Privacy Policy
Version of 03.10.2026 · English translation; the Russian version is authoritative
Privacy is the foundation of Erised. We built the service to collect as little data about you as possible.
0. Closed testing (before release): diagnostic logs
While the service is in closed testing, the app sends diagnostic logs to the server: which channels and exits worked, connection errors, and the host names that connections were made to (without content). They are used only to fix censorship-circumvention issues, are kept for 7 days and then deleted. They are not shared with anyone. Channel telemetry and service heartbeats (carrier, country, network type, without IP address) are kept for up to 35 days. If you send a diagnostics file to the bot yourself, it is forwarded to the administrators in Telegram and stays in that chat until deleted manually. After the Android release, diagnostics are switched off, and sections 1–2 below apply without this exception.
1. What we do NOT store
- Traffic logs and connection contents; outside the test period, also the history of visited sites and DNS queries.
- A link between “user ↔ activity ↔ IP address” over time.
- The contents of your connections.
Our exit servers are configured not to log users’ real IP addresses or SNI.
2. What we store (the minimum needed to run the service)
- Account identifier and, if you sign in on the website, a hash of your login/password (the password is never stored in plain text).
- Subscription status and expiry, amount of traffic used (to apply the plan).
- Technical operational data needed to deliver connection settings.
- If you ask us to email you the settings file: we do not store the address. To prevent unlimited sending to one address, only its irreversible fingerprint (HMAC) is kept for one day; the address cannot be recovered from it.
- If you use the bot: your Telegram ID and username (@username) — so the bot recognises your account.
- When you start a free trial — a browser or device fingerprint (browser type, screen, time zone and similar signals) and the registration IP address, so that one person cannot take the free period many times. The IP is erased after 7 days, the fingerprint after 30 days.
- For the per-subscription device limit — an irreversible device hash: the device itself cannot be identified from it.
- If you write to support through the bot (/support) — the text of your message. It is kept for 30 days after we reply (60 days if unanswered) and is deleted together with the account.
3. Payments
Payments go through external providers (Telegram, a crypto payment service). We do not store bank card data. The fact and amount of a payment may be kept for tax accounting.
4. Sharing with third parties
We do not sell or share your data with third parties. Data may be disclosed only upon a lawful and binding demand — and only to the extent we hold it (which is minimal by design).
For the service to work, some data inevitably passes through external services — only as much as they need to function:
- Cloudflare — serves the website; it sees the IP address of website visitors.
- Resend — sends the email with the settings file if you request it; it receives the address and the encrypted file. Like any email, it is also visible to your email provider.
- Telegram and @CryptoBot — the bot and payment processing.
- Google Play — app installation during closed testing: to add you as a tester we need the Google account address you send us yourself.
5. Warrant canary
We publish a “canary” about requests from authorities. If its date stops updating, that is a signal. The status is available in the app/bot.
6. Account deletion
You can delete your account at any time: the /delete command in the Telegram bot, the “Delete account” button in your account page on the website, or a request to support. We delete within 7 days. The fact and amount of payments remain without any link to the account — for tax accounting; encrypted database backups are deleted automatically within 8 weeks. Details: Account deletion.
7. Contact
Privacy questions — to support.