MultiOBX

Documents

Privacy policy

What data the MultiOBX service (the website and the app) processes, why, for how long and to whom it may be disclosed. Revision of 14 September 2026.

1. General

1.1. This policy applies to all data the service receives when the MultiOBX website and app are used.

1.2. Provider: the owner of the MultiOBX service.

1.3. By creating a key, paying for time or using the app you accept this policy. If you do not agree, do not use the service.

2. What data is processed

2.1. Access key. When a key is created, the server stores only its digest (HMAC-SHA256 with a server secret). The key itself is not stored and cannot be recovered from the digest.

2.2. Devices. For each device attached to a key (no more than 5) the following is stored: the WireGuard public key, the address inside the tunnel, a service name from a word list, the platform type (Windows, Android, iOS) and the date it was added. The real device name is never requested.

2.3. Payment. The date until which time is paid; order numbers, amounts and statuses; voucher redemption marks. Card, account and wallet details never reach the service: they are handled by the payment provider under its own rules, and the service only receives the fact of payment and the order number.

2.4. Website. After signing in, one session cookie is set: a random identifier stored in the database as a hash, valid for 30 days or until sign-out. There are no analytics, advertising or third-party cookies. The IP address is used for rate limiting and is not stored in the database. Web server logs containing IP addresses are kept for no longer than 7 days and are used only to protect against attacks.

2.5. Support requests. What you write yourself and the address you write from.

2.6. What the service does not collect. Name, e-mail, phone number, identity documents, payment details. Tunnel servers keep no connection logs: who connected, when and to which addresses is not recorded.

3. Purposes

3.1. To make sign-in with a key, devices and paid-time accounting work.

3.2. To accept payment and match it with a key by order number.

3.3. To answer support requests.

3.4. To protect the service from key guessing and attacks (rate limiting).

4. Disclosure

4.1. To the payment provider: the order number and amount needed to accept payment.

4.2. To public authorities: only where the law directly requires it, and only the data the service holds (see section 2). The service has no data about where you connected.

4.3. To nobody else. Data is not sold and not shared for advertising.

5. Retention and deletion

5.1. The key record, devices and orders are kept while the key exists. When a key is deleted, its devices, sessions and orders are deleted with it.

5.2. A website session is deleted on sign-out or after 30 days.

5.3. To delete a key with its related data, write to support and quote an order number or the date the key was created. Do not send the key itself.

6. Data protection

6.1. Keys are stored as digests, sessions as hashes. The website works over HTTPS only. The server secret is kept in a separate file with restricted access.

6.2. The website runs no scripts and loads nothing from third-party servers.

6.3. There is no absolute protection for data sent over the internet; the service takes reasonable measures but cannot guarantee the absence of risks outside its control.

7. Your rights

7.1. Everything stored in connection with your key is visible in the account page: devices, term, orders.

7.2. You may delete the data (clause 5.3), change the key in the account page or stop using the service at any time.

8. Changes

8.1. A new revision is published on this page with its date. Continued use of the service after publication means acceptance of the new revision.

9. Contact

9.1. Questions about data processing: see the contact on the Help page.