No KYC. Not a threshold — a policy.
No identity document, no selfie, no phone number, no billing address, no reviewer deciding whether you look legitimate. Ordering asks for an email address. Creating an account asks for an email address and a password. That is the complete list, and there is no spend level or account age at which it changes.
From $5.00/month on Linux VPS or $12.00 on Windows RDP · delivered in ~4 minutes · crypto only
Can I buy a VPS without KYC?
Everything we ask for, and everything we do not
Not a summary. The actual complete lists, which is why one of them is so much longer than the other.
Never requested
- Legal name
- Government ID or passport
- Selfie or liveness check
- Proof of address
- Phone number
- Date of birth
- Company registration
- Tax identification number
- Payment card details
- Bank account details
- Source of funds declaration
- Reason for purchase
Data that was never collected cannot be breached, sold, or produced under compulsion. That is the entire security argument for minimal collection, and it is a stronger one than any promise about how carefully we would have guarded it.
Collected, and why
| Data | Why | Kept |
|---|---|---|
| Email address | Delivering credentials, invoices, renewal reminders and incident notices. | Life of account + 24 months |
| Password hash | Authenticating you. Stored with scrypt — irreversible, unreadable by us. | Life of account |
| Invoice records | Accounting and tax obligations we cannot opt out of. | 7 years (statutory) |
| Support tickets | Answering you, and having context next time you write. | 36 months after closure |
| Sign-in log (IP, time) | So you can spot an account takeover on your security page. | 90 days |
| Hypervisor metrics | Capacity planning, fault detection, and your usage graphs. | 13 months, aggregated after 30 days |
| Sampled netflow headers | DDoS detection only. Headers, never payloads. | 72 hours, then discarded |
Only the invoice line is non-negotiable — tax law requires seven years. Everything else can be exported or deleted on request at [email protected], free, within 30 days.
No-KYC is a consequence of crypto-only, not a marketing choice
Most hosts verify identity because they accept cards. Remove the cards and the reason evaporates.
Cards create the need
A stolen card plus instant provisioning equals a free server for an attacker, so card-accepting hosts must either verify identity or review orders manually. Crypto payments are final on confirmation, so neither is necessary.
It made delivery instant
When we accepted cards, every order went through fraud review and delivery took 3-6 hours. Removing that step is why provisioning is now fully automatic and averages four minutes.
It made prices lower
Chargebacks, fraud-review staff and acquirer reserves cost roughly 9% of revenue. We stopped accepting cards in February 2022 and cut list prices 30% the same day.
How to actually stay anonymous
Skipping our KYC form is one link in a chain. Here is the rest of it, including the parts that are your job rather than ours.
- 01
Use an email address not tied to your identity
A dedicated alias, a forwarder, or an address on a domain unconnected to you. It must keep working — a bounced delivery email is unrecoverable because we hold nothing else that proves the account is yours.
- 02
Pay in Monero
Every other asset we accept is pseudonymous on a public ledger, which means a chain analysis firm can often link a payment to an exchange withdrawal and therefore to a verified identity. Monero does not have that property. It is the single biggest improvement available to you.
- 03
Choose an offshore region
Reykjavík, Zürich, Panama City, Bucharest, Sofia or Amsterdam. Same price as everywhere else, and disclosure requires a court in that country.
- 04
Connect through something
A VPN, Tor, or another server you control. Our sign-in log keeps the connecting IP for 90 days, and your own connection to the server is outside our visibility entirely — but it is not outside everyone's.
- 05
Do not undo it at the application layer
The most common failure by a wide margin. Jurisdiction and payment privacy do nothing if the software you run announces who you are: a personal domain in a mail header, an analytics account, a reused SSH key, a git config with your real name.
One honest caveat. No provider can make you anonymous, and any that claims to is overselling. What we can do is refuse to collect identifying information in the first place, place servers in jurisdictions where disclosure is hard, and tell you plainly which parts of the problem are yours. Everything above is the whole picture as we understand it.
Pair it with an offshore jurisdiction
No-KYC limits what exists about you. Offshore limits who can compel its production. Together they are considerably stronger than either alone — and both cost exactly nothing extra, because our pricing does not vary by region.
Questions about identity and privacy
Correct. There is no verification step anywhere in the process. Ordering requires an email address; creating an account requires an email address and a password. We have never asked a customer for an identity document, a photograph, a phone number or a billing address, and there is no threshold of spend or account age at which that changes. The reason is simple: we take crypto only, so we carry no card-fraud risk, and card fraud is what forces most hosts into identity checks.
It is where the server IP, username and password are sent, and where invoices and renewal reminders go. Without it there is no way to deliver the product. Aliases, forwarders and your own domain all work fine — we do not check whether the address looks like a real name, and plenty of customers use a randomly-generated alias. Avoid disposable ten-minute inboxes only because we genuinely cannot recover a server whose delivery email has stopped existing.
That depends mostly on you, not on us. What we hold is an email address, invoice records and a 90-day sign-in log. What we do not hold is any identity document, because we never asked. To keep it that way, pay in Monero rather than a transparent chain, use an email address not linked to your real identity, and connect through a VPN or Tor. We are not going to pretend that using your work email over your home connection is anonymous just because we skipped a KYC form.
All of them, because we only accept cryptocurrency. Roughly 40 assets through OxaPay: Bitcoin, Ethereum, USDT on several chains, USDC, Litecoin, TRON, BNB, Solana, Dogecoin, TON and Monero among them. Monero is the only one where the payment itself carries no public trail; the rest are pseudonymous on their chain. There are no cards, no PayPal and no bank transfers, which also means no payment processor holds your identity on our behalf.
We respond to valid legal process from a jurisdiction that binds us, and we push back on overbroad requests. What we can produce is limited to what exists: an email address, invoice and payment records, support tickets, hypervisor resource metrics and a 90-day authentication log. We do not inspect or retain traffic contents, there is no agent inside your instance, and there is no identity file because we never created one. Where we are lawfully permitted to notify you first, we do.
Because we hold no identity documents, we cannot verify you the way a bank would. What we can verify is control of a payment. Open a ticket with an order ID and the transaction hash you paid it with, ideally signed from the sending wallet, and support restores access. This is why we ask you to save your two-factor recovery codes somewhere separate from your authenticator device — they are a much faster route back in.