Privacy
Only the Catalan version of this document is legally binding, Catalan being the official language of the Principality of Andorra. This English version is a translation provided for convenience; in the event of any discrepancy, the Catalan text prevails.
The principle
ValiraVPN is built not to know who you are. This is not a promise of discretion but a technical constraint: most of the data an ordinary privacy policy undertakes to protect exists nowhere in our systems, and we could not produce it if we were asked to.
An account is created with no email address, no name, no password and no sign-up form at all. It amounts to a sixteen-digit number, drawn at random, held by you alone. That number is not even stored: the database keeps only a keyed cryptographic fingerprint of it, which lets us recognise the number you present but not recover it.
What we hold
The list is exhaustive. It matches the columns of our database exactly.
- For the account: the keyed fingerprint of the number, the creation date, the subscription expiry date, a counter of bytes used against the residential quota, and the country of tax residence you declare on first payment.
- For each device: the name you give it, its platform, its WireGuard public key, when it was added, when it was last active, and the internal tunnel address, which belongs to our private range and designates nothing outside it.
- For each payment: the Monero subaddress issued for it, the amount expected and received, the confirmation count, the duration bought and the tracking timestamps.
- For each invoice: the number, the period covered, the amount, the tax rate and the declared country of tax residence.
- For the current session: the keyed fingerprint of the login token and its expiry.
What we do not hold
We have no email address, no name, no postal address, no named payment instrument and no password. We do not record the sites you visit, the addresses you connect to, DNS queries, connection times, or your real IP address. None of this is ever written to a disk, at any point.
The residential quota counter is a plain total: it says how much data passed through, never where to.
Web server logs
The site is served behind a relay. The web server therefore never sees a visitor's IP address: it sees the relay's address, and that is what it writes to its logs. We have checked this against the entirety of the existing logs, in which only the two ends of the relay tunnel appear. Those logs are kept for fourteen days and then destroyed automatically.
The site is also reachable through an onion service, which goes through no relay and where the question does not arise: the Tor network carries no originating address.
The nodes
The servers carrying your traffic run in RAM only. They have no persistent storage. A power cut, a reboot or a physical seizure yields nothing, because there is nothing to read: the memory of a machine that is off is empty.
Exit nodes belong to the decentralised Sentinel network and are run by independent third parties we do not control. Your traffic is encrypted as far as the exit node, but what leaves it towards the public Internet follows the usual rules: whatever you have not encrypted end to end, typically anything outside HTTPS, is readable by the exit operator exactly as it would be by any access provider. We cannot guarantee those operators' behaviour.
Payment
We accept Monero only, a currency whose amounts and participants are encrypted by construction. No exchange, no payment processor and no bank stands between you and us, so no third party learns anything about your purchase.
We run our own Monero node. We consult no external service to verify your transactions.
A distinct subaddress is issued for each invoice. It ties that payment to that account in our database, and it is the only link that exists between an account and the chain. We never record the transaction identifier: it would be a direct pointer from your account to an operation on the chain, and we would rather not hold it.
The conversion rate is read over the Tor network from a public market. That request carries nothing about you: it asks for a price, not for a payment.
Tax residence
The law requires us to know our customers' country of residence in order to determine the applicable tax and issue proper invoices. So we ask for a country, on first payment, and nothing more: no region, no city, no address. One country out of a few dozen identifies nobody.
Trackers and third-party services
The site uses no analytics, no advertising tracker and no third-party content delivery network. Fonts, images, stylesheets and scripts are served by our own server. No request is made to a domain we do not own.
A single cookie is set, and only after you log in: it carries the session
token that keeps you authenticated. It is marked HttpOnly,
Secure and SameSite, it serves no tracking purpose, and
it disappears when you log out.
The site works without JavaScript. Scripts add comfort only, never access to the service.
Retention
- Session and interface tokens expire on their own and are deleted when they do.
- Web server logs are destroyed after fourteen days.
- Account data lives as long as the account does.
- Invoices and the matching payment records are kept for as long as accounting law requires, including after the account is closed. We cannot delete them on request: that obligation overrides the right to erasure.
Your rights
Processing falls under Llei 29/2021 on the protection of personal data of the Principality of Andorra, a text aligned with the European General Data Protection Regulation. You have rights of access, rectification, erasure, restriction, objection and portability.
You exercise them by writing to contact@grasandco.com. We will answer within one month.
Two limits follow from the design of the service itself. We can only answer a request that comes with proof you hold the account number concerned, failing which anyone could obtain someone else's data. And we cannot give you what we do not have: a request to access your browsing history will get a negative answer, not as a refusal, but because no history exists.
You may lodge a complaint with the Agència Andorrana de Protecció de Dades, the competent supervisory authority, or with the authority of your country of residence.
Requests from authorities
We respond to legal demands that are enforceable against us under Andorran law. What we can supply is limited to what the section "What we hold" describes, and in no case includes a browsing history, a customer IP address or an identity, since none of those exist.
Andorran law places no general obligation on service providers of this kind to retain connection data. We therefore retain none, and we do not intend to start.
Transfers
Data is processed on our own servers. Andorra holds an adequacy decision from the European Commission, which means transfers of data between the Union and Andorra require no additional safeguard.
Changes
Any change to this policy will be published on this page. A change reducing your protections will never be applied retroactively.