access historyThis refers to internet log records and access tracking data stored by StageVPN in accordance with relevant laws such as the Iran Communications Secrets Protection Act, and does not include the content of communications.
StageVPN automatically deletes connection records (connection time, connection IP, destination IP/port, etc.) for 93 days from the date of creation, and does not record communication content such as visited pages or messages. This is because it is a legal obligation for Korean telecommunications operators, and StageVPN decided to disclose the items, period, and provision procedures first, rather than leaving this fact in small print. This article cites the original text of the law and explains what remains and what does not remain, when records are erased, and who can receive them and through what procedures (as of September 2026).
- 93 days
- StageVPN connection record storage period (from creation date, automatically deleted thereafter)
- 3 months or more
- Minimum legal storage period for internet log records and access tracking data (Enforcement Decree Article 41, Paragraph 2)
- 92 days
- The longest number of days in a calendar month (e.g. July 1 - September 30)
- 7 years
- If data is provided, the period for keeping the provision ledger and request form (Article 13, Paragraph 7 of the Communications Secrets Protection Act)

Legal basis: What law requires me to keep access records?
The law requiring storage of access records is Article 15-2 of the Communications Secrets Protection Act and Article 41 of the Enforcement Decree of the same law. The law establishes the telecommunication business operator's obligation to cooperate and delegates the retention period, and the enforcement decree sets the minimum retention period for each type of data. Enbase Korea Co., Ltd., which operates StageVPN, is subject to this obligation as a telecommunications carrier in Korea.
“① Telecommunications business operators shall cooperate with requests by prosecutors, judicial police officers, or heads of intelligence and investigative agencies to provide communication-restricting measures and communication confirmation data implemented pursuant to this Act. ② Matters to be cooperated by telecommunications business operators for the execution of communication-restricting measures pursuant to the provisions of paragraph (1), the storage period of communication confirmation data, and other necessary matters regarding the cooperation of telecommunications business operators shall be determined by Presidential Decree.”
Article 15-2 of the Communications Secrets Protection Act (Telecommunications Business Operators' Obligation to Cooperate), Act No. 20735, effective August 1, 2025 — National Law Information Center
Article 15-2 establishes two things. First, telecommunication business operators must cooperate with requests to provide communication confirmation data in accordance with the law. Second, how long it must be kept is left to the Presidential Decree (Enforcement Decree). The enforcement ordinance is Article 41 below.
“② The retention period of communication confirmation data of a telecommunications business operator pursuant to Article 15-2, Paragraph 2 of the Act shall be longer than the period according to the following classifications: 1. Communication confirmation data pursuant to subparagraphs a to d and f of Article 2, Paragraph 11 of the Act: 12 months. However, in the case of data related to long-distance and local telephone service, it shall be 6 months. 2. Pursuant to Article 2, Subparagraph 11, e and g of the Act. Communication confirmation data: 3 months”
Article 41 (Telecommunications Business Operators' Cooperation Obligation, etc.) Paragraph 2 of the Enforcement Decree of the Communications Secrets Protection Act, Presidential Decree No. 35674, effective August 1, 2025 — National Law Information Center
What “e and pastoral items” in Article 41, Paragraph 2 are, is provided in Article 2, Item 11 of the Act. Communication confirmation data refers to data on the facts of communication, such as “when, who and where the communication was made,” rather than the content of the communication.
“11. ‘Communication fact confirmation data’ refers to data on telecommunication facts that fall under any of the following items: (…) E. Computer communication or Internet log record data regarding the fact that a computer communication or Internet user used telecommunication services (…) F. Access tracking data that can confirm the location of the information and communication device used by a computer communication or Internet user to access the information and communication network”
Communications Secrets Protection Act Article 2 (Definitions) No. 11 E and A — National Law Information Center
The records left on the VPN server showing “which account connected and where it communicated with and when” correspond to Mamok’s Internet log records, and the records leaving “which IP was accessed from” correspond to Samok’s access tracking data. Therefore, the legal minimum retention period for StageVPN’s access records is 3 months.
