StageVPN Guide

VPN connection records are kept for 93 days: StageVPN log policy read in full text

In accordance with Article 41 of the Enforcement Decree of the Communications Secrets Protection Act, StageVPN automatically deletes access records after keeping them for 93 days and does not record communication content. Explains how to read the original text of the law, archived items, deletion process, procedures for providing to investigative agencies, and records policy advertisements.

StageVPN Team22 min read

3D illustration expressing trust showing neatly organized record cards inside a transparent glass box

access historyThis refers to internet log records and access tracking data stored by StageVPN in accordance with relevant laws such as the Iran Communications Secrets Protection Act, and does not include the content of communications.

StageVPN automatically deletes connection records (connection time, connection IP, destination IP/port, etc.) for 93 days from the date of creation, and does not record communication content such as visited pages or messages. This is because it is a legal obligation for Korean telecommunications operators, and StageVPN decided to disclose the items, period, and provision procedures first, rather than leaving this fact in small print. This article cites the original text of the law and explains what remains and what does not remain, when records are erased, and who can receive them and through what procedures (as of September 2026).

93 days
StageVPN connection record storage period (from creation date, automatically deleted thereafter)
3 months or more
Minimum legal storage period for internet log records and access tracking data (Enforcement Decree Article 41, Paragraph 2)
92 days
The longest number of days in a calendar month (e.g. July 1 - September 30)
7 years
If data is provided, the period for keeping the provision ledger and request form (Article 13, Paragraph 7 of the Communications Secrets Protection Act)
Only access records required by the Communications Secrets Protection Act are kept.
Only access records required by the Communications Secrets Protection Act are kept.

What to keep: What stays and what doesn't?

What remains is the connection time and address information, and what does not remain is the content of the communication. The StageVPN app and StageVPN for Chrome work differently and have slightly different items. In both methods, the server collects records every minute and sends them to the StageVPN database via encrypted communication (HTTPS). The two tables below are Access record storage notice Articles 2 and 3 are translated verbatim.

Table 2. Records kept by the StageVPN app (iOS, Android, desktop) (Access record retention notice Article 2)
recorditemStorage period
External connection historyConnection start time, tunnel IP address (internal address assigned to the device), protocol (TCP·UDP·ICMP), destination IP address and port, departure port, recorded server93 days
Connection location recordIP address and port (WireGuard endpoint) connected to the VPN server, account (email), public key, tunnel IP, server, and confirmation time. Only recorded when the access address changes93 days
session historyAccount, server, tunnel IP, session start/end time, amount of data sent/received. Used to determine which account the tunnel IP is assigned toUntil membership withdrawal (minimum 93 days from creation date for parts required for comparison)

The destination domain (host name) is not included in the app history. DNS lookups are also processed within the VPN tunnel, but there is no record of which domains were looked up. The problem with DNS leaking out of the tunnel is DNS leak and WebRTC leakThis was explained separately.

Table 3. Records kept by StageVPN for Chrome (Access Record Retention Notice Article 3)
recorditemStorage period
Proxy connection historyConnection start time, account identifier, proxy session identifier, connection IP address, destination host name and port, destination IP address, number of bytes sent and received, connection duration, recorded server.93 days
Proxy session historyAccount, server, session start/end time, connection IP address that started the session93 days

StageVPN for Chrome sends browser communication to an HTTPS proxy, so it logs the destination host name required for the connection (e.g. www.example.com), but does not log page paths, search terms, query strings, or page content. It also doesn't decrypt encrypted content on HTTPS sites. The difference in protection scope between the two methods is Browser VPN vs App VPNPlease refer to .

We do not store the following information in any way (Article 4 of the Access Record Retention Notice):

  • Contents of communication exchanged: web page contents, email/message text, audio/video, files
  • URL path, search term, query string, entered form value, and cookie value
  • List of domain names (DNS lookups) and visited domains looked up in the StageVPN app
  • Decrypted content of HTTPS communications (does not intercept or decrypt encrypted communications)
  • Precise location information, such as your device’s GPS
Table 4. Examples of how the same behavior is recorded
actionStageVPN App HistoryStageVPN for Chrome HistoryWhat remains nowhere
Read articles from news sitesTime, destination IP/port (e.g. 443), protocolTime, host name/port, destination IP, number of bytesAddress and content of the read article
Search in the portalTime, destination IP/portTime, portal hostname/portSearch terms and search results
Send photos via messenger appTime, messenger server IP/portNo logging (only handles browser communications)Contacts, messages, photos
Internet banking loginTime, bank server IP/portTime, bank hostname/portID, password, transaction history

Apart from access records, there are several other records to prevent fraudulent use and ensure security. VPN key issuance and release records are automatically deleted after 90 days, service setting change audit records are automatically deleted after 180 days, and API request records (server logs) are automatically deleted after 30 days. The period for each item is privacy policy It's all written down in Article 3.

