Nimbus
Deploy a server

SHEET 006 · IDENTITY POLICY · WHAT WE ASK / WHAT WE NEVER ASK · REV. B

A no-KYC VPS, and the short list of what we do ask for.

One email address and a crypto payment. That is the entire onboarding. Everything else on this page is the rest of the answer: what we keep, how long we keep it, and why 'no KYC' is not 'no rules'.

2023founded — no ID collected since
24crypto assets accepted
55smedian time from payment to deploy

01 — The lists

What we ask for, and what we never will

Two lists, both complete. If it is not on the first one, we do not ask for it. If it is on the second one, we never will.

What we ask for

01An email address

Credentials, invoices and the six-digit sign-in code go there. One inbox, everything about your account, yours to delete on the way out.

02Cryptocurrency, settled in minutes

The payment proves ability to pay without proving identity. Twenty-four assets, quoted in euros, rate locked 60 minutes.

What we never ask for

  • Government identity documents
  • Selfies or liveness checks
  • Utility bills or proof of address
  • Phone number verification
  • A card on file or a billing name
  • Social accounts or referrals

02 — The retention table

Everything we store, and for how long

A complete inventory of customer data. If it is not in this table, we do not have it — there is no 'other' column, no analytics bucket, no data lake with your name in it.

WhatHow longWhy it exists
Email addressUntil the account closes, then deleted within 24 hSign-in and delivery of credentials and invoices.
Invoices10 yearsEstonian accounting law requires it. No payment identity is attached to them.
Server configurationUntil the instance is destroyedSo your server survives restarts, moves and our mistakes.
NetFlow metadata72 hoursAbuse investigations only. No payloads are stored, ever.
Support tickets24 monthsSo the engineer who helped you in March remembers it in May.
Payment identityNever collectedPayments are handled by a processor; we see a chain, not a person.
ID documentsNever collectedDocuments that do not exist cannot be leaked, subpoenaed or lost.
Phone numberNever collectedNothing on this service needs a phone. Neither do you.

Account closure starts a deletion sweep: servers, snapshots, backups, sessions and metadata are destroyed within 24 hours. The email address goes when you ask; invoices stay because the law outranks the delete button.

03 — Where the line sits

No KYC is not no rules

Privacy is a product decision. Abuse is a safety decision. The two never met on this page, and they will not meet on your invoice either.

Read the acceptable use policy

Phishing, spam, malware, botnet command-and-control and CSAM are terminated immediately, without refund and without appeal — privacy is not a licence to harm people.

Sanctions and law-enforcement requests are answered the same way everywhere: we have almost nothing to hand over, we publish what we did hand over, and we never had the documents other companies keep 'just in case'.

The acceptable use policy is two pages long, written in the same plain language as this one, and it is part of the contract you sign with an email address and a transaction.

04 — Questions

Asked often, answered in writing

The eight questions closest to being asked every day — answered in writing, so the answer outlives the conversation.

Do I really not need to verify my identity?
Correct. Ordering takes an email address and a crypto payment. No passport scans, no selfies, no phone verification, no card on file. The cheapest way to protect customer documents is to never hold any — and we have held none since 2023.
How does an email address open an account?
Sign-in is a six-digit code sent to your inbox — no password to steal, no recovery questions to guess. The address is also where credentials, invoices and the one email per year that matters go. We send no marketing; there is no list to be on.
What about anti-money-laundering rules?
We are a server company, not a financial institution, and the payment processor carries the regulatory load on the money side. What we carry is the abuse side: patterns that look like laundering get the same treatment as any other abuse — a human looks, and the terms decide. If the law changes, we will tell you first and adapt in the open.
Why crypto instead of cash or a bank transfer?
Cash cannot be verified at a distance and banks require identity by law. Crypto is the only payment rail that verifies solvency without identity — which is exactly the property we built the company on.
Do you respond to data requests from authorities?
We do, because the law applies to us like anyone else — and because there is almost nothing to give: an email address, an invoice, 72 hours of NetFlow metadata. Every request we act on is published, in aggregate, in the journal. Requests for ID documents, phone records or payment identity get the same answer every time: we do not have them.
Is Monero accepted, and can I pay over Tor?
Monero is accepted and has been since 2024 — it was the point. Tor works for checkout and for your server's traffic alike. What neither buys is immunity: abuse traced to an account terminates it, no refund, no appeal, anonymous or not.
What happens to my data when I close the account?
Servers, snapshots, backups and metadata are destroyed within 24 hours. Invoices stay 10 years for the law, and the email address goes when you ask. There is no retention team, no archive, and no one to sell the list to.
No KYC — so anything goes?
No. Phishing, spam, malware, botnet command-and-control and CSAM get terminated immediately, without refund and without appeal. Privacy is not a licence to harm people. The acceptable use policy is two pages and we mean all of it.

The whole identity section of checkout

One email field. Everything else on this page is the fine print, and it is all here so you never have to read fine print again.