Legal
Privacy policy
Last updated 5 September 2026
What we collect, why, and — just as importantly — what we deliberately do not.
Who is responsible for this data — unresolved
No company has been registered behind the Proxylexus name yet, so this policy cannot name a data controller, a registered address, or a supervisory authority you could complain to. That is a gap, we are not going to paper over it, and it has to be closed before the service takes personal data from anyone in a jurisdiction with a statutory regime.
Everything below describes what the software actually does today. Write to privacy@proxylexus.com for anything on this page.
What we collect
- Account data: your email address, a scrypt hash of your password, and which version of these documents you accepted and when. We never store the password itself.
- Subscription data: your plan, your balance, your billing window and the status of your account.
- Usage data: bytes transferred, measured on our own gateway as your traffic passes through it and written to your ledger every ten seconds, or sooner once enough has moved.
- Proxy users: the label you chose, the username we generated, a SHA-256 hash of the secret, and when each one was created, last used and — if you deleted it — withdrawn. The secret itself is shown to you once and never stored.
- Session data: a SHA-256 hash of your session token, when it was issued, when it was last used, and when it expires. The token itself lives only in your browser cookie.
- Password resets: a SHA-256 hash of the link we email you, when it expires, and whether it has been used. Deliberately not the address you asked from, or the browser you asked with.
- Payments: what you paid, in which currency, how many gigabytes it bought, the reference the payment provider gave it, and whether it went through. Card numbers and wallet addresses never reach us.
- Any email you send to one of our published addresses.
What we do not log
We do not log the destinations you connect to, the contents of your traffic, or the full credentials of your proxy users in any operational log. Errors returned by the network API are redacted before they reach a log sink.
The boundary moved, and it moved towards us. Your connections now pass through a gateway we operate before they reach the proxy network itself. That machine sees the destination host of every connection you open — it has to, in order to ask for it. It counts the bytes and writes those to your ledger; it does not write the destinations down, and it does not see inside an HTTPS connection, which is encrypted end to end between you and the site you asked for. A plain HTTP request is the exception and is worth knowing about: it is readable by everything it passes through, ours included. We do not write it down, but not writing it down is the only protection there is.
Past our gateway, your traffic still terminates on infrastructure we neither own nor operate. What its operator logs is governed by their privacy policy, not this one, and our visibility into it is limited. We say so rather than imply an oversight we do not exercise.
One thing we do keep, stated here rather than left for you to assume otherwise: the web server in front of this site writes an ordinary access log — the requesting address, the path, the response code — as every web server does. Nothing reads it back into our database and it is not joined to your account. We have not set a retention period for it, and that is a gap rather than a policy.
Why we collect it
To operate your account, to meter and bill traffic accurately, to enforce our acceptable use policy, and to respond when you contact us. We do not sell personal data, and we do not use it for advertising. There is no analytics, advertising or session-replay script on this site; the only cookie we set is the one that keeps you signed in.
The legal basis for each of those
A statutory regime does not ask only why we process your data, it asks under which basis. The purposes above map onto three, and nothing we do relies on consent, so there is no consent for you to withdraw and no cookie banner to dismiss.
- Performance of the contract: your account, your subscription, your proxy users, your sessions, and the usage metering. We cannot supply metered proxy traffic without measuring it, and we cannot sell you an account without keeping one.
- Legal obligation: the payment record. What was paid, when, in what currency and for what, kept because a business is required to be able to account for its sales — which is also why that one record outlives the account.
- Legitimate interests: securing the service and enforcing the acceptable use policy. That covers rate limiting, the hashes we keep instead of tokens, and investigating an abuse report. Our interest is in running a network that is not used to attack people; we consider it does not override yours, and you may object — see your rights, below.
Providing the data is not optional in the ordinary sense: an email address and a password are what an account is. If you do not want to provide them, we cannot supply the service.
How long we keep it
- Account and subscription data: for as long as the account exists, then deleted.
- Usage records: your ledger is the billing record, so it is kept for as long as the account exists and is deleted with it. Nothing prunes or aggregates it on a timer, and we would rather say that than state a retention period we do not enforce.
- Proxy users: for as long as the account exists, the ones you deleted included. Deleting one withdraws it rather than erasing it — a credential that spent money has to stay explainable afterwards — so its label, its username, the hash of its secret and its dates stay until the account itself goes.
- Sessions and password-reset links: until expiry. Expired sessions and spent or expired reset links are cleared by a housekeeping pass that runs off the sign-in and password-reset paths, at most once an hour — not by a scheduled job. Deleting your account deletes both immediately.
- Payment records: kept after the account is gone, and the only thing that is. What survives and what is stripped out is set out under your rights, below.