| division | legal data | Minimum storage period | Relationship with VPNs |
|---|---|---|---|
| Items A~L | Subscriber's telecommunication date and time, telecommunication start/end time, the other party's subscriber number, frequency of use | 12 months (6 months for data related to long-distance and local calls) | Focused on phone service. StageVPN doesn't have this material |
| Barmok | Location tracking data of the transmitting base station | 12 months | Mobile communication base station data. StageVPN doesn't have this material |
| mamok | Log record data on the fact that Internet users used telecommunication services | 3 months | VPN connection time, account/tunnel IP, destination IP/port |
| pastoral care | Tracking data of the access point that can confirm the location of the information and communication device used to access the Internet | 3 months | IP and port connected to VPN server |
The reason StageVPN chose 93 days is because the statutory language is “not less than three months.” The three calendar months vary from 89 to 92 days depending on the combination of three consecutive months, with a maximum of 92 days, such as July 1 to September 30. Records created in any month are set at 93 days to fulfill the statutory period, and are not arbitrarily kept longer than that. The legal content in this article is based on the enforcement ordinance of the Communications Secrets Protection Act (effective August 1, 2025) posted on the National Legislation Information Center in September 2026.
What to keep: What stays and what doesn't?
What remains is the connection time and address information, and what does not remain is the content of the communication. The StageVPN app and StageVPN for Chrome work differently and have slightly different items. In both methods, the server collects records every minute and sends them to the StageVPN database via encrypted communication (HTTPS). The two tables below are Access record storage notice Articles 2 and 3 are translated verbatim.
| record | item | Storage period |
|---|---|---|
| External connection history | Connection start time, tunnel IP address (internal address assigned to the device), protocol (TCP·UDP·ICMP), destination IP address and port, departure port, recorded server | 93 days |
| Connection location record | IP address and port (WireGuard endpoint) connected to the VPN server, account (email), public key, tunnel IP, server, and confirmation time. Only recorded when the access address changes | 93 days |
| session history | Account, server, tunnel IP, session start/end time, amount of data sent/received. Used to determine which account the tunnel IP is assigned to | Until membership withdrawal (minimum 93 days from creation date for parts required for comparison) |
The destination domain (host name) is not included in the app history. DNS lookups are also processed within the VPN tunnel, but there is no record of which domains were looked up. The problem with DNS leaking out of the tunnel is DNS leak and WebRTC leakThis was explained separately.
| record | item | Storage period |
|---|---|---|
| Proxy connection history | Connection start time, account identifier, proxy session identifier, connection IP address, destination host name and port, destination IP address, number of bytes sent and received, connection duration, recorded server. | 93 days |
| Proxy session history | Account, server, session start/end time, connection IP address that started the session | 93 days |
StageVPN for Chrome sends browser communication to an HTTPS proxy, so it logs the destination host name required for the connection (e.g. www.example.com), but does not log page paths, search terms, query strings, or page content. It also doesn't decrypt encrypted content on HTTPS sites. The difference in protection scope between the two methods is Browser VPN vs App VPNPlease refer to .
We do not store the following information in any way (Article 4 of the Access Record Retention Notice):
- Contents of communication exchanged: web page contents, email/message text, audio/video, files
- URL path, search term, query string, entered form value, and cookie value
- List of domain names (DNS lookups) and visited domains looked up in the StageVPN app
- Decrypted content of HTTPS communications (does not intercept or decrypt encrypted communications)
- Precise location information, such as your device’s GPS
| action | StageVPN App History | StageVPN for Chrome History | What remains nowhere |
|---|---|---|---|
| Read articles from news sites | Time, destination IP/port (e.g. 443), protocol | Time, host name/port, destination IP, number of bytes | Address and content of the read article |
| Search in the portal | Time, destination IP/port | Time, portal hostname/port | Search terms and search results |
| Send photos via messenger app | Time, messenger server IP/port | No logging (only handles browser communications) | Contacts, messages, photos |
| Internet banking login | Time, bank server IP/port | Time, bank hostname/port | ID, password, transaction history |
Apart from access records, there are several other records to prevent fraudulent use and ensure security. VPN key issuance and release records are automatically deleted after 90 days, service setting change audit records are automatically deleted after 180 days, and API request records (server logs) are automatically deleted after 30 days. The period for each item is privacy policy It's all written down in Article 3.

Data Life: How are records created and when are they deleted?
