Last updated 1 October 2026
Privacy policy
What we collect, why, how long we keep it, and what we will never do with it.
What we collect
Account data
An email address and a password hash. That is the whole signup. We do not ask for your name, company, phone number or what you plan to use it for.
Billing data
Payment records — amount, currency, method and timestamp. Card payments are handled by our payment processor; we never see or store your card number. Crypto payments are processed by CoinGate and we store the transaction reference and, for a crypto refund, the address of the wallet the payment was sent from, because that is where the refund goes. If you paid in crypto from an exchange and ask us to refund to your own wallet, we keep the exchange withdrawal record you show us and that wallet’s address. If a refund has to go by bank transfer because the card can no longer receive it, we keep the bank account details it is paid to and the identity check we ran before paying it.
Usage metadata
Per request, so that we can bill you and so that you can check us:
- A request ID and timestamp
- The destination hostname
- The exit country and network type
- The HTTP status code
- The number of bytes transferred
We do not log the contents of your requests or responses — no bodies, no headers you sent, no URLs beyond the hostname. We cannot show them to anybody because we do not have them.
Site analytics
This website uses Google Analytics 4, loaded through Google Tag Manager, to count visits and see which pages get read. It runs only if you agree to it. Nothing analytics-related is stored or sent until you accept on the cookie banner, and rejecting is one click in the same place, at the same size, as accepting.
You can change your mind whenever you like: “Cookie settings” in the footer of every page reopens the choice. The cookie policy lists every cookie we can set, what each one is for and how long it lasts.
What this does not touch is the traffic you send through the proxies. Site analytics is about pages on proxypanda.io, and it has no access to your requests — the two systems share no data at all. The section above still holds: we do not log what you send through the network, so no analytics tool can be given it.
Why we hold it
- Account and billing data — to run your account and take payment.
- Usage metadata — to bill accurately, to let you audit that bill, and to investigate abuse reports.
How long we keep it
- Usage metadata: 90 days, then deleted.
- Billing records: as long as tax law requires us to, currently seven years.
- Account data: until you close the account, then 30 days, then deleted.
Who we share it with
Only the providers we need to operate:
- CoinGate — crypto payment processing
- Our card payment processor — card payments
- Our hosting and email providers
We do not sell data, and we do not share it for advertising. We disclose data to law enforcement only where we are legally compelled, and we will tell you unless we are prohibited from doing so.
The what-is-my-IP tool: when you press “Look up my IP” on that page, your browser sends your IP address, with the details any web request carries, straight to ipapi.is, an IP data provider, which looks it up and returns the result to your browser. Nothing is sent before you press the button, the result never reaches our servers, and we do not store it; ipapi.is handles the request under its own privacy policy.
The proxy checker: when you press “Check my connection” on that page, your browser sends three requests. One goes to our API, which sends back the IP address the request arrives from, a short list of proxy-revealing headers and your user agent; we do not store the result. One goes to ipapi.is, as for the what-is-my-IP tool, to look up the network your IP belongs to. One goes to Google’s public STUN server, which tells your browser the address it sees, for the WebRTC check. Nothing is sent before you press the button, and ipapi.is and Google handle their requests under their own privacy policies.
Your rights
You can ask for a copy of what we hold, ask us to correct it, or ask us to delete it. Email [email protected] and we will action it within 30 days. You do not need to give a reason.
If you are in the UK or EU, you also have the right to complain to your data protection authority.
If you are a California resident, no personal information of yours is sold or shared, as those terms are defined under the California Consumer Privacy Act — and the rights above apply to you under the CCPA too, exercised the same way.
Where our IPs come from
Our residential IPs come from people who opted in through an SDK, are paid for their participation, and can withdraw at any time. This is relevant to your privacy in one direction: those participants are not incidentally exposed to your traffic contents, because the connection is proxied and not inspected.
Contact
[email protected]. If a policy here is unclear, say so in Discord and we will rewrite it rather than argue about it.
Something here unclear?
Ask in Discord and we will explain it in plain English. If the wording is confusing, we will rewrite it.