Who else sees it
The operator of that network necessarily processes the traffic you route through it. What reaches them is one identity belonging to us — every customer’s traffic leaves under the same one — carrying the targeting your connection asked for: proxy type, country, any state, city or network number you narrowed to, how often you asked the address to change, and any session name you chose. Your proxy user’s username and secret are ours and never leave our gateway, and neither does your email address, your account id or your billing details. A session name you pick yourself is the one field you control that they see, so do not put anything identifying in one.
If you pay, the provider handling that method sees the transaction. Paying by card sends them your email address, the amount, what it buys, and our own references for the purchase and for your account. Paying in cryptocurrency sends the amount, what it buys and that same purchase reference — and no address of yours. The payment page is theirs rather than ours, which is why we never hold your card number or your wallet.
We do not currently state which jurisdictions that infrastructure operates from or transfers data through. That is a real gap in this policy rather than an omission from it, and it closes when we can state it accurately.
Your rights, and how they work today
The three most people want are access, correction and deletion, and those are described below. The full set is shorter to list than to describe, so here it is in one place: you may ask for access to your data, its correction, its deletion, a restriction on how we use it while a dispute about it is open, a portable copy of what you gave us in a machine-readable form — that one is the export in your dashboard, and it is JSON — and you may object to the processing we do on the legitimate-interests basis named above. We do not make any automated decision that produces a legal effect for you: nothing here profiles you, and no algorithm decides whether you get an account.
You also have the right to complain to a data protection supervisory authority, and we would rather you had it than not. We cannot yet tell you which authority, because that follows from where the operating entity is established and no entity exists — the same gap named at the top of this page. It is listed as a blocker on our side rather than an inconvenience on yours, and the authority will be named here when it can be.
Write to privacy@proxylexus.com for any of them. We aim to answer within one month. We do not charge for it, and we will not ask you for identity documents to prove who you are — the address the request comes from, matched against the account, is what we go on.
You can ask for a copy of your data, a correction to it, or its deletion. Deleting your account takes your subscription, your sessions and reset links, your proxy users and your credit ledger with it.
Two things to know before you ask. First, export and closure are both in the dashboard, under Settings — you do not need to write to us for either. Correction is still by hand. Second, closing the account destroys any prepaid balance still on it: the credit ledger goes with the account row. If you have traffic left, use it or settle with us first.
One thing outlives the deletion, and it is better known before you ask than after. The record of what you paid stays: the amount, the currency, the gigabytes it bought, the provider’s reference and the dates, with the link to you removed. Nothing in what remains names you. We keep it because a sale has to stay accountable after the customer has gone — for our own books, and for a card dispute that can arrive months later. How long a payment record must keep an identity attached for tax purposes is a question with a different answer in every jurisdiction, and this policy does not have ours yet.
The file holds your account row, your subscription, your credit ledger and the dates on your sessions. Some things are deliberately left out of it: your password hash and your session and reset-link hashes, because handing those over creates an offline cracking target, and the secrets of your proxy users, because we hold only a one-way hash of each — there is nothing readable to give you. Two things we do hold are missing from the file rather than excluded from it: your proxy-user records and your payment history. Ask and we will send them. We would rather say that than let a download imply it is everything.
How it is protected
Stated as specifics rather than as a paragraph about taking security seriously, because the specifics are the only part you can hold us to.
- Your password is stored as a scrypt hash with a per-account salt, never as the password. The cost parameters travel with the hash so they can be raised later without invalidating anyone.
- Session tokens, password-reset links and proxy-user secrets are stored only as SHA-256 hashes. We hold nothing that could be replayed against you, and nothing we could hand over if we were asked to.
- The session cookie is httpOnly, sameSite and — in production — secure, so it is not readable from JavaScript and does not travel cross-site.
- Sign-in and password-reset are rate limited, and sign-in compares hashes on a fixed path so the timing does not reveal whether an address has an account.
- Traffic to this site is served over TLS. Errors from the network API are redacted before they reach a log, and full proxy credentials are never written to one.
- Card numbers and wallet addresses never reach us at all: the payment page belongs to the provider, not to us.
None of that makes a system safe, and we are not going to claim it does. It makes specific attacks expensive, and it limits what a breach of our database would actually yield.
If something goes wrong
If personal data we hold is exposed, we will tell you. Where a statutory regime applies we will notify the relevant authority within the period it sets — seventy-two hours, under the GDPR — and we will tell affected customers directly where the risk to them is high. The notice will say what happened, what data was involved, and what we have done, rather than that we take your privacy seriously.
The honest caveat: the obligation attaches to a legal person, and there is not one yet. The commitment above is what we will do regardless; whether it is also enforceable against us is part of what closes when the entity is registered.
Children
This service is not for children. It is sold to people who can enter a contract, and we do not knowingly collect personal data from anyone under 16. If you believe a child has created an account, write to us and we will delete it.
Contact
Data protection requests and questions about this policy go to privacy@proxylexus.com. Other addresses are on the contact page. A postal address and the controller’s identity will be published here once the operating entity exists; both are left open deliberately rather than filled with a placeholder.