use Pangea without giving you an email address?
Yes. Create an account number, top it up with Monero, and sign in with the number. That account has no email, no card and no name attached to it at any point.
Has the no-logs claim been audited?
Not by an independent auditor. We are small and self-funded and have not paid for one, and we would rather say so than imply otherwise. What we can offer instead: the desktop client is open source, the servers are never sent your identity, and we publish a signed warrant canary every month.
Does being a UK company undermine the whole thing?
It is a fair question. There is no blanket rule forcing a UK VPN to retain traffic logs, but under the Investigatory Powers Act we can be served an order for what we hold and forbidden to talk about it. That is the reason we hold so little, keep identity off the servers entirely, and publish a canary.

We can't hand over what we never collected.

That sentence is what the whole thing was built around. Everything above is what makes it true.

then from £2.33/mo · cancel anytime

See the warrant canary