Legal
Acceptable use policy
Last updated 21 August 2026
Proxies are dual-use. This policy is the line we draw, and the basis on which we suspend accounts that cross it.
Two policies apply, not one
We resell capacity on an upstream provider’s network, bought through an ordinary account with them. Your traffic is therefore subject to both this policy and theirs.
Their policy is enforced against our account as a whole, and we have no special standing with them to argue a case on your behalf. That is why we enforce ours strictly: one customer’s abuse can take every other customer offline at once.
Prohibited outright
These will result in immediate suspension without notice, and may be reported:
- Unauthorised access to systems, networks or accounts — including credential stuffing, brute forcing and vulnerability exploitation against targets you do not own or have permission to test.
- Denial-of-service traffic of any kind, distributed or otherwise.
- Child sexual abuse material, in any form and by any route.
- Distribution of malware, ransomware, or command-and-control traffic.
- Fraud, including payment fraud, account takeover, and phishing infrastructure.
- Traffic intended to harass, stalk, dox or threaten a specific person.
- Circumventing sanctions, or routing traffic on behalf of sanctioned entities.
- Spam — unsolicited bulk email, SMS or messaging at scale.
Permitted, and what we expect of you
Most proxy use is legitimate. Web scraping, price and ad monitoring, brand protection, SEO measurement, market research and QA from other geographies are all normal uses of this product. When you do them, we expect you to:
- Respect robots.txt and published rate limits, and back off when a target signals it is overloaded.
- Collect no more personal data than your lawful basis covers, and keep it no longer than you need it.
- Identify yourself honestly where a site asks you to, rather than impersonating another company or a real person.
- Accept that a destination’s terms of service may prohibit automated access, and that this is a matter between you and that destination.
Rate and volume
There is no fixed request-per-second cap; the constraint is impact. If your traffic degrades a destination, triggers network-level blocks on shared IPs, or generates abuse reports against the pool, we will ask you to reduce it.
Be aware that there is no middle setting. The upstream gives us no way to throttle or rate-limit an individual proxy user, so if asking does not work the only remaining action is suspension. We would rather tell you that in advance than have it arrive as a surprise.
How we enforce
Where circumstances allow, we contact you first and give you the chance to stop. For anything in the prohibited list, or where the upstream network requires immediate action, we suspend first and explain afterwards.
Suspension deletes your proxy users at the upstream, which is the only mechanism their API offers. Two consequences worth stating plainly: deletion takes about three minutes to propagate across their gateway, so traffic can survive briefly after we act, and it is irreversible — reinstatement issues a new proxy user with a new username and password rather than restoring the old one.
Unused prepaid traffic is refundable on a suspension we later determine to have been mistaken, and is not refundable following a substantiated abuse finding.
Reporting abuse
If traffic we routed has affected you, write to abuse@proxylexus.com. It is read ahead of our other addresses.
Addresses are shared, so a report we cannot match to one account is a report we cannot act on. Include the source IP you observed, a time window in UTC, the destination that was hit, and whatever log lines you have. The contact page lists the same four fields, if it is easier to work from there.
We will tell you when the traffic has actually stopped rather than when we requested it, because those are a few minutes apart.