New Product Launched: Budget Pool, 2 million IPs and starting @ $2.75/GB

Legal

Privacy Policy

We are a privacy product. Collecting data we do not need would make us worse at our job, so we do not.

Last updated 21 August 2026.


1. What we collect

datawhyretention
email addresslogin, invoices, service noticesuntil deletion
password hashauthentication, argon2iduntil deletion
balance and plan stateprovisioning and billinguntil deletion
aggregate GB countersmetering, totals only13 months
invoice recordsaccounting obligationsas required by law
panel login IP and timeaccount takeover protection7 days
support messagesanswering you12 months

2. What we do not collect

  • No request logs. We do not record the URLs, hostnames or IP addresses you connect to through the gateway.
  • No payload capture. Traffic is proxied, never inspected or stored.
  • No real names, addresses, phone numbers or identity documents. There is no KYC.
  • No third party analytics, ad pixels, session recorders or fingerprinting. This site loads one stylesheet, one script and two fonts.
  • No advertising cookies. See section 5.

Live connection state, meaning the source account and the upstream peer, exists in memory while a connection is open so we can route and meter it. It is never written to disk.

3. Payments

Payments are processed on chain. We store the invoice amount, the currency, the transaction ID and the settlement time. We never see a card number, a bank account or a legal name, because you never give us one.

4. Who we share with

Nobody, in the ordinary course. We do not sell, rent or trade data and we have no advertising partners. The narrow exceptions:

  • Infrastructure providers hosting our servers, who see traffic in transit as any host does.
  • Valid legal process from a jurisdiction with authority over us. We disclose only what we hold, which for traffic is nothing, and we notify the affected user unless we are prohibited from doing so.
  • Abuse investigations, where we may map a reported source IP and timestamp to an internal account ID in order to act.

5. Cookies

One cookie: a session token, set only after you log in. It is HttpOnly, Secure, SameSite=Lax, and it expires with your session. There is no consent banner because there is nothing to consent to.

6. Your rights

Wherever you live, you can:

  • Export everything we hold about you from the dashboard, as JSON.
  • Correct your email address at any time.
  • Delete your account. Email, password hash, usage counters and support history are purged within 30 days. Invoice records are retained where accounting law requires it.
  • Complain to your local data protection authority.

Requests to privacy@femboyproxies.com are answered within 30 days.

7. Peers in the network

Devices contributing bandwidth join through partner applications that disclose the arrangement and pay for participation, and they can withdraw at any time from a single control. We hold the peer identifier and the payout record, never the browsing activity of the person operating the device.

8. Security

  • TLS everywhere, HSTS on the panel.
  • Passwords hashed with argon2id, optional TOTP two factor.
  • Full disk encryption on every node we control.
  • Least privilege internal access, reviewed quarterly.
  • If a breach ever affects your data, you hear it from us within 72 hours of us confirming it.

9. Warrant canary

As of the date above we have not received a national security letter, a gag order, or any request for bulk user data. This line is removed if that stops being true.

10. Contact

privacy@femboyproxies.com. A PGP fingerprint is published in the client area.