Legal

Privacy Policy

Effective 12 August 2026. What we collect, why we collect it, where it lives, and when it is deleted.

1. Two kinds of data

We process account data — what you give us when you sign up and configure the service — and traffic data — what passes through the edge when the internet talks to hostnames you put behind it. They are held separately and treated differently.

2. Account data

Your email address, password (stored only as an Argon2 hash), optional profile fields (name, company, country), your plan, your zone and layer configuration, API keys (stored hashed), and an audit trail of configuration changes made in your account. Used to operate your account, verify sign-ins, and reach you about your service. Kept while the account exists; deleted when the account is deleted, except invoices and audit records we must retain by law.

3. Traffic data

Each request through the edge produces log rows: timestamp, client IP, country/city derived from it, requested hostname and path, protocol details (TLS version, cipher, HTTP version), the security verdicts of each layer (WAF score, bot classification, rate-limit decisions), status code, latency, and byte counts. This is what powers the analytics and logs in your portal, the security layers themselves, and abuse prevention. Request and response bodies are not logged; the API Shield layer can detect fields that look like personal data in API traffic and reports the field names, never the values.

4. Cookies

The portal sets a session cookie (HttpOnly) to keep you signed in, and the bot challenge sets a clearance cookie proving a solved challenge. Neither is used for tracking, and there are no third-party trackers or analytics scripts on any of our pages.

5. Where data lives, and who sees it

Account data and traffic logs are stored on infrastructure we operate in the European Union (Hetzner, Germany). Transactional email (verification and security codes) is delivered through our email provider, which sees the destination address and nothing else. We use no advertising networks and sell nothing about you or your traffic to anyone. We disclose data only when a law we are subject to compels it, and where lawful we will tell you first.

6. Retention

Traffic logs are retained for the analytics window of your plan — 7 days on Free, 30 on Basic, 90 on Pro and one year on Enterprise — and then expire from the log store automatically. Aggregated statistics (counts by minute, with no client identifiers) may be kept longer. Revoked sessions, used verification codes and expired challenges are purged on their own schedules, measured in days.

7. Your rights

You can export your full configuration from the portal, correct your profile yourself, and delete your zones or your whole account at any time. If you are in a jurisdiction that grants access/erasure/portability rights (GDPR and kin), send the request to support@netdistance.net (see Contact) and it is answered within the statutory deadline. For traffic data, note that you are the controller for the sites you put behind the service — we process that traffic on your instructions, and end users of your sites should be pointed at your own privacy policy.

8. Changes

Material changes to this policy are announced by email and on this page at least 14 days before they take effect. The Effective date at the top of this page identifies the version currently in force.