Service status & availability Crypto-only billing · No-KYC signup

Frequently asked questions

Account and privacy FAQ

Understand username-only registration, account recovery, session security, retained records, and the practical limits of no-KYC service.

10 questions · Updated September 5, 2026

What information is required to create an account?

Registration asks for a username and password. The username must contain 3 to 32 letters, numbers, underscores, or hyphens, and the password must contain 12 to 200 characters. Standard signup has no email, phone, legal-name, or identity-document field. A recovery code is shown once after registration. Save it before leaving the page because there is no email reset.

Back to top ↑

What does no KYC mean at Tungsto?

No KYC means the standard registration form does not request identity documents, an email address, or a phone number. It does not remove the Terms of Service, Acceptable Use Policy, security controls, or responses to valid legal process. It also does not make cryptocurrency transfers or network activity invisible. No KYC describes the signup data requested, not a guarantee of anonymity.

Back to top ↑

Does a username-only account make my server anonymous?

No. A username-only account reduces the information collected during registration, but blockchain transfers, IP traffic, timestamps, and operational metadata may still be observable. We keep the account, ledger, server, address, session, security, and control records needed to operate the service. Use suitable application-level privacy measures and read the policies before deciding whether the service matches your threat model.

Back to top ↑

Why is the recovery code important?

There is no email-based password reset or separate password-change flow. Your recovery code is required with your username to set a new password. It is shown at registration and replaced after every successful recovery. Store it offline and separately from the password. Anyone with both your username and recovery code can attempt recovery, so protect it as a sensitive credential.

Back to top ↑

What happens if I lose both my password and recovery code?

If you lose both your password and recovery code, the account may be unrecoverable. There is no reset through email, phone, or identity documents. The public contact form can record a message, but typing an account username does not prove ownership. Keep the recovery code safe and maintain independent copies of important server data outside the account.

Back to top ↑

What changes after a successful account recovery?

Successful recovery sets your new password, creates a replacement recovery code, and revokes existing sessions. The previous recovery code no longer works. Save the new code immediately, then sign in again on any other trusted device you still use. Recovery does not change ledger entries, server assignments, or paid-through dates; it changes only account access credentials and sessions.

Back to top ↑

How long does an account session last?

A browser session lasts up to seven days, after which you should expect to sign in again. Logging out revokes that session and clears its cookies. Recovering the account revokes existing sessions and creates new credentials. A signed-in session alone does not provide a separate password-change function; changing a forgotten or known password still requires the current recovery code.

Back to top ↑

What operational data is kept even without KYC?

Even without KYC, we retain records needed to operate and secure the service, including password verifiers, sessions, security events, payment references, ledger entries, orders, assigned addresses, support messages, and server-control requests. These records support authentication, accounting, duplicate-payment prevention, operations, security, and abuse handling. Retention and deletion limits are described in the Privacy Policy.

Back to top ↑

Does Tungsto inspect what runs on my server?

We do not proactively inspect customer files or applications. That does not mean all activity is unobservable. Network and management metadata may be processed to deliver traffic, defend infrastructure, investigate incidents, and handle abuse reports or valid legal requests. You remain responsible for securing the operating system, maintaining backups, and using the server lawfully under the Acceptable Use Policy.

Back to top ↑

Can I close or delete my account from the dashboard?

Not yet. There is no self-service account closure or deletion control. You can use the public contact form to record a request, but typing an account username does not prove ownership. Some ledger, security, accounting, or dispute records may also need to remain under the Privacy Policy after service use ends. No completion time is promised.

Back to top ↑