Case file · VPN
Windscribe
Sign up with no email (or nothing at all, via a hash account), pay in Monero. Audited and open-source, but based in Canada and keeps a little metadata.
The systematized overview
The bureau vs the internet.
8.5/10 · No-KYC in practice
One of the strongest no-KYC accounts among mainstream VPNs: a normal account needs only a username (email optional), and the Anonymous Account needs nothing but a 32-character hash. Audited, open-source, and now RAM-disk. It stays at level 1 rather than 0 because it keeps a little per-account metadata and sits in Canada (Five Eyes).
3 recurring praises · 3 recurring gripes
Most praised: praised for the no-email / anonymous-hash account and monero support. Most cited downside: some users dislike the retained bandwidth/connection metadata.
We track our editorial score and community sentiment separately — neither moves the other. Read together, they're the systematized overview.
The facts
Specs & jurisdiction.
- Jurisdiction
- Canada
- Intel-sharing
- 5 Eyes member
- Logging
- No session/IP/site logs; retains bandwidth/30d + last-activity timestamp + connection count
- Anon. payment
- Monero + ~25 crypto
- Protocols
- WireGuard, OpenVPN, IKEv2
- Network
- 69+ countries, 120+ cities
- Devices
- Unlimited
- Kill switch
- Yes (Firewall)
- RAM-only
- Yes — RAM-disk (FreshScribe)
- Open source
- Yes (apps)
- Audited
- Yes — Leviathan 2021/2022, Packetlabs 2024
- Free tier
- Yes (10 GB/mo)
The full read
Our analysis, in plain words.
Windscribe has one of the strongest no-KYC account models among mainstream VPNs. A standard account needs only a username and password, with email purely optional for recovery, and the Anonymous Account goes further: you log in with a single 32-character hash, no email and no username at all. Payment can be fully anonymous through Monero and around 25 other cryptocurrencies. On the account dimension this is close to an account-number VPN like Mullvad.
It stays at level 1 rather than 0 for two concrete reasons. First, unlike an account-number VPN that stores essentially nothing, Windscribe keeps a small amount of per-account metadata on all accounts: total bytes transferred in a 30-day period, a timestamp of your last activity, and the number of parallel connections. No browsing history, source IP, or visited sites are logged, but that residual metadata is real and is the main reason privacy lands at 86 rather than higher. Second, it is based in Canada, a member of the Five Eyes alliance, a weaker jurisdiction than Switzerland or a non-aligned country.
On trust, Windscribe is well ahead of the unaudited field: its apps are fully open-source and it has three published independent audits (Leviathan Security on the desktop app in 2021 and the mobile apps in 2022, and Packetlabs on the RAM-disk "FreshScribe" infrastructure in 2024). Worth being precise: these are application and infrastructure security audits, not a dedicated no-logs audit of the kind Mullvad and Proton commission, so we place trust at 84, at the level of AirVPN and below Proton (90).
Reliability tells a redemption story. In June 2021, two Ukraine servers were seized running a legacy stack with the OpenVPN certificate and key on disk and no full-disk encryption, a genuine gap that could have enabled server impersonation, though no user activity data existed to take. Windscribe disclosed it in unusual detail and rebuilt its provisioning around RAM-disk servers with short-lived, rotated keys. That fix appears to have held in a February 2026 Dutch server seizure, where, by Windscribe's account, investigators found nothing useful. We treat the 2026 event as neutral rather than a proven win: it is recent, self-reported, and security researchers rightly caution that RAM-only is not bulletproof.
The score, broken down
How the 8.5 is built.
Privacy
weight 50%What identity, data and metadata the service can demand or collect.
86 × 50% = 4.3 of 10
Trust
weight 30%Whether it can technically deliver what it claims — code, audits, age.
84 × 30% = 2.5 of 10
Reliability
weight 20%Whether the no-KYC claim holds under real-world pressure.
84 × 20% = 1.7 of 10
Weighted total 8.5 / 10 · no reliability rule triggered, so the score stands. See the rubric →
Every point, sourced
What earned the score.
Privacy
The fine print, read for you
The clause they bury.
“Windscribe reserves the right to terminate, suspend, or otherwise restrict your access to this Service ... with or without notice at any time for any reason whatsoever ... Windscribe may impose usage or service limits, suspend service, or block certain kinds of usage at our sole discretion.”
What it meansA very broad discretionary termination and access-restriction power. It is anti-abuse rather than an identity demand, so it does NOT force a higher KYC level, but "for any reason whatsoever" and "at our sole discretion" are exactly the vague clauses our methodology flags, and this is wider than an account-number VPN gives itself. It lowers Trust, not the level.
Read the source →“Total amount of bytes transferred in a 30 day period; Timestamp of your last activity on the Windscribe network; Number of parallel connections.”
What it meansWindscribe keeps a small amount of per-account metadata (bandwidth, a last-activity timestamp, live connection count) for abuse prevention, on ALL accounts, not just the free tier. No browsing history, source IP or visited sites are stored, but this is more than the zero-metadata posture of an account-number VPN, and it is the main reason privacy is 86 rather than higher.
Read the source →No government ID, ever. A standard account needs only a username and password (email optional, for recovery); an Anonymous Account needs neither, just a 32-character hash. Payment can be fully anonymous (Monero plus ~25 cryptocurrencies). What keeps it at level 1 rather than 0: Windscribe retains a little per-account metadata (bandwidth per 30 days, a last-activity timestamp, live connection count) and is based in Canada, inside the Five Eyes alliance.