Access records are created on the server at the moment of connection and transferred to the database every minute, and are deleted by the database's automatic expiration function 93 days from the date of creation. Rather than having a human determine the deletion schedule, each record is automatically erased at a set expiration time, so StageVPN can't keep it arbitrarily longer.
- 0 daysCreate connections and records
The VPN server or proxy server records the time and address information of new connections. The content of your communications is not subject to recording from the outset.
- 1 minute unittransfer to database
The server gathers the records and sends them over HTTPS. Records that cannot be sent due to network problems are temporarily stored on the server until retransmission is successful and then deleted after transmission.
- 1~93 dayscustody
Only the minimum number of people absolutely necessary for work can access it, and access details are managed. It is only used to respond to requests in accordance with laws and to confirm reports of abuse, and is not used for advertising, tendency analysis, or sales.
- 93 days have passedautomatic deletion
Outdated records are automatically deleted from the database.
- Backup cycleDelete backup
Information remaining in the backup is also deleted according to the backup storage cycle (Article 5 of the Personal Information Processing Policy).
The exception is the app's session history. Session records are kept until membership withdrawal as they are usage history necessary for service provision. However, the parts necessary for comparison with access records remain even after withdrawal until 93 days have passed from the date of creation. Even if a member withdraws, access records already created will be deleted after 93 days due to legal storage obligations, and will be separated from other information and stored only for the purposes stipulated by law.
User Rights: Can I view or delete my records?
You can request viewing, but deletion during the storage period will not be requested. After verifying their identity, members can ask to see whether their access records are being kept and to view their contents. However, viewing may be restricted in accordance with Article 35, Paragraph 4 of the Personal Information Protection Act, and in this case, StageVPN will notify you of the reason.
Access records during the retention period cannot be deleted before the end of the period even if deletion is requested due to legal storage obligations, and are automatically deleted after 93 days. Inquiries and requests can be sent to the Personal Information Protection Manager (privacy@stagevpn.com) or Customer Center (support@stagevpn.com). If you are not satisfied with StageVPN's handling, you can apply for consultation or dispute mediation to the Personal Information Dispute Mediation Committee (1833-6972, without area code) or the Korea Internet & Security Agency's Personal Information Infringement Reporting Center (118, without area code). The difference between membership withdrawal and subscription cancellation StageVPN plan informationThis is explained in .
Provision procedure: Who can receive access records and through what procedures?
Access records will be provided only upon written request that meets the requirements and procedures established by law, including court permission, and to the minimum extent necessary within the scope of the request. It is not automatically provided upon request, and StageVPN will request supplementation or refuse to provide any requests that are insufficient or overly broad. The request procedure for criminal investigation is determined by Article 13 of the Communications Secrets Protection Act.
“③ When requesting the provision of communication confirmation data pursuant to paragraphs 1 and 2, permission must be obtained from the competent district court (including military courts; hereinafter the same shall apply) or support in writing recording the reason for the request, the relationship with the relevant subscriber, and the scope of the necessary data. However, if there are urgent reasons for which permission from the competent district court or support cannot be obtained, the request for provision of communication confirmation data must be received without delay and sent to the telecommunications business operator. ④ Paragraph 3 If communication confirmation data has been provided for urgent reasons in accordance with the proviso, but permission has not been obtained from the local court or support, the provided communication confirmation data must be destroyed without delay.”
Communications Secrets Protection Act Article 13 (Procedures for Providing Communication Confirmation Data for Criminal Investigation) Paragraphs 3 and 4 — National Law Information Center
Article 13, Paragraph 1 specifies that the person who can make the request is a prosecutor or judicial police officer, and Paragraph 3 stipulates that the court's permission must be obtained in writing stating the reason for the request, its relevance to the subscriber, and the scope of the data. In case of emergency, you must request first and obtain permission without delay. If permission is not obtained, the received materials must be destroyed. The obligation to record after provision is provided in Paragraph 7 of the same Article.
“⑦ When a telecommunications business operator provides communication verification data to a prosecutor, judicial police officer, or head of an intelligence and investigative agency, it shall report the status of data provision to the Minister of Science, ICT and Future Planning twice a year, and keep a ledger containing necessary matters, such as the provision of the communication verification data, and related data, such as a request for provision of communication verification data, for 7 years from the date of providing the communication verification data.”
