What no-KYC actually means
KYC — Know Your Customer — is the process by which a business collects and verifies a customer’s legal identity before providing service. In practice it means an uploaded passport or national ID card, a utility bill as proof of address, sometimes a live selfie holding the document, and a phone number verified by SMS. Some hosting providers run all of it. Some run part of it only when an order trips a fraud score. Almost all of them retain whatever they collect indefinitely.
A no-KYC VPS is a virtual private server bought without any of that. At NimbusVPS the complete list of things we ask for at checkout is:
- An email address, so we can send you root credentials and renewal notices.
- A cryptocurrency payment.
That is the entire form. There is no name field. There is no address field. There is no company registration step, no identity document upload, no phone verification and no payment card. These are not fields we leave optional — they do not exist in the ordering system, which is a stronger guarantee than a policy promise, because a field that does not exist cannot be quietly populated later.
Is buying a VPS without KYC legal?
Yes, in the overwhelming majority of jurisdictions, and this is worth stating clearly because the phrase “no KYC” has acquired an aura of illicitness it does not deserve.
KYC obligations arise from anti-money-laundering law and are imposed on regulated financial institutions: banks, cryptocurrency exchanges, money transmitters, payment processors, and in some countries licensed gambling operators and telecoms carriers. Web hosting is not a regulated financial activity in the European Union, the United States, or any of the jurisdictions we operate in. No statute in those places requires a hosting provider to identify its customers.
Providers that demand identity documents do so for commercial reasons of their own — chargeback exposure, fraud scoring, the terms of their acquirer agreement — not because a regulator obliged them to. That is a legitimate business choice. It is simply not a legal requirement, and framing it as one is misleading.
What we store, exactly
A privacy claim is only as good as the specific list behind it. Here is ours, in full.
| Data | Stored? | Why |
|---|---|---|
| Email address | Yes | The only channel for credentials and service notices |
| Crypto transaction reference | Yes | Proof a given invoice was settled |
| Server specification | Yes | We have to build what you bought |
| Hostname and IP assignments | Yes | Required to operate the network |
| Legal name | No | Never collected |
| Postal address | No | Never collected |
| Identity document | No | Never collected |
| Phone number | No | Never collected |
| Payment card details | No | We do not accept cards at all |
| Browsing or traffic logs | No | No DPI, no mirroring, no identity-linked NetFlow |
| Server access logs | No | 0-day retention |
The practical consequence is that a request for customer records produces almost nothing, because almost nothing exists. That is a structural property of how the business is built, not a promise about how bravely we would resist. Promises about bravery are worth very little; an empty database is worth a great deal.
Why most hosting providers ask for ID
The honest answer is credit cards.
When a host accepts card payments it inherits chargeback liability. A fraudster buys a server with a stolen card, uses it for a week, and the real cardholder disputes the charge — the host loses the money, the service it already delivered, and pays a dispute fee on top. At scale this is existential, so card-accepting hosts build fraud controls, and the cheapest effective fraud control is demanding identity.
Once identity is being collected for payment reasons, it sits in the billing database, gets reused for account recovery, gets exported to a CRM, gets included in the next acquisition’s data migration, and eventually shows up in a breach. Very little of that is malicious. It is simply what happens to data that exists.
Accepting only cryptocurrency removes the original cause. Crypto payments are push transactions and cannot be reversed unilaterally, so there is no chargeback exposure, so there is no fraud-control case for identity collection, so the field never gets created. Crypto-only is what makes no-KYC structurally true rather than a line in a marketing page.
What no-KYC does not mean
Three things it is worth being blunt about.
It does not mean lawless. Our acceptable use policy applies in every location including the ones marked DMCA-ignored. Child sexual abuse material, spam, phishing, malware command-and-control and denial-of-service attacks get you removed without refund and without argument. A provider that tolerates those loses its upstream transit, and then everyone hosted there loses their servers. Our enforcement is a service to legitimate customers, not a betrayal of them.
It does not automatically mean anonymous. No-KYC describes what we ask you for. Anonymity describes what an observer could infer. If you pay with Bitcoin bought on an exchange that holds your passport, administer the server from your home connection, and register a domain in your own name, the association chain is intact — it just routes around us. See our page on anonymous VPS for the parts that are your job.
