Legal
Privacy policy
Last updated 21 August 2026
What we collect, why, and — just as importantly — what we deliberately do not.
Who is responsible for this data — unresolved
No company has been registered behind the Proxylexus name yet, so this policy cannot name a data controller, a registered address, or a supervisory authority you could complain to. That is a gap, we are not going to paper over it, and it has to be closed before the service takes personal data from anyone in a jurisdiction with a statutory regime.
Everything below describes what the software actually does today. Write to privacy@proxylexus.com for anything on this page.
What we collect
- Account data: your email address and a scrypt hash of your password. We never store the password itself.
- Subscription data: your plan, balance, billing window and the identifier of your proxy user.
- Usage data: bytes transferred per day, plus whatever dimensions the upstream network reports back to us.
- Session data: a SHA-256 hash of your session token and its expiry. The token itself lives only in your browser cookie.
- Anything you write to us — including the note attached to a purchase request, and any email you send to a published address.
What we do not log
We do not log the destinations you connect to, the contents of your traffic, or the full credentials of your proxy users in any operational log. Errors returned by the upstream API are redacted before they reach a log sink.
Note the boundary honestly: your proxy traffic terminates on the upstream provider’s gateway, not ours. What they log is governed by their privacy policy, not this one — and because we are an ordinary customer of theirs rather than a contracted partner, we have no special visibility into or influence over what that is.
Why we collect it
To operate your account, to meter and bill traffic accurately, to enforce our acceptable use policy, and to respond when you contact us. We do not sell personal data, and we do not use it for advertising. There is no analytics, advertising or session-replay script on this site; the only cookie we set is the one that keeps you signed in.
How long we keep it
- Account and subscription data: for as long as the account exists, then deleted.
- Daily usage records: retained for the period needed to bill and to resolve disputes, then aggregated or deleted.
- Sessions: until expiry, and purged on a schedule. Deleting your account deletes its sessions immediately.
Who else sees it
Our upstream network provider necessarily processes the traffic you route through it, and receives the proxy-user identifiers we create on your behalf. We do not pass them your email address or your billing details. The identifiers are namespaced with your internal account id, so they can be linked back to your account by anyone holding both — which includes them.
We do not know which jurisdictions the upstream operates from or transfers data through, which is a real gap in this policy rather than an omission from it. It closes when we can state it accurately.
Your rights, and how they work today
You can ask for a copy of your data, a correction to it, or its deletion. Deleting your account cascades to your subscription, sessions, usage records and credit ledger.
Two things to know before you ask. First, all three are handled by hand right now — there is no export button and no delete button in the dashboard, and we would rather say that than describe a feature that is not there. Second, deletion destroys any prepaid balance still on the account: the credit ledger goes with the account row. If you have traffic left, settle that with us first.
Some things are deliberately excluded from an export: your password hash and your session token hashes, because handing those over creates an offline cracking target, and your upstream proxy passwords, because we do not store them — they are read from the network on demand.
Contact
Data protection requests and questions about this policy go to privacy@proxylexus.com. Other addresses are on the contact page. A postal address and the controller’s identity will be published here once the operating entity exists; both are left open deliberately rather than filled with a placeholder.