Article 13, Paragraph 7 of the Communications Secrets Protection Act — National Law Information Center
The investigative agency that received the data must notify the person concerned. The notification deadline is determined by Article 13-3 for each case processing result.
“① A prosecutor or judicial police officer shall, in relation to a case for which communication verification data has been provided pursuant to Article 13, notify the party subject to the provision of communication verification data in writing of the fact that communication verification data has been provided, the agency requesting provision, the period, etc. within the period specified in the following categories: 1. A disposition not to file a public indictment, file a prosecution, or transfer to the prosecution (suspension of prosecution, suspension of witness, or suspension of investigation) (excluding decisions) or in the case of a disposition not to book a case: Within 30 days from the date of such disposition (…) 3. If an investigation is in progress: Within 30 days from the date of receipt of communication confirmation data (3 years in the case of a crime falling under any subparagraph of Article 6, Paragraph 8).
Communications Secrets Protection Act Article 13-3 (Notice of Provision of Communication Confirmation Data for Criminal Investigation) Paragraph 1 — National Law Information Center
Paragraph 2 of the same article stipulates that notification may be postponed if there is a risk of national security, threats to the life or body of persons involved in the case, risk of destruction of evidence or escape, or infringement of honor or privacy, and paragraph 4 stipulates that notification must be made within 30 days from the date the cause is resolved. Requests for national security follow separate procedures set forth in Article 13-4 of the same Act. Translating these provisions into StageVPN's actual processing order, it is as follows:
- Request from investigative agencyProsecutors, judicial police officers, etc. prepare a document stating the reason for the request, its relationship with the subscriber, and the scope of required data.
- court permissionPermission from the competent local court or branch office (if urgent, permission will be given without delay after request; if not received, data will be destroyed)
- StageVPN ReviewIdentify requirements, target period and scope of requests and permits. If insufficient, request supplementation or refuse
- Minimum range providedProvide only the bare minimum required within the scope of the request
- Records and NotificationsProvided by captain for 7 years, reported twice a year. Investigative agency notifies the parties in writing
There are also access logs and other types of requests. Article 83 of the Telecommunications Business Act stipulates requests for provision of subscriber information such as the user's name, ID, and subscription date, and with the revision in December 2023, the name was changed from ‘communication data’ to ‘communication user information’.
“③ A telecommunications business operator may comply with a request from a court, prosecutor or head of an investigation office (…), or head of an intelligence and investigative agency to view or submit (hereinafter referred to as ‘provision of communication user information’) the following data (hereinafter referred to as ‘communication user information’) for the purpose of trial, investigation (…), execution of sentence, or collection of information to prevent harm to national security: 1. User’s name 2. User’s resident registration number. 3. User’s address 4. User’s phone number 5. User’s ID (…) 6. User’s subscription date or termination date ④ Requests for provision of communication user information pursuant to paragraph 3 must be made in writing (hereinafter referred to as ‘information provision request’) stating the reason for the request, relationship with the relevant user, and scope of required communication user information.”
Article 83 (Protection of Communications Secrets) Paragraphs 3 and 4 of the Telecommunications Business Act, revised text on December 29, 2023 — National Law Information Center
The wording of Article 83, Paragraph 3 is “may follow.” In other words, the provision of communication user information is an area where the business operator's judgment intervenes, unlike communication confirmation data that requires court permission, and StageVPN reviews the legality and necessity of the request and responds only to the minimum extent necessary. The organization that received the data must notify the party within 30 days in accordance with Article 83-2 of the same law, and StageVPN does not collect resident registration numbers, so data No. 2 does not exist from the beginning.
