Privacy

Privacy is non-negotiable.

SpinGate is built so there is nothing on file to leak. Privacy here is not a setting you toggle and not a plan you buy — it is payment-rail-agnostic, per-session, and a consequence of how the network is built. See how SpinGate works.

What we collect

The minimum the tunnel needs to stay up.

Each item below names something the service genuinely has to hold for a feature to work. Everything else is not collected.

Connection metadata

SpinGate holds the bare minimum the tunnel needs to stay up while a session is active: an encrypted transport state with the exit-region endpoint. There are no VPN traffic logs, no DNS logs, no IP retention past the active session, and no account-bound browsing history. When the session ends, the state ends.

Email — buyer receipts only

If you opt in at checkout, an email is used solely to deliver a buyer receipt through Polsia’s email proxy. Email is never required for guest crypto checkout. Email is never used for marketing, never tied to your tunnel, and never linked back to a wallet address.

Payment metadata scope

Fiat card payments route through Stripe Connect and follow its terms — sign-in is required on that rail. Crypto rails (BTC, ETH, USDC) do not require an account, and no payment-metadata log is retained: the on-chain receipt is the only record, and it lives on the chain, not on SpinGate.

Auth credits

If you sign in for fiat checkout, we hold the minimum session auth needed to complete the purchase. No behavioral history, no profile, no cross-session tracking — the auth credit is scoped to the session and forgotten when it ends.

What we don’t collect

What is missing on purpose.

Every line below names a thing SpinGate deliberately does not collect, store, or link back to the person using the tunnel — matching the principles on /about.

Not collected, by design
When the network never asks for it, there is nothing to leak, retain, or hand over.
  • No VPN traffic logs — session metadata, browsing activity, and connection timestamps are never stored.
  • No DNS logs — DNS queries that pass through the tunnel are not logged or correlated to a user.
  • No IP retention past the active session — your source IP is held while you are connected and discarded the moment you disconnect.
  • No account-bound browsing history — without an account, there is no identity to bind a browsing trail to.
  • No resale to third parties — there is no dataset to sell because no per-user dataset is built in the first place.
Data retention windows

How long anything stays around.

SpinGate holds only what a session needs to run, plus a tiny set of hashed records used to validate vouchers and attribute partner clicks. Everything else expires with the session.

Per-session, by construction

A SpinGate session is a discrete slice of time you bought, used, and discarded. Connection state ends on disconnect — there is nothing left behind to outlast the tunnel.

Persistent records

Voucher validation may persist a short, hashed identifier so a voucher can be checked against its minting transaction. Partner-attribution clicks are recorded as a 16-character truncated hash and carry no IP, no user agent, and no wallet linkage.

What is explicitly absent

No browsing history is ever built. No link exists between a wallet address and a SpinGate identity. No per-session behavioral record outlasts the session that produced it.

Sub-processors

Who else touches your data.

SpinGate itself runs the tunnel. The list below is the complete set of parties who receive any user data — none of them resell it, and none of them build a SpinGate behavioral record.

Fiat card rail

Stripe Connect processes fiat card payments. Sign-in is required on this rail per Stripe’s terms.

BTC / ETH / USDC rails

Crypto payments settle on mainnet to a real on-chain address. The settlement lives on the chain, not on SpinGate.

Email proxy

The Polsia email proxy delivers buyer receipts when an email is provided at checkout. No other transactional mail is sent.

Your controls

Less to control, because less is collected.

There is no account dashboard holding your browsing history, no profile export to download, and no behavioral record to delete — because none of it was ever built. Control here looks like: opt out of email receipts at checkout, sign in only when a rail requires it, and disconnect when the session is done.

Questions about the architecture live on /about. Anything else — reach out via /waitlist and we will get back to you.

Pseudonymous, mainnet-first, $0.10 per session.

Compare rails, see how the network is built, and tunnel on your terms — the same encrypted exit-region whether you pay in BTC, ETH, or USDC.