$man privacy
Privacy policy
We keep what we need to bill you, run the box, and investigate a compromised bot. We do not sell your information. We do not rent mailing lists. Google sees brochure-page analytics. The client area stores cards. Authorize.Net charges cards. PayPal charges banks and crypto. That is the shape of it.
Last updated 2026-09-07. This page is the policy.
1. Who we are
KIRE, LLC d.b.a. KIRE.NET (“KIRE,” “we”). Linux shells, Eggdrop, Limnoria, ZNC, psyBNC, IRCD shells, vanity vhosts, identd, and @kire.net mail. Operating since 1998. Not a hyperscaler. Not a law firm.
We operate from Virginia, United States. Shells live in Denver, Colorado, United States (Sharktech).
Postal: 2085 Lynnhaven Pkwy Ste 106 #451, Virginia Beach, VA 23456.
Voice: +1 (877) KIRE-NET.
Privacy: privacy@kire.net (live; a human reads it).
Abuse: abuse@kire.net (live; a human reads it).
2. Scope
This page covers data we handle when you use:
- the public site (kire.net and kirenet.com brochure pages)
- the client area and cart at
/account/(WHMCS) - Linux shells over SSH, including the browser SSH convenience client at
/terminal - mail (
you@kire.net, webmail, IMAP/POP/SMTP) - bots and bouncers on the account (Eggdrop, Limnoria, ZNC, psyBNC)
- IRCD shells (dedicated IPv4/IPv6, the daemon, any domain we registered for that product)
- support: tickets, the contact form, phone, email
The acceptable use policy / terms is the deal for use of the service. This page is how we handle personal information. It is not a promise that we indemnify you.
3. What we collect and why
We collect what it takes to sell a shell, keep it up, and clean up after a bad process. Not a dossier for its own sake.
Account and billing
Name, email, postal address, phone, company if you typed one, usernames, service plan, invoices, payment history, tickets, and the notes we write when you open a ticket. That lives in the client area so we can create the account, bill it, reset access, and answer you.
This brochure site does not collect cards. Do not paste a card number into a ticket or the contact form. The client area (WHMCS) stores cards on the account so the next cycle can bill. Authorize.Net charges cards. PayPal charges banks and crypto — not a fourth processor and not a wallet we run. Stored cards live with the billing record, not in the six-month log pile. Update or remove a card in the client area, or write us from the email on the account.
Auth and SSH
Username, public keys you install, login success/failure, source IP, timestamps, and the fact of a session. We keep SSH login IPs so we can investigate a compromised bot, a stolen password, or a ticket that starts with “I did not log in from that country.”
Service and process
What is running, what ports it opened, CPU/RAM/disk, vhost assignment, identd answers, and connection metadata when we are hunting abuse or a box that is falling over. Shared shells are shared. We can see processes. That is the product, not a surprise.
Mailbox contents for @kire.net addresses we host, plus mail logs (source, destination, time, size, bounce). We do not read your mail for fun. We can look if the queue is on fire, if we are an open relay in someone’s report, or if the law requires it.
Web logs
IP, user-agent, referrer, URL, time, status code. The web server logs requests. So does the client area. So does the contact form (name, email, service wanted, optional IRC nick, message, IP, reCAPTCHA token).
Tickets and phone
Whatever you send us. If you paste a userfile into a ticket, that paste is now in the ticket.
4. What we do not do
- We do not sell personal information.
- We do not rent or swap mailing lists.
- We do not share personal information for advertising.
- We do not run a 2004-style “visitor profile” to tailor banner ads. We never should have said we did.
- We do not claim ISO, SOC, PCI, or HIPAA. We are a small shell host.
Google Analytics on brochure pages is analytics, disclosed below. It is not us selling your name to a list broker.
5. Sharing
We share personal information when it is required to run the service, or when the law leaves no useful choice.
- Authorize.Net — cards. PayPal — banks and crypto. Chargebacks and the usual processor records go with that.
- WHMCS — the billing panel. Account, invoices, tickets, stored cards. We run it. The company behind the software still exists.
- Cloudflare — in front of the site. They see requests because they are in the path, not because we sold them a list.
- Sharktech — datacenter / upstream / DDoS path. Denver lives here. Packet-handling, not marketing.
- Google — Analytics on brochure pages; reCAPTCHA on the contact form and, where enabled, the client area.
- Semrush — site and SEO tooling. Not a customer list we rented to them.
- SpaceXAI — AI we use. If a prompt includes your ticket, your question, or other account data, they can see that prompt. Do not treat a model as a vault.
- Domain registrar — if we registered a domain for an IRCD (or similar) product. Registrars get what a registration requires.
- Law — court order, subpoena, search warrant, or other legal process served on us. We may also disclose when we have a good-faith belief it is necessary to comply with the law, to stop an ongoing attack on the network, or to report material we are required to report.