Policy review — point by point
-
Broad discretionary termination
Terms reserve the right to "terminate, suspend, or otherwise restrict your access ... at any time for any reason whatsoever" and to "block certain kinds of usage at our sole discretion." Anti-abuse in intent, but very broad and vaguely worded. ↗
-
Unilateral terms changes
Windscribe "reserves the right to modify these Terms of Use at any time upon posting," with continued use counted as acceptance. ↗
-
Retains minimal per-account metadata
Bandwidth per 30 days, a last-activity timestamp, and live connection count are stored for all accounts (abuse prevention). No browsing, IP, or site logs. ↗
-
No government-ID requirement
Nothing in the terms requires government ID or KYC to sign up or pay. ↗
Canada, a member of the Five Eyes intelligence alliance, which is a meaningful downside versus Switzerland (Proton) or a non-aligned jurisdiction. Windscribe mitigates the risk structurally rather than legally: it keeps no browsing logs, and its RAM-disk servers hold no persistent data, as apparently tested in the 2026 Dutch seizure.
We keep watching
Incident & policy timeline.
- Apr 2025
Founder acquitted in Greece; no-logs upheld
Windscribe founder Yegor Sak was acquitted by an Athens court on 11 April 2025 after a Finland-based Windscribe server was traced in a criminal case. Charges were dismissed and the court accepted that the no-logs policy meant there was no user data to produce - a rare real-world court validation of a no-logs VPN.
source ↗ - Feb 2026
Dutch server seizure (RAM-disk held)
Dutch authorities physically seized a Windscribe server. Per Windscribe, its RAM-disk servers meant investigators found only a fresh disk image with no identifying data. The outcome is not yet independently confirmed, and researchers note RAM-only is not bulletproof (e.g. hot-plug seizure without cutting power, or upstream traffic correlation), so we log it as neutral rather than a proven win.
source ↗ - Jun 2024
FreshScribe RAM-disk infrastructure audited
Packetlabs audited the new RAM-disk server infrastructure ("FreshScribe") with a positive outcome. Keys exist only in memory and are rotated.
source ↗ - 2021-2022
Apps audited by Leviathan Security
The desktop app was audited by Leviathan Security Group in September 2021, and the Android and iOS apps in March 2022; raised issues were addressed.
source ↗ - Jun 2021
Ukraine servers seized with keys on disk
Two OpenVPN servers in Ukraine were seized while running a legacy stack with the server certificate and private key stored on disk and no full-disk encryption, which could have enabled server impersonation or interception. No user activity data existed to seize (no-logs). Windscribe disclosed it fully, remediated by July 2021, and moved to RAM-disk servers with short-lived, rotated keys.
source ↗
The verdict
Where it stands.
Strengths
- Anonymous Account with no email or username (a 32-character hash)
- Accepts Monero plus ~25 cryptocurrencies
- Open-source apps and three independent audits
- RAM-disk servers (held up in a 2026 seizure)
- Unlimited simultaneous devices
- Genuine free tier (10 GB / month)
Trade-offs
- Retains some per-account metadata (bandwidth/30d, last-activity timestamp, connection count) on all accounts
- Based in Canada, inside the Five Eyes alliance
- Broad "terminate for any reason / at our sole discretion" clause
- Audits cover apps + infrastructure, not a dedicated no-logs audit
- 2021 Ukraine incident exposed a real server-config gap (since fixed)
Across the internet
What reviewers report.
Consistently praised
- Praised for the no-email / anonymous-hash account and Monero support
- Its open-source apps and three audits are cited as real transparency
- The detailed 2021 incident post-mortem earned goodwill for honesty
Recurring complaints
- Some users dislike the retained bandwidth/connection metadata
- Canada (Five Eyes) is a recurring concern
- Occasional complaints about account restrictions under the broad terms
Sentiment is positive on transparency, open-source, and the anonymous account, and mixed on jurisdiction and the retained metadata. No corroborated fund-freeze or data-betrayal pattern exists; both server seizures (2021, 2026) left no user activity data exposed, consistent with the no-logs claim.
Keep exploring
Related lists & categories.
Ask the bureau
Windscribe, common questions.
Can you use Windscribe without an email?
Yes. A standard account needs only a username and password (email is optional, for recovery), and the Anonymous Account needs neither: you log in with a single 32-character hash, no email and no username. You can also pay in Monero or ~25 other cryptocurrencies, so both the account and the payment can be anonymous.
Is Windscribe no-KYC?
In practice, yes (level 1). No government ID is ever required, and the account can be fully anonymous. We keep it at level 1 rather than 0 because Windscribe retains a little per-account metadata (bandwidth, a last-activity timestamp, connection count) and is based in Canada, inside the Five Eyes alliance.
What happened with the server seizures?
In June 2021, two Ukraine servers were seized with the VPN certificate and key stored on disk, a real config gap, though no user activity was logged to take. Windscribe disclosed it in detail and moved to RAM-disk servers. In February 2026 a Dutch seizure reportedly found nothing on a RAM-disk server, which suggests the fix worked, though that outcome is not yet independently confirmed.
Has Windscribe been audited?
Yes: Leviathan Security audited the desktop app (2021) and mobile apps (2022), and Packetlabs audited the RAM-disk infrastructure (2024). These are app and infrastructure security audits rather than a dedicated no-logs audit, which is why we rate its trust below Mullvad and Proton.
Your exact case not covered? The live Ask the bureau answers it and turns it into a public FAQ.