KotoVPN

Guide · Updated August 13, 2026

Paying for a VPN without undoing the point of it

How do I buy a VPN privately?

Short answer

The account is rarely the weak link — the payment is. A random account number paired with a personal credit card still ties the subscription to you through the processor. If the payment trail matters to your threat model, the options are cash, certain cryptocurrencies, or a provider that never collects an identity in the first place.

What the provider ends up holding

A typical signup produces an email address, a payment method, a billing country, and a creation timestamp. Even with a genuine no-logs policy on traffic, that record exists in billing systems and is subject to ordinary financial record-keeping obligations.

This is why anonymous signup is scored separately from logging in our rubric. They are different exposures and a provider can be excellent at one and indifferent to the other.

The options, ranked by what they actually remove

Each step removes a different link between you and the subscription.

  • Account number instead of email: removes the identifier most likely to be reused elsewhere
  • Cash by post: removes the financial trail entirely, and a small number of providers accept it
  • Monero: designed for untraceability, and accepted by fewer providers
  • Bitcoin: pseudonymous, not anonymous — the ledger is public and exchange onboarding is identified
  • Prepaid card bought with cash: removes the link to your bank, subject to local rules on registration
  • Gift card or voucher: some providers accept them, which is effectively cash at one remove

The mistake almost everyone makes

Using a personal email and a personal card, then treating the subscription as anonymous. The provider now has an identity, a payment method and a billing address, regardless of what the traffic policy says.

The second mistake is buying cryptocurrency on an identified exchange and paying directly from it. The chain from your verified account to the provider is public and permanent.

Avoid

  • Assuming Bitcoin is anonymous — it is a public ledger with identified on-ramps
  • Reusing an email address that appears in breach databases alongside your real name
  • Paying with a card and then worrying about the no-logs policy, which is the smaller exposure

When none of this is necessary

For most readers it is not. If your goal is to stop your ISP building a browsing profile, a card payment and an email are irrelevant to that goal. This page is for people whose threat model includes the provider’s billing records, and it is worth being honest that most people’s does not.

Questions

Which providers accept cash?
A small number, and it is a scored feature in our dataset. The shortlist for signup without an email lists the providers that treat account anonymity as a product requirement rather than an edge case.
Does a refund work if I paid in cash or crypto?
It varies and is worth checking before paying. Refunds to an anonymous payment method are awkward by construction, and some providers issue account credit instead.
Is a burner email enough?
It removes one link. The payment method usually remains, and for most threat models the payment is the stronger identifier.

Terms used here

Anonymous signup

Creating an account without providing an email address, name or other identifying detail.

No-logs policy

A provider’s commitment not to record which sites you visit, when you connected, or what address you connected from.

Refund window

The period during which a subscription can be cancelled for a full or partial refund.

Related