Atari VPN separates account, subscription, and payment data. Public statements are limited to what the current code and configuration can demonstrate; stronger no-logs or storage claims require a dedicated infrastructure audit.
01
Encrypted VPN connection
A connection creates an encrypted tunnel between a compatible client and the VPN server. The installed app receives the selected profile through the user's personal subscription link.
Tunnel protection does not replace security after traffic leaves the VPN server. Account safety, website HTTPS, and the security of the device remain important.
Do not share a subscription link.
Use a current client from the instructions channel.
Protect and update the device.
02
Account data
The website requires an email for registration, sign-in, and access recovery. The password is not stored as plain text; the database retains a cryptographic result of password processing.
The web session is also checked with a protected token. When Telegram is linked voluntarily, the account is associated with the corresponding Telegram ID.
Account email
Password hash
Protected web session
Telegram ID only after linking
03
Payment data
Atari VPN does not store the full bank card number or CVC. The card operation is processed by the payment provider.
When the user saves a payment method, the service stores an encrypted provider identifier, an HMAC fingerprint, the type and display title, and the last four digits. This is not the same as storing only one hash and cannot reconstruct the full card number.
No full card number
No CVC
Saving a method is the user's choice
04
Operational logs and diagnostics
The website and infrastructure may require technical events to diagnose errors, monitor availability, and prevent abuse. This should not be described as the absence of every type of log.
A separate claim about not retaining network activity history is published only after auditing VPN nodes, DNS, the control panel, containers, and reverse proxy. Until then Atari VPN does not use an absolute no-logs statement.
Do not use logs for advertising profiles
Minimise operational log fields
Review retention after infrastructure changes
05
Protection of stored values
Sensitive application values are protected according to purpose: passwords are hashed and the payment provider identifier is encrypted with a separate key. This is not a claim that every database record is encrypted.
A statement about full database and backup encryption requires evidence of encrypted storage, protected backups, separate keys, and a tested restoration process.
Keys must not be stored in database dumps
Backup restoration is tested separately
Access to production secrets is restricted
06
What a VPN cannot guarantee
A VPN does not make a person completely anonymous. Websites may recognise a signed-in account, browsers may store cookies, and the device itself can contain unsafe or malicious software.
The service also cannot guarantee one speed, availability of every external website, or protection from actions performed after signing into a third-party account.
Check HTTPS
Never share passwords or one-time codes
Use unique passwords
07
Report a security issue
If you notice suspicious activity, an access error, or a possibly exposed subscription link, contact AtariVPNBot. Support can help revoke access or check the account.
Do not send a password, CVC, full card number, or exposed subscription secret through Telegram. A device description, event time, and safe screenshot are normally enough for initial diagnostics.