Barely-Free VPN
Эта страница на английском, и действует именно английский текст.
Legal

Privacy Policy

What Barely-Free VPN keeps, why, and for how long. Last updated 2026-09-24.

In short

Your key

A random name (like u-1a2b3c4d), the key itself, its plan, device limit and end date, and how much data it has used (totals per day). Kept while the key exists.

While you are connected

For about 15 minutes, in memory only: the network address your device connects from, your key's name, the profile, and the addresses your connections go to. We use this to count devices per key and to fix problems as they happen; it is never written to disk. To enforce device limits we also keep, on disk, the network addresses each key used in the last 5 minutes. Nothing we keep records which sites you visited.

When you visit this website

Our web server logs the first three parts of your IP address (for example 203.0.113.x), the page — with any key in it hidden — the time and the result, for about a week. Nothing else about you.

When you get a free key

A one-way, keyed fingerprint of your network address — not the address itself — so we can allow one free key per network in 30 days. It is deleted after 30 days. A free key that ran out is forgotten 90 days later.

When your app updates

For each key: when it last updated, from which app, and the first three parts of the address it came from. Only the latest update is kept; our administrators see it when helping you.

Abuse protection

An address that floods this website is blocked for up to 24 hours; the block list holds that full address only while the block lasts. Block and unblock decisions are kept in a security log: with the full address for 30 days, then with only its first three parts, and deleted after 12 months.

If you pay

Stripe collects and keeps your payment details, email address and billing information, under its own privacy policy. We keep which Stripe subscription pays for which key, the plan, and the paid-until date. We never see your card number. Your email address we do not keep either: we keep a one-way, keyed fingerprint of it, which lets you sign in on the Keys page and cannot be turned back into the address.

If you sign in

On the Keys page you type your email; if it paid for a key we send it a 6-character code, valid for 10 minutes. The address is used to send that one message and is not stored. The code is kept only as a fingerprint until it is used or expires. A signed-in browser holds a random token for up to 30 days; signing out ends it. Codes are sent through Resend, an email delivery service.

If you email us

Your message and address stay in our support mailbox for as long as we need them to help you.

Cookies

There are no other cookies.

Who else is involved

Stripe (payments); the companies that rent us servers and data centres; Cloudflare (our domain's DNS, and forwarding our email); Resend (sending sign-in codes); GitHub (private backups of server settings, which include key names and identifiers but nothing about your activity); Telegram (alerts to our administrators, with key names and shortened addresses). We share nothing with anyone else unless the law requires it, and we can only hand over what this page lists.

Why we may use it

We do not use your information for advertising, profiling or any purpose not listed here, and no decision with legal effect on you is made by software alone: a person reviews any block or ended key on request.

Where

Our servers are in data centres in Europe and North America. Barely-Free is based in Ontario, Canada; the European Commission recognises Canada's private-sector privacy law as giving adequate protection to data sent from the EU. The companies listed above may process data in other countries, mainly the United States, under the safeguards they provide for international transfers (such as standard contractual clauses).

Who is responsible

Barely-Free is responsible for your personal information. Our Privacy Officer is accountable for this policy and answers questions and requests about it: [email protected].

Your rights

You can ask what we hold about your key and a copy of it, ask us to correct it, to delete it, or to stop or limit using it: email [email protected] with your key's name — never the key link itself. We answer within 30 days, free of charge.

If you are not satisfied, you can complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca); in Quebec, to the Commission d'accès à l'information; in the EU, to the data protection authority where you live; in the UK, to the Information Commissioner's Office.

If something goes wrong

If a breach of our safeguards creates a real risk of significant harm to you, we tell the people affected as directly as we can (by email for paying customers, and on this website) and report it to the Privacy Commissioner, as soon as we can. We keep a record of every breach for at least two years.

Children

The service is not meant for children under 13, and we do not knowingly hold data about them.

Changes

We update this page whenever what we keep changes; the date at the top shows the current version.

Contact

[email protected]