IRVIO Project

OPEN SOURCE · ONE-HOP · PEER-TO-PEER VPN

Policy / 02

Privacy

01

Scope and responsibility

This notice describes the official IRVIO website, official software and the protocol behaviour of the current implementation.

The IRVIO network has no single operator or central control point. Each independently operated node is controlled by its owner, including its operating-system configuration and local logs. This notice cannot govern independent nodes, modified software or third-party services.

02

Website and contact

The official website does not use cookies, analytics, advertising trackers, profiling or user accounts. IRVIO does not retain website access logs. Network data required to deliver a requested page is processed transiently and is not intentionally stored by the site.

If you contact irvio@proton.me, the email address, message content and normal email metadata are processed in order to read and answer the message. Correspondence may be retained for as long as it is needed to handle the request or a security matter.

03

Local diagnostics

The official IRVIO client contains no analytics service, centralized telemetry or automatic crash-report upload. It does not use Sentry, Crashlytics or an equivalent remote reporting service.

The local daemon writes INFO-and-higher operational events to its process output. The user interface can display a bounded and sanitized ring of up to 512 recent records, held only in RAM and obtained through a local Unix socket. The ring is lost when the daemon restarts and is never uploaded automatically.

The operating system or the device owner may separately retain process output, system journal entries or crash artifacts. Their retention is determined by the configuration of that device, not by IRVIO.

04

Protocol metadata

IRVIO must process limited technical metadata to discover participants and establish a direct connection. This functional control-plane traffic is not analytics or telemetry.

  • Bootstrap and DHT participants can observe peer identifiers, network addresses and discovery requests.
  • Rendezvous participants can observe an authenticated PeerID, the source address seen by the server, registrations, requested country and bounded signaling metadata.
  • A STUN service can observe the public source IP address and port of a probe and its STUN transaction.
  • The selected Exit Node can observe the client tunnel endpoint and session metadata required to provide the connection.

These data are exposed only where required by the relevant protocol. Independently operated participants may apply their own logging policies.

05

Node operational logs

Discovery, Rendezvous and Exit roles run inside the same daemon process and can write structured operational events to local process output. The official implementation has no central log collector and defines no global retention period.

The current software does not implement per-packet access logs, DNS query logs, destination-domain history or payload logging for user traffic. A node operator can nevertheless retain local process logs through systemd, a container runtime, file redirection or another external collector.

IRVIO does not currently include an official production STUN server. An external STUN provider necessarily sees the source IP address and port of each request; its storage and retention rules are determined by that provider.

06

User traffic

After connection setup, user traffic travels through a one-hop encrypted tunnel directly between the Client and the selected Exit Node. Nodes providing only Bootstrap, DHT or Rendezvous services are not part of the user-data path. If the same node is selected as an Exit Node, it handles user traffic in that role.

The Exit Node must process the decrypted inner IP traffic before forwarding it to the internet. It can therefore observe connection metadata and any application data that does not use end-to-end encryption. HTTPS and other end-to-end encrypted protocols remain protected by their own encryption. Internet services see the public IP address of the Exit Node.

IRVIO does not provide a guarantee of absolute anonymity. Traffic correlation, external service logs, device compromise or the conduct of an independent Exit operator may reveal information about a connection.

07

Storage, disclosure and questions

IRVIO does not sell personal data or provide it to advertising networks. The official website and software do not create a central database of browsing history.

  • Website access logs are not retained.
  • The local diagnostic ring remains in RAM until records are overwritten or the daemon restarts.
  • Live Rendezvous state expires through the protocol lifecycle and is lost when the node restarts.
  • Operating-system logs and independently operated nodes follow the policies chosen by their owners.

Questions about the official website or software can be sent to irvio@proton.me.

Last updated: 1 October 2026.