It does not put you outside every jurisdiction. Your server physically sits in a building in a country with courts. A valid order from those courts is honoured. What no-KYC changes is that such an order reaches the machine, not a folder with your identity documents in it. Choosing which country that is is the decision that actually matters.
How to evaluate a no-KYC host
The phrase appears on a great many hosting front pages, including some that will ask for a passport the moment an order trips their fraud score. Five questions separate the real ones from the rest.
- Do they accept cards? If yes, chargeback exposure exists, and identity verification will appear the moment an order looks unusual. Crypto-only is the structural tell.
- Do they accept Monero? Bitcoin is a public ledger. A provider that accepts only BTC is offering less privacy than one that accepts XMR, whatever the front page says.
- What does the privacy policy enumerate? Look for a specific list of fields. Vague assurances about “respecting your privacy” describe an intention; an enumerated list describes a schema.
- Is there a transparency report? A provider publishing request counts has thought about what happens when a request arrives. One that has not, has not.
- Do they own their IP space? A provider reselling someone else’s addressing can have a customer’s prefix pulled by its upstream on a phone call, regardless of its own policies. NimbusVPS announces its own space; the AS number and where it currently stands are on the network page.
Frequently asked questions
What is a no-KYC VPS?
A no-KYC VPS is a virtual private server that can be purchased without identity verification. KYC — Know Your Customer — is the process by which a business collects and verifies a customer's legal identity, typically an ID document, a proof of address and sometimes a live selfie. A no-KYC hosting provider skips that process entirely. At NimbusVPS the complete signup surface is an email address and a cryptocurrency payment.
Is buying a VPS without KYC legal?
Yes, in the overwhelming majority of jurisdictions. KYC obligations are imposed on regulated financial institutions — banks, exchanges, money transmitters, payment processors — and on certain licensed sectors such as gambling and telecoms. Web hosting is not a regulated financial activity in the EU, the US, or the jurisdictions we operate in, so no statute requires a hosting provider to identify its customers. Providers that demand ID do so for chargeback and fraud reasons of their own, not because the law obliges them.
What does NimbusVPS actually store about a customer?
Three things. The email address you supply at checkout. The cryptocurrency transaction reference for each invoice, which the payment processor generates. And the technical metadata needed to run your server: hostname, IP assignments, resource limits and snapshot index. There is no name field, no address field, no identity document, no payment card, and no phone number anywhere in the system. Control panel access logs have 0-day retention, which is to say they are not kept.
Why do most hosting providers require ID?
Because they accept credit cards. Card networks push chargeback liability onto the merchant, so a host taking cards has a direct financial incentive to identify buyers and a contractual obligation under its acquirer agreement to run fraud controls. Once identity is being collected for payments it tends to be retained and reused. A provider that accepts only cryptocurrency has no chargeback exposure and therefore no reason to collect identity at all.
Does no KYC mean anything goes?
No, and any provider claiming otherwise is either lying or about to be shut down by its upstream. NimbusVPS enforces an acceptable use policy in every location: no child sexual abuse material, no spam, no phishing, no malware distribution or command-and-control, no denial-of-service attacks, and nothing criminal under the law of the country hosting the server. Not collecting your passport is a privacy position, not a promise of impunity.
Can I use a disposable email address?
Yes, and many customers do. The only requirement is that you can actually read it, because it is where root credentials, renewal notices and any abuse correspondence arrive. If you lose access to the address you lose the ability to prove ownership of the order, since there is nothing else on file to prove it with. An aliasing service such as SimpleLogin or addy.io is the practical middle ground.
How do you handle a law enforcement request with no customer data?
NimbusVPS responds only to legally valid orders from a court with jurisdiction over the datacenter holding the server. Where such an order arrives, we comply with what it actually compels — which, given we hold an email address and a transaction hash, is usually very little. Informal requests by email, foreign agency enquiries and civil demands without a court order are refused. Counts go into our transparency report at each quarter end; the first reporting period has not closed, so that page currently shows the method and an empty table.
Is a no-KYC VPS the same as an anonymous VPS?
They overlap but are not identical. No-KYC describes what the provider asks you for. Anonymous describes what an observer can infer. A no-KYC VPS paid for with Bitcoin bought on a KYC exchange and accessed from your home IP address is not anonymous, because the chain of association still exists — it just runs through third parties instead of through us. Genuine anonymity additionally requires care with the payment path, the access path and the email address.