⚠ Recorded incidents
minor
2026-07-24 Policy
Ongoing
The operators are anonymous and the service has never commissioned an independent no-logs audit, so its claims rest on published configuration rather than third-party verification. One long-term reviewer puts it plainly: the technical setup is excellent but there is no way to know who is behind it. KYCnot.me rates trust 70 against a privacy score of 97 for exactly this reason. Source: kycnot.me/service/cryptostorm
minor
2024-01-01 Policy
Ongoing
The promotional website runs Apache with default logging, retaining visitor IP, user agent, referrer and request time for two weeks before automatic rotation. The operator discloses this openly, explains why the logs exist, points users to its onion address to avoid them entirely, and will purge a visitor early on request. The VPN nodes themselves have logging disabled, with only aggregate per-server bandwidth collected. Source: cryptostorm.is/privacy
minor
2026-07-24 Policy
Ongoing
Refunds require the order to be under 180 days old with 50 percent or less of the token duration used, are limited per customer, and lifetime tokens cannot be refunded at all. Reviewers also consistently describe the site as dated and the setup as demanding: token hashing and manual config editing are expected of the user. Source: cryptostorm.is/refund, kycnot.me user reviews