We do not sell the customer list to the next “exclusive IRC partnership.” Staff and contractors who work the box see what they need to work the box.
6. Your files vs our logs
Your home directory, Eggdrop userfile, Limnoria data, ZNC buffer, mailbox, and IRCD configs/logs are your content. You put them there. You are responsible for them. See the AUP.
Our records are the billing database, auth logs, web logs, mail logs, backups we take of the machines, and tickets. Backups exist so a dead disk is not the end of the host. They are not your undo. The FAQ already said that.
We do not mine your home directory for advertising. We may access an account, a process list, logs, and — when abuse, a compromise, a backup restore, or legal process requires it — the files themselves. On a multi-tenant shell that is how you keep the neighbor’s fork bomb from becoming your outage.
IRCD shells are still our machines. Dedicated IPs do not mean we cannot look. They mean you are not sharing the login with the next customer.
7. Retention
Auth, web, and mail logs: six months. That is so we can investigate a compromised bot, an abuse ticket, or a legal demand. Older than that, they rotate off.
Billing and client-area (MySQL) records are not that six-month pile. Invoices, the account, and tickets last as long as tax and dispute reality requires. If you ask what we still have on you, write privacy@kire.net.
When an account is terminated, the shell contents can go immediately. The AUP already warned you: do not count on a retrieval window. Billing records and whatever of the six-month log window is still running can remain after the login is dead.
8. Security
Reasonable measures for a shop this size: SSH, keys preferred, restricted admin access, DDoS in front of the servers, passwords stored hashed in billing, logs not published as a souvenir.
The wire is not a vault. Email, IRC, and a stolen laptop are still how most people lose a nick. We are not liable for a password you reused from 2008. No document on this site is a guarantee against breach, and this page is not an insurance policy.
9. Cookies, sessions, analytics
- Client area. Session cookies so you stay logged in. That is the login. Clearing them logs you out.
- Affiliate cookie. If you arrived on a referral link, WHMCS may remember the referrer.
- Google Analytics (
G-8S25TGK2ZB) on brochure pages, loaded after idle/load. Google gets the usual: pages, referrer, device, and an IP they may truncate. We delay the tag; we do not pretend it is off. - Google reCAPTCHA on the contact form (and client area where enabled) so the form is not a botnet toy.
- Cloudflare may set a cookie so the edge can tell a browser from a bot. The shell does not depend on it.
No cookie wall. No “we value your privacy” overlay. If you block the analytics tag, the shell still works. If you block cookies on /account/, the client area will not.
10. Rights and how to ask
Write privacy@kire.net. Ask for a copy of the account data we hold, a correction, or deletion.
We will need to know it is you. Expect a check against the email on the account, a ticket from the client area, or the same sort of verification we already use for password resets.
Deletion is not a magic rm of invoices, fraud holds, or logs still inside the six-month window. If we cannot delete a row, we will say so.
California: we do not sell personal information. A “do not sell” request is recorded as a confirmation that we don’t, plus whatever access/deletion you also asked for. We do not run a separate dark-pattern portal.
EEA/UK: you can ask for access or deletion the same way. We are a US operator. We do not appoint a DPO. We do not claim a European establishment.
11. Children
You must be eighteen to hold an account. We do not knowingly collect personal information from children as customers. If a parent or guardian finds an account that should not exist, write privacy@kire.net and we will close it.
If you let a minor use your login anyway, that is your problem under the AUP, not a kids’ social network we never built.
12. International visitors
You are buying a US service. The company is in Virginia. The shells are in Denver. Logs, mail, and billing records are in the United States. The terms are governed by the law of the Commonwealth of Virginia (state-law issues: Virginia Beach Circuit Court; federal: Eastern District of Virginia). If that is the wrong country for your data, do not open an account.
GDPR/UK GDPR in plain language: we are the operator; we collect account, billing (including stored cards in WHMCS), auth, mail, web, and ticket data to provide the service, secure it, and bill it; we share with the processors named above; logs are kept six months, billing records longer; you can ask privacy@ for access or deletion. We do not sell personal information.
13. Changes
We can change this page. The new text lives here. The date at the top moves. Keep reading it if you care. Continued use after a change is acceptance of the new text. This is not a contract that we indemnify you, and it is not a promise that the policy is frozen in amber.
14. Contact
Privacy: privacy@kire.net — live, a human reads it.
Abuse: abuse@kire.net — live, a human reads it. Copyright complaints go here. We do not have a designated DMCA agent on file.
Support: support@kire.net · +1 (877) KIRE-NET · contact form
Client area: /account/clientarea.php
KIRE, LLC d.b.a. KIRE.NET
2085 Lynnhaven Pkwy Ste 106 #451
Virginia Beach, VA 23456
United States
This page can be updated. It is not a contract of indemnity. The terms of use are aup.php.