noKYCme

Case file · VPN

Windscribe

Sign up with no email (or nothing at all, via a hash account), pay in Monero. Audited and open-source, but based in Canada and keeps a little metadata.

No-KYC · Level 1
Based
Canada
Price
Free tier (10 GB / month); paid from ~$5-9 / month
Reviewed
2026-07-21
Audited by
The noKYCme Bureau

The systematized overview

The bureau vs the internet.

What the bureau found

8.5/10 · No-KYC in practice

One of the strongest no-KYC accounts among mainstream VPNs: a normal account needs only a username (email optional), and the Anonymous Account needs nothing but a 32-character hash. Audited, open-source, and now RAM-disk. It stays at level 1 rather than 0 because it keeps a little per-account metadata and sits in Canada (Five Eyes).

What the internet says

3 recurring praises · 3 recurring gripes

Most praised: praised for the no-email / anonymous-hash account and monero support. Most cited downside: some users dislike the retained bandwidth/connection metadata.

We track our editorial score and community sentiment separately — neither moves the other. Read together, they're the systematized overview.


The facts

Specs & jurisdiction.

Jurisdiction
Canada
Intel-sharing
5 Eyes member
Logging
No session/IP/site logs; retains bandwidth/30d + last-activity timestamp + connection count
Anon. payment
Monero + ~25 crypto
Protocols
WireGuard, OpenVPN, IKEv2
Network
69+ countries, 120+ cities
Devices
Unlimited
Kill switch
Yes (Firewall)
RAM-only
Yes — RAM-disk (FreshScribe)
Open source
Yes (apps)
Audited
Yes — Leviathan 2021/2022, Packetlabs 2024
Free tier
Yes (10 GB/mo)

The full read

Our analysis, in plain words.

Windscribe has one of the strongest no-KYC account models among mainstream VPNs. A standard account needs only a username and password, with email purely optional for recovery, and the Anonymous Account goes further: you log in with a single 32-character hash, no email and no username at all. Payment can be fully anonymous through Monero and around 25 other cryptocurrencies. On the account dimension this is close to an account-number VPN like Mullvad.

It stays at level 1 rather than 0 for two concrete reasons. First, unlike an account-number VPN that stores essentially nothing, Windscribe keeps a small amount of per-account metadata on all accounts: total bytes transferred in a 30-day period, a timestamp of your last activity, and the number of parallel connections. No browsing history, source IP, or visited sites are logged, but that residual metadata is real and is the main reason privacy lands at 86 rather than higher. Second, it is based in Canada, a member of the Five Eyes alliance, a weaker jurisdiction than Switzerland or a non-aligned country.

On trust, Windscribe is well ahead of the unaudited field: its apps are fully open-source and it has three published independent audits (Leviathan Security on the desktop app in 2021 and the mobile apps in 2022, and Packetlabs on the RAM-disk "FreshScribe" infrastructure in 2024). Worth being precise: these are application and infrastructure security audits, not a dedicated no-logs audit of the kind Mullvad and Proton commission, so we place trust at 84, at the level of AirVPN and below Proton (90).

Reliability tells a redemption story. In June 2021, two Ukraine servers were seized running a legacy stack with the OpenVPN certificate and key on disk and no full-disk encryption, a genuine gap that could have enabled server impersonation, though no user activity data existed to take. Windscribe disclosed it in unusual detail and rebuilt its provisioning around RAM-disk servers with short-lived, rotated keys. That fix appears to have held in a February 2026 Dutch server seizure, where, by Windscribe's account, investigators found nothing useful. We treat the 2026 event as neutral rather than a proven win: it is recent, self-reported, and security researchers rightly caution that RAM-only is not bulletproof.


The score, broken down

How the 8.5 is built.

Privacy 4.3Trust 2.5Reliability 1.7 Headroom 1.5

Privacy

weight 50%

What identity, data and metadata the service can demand or collect.

86/100

86 × 50% = 4.3 of 10

Trust

weight 30%

Whether it can technically deliver what it claims — code, audits, age.

