Skip to content
Transparency

What we were asked for, and what we handed over.

Published quarterly, once a quarter has closed. No reporting period has closed yet, so every column below is empty — the method is here, the numbers arrive when they are counted rather than estimated.

No reporting period has closed yet
This page has no counts on it. That is the accurate state of things, and it is deliberate: the previous version of this report published four quarters of specific figures — requests received, refused, abuse reports by category — that were never counted from anything. They are gone. A transparency report is the one document on a hosting site whose whole worth is that it is true, so it gets an empty table rather than a convincing one. The methodology below is what we will count, and how.
Legal requests received
no period closed yet
Valid, complied with
court order, correct jurisdiction
Refused
invalid, informal or out of scope
Requests producing data
email address only
Legal requests

Quarterly breakdown

A request is counted as valid only where it came from a court with jurisdiction over the datacenter holding the server. Everything else is refused and logged.

QuarterReceivedValidRefusedData producedUsers notified
No quarter has been published yet.
Why we expect 'data produced' to run below 'valid'
A valid order can compel us to hand over what we hold. What we hold is an email address, a cryptocurrency transaction reference and a server configuration — see the privacy policy for the complete enumeration. An order for anything outside that list can be answered only with the fact that it was never collected, which is the whole argument for structural privacy. Whether the columns bear that out is something you will be able to read here rather than take from us.
Abuse handling

What was reported, and what we acted on.

Reports are counted by category, and separately by whether they produced an action. We expect copyright to dominate the volume and account for very few of the actions — but that is a prediction about our own future table, not a result, and it is labelled as one until a quarter closes.

QuarterTotal reportsCopyrightSpamPhishingMalwareDDoSCSAMActioned
No quarter has been published yet.

Copyright complaints

Of our 8 locations, 4 sit outside both the US and EU frameworks — Iceland, Moldova, Panama and Seychelles — where a US copyright notice has no legal force and nothing behind it, so the policy is to log it and forward it to the customer. Our 3 EU sites (the Netherlands, Romania and Bulgaria) assess a substantiated notice under the Digital Services Act instead, and the United States location runs full DMCA procedure. All three paths get counted separately here once there is something to count.

CSAM: actioned without exception

A confirmed report results in immediate suspension and a report to the relevant authority, in every location, with no notice period and no refund. There is no jurisdiction where this is treated differently, and this is the one row we hope stays at zero.

Compromises versus intent

Spam, phishing and malware reports usually turn out to be a customer whose server was taken over rather than a customer doing the taking, so the table will distinguish them. Where the harm allows it, the customer gets 48 hours to remediate rather than an immediate suspension.

Methodology

  • Legal request means any demand for customer data or content action from a law enforcement agency, court, regulator or civil litigant.
  • Valid means issued by a court with jurisdiction over the datacenter holding the server in question. Informal enquiries, foreign agency requests that have not gone through mutual legal assistance, and civil demands without a court order are counted as refused.
  • Data produced counts requests where we handed over anything at all. Given what we hold, this means an email address and a transaction reference.
  • Users notified counts affected customers we were able to inform. We notify unless the order prohibits it, and we seek permission to notify once any gag period expires.
  • Actioned counts reports that resulted in suspension, termination or a forced remediation. It does not count reports we investigated and dismissed.

We publish within 30 days of each quarter end, starting with the first quarter that closes after this page goes up. If we ever receive an order that prohibits us from publishing an accurate count, the absence of an update on schedule is itself the signal — we will not publish a figure we know to be wrong, and we would rather this page stayed embarrassingly empty than became quietly fictional.

Nothing on this page is signed yet, and no warrant canary is running. Both need an OpenPGP key and we have not published one, so we are not going to display a canary you would have no way to verify. /pgp.txt sets out the state and what has to happen; when the key is published, the quarterly reports, our security advisories and the canary are all signed with it. Until then the schedule above is the only signal, and it is a weaker one than a signature — which is worth saying plainly rather than leaving you to notice.

Privacy you can check, not just believe.

An empty database is worth more than a strong promise. See exactly what we store.

7-day money-back guarantee · No KYC · Cancel any time from the panel