The process by which records are created and erased
The process by which records are created and erased

Data Life: How are records created and when are they deleted?

Access records are created on the server at the moment of connection and transferred to the database every minute, and are deleted by the database's automatic expiration function 93 days from the date of creation. Rather than having a human determine the deletion schedule, each record is automatically erased at a set expiration time, so StageVPN can't keep it arbitrarily longer.

  1. 0 daysCreate connections and records

    The VPN server or proxy server records the time and address information of new connections. The content of your communications is not subject to recording from the outset.

  2. 1 minute unittransfer to database

    The server gathers the records and sends them over HTTPS. Records that cannot be sent due to network problems are temporarily stored on the server until retransmission is successful and then deleted after transmission.

  3. 1~93 dayscustody

    Only the minimum number of people absolutely necessary for work can access it, and access details are managed. It is only used to respond to requests in accordance with laws and to confirm reports of abuse, and is not used for advertising, tendency analysis, or sales.

  4. 93 days have passedautomatic deletion

    Outdated records are automatically deleted from the database.

  5. Backup cycleDelete backup

    Information remaining in the backup is also deleted according to the backup storage cycle (Article 5 of the Personal Information Processing Policy).

Figure 1. From creation to deletion of access records

The exception is the app's session history. Session records are kept until membership withdrawal as they are usage history necessary for service provision. However, the parts necessary for comparison with access records remain even after withdrawal until 93 days have passed from the date of creation. Even if a member withdraws, access records already created will be deleted after 93 days due to legal storage obligations, and will be separated from other information and stored only for the purposes stipulated by law.

User Rights: Can I view or delete my records?

You can request viewing, but deletion during the storage period will not be requested. After verifying their identity, members can ask to see whether their access records are being kept and to view their contents. However, viewing may be restricted in accordance with Article 35, Paragraph 4 of the Personal Information Protection Act, and in this case, StageVPN will notify you of the reason.

Access records during the retention period cannot be deleted before the end of the period even if deletion is requested due to legal storage obligations, and are automatically deleted after 93 days. Inquiries and requests can be sent to the Personal Information Protection Manager (privacy@stagevpn.com) or Customer Center (support@stagevpn.com). If you are not satisfied with StageVPN's handling, you can apply for consultation or dispute mediation to the Personal Information Dispute Mediation Committee (1833-6972, without area code) or the Korea Internet & Security Agency's Personal Information Infringement Reporting Center (118, without area code). The difference between membership withdrawal and subscription cancellation StageVPN plan informationThis is explained in .

Provision procedure: Who can receive access records and through what procedures?

Access records will be provided only upon written request that meets the requirements and procedures established by law, including court permission, and to the minimum extent necessary within the scope of the request. It is not automatically provided upon request, and StageVPN will request supplementation or refuse to provide any requests that are insufficient or overly broad. The request procedure for criminal investigation is determined by Article 13 of the Communications Secrets Protection Act.

“③ When requesting the provision of communication confirmation data pursuant to paragraphs 1 and 2, permission must be obtained from the competent district court (including military courts; hereinafter the same shall apply) or support in writing recording the reason for the request, the relationship with the relevant subscriber, and the scope of the necessary data. However, if there are urgent reasons for which permission from the competent district court or support cannot be obtained, the request for provision of communication confirmation data must be received without delay and sent to the telecommunications business operator. ④ Paragraph 3 If communication confirmation data has been provided for urgent reasons in accordance with the proviso, but permission has not been obtained from the local court or support, the provided communication confirmation data must be destroyed without delay.”

Communications Secrets Protection Act Article 13 (Procedures for Providing Communication Confirmation Data for Criminal Investigation) Paragraphs 3 and 4 — National Law Information Center

Article 13, Paragraph 1 specifies that the person who can make the request is a prosecutor or judicial police officer, and Paragraph 3 stipulates that the court's permission must be obtained in writing stating the reason for the request, its relevance to the subscriber, and the scope of the data. In case of emergency, you must request first and obtain permission without delay. If permission is not obtained, the received materials must be destroyed. The obligation to record after provision is provided in Paragraph 7 of the same Article.

