Privacy Policy
Last updated: September 2026
Leid provides privately managed VPN connections using WireGuard. This policy explains what personal data we collect, why we collect it, how long we keep it, and what rights you have over it. We process personal data in accordance with the General Data Protection Regulation (GDPR).
1. Who we are
Leid is operated by Elvelangs IT AS. If you have questions about this policy or how your data is handled, you can reach us at privacy@samn.me.
2. Data we collect and why
Account data
When you request access, we store your email address and account timestamps such as when the account was created, updated, or last used. Leid uses passwordless magic-link authentication; we do not collect or store a password or password hash. We use your email address to provide the service and send sign-in links. We do not use it for marketing without your explicit consent.
Authentication and security data
To send and verify a magic link, we store a hash of the link token, its expiry time, and whether it has been used. When you sign in, we create a server-side session. Session tokens are stored as secure hashes so we cannot read the plain-text token. Sessions also contain an expiry time and may contain the connection address and browser user agent associated with the sign-in. We use this information, together with a CSRF token for state-changing requests, to maintain sessions and protect the service against abuse.
VPN server and infrastructure data
To provision and manage your VPN servers, we store information such as the selected location, server name, provider and host identifiers, server status, public endpoint addresses, WireGuard listen port, and allocated network addresses where applicable. We use this data to operate the service and show your servers in the dashboard.
WireGuard configuration data
We generate and store the configuration needed to connect your devices. This can include client names, IP addresses, public keys, private keys, and generated configuration files. These data are necessary to provide and manage your VPN connection. Treat downloaded configuration files and QR codes as secrets.
Usage and operational data
We may keep operational logs containing request metadata, timestamps, error information, provisioning events, endpoint health, and security events. These logs are used to operate, troubleshoot, secure, and improve Leid. We do not intentionally inspect, analyse, or log the contents of traffic sent through your VPN connection, and we do not use operational logs to build a browsing history.
3. Legal basis for processing
We rely on the following legal bases under GDPR:
- Contract - processing your account, authentication, VPN server, and configuration data is necessary to provide the service you request.
- Legitimate interest - processing IP addresses, user agents, and operational events for security, fraud prevention, abuse detection, and service reliability.
- Legal obligation - retaining records where required by applicable law.
4. Data storage and security
Leid is operated from European infrastructure where available. VPN endpoints may be operated on dedicated infrastructure or on a shared host with other Leid users. On a shared host, users are separated by WireGuard interfaces, private network allocations, and host firewall rules. This means that users may share the host's public IP address and infrastructure failure domain, while their VPN network traffic remains logically isolated.
Data is encrypted in transit using HTTPS/TLS. Magic-link and session tokens are stored as one-way hashes. We apply access controls so that only processes and people that need the data can access it. WireGuard private keys are particularly sensitive and access to them is restricted. You should treat downloaded configuration files and QR codes as secrets and remove them from devices or storage where they are no longer needed.
5. Third-party services
- Hosting and infrastructure providers - VPN endpoints may be operated using a hosting provider such as Scaleway or on other infrastructure selected for the service. The provider may receive the infrastructure and network information needed to create and operate the endpoint. On a shared host, the host operator may also process endpoint and resource metadata.
- Email provider - we use an email delivery provider to send magic links and service messages. It receives your email address and the information required to deliver the message.
We do not sell your data to any third party.
6. Data retention
- Account and VPN server data - kept while your account or server remains active and for as long as needed to complete deletion, resolve disputes, or meet legal obligations. We then delete or anonymise it, subject to applicable backup and legal-retention requirements.
- Magic links and sessions - magic links expire after 15 minutes and sessions expire after the configured session lifetime, currently seven days. Expired sessions are periodically purged.
- Configuration and key data - retained while needed to provide or manage the associated VPN server. It is deleted or anonymised when the server is deleted, subject to recovery, backup, security, and legal-retention requirements.
- Operational and security logs - retained only for as long as needed for security, troubleshooting, service operation, and compliance, then deleted or anonymised according to our operational retention procedures.
7. Your rights
Under GDPR you have the right to:
- Access - request a copy of the personal data we hold about you.
- Rectification - ask us to correct inaccurate data.
- Erasure - request deletion of your account and associated data, subject to applicable legal requirements.
- Restriction - ask us to restrict how we process your data.
- Object - object to processing based on legitimate interests.
- Data portability - request your data in a commonly used format.
- Lodge a complaint - you have the right to lodge a complaint with your local data protection authority.
8. Cookies
We use strictly necessary cookies to maintain authenticated sessions. No tracking or advertising cookies are used.
9. Changes to this policy
If we make material changes to this policy we will update the date at the top of this page and publish the revised policy before the changes take effect where required.
10. Contact
For privacy-related questions or requests, please email privacy@samn.me.