Draft

Privacy policy

Last updated: July 2026 · pre-launch draft.

Who we are

tocoro is a VPN service operated by the tocoro project ("tocoro", "we"). Contact: [email protected].

The principle

We can't expose, sell, or hand over data that doesn't exist. The entire service is designed to know as little as possible about you, and this policy describes exactly that minimum — in plain language, because a policy no one understands protects no one.

What we keep

  • Your account number. Random, generated by the app. It contains and requires no information about you.
  • Your subscription's expiry date.
  • Total data usage per account. How much you transfer in total, to operate and size the service. Never which sites, never from where.
  • Redeemed prepaid codes. Which code was redeemed on which account, to prevent fraud.
  • A recovery email — only if you add one. It's optional and you can delete it from the app at any time.
  • When card payments open (Stripe): the processor will know your payment details under its own policy; we'll keep a reference (amount, date, time credited). If you'd rather no payment be linked to you, use a prepaid code — anyone, anywhere, can buy one.
  • Minimal technical logs to detect errors and service abuse (never your browsing activity), automatically deleted within days, not months.

What we don't keep

  • Your name, address, or phone number — we don't ask for them.
  • Browsing history or the content of your traffic.
  • DNS queries.
  • Logs linking your IP address to your activity or your account.
  • Device fingerprints, advertising identifiers, usage analytics.

Where the data lives

Accounts and subscriptions live on our backend in Germany (Hetzner). Your VPN traffic flows through nodes in the location you choose (today: USA), encrypted, and is stored nowhere.

Retention and deletion

  • Your data exists for as long as your account does.
  • Deleting your account from the app erases the number, the expiry date, the recovery email, and the usage counters.
  • Accounts expired for more than 12 months are deleted automatically.
  • Card payment references are kept only as long as accounting law requires.

Third parties we use

Vultr (VPN nodes, USA) · Hetzner (backend, Germany) · Stripe (card payments) · ZeptoMail (recovery email delivery, only if you set one up). None of them receives your browsing activity. We use no analytics or advertising providers — there are no third parties beyond these.

Legal requests

We respond only to valid legal demands, and only with what exists — the "What we keep" list above. We publish a count of requests received at /transparency.

No trackers

Neither this site nor the app uses analytics, pixels, or third-party trackers.

Changes

We'll publish any change on this page with its date. Substantial changes are additionally announced inside the app before taking effect.

Contact

Questions about this policy: [email protected].