Security & Transparency

In plain language: what protocol 404 VPN runs on, what data we store, and what we deliberately don't.

What protocol we use

404 VPN runs on the VLESS protocol over WebSocket with TLS 1.3 encryption. It's a modern protocol designed to make encrypted traffic hard to distinguish from ordinary HTTPS traffic to a website — which makes network-level traffic-type blocking harder.

What data we store

Running your account needs a minimum: your email (or Telegram ID if you signed in via Telegram), a password hash, your selected plan and its expiry date, and technical counters of traffic used — so we can apply plan limits (like the 5GB/day on Free).

What data we don't store

We don't keep logs of visited websites, we don't log DNS requests, and we don't save the content of your traffic. Our infrastructure isn't built to answer "what did you do online" — because we don't hold the answer to that question ourselves.

How long data is kept

Account data (email, plan) is kept while the account is active. Free-plan traffic counters reset daily and aren't kept as history. Deleting your account from settings removes your personal data from our primary database.

Where our servers are

Server infrastructure is currently based in Amsterdam, Netherlands — see the Servers page for the current location list and status. We're working on expanding the list of countries.

What happens after your key ends

On the Free plan, a key doesn't "end" — the 5GB limit simply resets every day. On paid plans, access runs until the end of the paid period, after which the account automatically drops to Free — data and settings aren't deleted.

What's needed to purchase

Just an email and a payment method (Visa/Mastercard/MIR). We don't ask for ID documents and don't require your real name.

How support works

Through the form on our About page, or at support@404vpn.io. Requests are handled directly by our team, never passed to a third party.

Threat model — what we protect against, and what we don't

security@404vpn:~$ cat threat-model.log
[protects] Hides your real IP address from sites and services you visit
[protects] Encrypts traffic between your device and our server — your ISP can't see the content
[protects] Keeps no logs of visited addresses or DNS requests on our side
[depends on your app] Kill Switch and DNS leak protection are settings of your chosen client (Happ, Hiddify, etc.), not of our infrastructure — see How It Works
[doesn't protect] Threats that require action on the device itself (malware, phishing)
[doesn't protect] Anonymity when logging into accounts that identify you themselves (email, social media)
process exited, code 0

Separately, our Privacy Policy covers the same ground in legal language.