O
Privacy Policy
Last updated: 2026-04-29 · GDPR-compliant
Short version: We don't log your traffic. We don't sell your data. We collect only what's needed for billing and account management. Server logs are RAM-only and disappear on restart.
1. What we collect
Account information
- Email address (if you registered with email)
- Telegram ID + username (if you registered via @OGFlowBot)
- Hashed password (bcrypt, never stored in plaintext)
- Account creation timestamp + last login timestamp
- Locale preference (e.g., "en", "ru")
Subscription & billing
- Subscription tier and expiry date
- Payment method type (Telegram Stars / crypto / card processor)
- Payment amounts and timestamps
- External payment IDs (for refund processing)
We do not store payment card numbers. Card data is handled by Stripe/ЮKassa directly — we receive only tokens.
Devices
- Device name (you choose this)
- Platform (iOS/Android/Windows/etc.)
- Last connection timestamp (per device)
- Device-unique subscription token (revocable)
Usage aggregates
- Daily total bytes per user (no per-flow, no destinations, no times-of-day)
- Used to enforce fair-use bandwidth caps and capacity planning
2. What we DO NOT collect
- ❌ Browsing history / DNS queries / destination IPs
- ❌ Source IP logs of your connections
- ❌ Per-flow connection metadata (start/end times, ports)
- ❌ Device fingerprints (User-Agent, screen size, etc.)
- ❌ Cross-site analytics or tracking pixels
3. How long we keep data
- Account data: until you delete your account
- Payment records: 5 years (legal requirement for tax purposes in most jurisdictions)
- Aggregated bandwidth: 90 days
- Server operational logs: until next reboot (RAM-only, no persistence)
- Anonymized stats: indefinitely (no PII)
4. Server-side technical setup (transparency)
- VPN exit servers run xray, sing-box, and AmneziaWG with logging disabled
- Logs that do exist (debug, errors) are written to tmpfs (RAM-only, lost on reboot)
- systemd journal volatile mode
- No bash history (HISTFILE=/dev/null)
- Open-source stack at github.com/OGSENS/ogflow — audit yourself
5. Third parties
Limited data sharing with:
- Stripe / ЮKassa / Paddle — card payments (handle PCI scope, we don't see numbers)
- Telegram — bot interactions (Telegram has its own privacy policy)
- Cloudflare — DDoS protection on landing page; sees IP of website visitors (not VPN traffic)
- Let's Encrypt — TLS certificates (no user data, just domain validation)
We do not share data with advertising networks, data brokers, or analytics platforms.
6. Your rights (GDPR)
- Right to access: Request all data we hold about you. Email
privacy@ogflow.app
- Right to deletion: /account in @OGFlowBot, or email — we anonymize within 30 days
- Right to portability: Export your account + subscription history as JSON
- Right to rectification: Update any incorrect personal data via dashboard or support
- Right to object: Withdraw consent at any time
7. Security measures
- HTTPS everywhere (TLS 1.3 with Let's Encrypt)
- Bcrypt password hashing (cost factor 12)
- JWT tokens for authentication (HMAC-SHA256, 7-day expiry)
- HMAC-authenticated internal APIs (server-to-server)
- Rate limiting on authentication endpoints (Redis-backed)
- CORS restricted to known origins
- Daily encrypted database backups (last 14 retained)
8. Warrant canary
As of 2026-04-29, OGFlow has not received any:
- National security letters
- Gag orders
- Government requests for user data we could not legally publish
This statement is updated quarterly. If we are ever required to comply with such requests, this canary will be removed.
9. Data location
User database hosted in Frankfurt, Germany (EU jurisdiction, GDPR enforced). VPN exit servers distributed across DE/RU/NL with country-specific privacy laws applying to traffic flowing through each location.
10. Changes
This policy may be updated. Material changes announced via Telegram channel + email at least 14 days in advance.
11. Contact
Privacy questions: privacy@ogflow.app (when domain registered) or @genesis_og on Telegram.
← Back to home