No documents. Not at any threshold.
Most hosts advertising no-KYC mean “no KYC until an invoice looks unusual”. This page is the other kind: the complete policy, the mechanism that keeps it true, and the parts of it that cannot protect you.
What sign-up requires
An email address that can receive mail, and a password you choose. That is the entire form.
One field. It has been one field since the first order in 2019.
Nothing on the sign-up page is validated against anything outside our own database. We do not check the address against a disposable-domain list, we do not send a code to a phone, and we do not ask which country you are in. If the confirmation mail arrives, the account exists.
Some people use a throwaway address and rotate it every few months. Others run their own mail server and hand out a per-vendor alias, and roughly a third of active accounts sit on a domain that resolves to a single mailbox. We mention it because the question comes up weekly: no, alias addresses are not flagged. There is nothing to flag them with.
An email address
Used for password resets, invoice delivery and the one message that carries your root credentials. It is not shared, not sold, and not passed to the payment provider.
A password
Stored as a scrypt hash with a per-account salt. We could not tell you what your password is if a court asked us nicely.
Nothing else
No name, no postal address, no telephone number, no company, no country, no date of birth, and no explanation of why you want a server.
What we never ask for
The right-hand column is short on purpose.
The first two columns describe what a mainstream host collects and roughly when. None of it is unusual, and most of it is demanded by their card processor rather than by any law. We took a different route at the payment layer, which is the only reason the third column reads the way it does.
| What most hosts collect | When they ask | What we collect |
|---|---|---|
| Government photo identification | At sign-up, or on the first unusual invoice | Never |
| Legal name and billing address | At checkout, every time | Never |
| Telephone number, verified by code | At sign-up | Never; we have no phone number either |
| Card or bank details | At every renewal | Never; no fiat instrument is accepted |
| Proof of address, such as a utility bill | On escalation | Never |
| Selfie or liveness check | On escalation, and often on refund | Never |
| Company registration papers | For business accounts | Never; there are no business accounts |
| Network address at sign-up | Silently, always | Not written to disk |
| Email address | Always | Always. That is the whole list. |
One consequence, stated plainly: because we hold no identity, we cannot restore an account to “the real owner” in a dispute. Whoever controls the mailbox controls the account. Treat that mailbox as the credential it is.
There is no threshold, and no escalation
The usual failure mode is a policy that holds right up until an invoice crosses four figures. Ours contains no such number, because the machinery that would enforce one was never built.
Order value
A €29 Ryzen instance and a €1,420 dual-GPU node travel the same code path. Nothing queues for review above a figure, because nothing queues for review.
Payment volume
An account five years and six figures deep carries exactly what one opened this morning carries: an address, a hash, and a run of invoices.
Refunds
Money goes back in the asset you paid with, to an address you nominate. There is no ownership check, no selfie, and no verification step that turns into identity collection when nobody is looking.
Support
Ticket authentication is possession of the account rather than proof of who you are. Sign in and you are the customer.
Abuse
A live report gets an instance filtered or suspended within minutes. It does not get you a document request, because a document would not stop the abuse.
Longevity
Nothing accrues. There is no reputation score, no risk tier and no quiet flag that ages into a review after the eleventh order.
What happens when a legal request arrives
We are not a jurisdiction unto ourselves and we do not pretend to be. Servers sit in buildings, in countries, under laws.
Ten productions in seven years. The transparency report has the breakdown.
A valid order served under the law of the country a site sits in gets answered. What leaves the building is whatever we actually hold: an email address, a password hash useless to everybody including us, invoice records with no name on them, and, where the request lands inside a seven-day window, a panel access log truncated to a network prefix.
The rest of the request goes back unanswered with a written explanation that the data does not exist. That is not defiance. You cannot produce a flow record from a router that was never configured to write one.
Where notification is permitted, you are told before anything is produced, with time to respond through your own counsel. So far it has been permitted in every case since 2019.