| request type | legal basis | Target information | StageVPN’s Response |
|---|---|---|---|
| Provision of communication confirmation data | Article 13 of the Communications Secrets Protection Act, etc. | Connection history (time, connection IP, destination IP/port, host name for Chrome) | Minimum scope available only on written requests with court permission (including post-release permission in emergency cases) |
| Provision of communication user information (former name ‘communication data’) | Article 83 of the Telecommunications Business Act | Subscriber information such as user name, ID, subscription date and cancellation date | Review the legitimacy and necessity of the request and respond only to the minimum extent necessary |
| Request for national security | Article 13-4 of the Communications Secrets Protection Act | Communication confirmation data | Respond only when separate procedures prescribed by law are in place |
| Requests from foreign governments and organizations | Korean laws and regulations such as international criminal legal assistance, etc. | Different for each request | Respond only if procedures stipulated by Korean laws are followed. |
Even administrators of corporate VPNs cannot see these statutory access records. What is provided to the administrator is the company qualification session time, usage time, data amount, server name/country, and even the dedicated IP used. Enterprise Fixed IP VPN Introduction GuideIt was covered in .

How to read no-log ads
You should first check what the phrase “do not leave records” means not to leave behind. This is because the meaning varies greatly depending on whether it means not leaving any communication content or not leaving any metadata such as connection time and address. VPN operators are technically in a position to see multiple layers of information, and which layers they must leave behind depend on which country's laws the operator follows.
- Account/Payment InformationSignup email, subscription status, payment history
- Connection metadataConnection IP, connection time, data amount
- Destination informationDestination IP/port, host name
- DNS queriesDomain viewed
- Content of communicationIf it is HTTPS, it is encrypted and cannot be viewed without decryption.
| layer of information | Whether to store StageVPN | Period/Conditions |
|---|---|---|
| Account/Payment Information | custody | The account lasts until cancellation, and transaction records last for 5 years. Card number is not stored |
| Connection metadata | custody | Access IP 93 days, app session records until withdrawal (minimum 93 days) |
| Destination information | custody | Destination IP/port 93 days. Hostname is StageVPN for Chrome only |
| DNS queries | Not kept | StageVPN app does not log domains viewed |
| Content of communication | Not kept | Do not intercept or decrypt encrypted communications |
When comparing VPN services' logging policies, check to see if the items below are listed in their documentation: Neither question can be answered with one word: ‘no logs’.
- Is there a list of what items to keep and what not to keep? Does it say time, IP, destination, DNS, and content separately, rather than just a single line saying “no logs”?
- Are the retention period and deletion method written in numbers? If there is only an open expression such as “as long as necessary,” the time period is not set.
- Does it disclose which country the operator is located in and what laws it applies to? Since Korean telecommunications operators are obliged to keep connection records, you should be suspicious of “no log” advertisements from Korean operators.
- Do you disclose what procedures are used to respond to requests from investigative agencies? Are the criteria for requesting court permission, scope review, and denial stated?
- Does it specify that the records will not be used for advertising, behavioral analysis, or sales purposes?
- Is there a window for users to view or inquire about their records?
Conversely, saying that access records are kept does not mean that the content of communications is also examined. The reason StageVPN discloses all items, periods, and delivery procedures is because we believe that the starting point of trust is for users to know exactly what they can and cannot expect. The published policy becomes the standard that the operator must adhere to, and users can ask questions based on that standard. The scope and limitations of a VPN are What VPNs Prevent and Can't Prevent, the overall structure of service security is Security InformationI organized it in .
reference material
- Communications Secret Protection Act — Article 2, Paragraph 11 (Definition of communication confirmation data), Article 13 (Provision procedure and court permission), Article 13-3 (Notification), Article 13-4 (Provision for national security), Article 15-2 (Telecommunications business operator's obligation to cooperate) (National Legislation Information Center)
- Enforcement Decree of the Communications Secrets Protection Act — Article 41, Paragraph 2 (Retention period by type of communication confirmation data) (National Legislation Information Center)
- Telecommunications Business Act — Article 83 (Protection of communication secrets, provision of communication user information), Article 83-2 (Notification of provision) (National Legislation Information Center)
- Personal Information Protection Act — Article 35 (View of personal information) and reasons for restriction of view (National Legislation Information Center)
- Personal Information Protection Committee — Personal information protection policy and information subject rights information (Personal Information Protection Committee)
- Personal Information Dispute Mediation Committee — Application for mediation of disputes related to personal information (Personal Information Dispute Mediation Committee)
- Personal Information Infringement Reporting Center — Personal information infringement reporting and consultation (118 without area code) (Korea Internet & Security Agency)



