How this actually works
Your whole internet goes through Cinderpath. Websites see one public address — the city you picked — and we leave that alone for as long as a page is loading. The café Wi-Fi sees a different machine: the one you actually connect to. Extra stops don’t make this Tor.
- Your address
- The stops
- The app
- If the usual connection is blocked
- This website
- Who sees what
- What we keep
- When you connect
Your address
We try to give you your own public address, not one shared with other customers. That’s the address websites talk back to. Random people on the internet can’t open connections to you. We still allow the tiny messages that keep downloads from stalling.
If we run out of those addresses, some plans share. We’ll say so. The gamer path never shares. Games hate being behind two layers of sharing — your home router plus ours — and matchmaking and voice fall over.
First stop and last stop
The last stop stays put. Changing it while a page is loading would break things, and it wouldn’t hide you. We never send one connection out two public addresses.
The first stop can move — about every three minutes on paths with extra stops — so a hotel network isn’t staring at one address all afternoon. Ordinary WireGuard can’t follow that. The Cinderpath app can. On city-only and same-city gamer, the first stop and the last stop are the same box, so there’s nothing useful to move.
Gamer (out of the country) and Super Secure add boxes between you and the city websites see. Those stops are encrypted. The machine you connect to is supposed to pass you along, not put you on a shared address. Super Secure’s Los Angeles stop is still the United States. A stop in a country we don’t run is not live. Details: the path.
The app
QR code, a home mesh, Mac, Linux: one address until you make a new file. That’s the simple product.
The Windows app can follow a moving first stop. The city websites see does not change. If that mode doesn’t come up, it falls back to ordinary WireGuard.
The app is not a speed boost. Don’t pick it hoping for a faster download. It’s so the first stop can move.
If the usual connection is blocked
We can ride along with ordinary web traffic. That’s slower. Disguising the connection is off unless you turn it on — it adds delay, so we don’t leave it on all the time.
This website
Sign-in, the shop, and making a connection are described in a small file other AgenticOps tools already know how to read. That is not a filter on the sites you visit through the VPN. Machine status: /cwl-security. The file: /cwl.
Who sees what
| Who | Sees | What we do |
|---|---|---|
| Café Wi-Fi | The first stop | Move it, if you’re on the app |
| Your internet provider | That you’re on a VPN, or ordinary web traffic | The slower fallback; disguise if you turn it on |
| The site you’re visiting | The last city’s address | A new connection file burns that address |
| Us | Enough to connect the dots, today | Split-trust isn’t shipped |
| Everyone, everywhere | — | Not the goal |
The bar we’d like: nobody in one country can map your account to the sites you visit from data they alone possess. We’re not there until the last stop sits in a country we don’t run. Don’t read Super Secure as that.
We don’t add fake traffic to hide when you’re online. This is not Tor.
What we keep
| Part | May have | Must not have |
|---|---|---|
| Where you connect | Session id, which city, how much data, abuse flags | The sites you visit, the last-stop address joined to your account, payments |
| Where you leave | The address websites see | Your account, payments |
| Billing | Your account, payments | The session, the sites you visit, the last-stop addresses |
No single warehouse joining the three. “No logs” without that split is a slogan. When you disconnect, or sit idle long enough, the connection on our side is gone. While it exists, the server still knows the address you’re connecting from. That’s how this kind of VPN works. Making a new connection file burns the old one.
What we don’t ship
- A stop in a country we don’t run (split-trust)
- Fake traffic, mixing, Tor-style cover
- Always-on disguise
- IPv6 for everything
- Per-app split (some apps on, some off)
Kill switch: the official app holds the usual internet so a dropped connection doesn’t leak. Ordinary WireGuard apps need their own. Official Windows disconnect puts your DNS back.
When you connect
- Pick a path. Super Secure and out-of-country gamer use extra stops.
- Ordinary WireGuard: import the file or scan the QR. One address until you generate again.
- If you want the first stop to move: Windows app. Last stop still stays the city you picked.
- Turn on the kill switch if you’re on ordinary WireGuard.
- Generate again when you want a new address. The old one is gone.