No-KYC hosting privacy policy. Zero identity documents on file.
GPU Rent Hub Compute LLC rents dedicated GPUs without verifying anyone's identity: an account is a username and a password, payment is in Bitcoin, Ethereum, USDT, USDC, Monero, Solana or Litecoin, and we hold no name, address or identity document for any customer. Short, because there isn't much to say when you don't collect much. This is the complete policy, not a summary of a longer one.
1. No KYC
We do not perform identity verification of any kind, at sign-up or later. We do not ask for, and will refuse if offered, government identification, proof of address, phone numbers, selfies, or payment cards. An account is a username and a password.
This is not a promotional feature. It is how the service was built and how it will stay: we are a hardware landlord, and a landlord who insists on photographing your passport before handing over a key is collecting a liability, not a safeguard. What that means in practice at sign-up, deposit and support is set out on no-KYC GPU hosting.
2. What we collect
- Username. Chosen by you. Not required to be unique to you across the internet; please don't reuse one you use elsewhere if that matters to you.
- Password hash. PBKDF2-HMAC-SHA-256 with 600,000 iterations and a per-user salt. We cannot read your password.
- Balance ledger. Deposit transaction IDs, coin, amount, USD value credited, and every debit against the balance. This is the accounting record and is what an invoice is generated from. How each coin is confirmed and credited is described on paying for GPU rental with crypto.
- Instance metadata. GPU type, count, region, template name, start and stop timestamps, term, assigned IP addresses, SSH public keys you uploaded.
- Optional recovery data you add: a recovery email (stored hashed; we can send to it but not display it back), a PGP public key, a TOTP secret.
- Support messages you send us, for the life of the thread plus 30 days.
- Login source IP for the dashboard and API, kept 7 days for brute-force defence.
3. What we never collect
- Names, addresses, dates of birth, nationality, identity documents, phone numbers.
- Payment card or bank details — we have no way to accept them.
- The contents of your instance's disk, memory, or network traffic.
- Process lists, command history, container images, models, datasets, or any other description of your workload.
- Browser fingerprints, analytics events, advertising identifiers.
- Anything from third-party data brokers. We have never bought data and never will.
4. Instance telemetry
To bill correctly and keep the datacenter cool, our hosts in DFW-1, IAD-1 and PDX-1 report the following about each instance, sampled every 30 seconds, kept for 90 days as aggregates: power draw per GPU, GPU and host temperature, fan speed, bytes in and out per network port, and whether the host answers a health probe. That is the exhaustive list. There is no software agent inside your operating system, the console is not recorded, and your NVMe is encrypted with a key held in the host's TPM that is destroyed when you release the instance.
5. Retention
- Account record: for the life of the account plus 30 days after deletion.
- Balance ledger: 7 years, as required for our own accounting. It contains no identity — a ledger line is a transaction ID, a coin, an amount and a username.
- Instance metadata: 12 months after the instance is released.
- Telemetry aggregates: 90 days.
- Login IPs: 7 days.
- Support threads: 30 days after close.
6. Cookies & this website
The marketing pages set no cookies and load no third-party scripts except the web fonts from Google Fonts (you can self-host them; the CSS falls back to system fonts if they're blocked). The dashboard sets one session cookie, grh_session, HttpOnly and SameSite=Strict, which expires when you log out or after 30 days of inactivity. There is no analytics of any kind. Server access logs are kept for 24 hours and contain no query strings.
7. Legal requests
We respond to valid legal process issued by a court or agency with jurisdiction over GPU Rent Hub Compute LLC in the United States. We do not respond to informal requests, foreign process not domesticated in the US, or requests from private parties. When we do respond, we can only produce what section 2 lists — we hold no content and no identity. We notify the affected account through the dashboard unless legally prohibited from doing so, and we count every request in the transparency report published each January.
8. Tor
The dashboard and API are available as an onion service. Tor users are treated identically to everyone else, including for deposits and deployments. We do not flag, rate-limit or log Tor traffic differently. Monero deposits are handled by a node we run ourselves, so a payment over Tor never passes through a third-party processor: see Monero GPU hosting.
9. Changes
Changes to this policy are announced in the dashboard 30 days before they take effect and every version is archived with a diff. The only direction we have ever changed it is to collect less: version 3 (2022) dropped login IP retention from 30 days to 7; version 5 (2024) removed the optional phone recovery we briefly offered.