- 01
It arrives in writing
Through the abuse address or through counsel. Nothing is actioned from a telephone call, which is straightforward given that we do not have a telephone number.
- 02
It is checked
Correct court, correct country, correct scope, correct signature. Roughly one in four is not a legal order at all but a private party on convincing letterhead.
- 03
You are notified
Before production, unless we are prohibited. We have never yet been prohibited, which is also clause one of the canary.
- 04
We produce what exists
Item by item, with a written statement of which parts cannot be answered and why not.
- 05
It appears in the report
Counted in the next quarterly update with its category, its outcome and the number of accounts touched.
If the law changed
The honest answer is that you would hear about it before anything changed, because telling you is the first step of the sequence rather than the last.
A rule requiring identity collection would not land everywhere at once. It would apply to one country, and the response would be to stop selling in that country rather than to start collecting documents in the other twenty-eight. Sites have been closed here for worse reasons than that.
Were a change genuinely unavoidable across the fleet, three things happen in order. The canary drops the clause it can no longer assert. This page changes, with the previous text kept visible so the edit is legible. Existing accounts then continue under the terms they signed up under for as long as the law allows, and only new sign-ups meet the new requirement.
Anyone who wanted out at that point would get the unused portion of their term back on request. That obligation sits in the terms, not in a paragraph of reassurance on a marketing page.
Verify instead of trusting us
Every claim on this page is either testable from outside or worth precisely nothing.
Open an account with nothing
Fresh alias, smallest Ryzen instance, one payment. The route from sign-up to root takes about a minute and never asks a personal question. If it ever does, you have caught us.
Read the terms against this page
A document request would need a clause to live in. No such clause exists in the terms, and the acceptable use policy does not smuggle one in through the side door.
Watch the canary
Forty-two consecutive monthly statements as of August 2026. A missing signature is information. So is a signature on a statement that has quietly lost a sentence.
Check the panel
Your account page lists every field we hold, read live from the database, with a retention countdown beside each one. If it is not on that page, it is not held.
Ask for your file
Mail the privacy address and a machine-generated export of everything attached to your account comes back. Most people find it anticlimactic, which is the point.
Where this does not help you
A policy is not a threat model.
No-KYC means we do not know who you are. It does not mean nobody can find out. Your instance has a public address, everything that address does is visible to the networks between it and its destination, and if you administer it over a plain connection from home then the connection is the identifying artefact rather than our sign-up form.
Payment is the other seam. A transparent-ledger asset sent straight from an exchange account in your name ties that account to an invoice, and the exchange knows exactly who you are even though we never will. Customers who care about this either use an asset without that property or move value at least once before it reaches us.
Last of all, we are a hosting company rather than a shield. Content that is criminal in the country your instance sits in remains criminal, and a valid order will still be answered with whatever little we hold. Choosing a site is choosing a legal system, and it deserves more thought than choosing a latency figure.
Questions this policy attracts
No. Not at €29, not at €1,420 a month, not across a hundred instances. The check does not exist as code, which is a considerably stronger guarantee than a promise never to run it.
That is between the two of you. We have no concept of an account holder beyond whoever controls the mailbox, so there is nothing to declare and nobody here to declare it to.
Sign-up is not geoblocked. A handful of individual sites cannot lawfully take orders from certain places, and the configurator says so at the point of choosing rather than after you have paid.
Yes, and plenty of accounts do. Lose access to it and you lose the account, because no second form of identity exists for us to fall back on. Recovery codes are the entire lifeline; print them.
It is not written to disk. The web tier never passes the address through to the application, and the reverse proxy keeps only a truncated prefix that rotates out after seven days.
A law we cannot route around, and nothing else. Commercial pressure has been applied twice, both times by a payment provider, and both times the outcome was that we stopped using the payment provider.
Test it rather than believe it.
The smallest instance we sell is €29 a month and appears in about a minute. If any step on that route asks who you are, we have a much bigger problem than a marketing page.