Spectre  ·  global privacy
Legal

Privacy Policy

Effective 8 September 2026 · Australia

1. The short version

We sell privacy. The business is built so that we hold as close to nothing about you as we can manage:

2. What we do collect

Order communications. If you contact us by email or Signal to place an order, we hold that correspondence and whatever details you chose to share (typically a delivery or meeting arrangement and the model you want). We don’t ask for more than the order needs.

Setup tokens. When a setup code is issued and redeemed, our server records the token’s state (issued, redeemed, which device model, timestamps) so codes are single-use and interrupted setups can resume. Tokens are opaque identifiers — they are not linked to your name unless your order correspondence links them.

Connectivity bundle assignment. We record which eSIM / VPN / messaging licence bundle was dispensed to which token, so each bundle is handed out exactly once. After handoff, those services are operated by their providers under their own accounts and policies — we don’t see your VPN traffic, messages, or data usage.

Basic service logs. Our hosting provider (Cloudflare) processes IP addresses and request metadata to serve the site and defend it against abuse, with short retention. We do not build profiles from these.

Payment. Cash sales leave no payment record with us beyond the order itself. If online card payment is offered, it is processed by the payment provider; we receive confirmation of payment, not your card details.

3. What we never collect

4. How we use and share information

We use the information above solely to fulfil orders, operate the Portal, meet legal obligations, and defend the service against abuse. We do not sell or rent personal information. We share it only with:

Because we hold so little, there is very little to hand over: no message contents, no device data, no credentials, no traffic logs.

5. Retention

6. Security

The Portal is designed fail-closed: software is verified against pinned cryptographic keys in your browser before anything is installed, secrets live in the server-side secret store, and assets are integrity-addressed. Details of the security design are summarised on the site and in our published security notes.

7. Your rights

You may ask us what we hold about you, ask for it to be corrected, or ask for it to be deleted (subject to records we must keep by law). Contact ausprivacygroup@protonmail.com or Signal apg.98.

If you are unsatisfied with our response to a privacy complaint, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).

8. Changes

If we change this policy we will publish the new version here with a new effective date. We will not weaken the “what we never collect” commitments for existing customers without saying so plainly.

Draft for review by Australian counsel before publication. See also our Terms of Service and Warranty.