About 404 VPN

Who you’re trusting with your traffic, what we can technically see, what we actually keep, and how we back it up.

Why we build 404 VPN

404 VPN started with a simple idea: a secure connection shouldn’t require technical know-how.

We’re building a VPN that makes sense to regular people: you’re connected in a couple of minutes, it runs on the modern VLESS protocol, and we’re open about data. The free plan gives you 2 GB a day with no card, and there are apps for Android and Mac. We don’t promise “total anonymity”: no VPN can honestly guarantee that.

Who’s behind 404 VPN

404 VPN is operated by:

Legal name404 Privacy Networks Limited
Registration number93497261
JurisdictionHong Kong SAR

Privacy Policy · Terms of Service

Team

404 VPN is built by a small team that looks after the product, the apps and the servers.

Ethan Brooks 🇺🇸

Founder, CEO

Runs the company

Noah Whitaker 🇺🇸🇮🇳

CTO

Service architecture and security

Claire Tan 🇸🇬

Head of Product

The apps and how people use them

Nur Aisyah Rahman 🇸🇬

Head of Infrastructure

VPN servers and the network

What we know about you

We don’t just say “no logs.” Here’s what that means at 404 VPN, item by item.

DataKept?Why and for how long
What you do through the VPN
Browsing historyNoOur servers don’t record which sites you visit
DNS queriesNoNot recorded
Traffic contentNoEncrypted in transit and never stored
Your account
Email or Telegram ID, password hashYesSo you can sign in, for as long as the account exists
Plan, expiration date, paymentsYesAmount, plan and payment status, for billing and renewals
Traffic volume and last connection timeYesTo count the 2 GB daily limit and plan limits
The browser or app you signed in fromYesFor the list of sign-ins to your account
Support requestsYesYour message and our reply, otherwise we can’t answer
Technical data
Technical data needed to run and protect the serviceLimitedServer logs kept for a limited time, with no browsing history
IP address at sign-upHash onlyA one-way hash that protects the referral program from abuse
Which site pages get openedYesGoogle Analytics 4, _ga cookie

Privacy Policy →

Where our servers are

Seven locations. The list comes from the same source as server selection in your account.

🇳🇱 NLAmsterdam
🇩🇪 DEFrankfurt
🇫🇷 FRMarseille
🇹🇷 TRIstanbul
🇪🇬 EGCairo
🇭🇰 HKHong Kong
🇯🇵 JPTokyo
✓ Last configuration check: September 15, 2026, Amsterdam server
✓ Recording of visited sites on the server: off

Independent audit

No independent audit has been done yet.

Our first external security audit is planned for Q4 2026. We’ll publish the results here, whatever they turn up.

Transparency report

Period: August 28, 2026, when our Privacy Policy took effect, through September 15, 2026

0
Requests from government agencies
0
Requests for browsing history
0
Times browsing history was handed over
0
Accounts affected by legal requests

No requests so far. When they come in, we’ll publish everything we’re able to disclose here: how many requests arrived, what data they asked for and what we handed over.

We don’t keep browsing history, so we can’t hand it over. We do have account data, such as your email or Telegram ID, plan and payments, and we’ll report requests for that here too.

Updated: September 15, 2026

Found a vulnerability?

Email support@404vpn.io with “Vulnerability” in the subject line. We welcome responsible disclosure and won’t pursue researchers who report issues in good faith and follow the rules below.

  • Describe the issue and the steps to reproduce it.
  • Don’t access or change other people’s data beyond what you need to demonstrate the issue.
  • Don’t disrupt the service: no load attacks, spam, or tricking users or our team.
  • Give us time to fix the issue before you talk about it publicly.

This contact is also published in security.txt

What 404 VPN doesn’t promise

We don’t sell the myth of “total anonymity.”

404 VPN hides your real IP address from the sites you visit and encrypts the connection between your device and our server. But a VPN doesn’t protect against everything: cookies, browser fingerprinting, malware and signing in to your personal accounts can still identify you.

cat threat-model.log
[protects] Hides your real IP address from the sites and services you visit
[protects] Encrypts traffic between your device and the server: your ISP can’t see the content
[does not protect] Cookies and accounts you’re signed in to under your own name
[does not protect] Browser fingerprinting
[does not protect] Malware and phishing on the device itself

More: threat model →

Contact Us

For partnerships and press inquiries, write to hello@404vpn.io. For technical support, use the form below and your message will go straight to our team.

support@404vpn:~$ ./send-message.sh
Trust shouldn’t rest on words alone.

That’s why we show who runs 404 VPN, what data we keep, where our infrastructure runs, and what our VPN can and can’t do.

Try 404 VPN for free

2 GB a day, no card