“⑦ When a telecommunications business operator provides communication verification data to a prosecutor, judicial police officer, or head of an intelligence and investigative agency, it shall report the status of data provision to the Minister of Science, ICT and Future Planning twice a year, and keep a ledger containing necessary matters, such as the provision of the communication verification data, and related data, such as a request for provision of communication verification data, for 7 years from the date of providing the communication verification data.”

Article 13, Paragraph 7 of the Communications Secrets Protection Act — National Law Information Center

The investigative agency that received the data must notify the person concerned. The notification deadline is determined by Article 13-3 for each case processing result.

“① A prosecutor or judicial police officer shall, in relation to a case for which communication verification data has been provided pursuant to Article 13, notify the party subject to the provision of communication verification data in writing of the fact that communication verification data has been provided, the agency requesting provision, the period, etc. within the period specified in the following categories: 1. A disposition not to file a public indictment, file a prosecution, or transfer to the prosecution (suspension of prosecution, suspension of witness, or suspension of investigation) (excluding decisions) or in the case of a disposition not to book a case: Within 30 days from the date of such disposition (…) 3. If an investigation is in progress: Within 30 days from the date of receipt of communication confirmation data (3 years in the case of a crime falling under any subparagraph of Article 6, Paragraph 8).

Communications Secrets Protection Act Article 13-3 (Notice of Provision of Communication Confirmation Data for Criminal Investigation) Paragraph 1 — National Law Information Center

Paragraph 2 of the same article stipulates that notification may be postponed if there is a risk of national security, threats to the life or body of persons involved in the case, risk of destruction of evidence or escape, or infringement of honor or privacy, and paragraph 4 stipulates that notification must be made within 30 days from the date the cause is resolved. Requests for national security follow separate procedures set forth in Article 13-4 of the same Act. Translating these provisions into StageVPN's actual processing order, it is as follows:

  1. Request from investigative agencyProsecutors, judicial police officers, etc. prepare a document stating the reason for the request, its relationship with the subscriber, and the scope of required data.
  2. court permissionPermission from the competent local court or branch office (if urgent, permission will be given without delay after request; if not received, data will be destroyed)
  3. StageVPN ReviewIdentify requirements, target period and scope of requests and permits. If insufficient, request supplementation or refuse
  4. Minimum range providedProvide only the bare minimum required within the scope of the request
  5. Records and NotificationsProvided by captain for 7 years, reported twice a year. Investigative agency notifies the parties in writing
Figure 2. Procedure for providing communication confirmation data for criminal investigation (Summary of Article 13, Article 13-3 of the Communications Secrets Protection Act)

There are also access logs and other types of requests. Article 83 of the Telecommunications Business Act stipulates requests for provision of subscriber information such as the user's name, ID, and subscription date, and with the revision in December 2023, the name was changed from ‘communication data’ to ‘communication user information’.

“③ A telecommunications business operator may comply with a request from a court, prosecutor or head of an investigation office (…), or head of an intelligence and investigative agency to view or submit (hereinafter referred to as ‘provision of communication user information’) the following data (hereinafter referred to as ‘communication user information’) for the purpose of trial, investigation (…), execution of sentence, or collection of information to prevent harm to national security: 1. User’s name 2. User’s resident registration number. 3. User’s address 4. User’s phone number 5. User’s ID (…) 6. User’s subscription date or termination date ④ Requests for provision of communication user information pursuant to paragraph 3 must be made in writing (hereinafter referred to as ‘information provision request’) stating the reason for the request, relationship with the relevant user, and scope of required communication user information.”

Article 83 (Protection of Communications Secrets) Paragraphs 3 and 4 of the Telecommunications Business Act, revised text on December 29, 2023 — National Law Information Center

The wording of Article 83, Paragraph 3 is “may follow.” In other words, the provision of communication user information is an area where the business operator's judgment intervenes, unlike communication confirmation data that requires court permission, and StageVPN reviews the legality and necessity of the request and responds only to the minimum extent necessary. The organization that received the data must notify the party within 30 days in accordance with Article 83-2 of the same law, and StageVPN does not collect resident registration numbers, so data No. 2 does not exist from the beginning.

Table 5. Basis for each request type and StageVPN’s response
request typelegal basisTarget informationStageVPN’s Response
Provision of communication confirmation dataArticle 13 of the Communications Secrets Protection Act, etc.Connection history (time, connection IP, destination IP/port, host name for Chrome)Minimum scope available only on written requests with court permission (including post-release permission in emergency cases)
Provision of communication user information (former name ‘communication data’)Article 83 of the Telecommunications Business ActSubscriber information such as user name, ID, subscription date and cancellation dateReview the legitimacy and necessity of the request and respond only to the minimum extent necessary
Request for national securityArticle 13-4 of the Communications Secrets Protection ActCommunication confirmation dataRespond only when separate procedures prescribed by law are in place
Requests from foreign governments and organizationsKorean laws and regulations such as international criminal legal assistance, etc.Different for each requestRespond only if procedures stipulated by Korean laws are followed.