84/100

84 × 30% = 2.5 of 10

Reliability

weight 20%

Whether the no-KYC claim holds under real-world pressure.

84/100

84 × 20% = 1.7 of 10

Weighted total 8.5 / 10 · no reliability rule triggered, so the score stands. See the rubric →


Every point, sourced

What earned the score.

Privacy

  • +10Anonymous Account option: a 32-character hash, no email or username
  • +5Accepts Monero (plus ~25 other cryptocurrencies)
  • +4No logs of session history, source IP or sites visited
  • +3Email optional even on a standard account (username + password only)

Trust

  • +6Open-source apps (desktop, Android, browser extension)
  • +6Three independent security audits of apps + infrastructure (Leviathan 2021/2022, Packetlabs 2024) - note: not a dedicated no-logs audit
  • +4Named operator with detailed public incident post-mortems

The fine print, read for you

The clause they bury.

Verbatim — the catch
“Windscribe reserves the right to terminate, suspend, or otherwise restrict your access to this Service ... with or without notice at any time for any reason whatsoever ... Windscribe may impose usage or service limits, suspend service, or block certain kinds of usage at our sole discretion.”

What it meansA very broad discretionary termination and access-restriction power. It is anti-abuse rather than an identity demand, so it does NOT force a higher KYC level, but "for any reason whatsoever" and "at our sole discretion" are exactly the vague clauses our methodology flags, and this is wider than an account-number VPN gives itself. It lowers Trust, not the level.

Read the source →
Verbatim — the catch
“Total amount of bytes transferred in a 30 day period; Timestamp of your last activity on the Windscribe network; Number of parallel connections.”

What it meansWindscribe keeps a small amount of per-account metadata (bandwidth, a last-activity timestamp, live connection count) for abuse prevention, on ALL accounts, not just the free tier. No browsing history, source IP or visited sites are stored, but this is more than the zero-metadata posture of an account-number VPN, and it is the main reason privacy is 86 rather than higher.

Read the source →
KYC trigger threshold

No government ID, ever. A standard account needs only a username and password (email optional, for recovery); an Anonymous Account needs neither, just a 32-character hash. Payment can be fully anonymous (Monero plus ~25 cryptocurrencies). What keeps it at level 1 rather than 0: Windscribe retains a little per-account metadata (bandwidth per 30 days, a last-activity timestamp, live connection count) and is based in Canada, inside the Five Eyes alliance.

Policy review — point by point

  • Broad discretionary termination

    Terms reserve the right to "terminate, suspend, or otherwise restrict your access ... at any time for any reason whatsoever" and to "block certain kinds of usage at our sole discretion." Anti-abuse in intent, but very broad and vaguely worded.

  • Unilateral terms changes

    Windscribe "reserves the right to modify these Terms of Use at any time upon posting," with continued use counted as acceptance.

  • Retains minimal per-account metadata

    Bandwidth per 30 days, a last-activity timestamp, and live connection count are stored for all accounts (abuse prevention). No browsing, IP, or site logs.

  • No government-ID requirement

    Nothing in the terms requires government ID or KYC to sign up or pay.

Jurisdiction analysis

Canada, a member of the Five Eyes intelligence alliance, which is a meaningful downside versus Switzerland (Proton) or a non-aligned jurisdiction. Windscribe mitigates the risk structurally rather than legally: it keeps no browsing logs, and its RAM-disk servers hold no persistent data, as apparently tested in the 2026 Dutch seizure.


We keep watching

Incident & policy timeline.

