
cryptostorm
grade A
Privacy-friendly VPN, no logs, anonymous payment methods, and Tor and I2P website access Supports OpenVPN and WireGuard.
grade A
What the documents mean for you
Cryptostorm inspects tunnel traffic with an intrusion-prevention system and blocks SMTP or specific sites for everyone on a server after spam complaints. Refunds need 50% or less token use within 180 days. It never asks for ID; web logs are kept 2 weeks.
The Terms of Service state outright that the operator does not and will not implement any KYC policy, and also refuses to implement age or ID verification, adding that tokens can be ordered anonymously over .onion/.i2p with Monero. No clause anywhere in the corpus lets them ask you to identify yourself or hold your money until you do.
Nothing in these documents sets off an identity check: they say they will not run KYC and will not build age or ID verification into their software. To buy access you need a payment method; with Monero or NOWPayments they do not ask for or keep an email address, and delivery happens in the browser. For a refund you send the payment processor used, the order email if there was one, and the transaction ID, not identity documents.
Warnings
They run snort as an intrusion prevention system against the tunnel interface on the server side to stop scanning and hacking. This means an automated system examines traffic leaving the tunnel.
They state that a data center, its ISP, or an upstream ISP could start logging traffic into and out of the leased servers. They lease all servers and have no physical access to them.
The refund policy excludes lifetime tokens entirely, citing high processing fees. It also limits how many refunds one customer can get.
The authentication database stores the token hash, its duration, the time it was first activated and a live session count. They state it holds nothing tying a token to when or where you connect from.
How the score was reached
Privacy100/100
Trust71/100
Overall = (privacy × 0.6 + trust × 0.4) / 10, rounded = 9/10, grade A. Each attribute above rests on a clause quoted below or was assigned by a moderator; the rest is what the listing knows.
Attributes11 moved the score
Third party infrastructuretrust -1
Entirely on rented servers, so the infrastructure operator is an additional party to trust.
All servers are rented from data centers, so the hosting companies are extra parties in the chain.
“No, we lease our dedicated servers from data centers all over the world.”
https://cryptostorm.is/faq
Identity-free registrationprivacy +10
Users can create accounts without giving personal information such as a full name, address or phone number.
The service says access tokens can be ordered anonymously, with no personal information, over Tor/I2P and with Monero.
“That's why we have a .onion and .i2p and why we accept Monero, so people can order an access token anonymously without providing any personal information.”
https://cryptostorm.is/tos
Verifiedtrust +10
Passed repeated checks over time and showed consistent behavior.
Strict no-log policyprivacy +5 · trust +3
The service has a strict no-log policy: it does not collect or store any information about its users.
Open source codetrust +7
The source code of the service is publicly available and licensed as open source.
Accepts Moneroprivacy +5
This service accepts Monero, a privacy-focused cryptocurrency that provides enhanced anonymity.
Has Onion or I2P URLsprivacy +5
Onion (Tor) and I2P URLs enhance privacy and anonymity.
No registration neededprivacy +5
Users can access and use the service without creating an account.
Defends against takedown requeststrust +2
The provider evaluates takedown complaints rather than suspending on receipt.
The operator answers DMCA complaints with an explanation of its model instead of acting against users.
“Irrespective of that, we receive hundreds of DMCA letters a week - and respond to them individually with a (mostly) polite explanation of our operational model, cryptographic framerwork, and member-agnostic authentication topology.”
https://cryptostorm.is/tos
Token-based loginprivacy +1
Access is through a secret token rather than a username and personal details.
Access is granted by a secret network access token rather than a username and personal details.
“In conclusion, a valid network access token gains you access to cryptostorm.”
https://cryptostorm.is/tos
No JavaScript neededprivacy +1
The service does not require JavaScript to be enabled.
What costs you most first. Tap one to read the clause it rests on, or what the listing knows, priced as kycnot.me prices it.
What the documents say
They refund only if you used 50% or less of the token's duration and ordered less than 180 days ago. They cap how many refunds you get, and lifetime tokens are never refunded.
“If you're unsatisfied with our service and have used 50% or less of your token's duration, and your order was placed less than 180 days ago, then we'll refund your order.”
https://cryptostorm.is/refund
For each order they keep your email, the token delivered, and the payment processor's transaction ID. With Monero or NOWPayments they do not ask for or save an email.
“No matter what payment method you choose, the data we retain is always the same: email, token delivered, and a transaction ID provided by the payment processor.”
https://cryptostorm.is/privacy
The website records your IP address, browser, referrer and request times, and deletes them after two weeks. You can email support to be removed earlier.
“We have no reason to maintain historical records of our web visitors, so those logs are rotated/deleted automatically after 2 weeks.”
https://cryptostorm.is/privacy
They say they hold no data to give police, but note that law enforcement can ask their payment providers PayPal or CCBill for whatever you gave those companies.
“Keep in mind though, it is possible for law enforcement to request data from one of our payment providers (PayPal or CCBill).”
https://cryptostorm.is/faq
They run the snort intrusion prevention system directly on the tunnel interface to stop scanning and hacking attempts coming from users.
“No, and we use [snort](https://www.snort.org) as an intrusion prevention system to prevent most basic types of hacking (SQL injection, brute force, automated vulnerability scanning, etc.).”
https://cryptostorm.is/faq
After a spam complaint they block all SMTP on that server, or block the target website, for everyone connected, because they cannot tell which user is responsible.
“When we get complaints from one of our data centers about a VPN client of ours sending SPAM, we'll temporarily block all SMTP on that server until the SPAM stops, since we have no way of knowing which customer of ours was doing that.”
https://cryptostorm.is/faq
You can delete the plaintext token from their delivery database yourself, if you accept that they are not responsible if you then lose it.
“There's also a new option in the token delivery page where you can remove your plaintext token from our database (provided you agree not to hold us responsible if you lose it).”
https://cryptostorm.is/privacy
Documents read
Community
Write a reviewCancel
No reviews yet. If you have used it, say what actually happened.
The average is weighted by each reviewer's standing: verified reviews and accounts with karma count more, new or untrusted accounts less. How karma works.