LNVPS

WireGuard VPN from €4/month

Tunnels on the same infrastructure as our VPS fleet: our own hardware and AS214973 address space where we have it, leased capacity where we do not. Your device generates the keypair and hands over only the public half, so the key your traffic is encrypted with never exists on our side.

How it works

  1. Buy a plan and pay its subscription with Lightning, Bitcoin or card.
  2. Register each device by its WireGuard public key. Generate it with the WireGuard app or wg genkey, or let the browser make one for you.
  3. Download a config, or scan its QR code, and bring the tunnel up. One file per exit region, all sharing the same key.

Plans

PlanDevicesAddressesPrice
Gold5IPv4 + IPv6€4/month

A device is one registered public key: your phone, your laptop, your router. Up to 5 devices on one plan, and a device you remove frees its slot.

Exit regions

DublinLondonQuebec

Every device reaches every region. The address inside the tunnel is the same wherever you exit, so switching country is a config file, not a re-registration.

What we hold, and what we do not

  • We hold your public key and the internal address assigned to it. That pair is what a WireGuard peer is, and it is all a route server needs to carry you.
  • No traffic or connection logs are written. WireGuard itself keeps a last handshake time and the endpoint you are currently dialling from, in memory, because the protocol cannot route a packet back without them.
  • The private key that decrypts your traffic is generated on your device and never sent to us, so it is not ours to lose, to leak, or to be compelled to produce.
  • Nothing is configured on a route server until the plan is paid for, and removing a device revokes its key on every server the service terminates on.
  • Sign in with a Nostr key and there is no email or name on the account at all. Pay with Lightning or on-chain Bitcoin and there is no card statement either.

When you want a whole machine instead

A VPN plan gives you an exit, not a server. If you want a box to run your own services on, with a static IPv4 and IPv6 and unmetered traffic, our VPS hosting runs on the same fleet.

FAQ

Who generates the keys?
You do. Your device makes the WireGuard keypair and sends us only the public half, so the key that decrypts your traffic is never ours to hand over or to lose.
Do you keep logs?
No traffic or connection logs are written. A route server holds the public keys it carries and the internal address each one has, and WireGuard keeps a last handshake time and your current endpoint in memory, which is what the protocol needs to route a packet back to you.
What do I need to connect?
The official WireGuard client, on any platform it supports. We give you a ready-to-use config file per region, or a QR code to scan on a phone.
Do I have to pick a region when I buy?
No. A device holds one keypair and one address that work in every region, so switching exit is a different config file, not a different plan or a new key.
Do you need my email?
Not if you sign in with a Nostr key: no email, no name, no KYC. Signing in with Google or a passkey uses whatever that account gives us, and paying by card means the card processor sees your billing details.
How do I pay?
Lightning, on-chain Bitcoin, or card. We run our own Lightning node, so sats do not route through a third-party processor.
What happens if I stop paying?
The plan lapses and its devices stop connecting. Your keys and addresses are held until you remove the devices, so renewing brings the same tunnels back.
Get a tunnel from €4/month