  1. Apr 2025

    Founder acquitted in Greece; no-logs upheld

    Windscribe founder Yegor Sak was acquitted by an Athens court on 11 April 2025 after a Finland-based Windscribe server was traced in a criminal case. Charges were dismissed and the court accepted that the no-logs policy meant there was no user data to produce - a rare real-world court validation of a no-logs VPN.

    source ↗
  2. Feb 2026

    Dutch server seizure (RAM-disk held)

    Dutch authorities physically seized a Windscribe server. Per Windscribe, its RAM-disk servers meant investigators found only a fresh disk image with no identifying data. The outcome is not yet independently confirmed, and researchers note RAM-only is not bulletproof (e.g. hot-plug seizure without cutting power, or upstream traffic correlation), so we log it as neutral rather than a proven win.

    source ↗
  3. Jun 2024

    FreshScribe RAM-disk infrastructure audited

    Packetlabs audited the new RAM-disk server infrastructure ("FreshScribe") with a positive outcome. Keys exist only in memory and are rotated.

    source ↗
  4. 2021-2022

    Apps audited by Leviathan Security

    The desktop app was audited by Leviathan Security Group in September 2021, and the Android and iOS apps in March 2022; raised issues were addressed.

    source ↗
  5. Jun 2021

    Ukraine servers seized with keys on disk

    Two OpenVPN servers in Ukraine were seized while running a legacy stack with the server certificate and private key stored on disk and no full-disk encryption, which could have enabled server impersonation or interception. No user activity data existed to seize (no-logs). Windscribe disclosed it fully, remediated by July 2021, and moved to RAM-disk servers with short-lived, rotated keys.

    source ↗

The verdict

Where it stands.

Strengths

  • Anonymous Account with no email or username (a 32-character hash)
  • Accepts Monero plus ~25 cryptocurrencies
  • Open-source apps and three independent audits
  • RAM-disk servers (held up in a 2026 seizure)
  • Unlimited simultaneous devices
  • Genuine free tier (10 GB / month)

Trade-offs

  • Retains some per-account metadata (bandwidth/30d, last-activity timestamp, connection count) on all accounts
  • Based in Canada, inside the Five Eyes alliance
  • Broad "terminate for any reason / at our sole discretion" clause
  • Audits cover apps + infrastructure, not a dedicated no-logs audit
  • 2021 Ukraine incident exposed a real server-config gap (since fixed)
Visit Windscribe No affiliate relationship. We link to the official site directly.

Across the internet

What reviewers report.

Consistently praised

  • Praised for the no-email / anonymous-hash account and Monero support
  • Its open-source apps and three audits are cited as real transparency
  • The detailed 2021 incident post-mortem earned goodwill for honesty

Recurring complaints

  • Some users dislike the retained bandwidth/connection metadata
  • Canada (Five Eyes) is a recurring concern
  • Occasional complaints about account restrictions under the broad terms

Sentiment is positive on transparency, open-source, and the anonymous account, and mixed on jurisdiction and the retained metadata. No corroborated fund-freeze or data-betrayal pattern exists; both server seizures (2021, 2026) left no user activity data exposed, consistent with the no-logs claim.


Keep exploring

Related lists & categories.


Ask the bureau

Windscribe, common questions.

Can you use Windscribe without an email?

Yes. A standard account needs only a username and password (email is optional, for recovery), and the Anonymous Account needs neither: you log in with a single 32-character hash, no email and no username. You can also pay in Monero or ~25 other cryptocurrencies, so both the account and the payment can be anonymous.

Is Windscribe no-KYC?

In practice, yes (level 1). No government ID is ever required, and the account can be fully anonymous. We keep it at level 1 rather than 0 because Windscribe retains a little per-account metadata (bandwidth, a last-activity timestamp, connection count) and is based in Canada, inside the Five Eyes alliance.

What happened with the server seizures?

In June 2021, two Ukraine servers were seized with the VPN certificate and key stored on disk, a real config gap, though no user activity was logged to take. Windscribe disclosed it in detail and moved to RAM-disk servers. In February 2026 a Dutch seizure reportedly found nothing on a RAM-disk server, which suggests the fix worked, though that outcome is not yet independently confirmed.

Has Windscribe been audited?

Yes: Leviathan Security audited the desktop app (2021) and mobile apps (2022), and Packetlabs audited the RAM-disk infrastructure (2024). These are app and infrastructure security audits rather than a dedicated no-logs audit, which is why we rate its trust below Mullvad and Proton.

Your exact case not covered? The live Ask the bureau answers it and turns it into a public FAQ.