nbase (엔베이스) (trade name: NBASE KOREA Co., Ltd. (엔베이스코리아 주식회사); the “Company,” “we” or “us”) publishes this notice so that people who use StageVPN can know exactly what records are kept and choose the service on that basis. This notice explains in detail the connection log provisions of our Privacy Policy.
Summary
93 days from creation. After that, records are deleted from the database automatically.
When and which account (or tunnel IP) connected to which destination (IP and port; host name for Chrome), and the connecting IP
Communication content: page content, URL paths and search terms, messages, entered values, files, DNS query content
Only in response to requests from investigative agencies and others that follow the procedures prescribed by law, such as court permission, and only to the minimum extent necessary
StageVPN is not a “no-log” VPN. As a telecommunications business operator in Korea, we retain the records required by law and disclose their scope and retention period openly rather than hiding them.
1. Legal Basis and Retention Period
- Article 15-2 of the Protection of Communications Secrets Act (통신비밀보호법) requires telecommunications business operators to retain data for the period prescribed by Presidential Decree in order to cooperate with requests from investigative agencies and others for communication confirmation data.
- Article 41(2) of the Enforcement Decree of the same Act requires internet log records and access location tracking data that can identify the location of information and communications devices to be retained for at least 3 months.
- Because 3 months is at most 92 days depending on the month, we set the retention period at 93 days so that the statutory period is met in every case. Records older than 93 days are deleted by the database’s automatic expiry function, and we do not keep them longer at our own discretion.
2. Records Kept for the App VPN (iOS, Android and Desktop)
The WireGuard VPN servers collect records of new connections in 1-minute batches and send them to our database over an encrypted connection (HTTPS).
| Record | Items | Retention period |
|---|---|---|
| Outbound connection records | Connection start time, tunnel IP address (the internal address assigned to the member’s device), protocol (TCP, UDP, ICMP), destination IP address and port, source port, the server that made the record | 93 days |
| Access location records | The IP address and port from which the member connected to the VPN server (WireGuard endpoint), account (email), public key, tunnel IP, server, time observed. Recorded only when the connecting address changes. | 93 days |
| Session records | Account, server, tunnel IP, session start and end times, amount of data sent and received. Used to confirm which account a tunnel IP was assigned to. | Until account deletion (the parts needed for matching are kept for at least 93 days from creation) |
App VPN records do not include the destination’s domain (host name). DNS queries are also handled inside the VPN tunnel, but we do not record which domains were queried.
3. Records Kept for StageVPN for Chrome
The Chrome extension sends browser traffic to the HTTPS proxy on our servers. The proxy servers collect connection records in 1-minute batches and send them to our database.
| Record | Items | Retention period |
|---|---|---|
| Proxy connection records | Connection start time, account identifier, proxy session identifier, member’s connecting IP address, destination host name and port, destination IP address, bytes sent and received, connection duration, the server that made the record | 93 days |
| Proxy session records | Account, server, session start and expiry times, connecting IP address from which the session was started | 93 days |
The proxy records only the destination host name needed for the connection (e.g., www.example.com). It does not record page paths, search terms, query strings or page content. For HTTPS sites, the proxy does not decrypt the encrypted content.
4. Information We Do Not Keep
- The content of communications sent and received: web page content, email and message bodies, voice and video, files
- URL paths and search terms, query strings, values entered in forms, cookie values
- Domain names queried through the app VPN (DNS query content) and lists of domains visited
- Decrypted content of HTTPS traffic (we do not intercept or decrypt encrypted communications)
- Precise device location information such as GPS
5. Limits on Use and Safeguards
- We use connection logs only when necessary to protect the service, such as to respond to requests for data made under law or to verify reports of abuse such as attacks and spam.
- We do not use connection logs for advertising, user profiling, sale to third parties or similar purposes.
- Access to connection logs is limited to the minimum number of staff who strictly need it for their work, and access history is managed.
- Records are encrypted in transit and stored in our database. The VPN and proxy servers keep records only temporarily in order to transmit them. Records that cannot be transmitted because of network problems are stored temporarily on the server until retransmission succeeds and are deleted after transmission.
6. Procedure for Disclosure to Investigative Agencies and Others
- Communication confirmation data: Provided only when a prosecutor, a judicial police officer or the head of an intelligence and investigative agency requests it in writing with court permission (including subsequent permission under the law in urgent cases) under Article 13 and other provisions of the Protection of Communications Secrets Act.
- Review: We check the requirements of the request and the court permit, as well as the period and scope covered. For requests that do not meet the requirements or are excessive in scope, we ask for them to be supplemented or refuse to provide data. Data is provided only to the minimum extent necessary within the scope of the request.
- Records: As required by law, we report on the status of data provision and keep a register recording each provision, together with the requests and other related documents, for 7 years from the date of provision.
- Notification: Investigative agencies and others that receive data notify the data subject of the provision under the Protection of Communications Secrets Act.
- Subscriber information: For requests for subscriber information (통신자료) under Article 83 of the Telecommunications Business Act (전기통신사업법), we review the lawfulness and necessity of the request and respond only to the minimum extent necessary.
- Foreign authorities: We respond to requests from foreign governments or authorities only when they have gone through the procedures prescribed by Korean law, such as international mutual legal assistance in criminal matters.
7. Rights of Data Subjects
- After identity verification, members may ask whether their connection logs are retained and request access to their content. However, access may be restricted under Article 35(4) of the Personal Information Protection Act (개인정보 보호법, PIPA), in which case we will inform you of the reasons.
- Because of the statutory retention obligation, connection logs within the retention period cannot be deleted before the period ends, even if deletion is requested. Even if a member deletes their account, connection logs already created are deleted after 93 days have passed.
- Please send inquiries and requests to the Chief Privacy Officer (privacy@stagevpn.com) or the customer center (support@stagevpn.com).
Revision history
| Version | Published | Effective | Summary of changes |
|---|---|---|---|
| 1.0 | 29 September 2026 | 1 October 2026 | Initial version |
Questions about this document
Send questions about our terms and policies, or requests to exercise your rights, to the contacts below. We respond without undue delay.
- Customer center: [Customer center phone] ([Customer center hours])
- Email: support@stagevpn.com
- Chief Privacy Officer: privacy@stagevpn.com