Even administrators of corporate VPNs cannot see these statutory access records. What is provided to the administrator is the company qualification session time, usage time, data amount, server name/country, and even the dedicated IP used. Enterprise Fixed IP VPN Introduction GuideIt was covered in .

Procedures under Article 13 of the Communications Secrets Protection Act
Procedures under Article 13 of the Communications Secrets Protection Act

How to read no-log ads

You should first check what the phrase “do not leave records” means not to leave behind. This is because the meaning varies greatly depending on whether it means not leaving any communication content or not leaving any metadata such as connection time and address. VPN operators are technically in a position to see multiple layers of information, and which layers they must leave behind depend on which country's laws the operator follows.

  1. Account/Payment InformationSignup email, subscription status, payment history
  2. Connection metadataConnection IP, connection time, data amount
  3. Destination informationDestination IP/port, host name
  4. DNS queriesDomain viewed
  5. Content of communicationIf it is HTTPS, it is encrypted and cannot be viewed without decryption.
Figure 3. Layers of information technically accessible to VPN operators.
Table 6. Whether StageVPN retains each layer of information.
layer of informationWhether to store StageVPNPeriod/Conditions
Account/Payment InformationcustodyThe account lasts until cancellation, and transaction records last for 5 years. Card number is not stored
Connection metadatacustodyAccess IP 93 days, app session records until withdrawal (minimum 93 days)
Destination informationcustodyDestination IP/port 93 days. Hostname is StageVPN for Chrome only
DNS queriesNot keptStageVPN app does not log domains viewed
Content of communicationNot keptDo not intercept or decrypt encrypted communications

When comparing VPN services' logging policies, check to see if the items below are listed in their documentation: Neither question can be answered with one word: ‘no logs’.

  • Is there a list of what items to keep and what not to keep? Does it say time, IP, destination, DNS, and content separately, rather than just a single line saying “no logs”?
  • Are the retention period and deletion method written in numbers? If there is only an open expression such as “as long as necessary,” the time period is not set.
  • Does it disclose which country the operator is located in and what laws it applies to? Since Korean telecommunications operators are obliged to keep connection records, you should be suspicious of “no log” advertisements from Korean operators.
  • Do you disclose what procedures are used to respond to requests from investigative agencies? Are the criteria for requesting court permission, scope review, and denial stated?
  • Does it specify that the records will not be used for advertising, behavioral analysis, or sales purposes?
  • Is there a window for users to view or inquire about their records?

Conversely, saying that access records are kept does not mean that the content of communications is also examined. The reason StageVPN discloses all items, periods, and delivery procedures is because we believe that the starting point of trust is for users to know exactly what they can and cannot expect. The published policy becomes the standard that the operator must adhere to, and users can ask questions based on that standard. The scope and limitations of a VPN are What VPNs Prevent and Can't Prevent, the overall structure of service security is Security InformationI organized it in .

reference material

  1. Communications Secret Protection Act — Article 2, Paragraph 11 (Definition of communication confirmation data), Article 13 (Provision procedure and court permission), Article 13-3 (Notification), Article 13-4 (Provision for national security), Article 15-2 (Telecommunications business operator's obligation to cooperate) (National Legislation Information Center)
  2. Enforcement Decree of the Communications Secrets Protection Act — Article 41, Paragraph 2 (Retention period by type of communication confirmation data) (National Legislation Information Center)
  3. Telecommunications Business Act — Article 83 (Protection of communication secrets, provision of communication user information), Article 83-2 (Notification of provision) (National Legislation Information Center)
  4. Personal Information Protection Act — Article 35 (View of personal information) and reasons for restriction of view (National Legislation Information Center)
  5. Personal Information Protection Committee — Personal information protection policy and information subject rights information (Personal Information Protection Committee)
  6. Personal Information Dispute Mediation Committee — Application for mediation of disputes related to personal information (Personal Information Dispute Mediation Committee)
  7. Personal Information Infringement Reporting Center — Personal information infringement reporting and consultation (118 without area code) (Korea Internet & Security Agency)
  • #Access record
  • #Communication Secrets Protection Act
  • #VPN logs
  • #personal information
  • #transparency