TRUST CENTRE

We earn trust
with proof, not words.

How Colitu protects your data, what we never record and how we answer the requests we receive: all here, in the open.

01

Security and privacy

The measures we take in the apps, on the servers and on the site to protect your data.

Connection without activity logs

We don't record the sites you visit, your DNS queries or the content of the traffic in the tunnel. Our servers only count traffic volume, for the quota and fair use. For account security we keep sign-in and IP history for 180 days and per-user traffic records for 90 days.

Modern encryption

Connections are encrypted with Hysteria2, VLESS Reality and Trojan over TLS 1.3, or with Shadowsocks 2022 (AES-256-GCM). If a protocol is blocked, the app switches to another on its own.

Not even we can see your password

Passwords are stored irreversibly with Argon2id. Session keys are encrypted on the device: with the Android Keystore on Android and DPAPI on Windows.

A separate key for every device

Every device gets its own connection details. You can remove a lost device from your dashboard with one tap.

Verified updates

The apps only install a package whose hash matches the release manifest; on Windows the manifest is also signed.

Strict web security

Our site is protected by a strict content security policy, HSTS, CSRF protection and limits on sign-in attempts. Your card details never reach Colitu.

Technical security detailsProtocols, encryption, signed updates, server logging policy and incident response.

11 servers in 11 countries are running right now. The live status of every one is public.

System status →
02

Transparency

We publish regular reports on the official requests we receive and the action we take against abuse. Our users deserve to know how their privacy is protected.

Transparency reports

Published period by period; newest first.
  • Transparency report · Q3 20261 July 2026 – 30 September 2026Published: 1 October 2026
    Requests from authorities
    0
    Requests with data disclosed
    0
    Content and copyright notices
    0
    Abuse reports
    0
    Accounts restricted
    0

    Colitu opened on 12 September 2026; this first report covers the time from opening to 30 September. In this period we received no request for user data from any authority and shared no user data with anyone.

Every report shows
  • Requests from authoritiesRequests for user data from courts, police or other authorities.
  • Requests with data disclosedHow many of these requests led to any data being shared.
  • Content and copyright noticesDMCA and similar notices.
  • Abuse reportsReports of spam, attacks or fraud involving traffic from our servers.
  • Accounts restrictedAccounts restricted for abuse such as spam, attacks or free accounts opened one after another.

What happens when we receive a request?

We check the legal basis of every request. We can only hand over what we have: we do not record browsing history, DNS queries or traffic content, so we cannot share them with anyone. The limited data we keep and how long we keep it are set out in our privacy policy.

Privacy policy →

What do we keep?

Your e-mail and encrypted password for your account, device name and app version for device slots, traffic volume per user for the quota. The reason and retention period for each are listed openly in the Help Centre.

Privacy explained ↗
03

Open source

All of the code of our Windows and Android apps is public on GitHub. You can verify for yourself what the app does on your device.

Found a vulnerability?

Please tell us before making it public. Send the details to support@colitu.com with "Security" in the subject; we will look into it and get back to you.

support@colitu.com

Last updated: 1 October 2026