PeerBlade
Back to home
LEGAL INFORMATION

Privacy policy

Updated: 5 August 2026

This document explains what data is processed when you use peerblade.com and, where you have access to it, the my.peerblade.com control panel — for which purposes and for how long it is kept.

1. Data controller

Data processing for peerblade.com and the my.peerblade.com panel is carried out by the PeerBlade project, run by an individual developer. For any question about data processing, write to info@peerblade.com.

2. Self-hosted installations

If you deploy PeerBlade in your own infrastructure, you determine the purposes and means of processing data inside that installation yourself. The PeerBlade project has no access to the data of your installation unless you deliberately share it — for example when contacting support or sending feedback.

This covers accounts as well: in a self-hosted deployment they live in your own database. The PeerBlade project never receives the usernames, display names or password hashes of your users and cannot manage them.

If you are reading this document inside a PeerBlade installation deployed by somebody else, the operator of that installation is its owner rather than the PeerBlade project, and questions about data processing go to them.

The sections below describe processing on peerblade.com and in the panel hosted by the PeerBlade project.

3. What data is processed

When using the control panel

  • Account: username, display name, password hash, role, last sign-in date and the failed sign-in counter.
  • Session: session token hash, creation, expiry and last-seen timestamps.
  • Audit log: IP address, browser user agent, the action performed, its result and the time. The log exists for security — it shows sign-ins and administrative operations.
  • Infrastructure data: names and addresses of the servers you add, peer names, public keys, transferred traffic counters, the last handshake time, and the public address and port a peer last connected from.

When visiting the website

  • Technical connection data in web server logs: IP address, user agent, requested path, request time.
  • Google Analytics data — only with your consent (see section 6).

4. What is not processed

  • Peer private keys and preshared keys — they stay on your servers and are never sent to the panel.
  • The contents of your traffic — PeerBlade is a control panel, not a VPN provider: user traffic never passes through PeerBlade infrastructure.
  • Passwords in plain text — only a hash is stored.
  • Advertising, remarketing and Google Signals are not used.

5. Purposes and legal bases

  • Authentication and service operation — performance of the agreement with the user.
  • Security (audit log, lockout after failed sign-ins) — legitimate interest of the controller.
  • Landing page visit statistics — your consent, which you can withdraw at any time.

6. Cookies

CookiePurposeLifetime
peerblade_sessionNecessary. Stores the panel sign-in session; authentication is impossible without it.Until the session expires (7 days by default) or sign-out
peerblade_localeNecessary. Stores the selected interface language so the site opens in it on your next visit.1 year or until you change the choice
_ga, _ga_*Analytics. Google Analytics 4, landing page visit analytics.Up to 2 years — depending on Google Analytics and browser settings. Set only after consent and deleted when consent is withdrawn.

Before consent is given the Google Analytics script is not loaded at all. You can withdraw or change your decision at any time through the “Cookie settings” link in the site footer — analytics cookies are deleted when you decline.

7. Retention periods

  • Account data — for as long as the account exists.
  • Sessions — until expiry or sign-out from the panel.
  • Audit log — until deleted by the infrastructure administrator; scheduled automatic deletion is not performed in the current version.
  • Analytics data — according to Google Analytics retention settings.

8. Recipients of data

Data is not sold. Recipients may be:

  • Google LLC — analytics data about landing page visits, only where you have consented to analytics.
  • flagcdn.com — the panel loads country flag images from this content delivery network, so it learns the IP address of your browser and the country code being displayed. No panel data, server names or peer data are transmitted.
  • The hosting provider — as far as hosting the service and its infrastructure requires.
  • Competent authorities — where disclosure is required by law.

9. International transfers

When Google Analytics is used, data may be processed by Google LLC and its affiliates outside your country. Analytics is enabled only after your consent; before that the Google Analytics script is not loaded and no analytics data is sent to Google.

If PeerBlade is deployed in your own infrastructure, where the panel data is stored is determined by the infrastructure you choose.

10. Your rights

To the extent provided by applicable law, you may request information about the processing of your data, require its correction, restriction or deletion, and withdraw consent for analytics. To do so, write to info@peerblade.com.

If you believe your rights have been infringed, you may also lodge a complaint with the competent data protection authority.

11. Changes to this policy

The current version of the policy is always available on this page. The date of the last update is shown at the top of the document.

The policy is published in Russian and English. In case of any discrepancy, the Russian version prevails.

PeerBlade
FeaturesHow it worksFAQDeploy
© 2026 PeerBlade. All rights reserved.For data protection enquiries: info@peerblade.com
Privacy policyTerms of use