Privacy

Privacy Policy

Last updated: May 2026

Our philosophy

We collect the absolute minimum data necessary to operate the service. We don't want your data. The less we have, the less can be compromised, subpoenaed, or leaked.

What we collect

DataPurposeRetention
Account number (random)AuthenticationUntil account closes
Password hash (bcrypt)AuthenticationUntil account closes
Active plan + expiryBillingUntil account closes
VM ID, WireGuard keysProvisioningDeleted when popped
VM IP address (internal)NetworkingDeleted when popped

What we do NOT collect

System logging

System logging on the hypervisor is configured to use volatile storage only (RAM). Logs are never written to disk and are wiped on every reboot. There is no persistent audit trail of system activity.

Encryption

All customer VM disks are stored on a LUKS-encrypted partition. The encryption key is entered manually at boot and exists only in RAM while the server is running. If the server is powered off or seized, the encrypted partition is unreadable.

Data destruction

When you pop a bubble:

There is no undo. There is no retention period. There is no backup. The data is gone.

Third parties

We do not share any customer data with third parties except when required by valid legal process (subpoena, court order) or for CSAM reports to NCMEC as required by federal law. We do not use analytics services, advertising networks, or data brokers. There are no third-party scripts on this website.

Legal requests

If we receive a valid legal request for customer data, we can only provide what we have — which is very little. We cannot provide browsing history, connection logs, or IP addresses because we don't collect them.

Changes

We may update this policy. Changes will be posted on this page with an updated date.

Contact

For privacy concerns: admin@bubbl.cx