EN
Back to the archive

The archive · Marketing & Growth · Marketing decision · 2019

WifiMask: Dutch brothers make their VPN's no-log promise a legal fact

Two Dutch brothers anchored their bootstrapped VPN's no-log promise in Dutch law — and said exactly what data they do keep.

WifiMask VPN

The ideaMake no-log a legal fact, not a slogan: point to the Dutch court that suspended data retention, then disclose exactly what data the VPN still holds.incremental

What it had to solve

WifiMask VPN is House of Cyber BV, run since 2015 by Dutch brothers Joris, a designer, and Joost, a hosting engineer. VPN buyers rightly doubt no-log promises, so the company's About page had to make one believable.

How it works

In November 2019 WifiMask, a VPN run by two Dutch brothers, reached the front page of Hacker News through its About page. The pitch was deliberately unglamorous: a small bootstrapped company in 's-Hertogenbosch, providing internet privacy since 2015. The page earned 154 points and 108 comments - not for speed or server counts, but for how it handled the question every VPN faces: why should anyone believe your no-log promise?

The page's closing note made the legal regime the argument. Under Dutch law an ISP is not required to retain customers' communications metadata after a Hague court suspended the data-retention law in 2014, so WifiMask could offer a strict no-log policy as a matter of statute rather than self-declaration. In the discussion the team went further, naming what it does store - a registered email address, a hashed password and the last four digits of a credit card - and admitting no third-party audit had been done yet.

The thread became a genuine audit rather than a launch cheer. Commenters pushed back with the Nine Eyes alliance and the point that a no-log policy cannot prove a negative; one professional noted that the disbanded Dutch retention duty worked in the company's favour, with GDPR caveats. The founders' candor drew suggestions from the thread into their roadmap, from transparency reports to a warrant canary.

Why it lands

  • Choosing a jurisdiction whose law does not compel logging let them make no-log an external legal fact instead of a self-reported promise.
  • Naming exactly what they do hold - email, hashed password, card digits - gave skeptics something concrete to challenge rather than a slogan to distrust.
  • Admitting the missing audit and asking for advice read as honesty in a category where anonymity and hype are the norm.
  • Putting two named brothers and a registered company on the page answered the first question privacy buyers ask: who is actually behind this?

What it did

The Show HN drew 154 points and 108 comments on 2019-11-25, and the thread became an open audit of a two-person VPN: critics raised the Nine Eyes alliance and the unprovability of no-log, while others said publicly declaring who you are is already rare in the category. The exchange pushed the team toward transparency reports and a warrant canary.

Their siteWifiMask About page

What you can take

When a category's core promise cannot be verified, move the debate onto checkable ground: name the legal regime, list the little data you do keep, and admit what you have not audited yet.

Since then

In the thread the team offered an HN discount code, said every advertising euro was returning two, and listed next steps: OpenVPN configurations for other platforms, third-party audits, alternative payment methods, transparency reports and a warrant canary suggested by a commenter. Critics kept the honest-terms point alive, noting that WifiMask's own terms reserved the right to respond to Dutch legal requests and that a no-log claim is ultimately only as good as its reputation. The same law-based framing stayed on the About page in the years after the launch.

Sources

spotted an error? The archive wants to know.

Your turn

You just read one. Describe the brief you are staring at, and see who has been given the same problem.

Free account · 3 free questions · no card

Related cases