TL;DR
- What the page said: that your IP address is never written to disk, that the service runs on RAM-only infrastructure with zero logs, and that security logs are deleted within 24 hours.
- What the audit found: client IP addresses retained longer than intended by our DDoS defence layers and system diagnostics, short diagnostic captures of DNS traffic kept on disk, and weekly off-site backups containing some of these records without encryption.
- What changed: legacy logs purged; retention limits enforced (at most 30 days for defence decisions, 7 days for diagnostic captures); off-site backups encrypted with age on the server before upload.
- What did not change: our resolvers keep no query logs.
In plain words: we kept more than we said, for longer than we said. That is fixed.
The discrepancy was found while checking a single privacy sentence before publishing it. We fixed the system first and the wording second, so the new page describes a server that already behaves the way it says. The privacy page now lists every record that holds a source address, what it contains and how long it is kept. The footer, the home page, the FAQ and the terms were corrected the same day, and the correction note stays at the top of the privacy page.