Privacy Policy

Version of 30 July 2026.

The company warrenBrowse is being incorporated. Until it is registered, the responsible entity is referred to in this document as "the Warren team".

This policy describes the processing of your personal data during the Warren public beta. It supplements the Public Beta Terms.

1. Controller

The Warren public beta is operated by the Warren team.

No commercial company operates the service at this stage. A legal entity is being incorporated; it will become the controller for the paid service and will then publish its full registration details.

Processing is subject to the GDPR (Regulation (EU) 2016/679). You may contact the data protection authority of your country of residence.

2. The Warren team's principle: no logging

Warren is designed so that it cannot watch you. The Warren team logs no user activity. In particular, it does not collect:

  • traffic logs (the sites, services or content you reach);
  • DNS query logs;
  • connection logs (per-user connect or disconnect timestamps);
  • your source IP address;
  • your bandwidth or data volume per user;
  • browsing history or session metadata correlatable to your identity.

The Warren team's exit servers run in RAM only, with no persistent disk for activity data, and DNS caches live in volatile memory. This absence of logging is architectural: the data is written nowhere, so there is nothing to retain, nothing to look up and nothing to hand over.

No-log does not mean "no data". It means no traffic or activity data. Section 3 lists the little that the Warren team does process.

3. Data the Warren team processes during the beta

Data Purpose Legal basis (GDPR art. 6) Retention
Account identifier (pseudonymous public key) Give you access to the beta performance of the contract 6(1)(b) life of the account; erasable (section 8)
Beta voucher allocation record (hashed account, not reversible) Credit free access and avoid duplicate allocations performance of the contract 6(1)(b) purged automatically by the periodic database sweep
Forum identity (pseudonym derived from your key) and your posts Support, tracking and fixing of reported bugs performance of the contract 6(1)(b) life of the forum account, or until erasure on request
Problem report and attached logs Reproduce and fix the defect you report consent 6(1)(a), given in the app for as long as the report is being handled
Support message (email or help form) Answer you legitimate interest 6(1)(f) for as long as support requires
Site language preference (PARAGLIDE_LOCALE cookie) Show the site in your language strictly necessary for the requested service 400 days, in your browser
Abuse strike counter (account identifier, number of recent strikes, last report category) Preserve network availability against reports targeting a forwarded port legitimate interest 6(1)(f) in memory only, rolling 90-day window, wiped on every service restart

No payment data. The beta is free: no payment method is stored, no payment provider is involved, and the Warren team produces no billing record, no tax location evidence and no accounting ledger concerning you.

4. Your identity on the forum

The forum is the bug reporting channel. Its design avoids linking your posts publicly to your Warren account:

  • Your forum pseudonym is derived from your account key by a keyed hash (for example lusab-babad-dovok). It is stable for you and cannot be traced back to your account key by a forum reader.
  • The forum never receives your account key, nor your real IP address (it is replaced by a fixed value before reaching the forum), nor a real email address (a non-routable technical address is generated), nor a password (none exists).
  • Internally, the Warren team can match a forum pseudonym to an account key in order to handle a support request. That access is restricted, protected by strong authentication and logged.
  • Your public posts are public. What you post is visible to everyone, including search engines.

5. Problem reports and attached logs

When you report a bug, you can attach your application's technical logs. This processing rests on your consent and works as follows:

  • You keep the initiative. Nothing is sent without an explicit confirmation by you in the app.
  • Logs are redacted before leaving your device. An automatic pass replaces IPv4 and IPv6 addresses, MAC addresses, technical identifiers (UUIDs), long digit strings and your home directory paths.
  • They contain technical information: app and service events and errors, versions, operating system, connection state. They do not contain the content of your browsing.
  • They are never public. They pass through the Warren team's own service (connect.warrenbrowse.com) and are delivered to the support team alone by private message. They do not appear in your forum topic, and you receive a private acknowledgement.
  • You may withdraw your consent for the future and ask for the deletion of a report already sent (section 8).

6. What the Warren team does not do

The Warren team does not carry out advertising profiling, does not sell or share your data for commercial purposes, does not run third-party tracking, and does not inspect your traffic. No automated decision producing legal effects is taken in respect of you.

The beta.warren.ro site contains no analytics tool, no third-party script and no advertising cookie. The only cookie set is your language preference.

7. Recipients and processors

The Warren team uses only the providers strictly necessary to run the beta:

  • Infrastructure hosts: Hetzner (European Union) for the API, the database and the forum; Hetzner (Germany, Finland, Singapore) and FDCservers (Netherlands) for the exit servers. Those exit servers run in RAM, with no activity logs.
  • The forum is a Discourse instance the Warren team hosts itself on its own server: no third-party operator is involved and no forum data is entrusted to an external service.
  • No payment provider, the beta being free.

The hosts act as processors within the meaning of art. 28 GDPR, under their data processing terms.

8. Your rights

Under the GDPR (art. 15 to 22) you have the rights of access, rectification, erasure, restriction, portability and objection, as well as the right to withdraw your consent for the logs you have sent the Warren team.

  • How to exercise them: write to contact@warrenbrowse.com, or send a private message to the @support group on the forum from your account.
  • Erasure: on request, the Warren team deletes your Warren account and the forum identity derived from it. No accounting record requires it to keep anything, the beta being free. Your account key lives on your device: logging out in the app erases it there, and the Warren team holds no copy of it.
  • Access: because the Warren team keeps no activity data, a request of the kind "what activity data do you hold about me" gets a simple answer: it holds none.
  • Complaint: you may contact the data protection authority of your country of residence.

9. Security

Your traffic is encrypted by the tunnel. Exit servers run in RAM, with no persistent disk for activity data, and core dumps are disabled on them. The Warren team applies proportionate technical and organisational measures (art. 32 GDPR). In the event of a data breach presenting a risk, the Warren team notifies the competent supervisory authority and, where applicable, the data subjects (art. 33 and 34 GDPR).

The beta is a test environment: its robustness is that of software under development, which is the very reason the programme exists.

10. Authority requests

Because the Warren team keeps no activity data, in most cases it has nothing to provide in response to a request targeting a user's activity: it cannot produce what was never recorded.

11. Transfers outside the European Union

Account data, the database and the forum are hosted in the European Union. One exit server is located in Singapore: if you choose it, your traffic transits there without being logged, and no account data is stored there.

12. Minors

The beta is not intended for people under 18 (see the Public Beta Terms). The Warren team does not knowingly collect minors' data.

13. Changes to this policy

The Warren team may change this policy. Changes are dated and announced on https://beta.warren.ro and on the forum. The applicable version is the one in force at the time of processing.

14. Contact

For any question about your data: contact@warrenbrowse.com.