VeilSocks
Legal

Privacy Policy

Last updated 15 August 2026

The short version. We do not log the destinations or contents of your traffic. We keep the minimum needed to bill you accurately and run the network: your account email, billing metadata, and per-gigabyte usage totals. We do not sell data to anyone.

The part most providers leave out. We are not the only party your traffic passes through. The upstream networks that carry it keep their own connection records, which can include destination IP addresses, for 30 days before automatic deletion. We do not receive those records and cannot delete them — but you should know they exist. See Upstream networks below.

This policy explains how VeilSocks ("we", "us") handles personal data in connection with veilsocks.com and the proxy service. For the purposes of the GDPR, we are the data controller for the personal data described below.

What we collect

Account data

Billing metadata

Card numbers never reach our servers. Card payments are handled by our payment processor, which collects billing details directly under its own privacy policy. Cryptocurrency top-ups require no personal billing details at all.

Usage data

What we deliberately do not collect

We do not record the destination hosts, URLs, or IP addresses you connect to through the proxy, and we do not inspect, store, or analyse the contents of your traffic. There is no browsing history attached to your account, because we never create one.

This is a design decision, not just a policy statement: the per-GB billing that charges you counts bytes, not destinations. A practical consequence is that if you ask us what you visited, or a third party demands it, we cannot produce it — we do not have it.

Upstream networks

What we do not collect is only half the picture, and the half that most proxy providers describe. Here is the other half.

Your traffic reaches the internet through mobile carriers and upstream infrastructure providers that we do not own. Those networks keep their own connection records, which can include destination IP addresses and timestamps. That logging happens at their layer, under their retention policies and the law of their jurisdiction.

Retention: 30 days. Our upstream provider states that these connection records are held for 30 days and then deleted automatically from their systems. That period is set by them, not by us, and they could change it — we will update this page if we are told it has changed.

What this means in practice:

We state this plainly because a privacy promise you cannot verify is worth nothing. If your threat model requires that no party anywhere retains connection metadata, a commercial proxy — ours or anyone else's — is not the right tool.

Why we process it, and on what basis

Who we share it with

We do not sell personal data, and we do not share it for advertising. We share only with:

Each of these acts as a processor or subprocessor bound by a written agreement that restricts them to processing data on our instructions and requires confidentiality. They may not use your data for their own purposes.

How long we keep it

Cookies and analytics

This site sets no advertising cookies and sends nothing to an advertising network.

We do measure traffic, using Umami — analytics software we run on our own server. It is served from this domain, stores its data on our infrastructure, and sets no cookies at all. It records the page visited, the referring site, any campaign parameters in the link, and coarse details such as browser, operating system, device type and country. It does not fingerprint you, does not follow you to other websites, and no third party receives that data.

The customer dashboard at app.veilsocks.com uses a strictly necessary session cookie to keep you signed in. That is functional, not tracking, and it is not used to profile you.

Fonts and scripts are served from our own domains rather than a public CDN, so ordinary browsing here makes no third-party requests.

Your rights

Depending on where you live, you may have the right to:

If you are in the EU or UK, these rights come from the GDPR, and you may also complain to your local supervisory authority. If you are a California resident, the CCPA gives you rights of access, deletion, and correction, plus the right to opt out of "sale" or "sharing" of personal information — we do neither, so there is nothing to opt out of. We will not discriminate against you for exercising any of these rights.

To exercise a right, email support@veilsocks.com from your account address. We respond within 30 days.

Security

Traffic to this site and to the customer dashboard is encrypted with TLS. Access to billing and account systems is restricted to people who need it. No system is perfectly secure, and we cannot guarantee absolute security — but the strongest protection here is structural: the most sensitive data, your browsing activity, is never collected by us in the first place. That protection stops at our boundary; see Upstream networks.

International transfers

Our infrastructure is hosted in the United States, and our network spans 190+ countries. If you are outside the US, using the service involves transferring your account and billing data to the US. Where required, we rely on appropriate safeguards such as the European Commission's standard contractual clauses.

Children

The service is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.

Changes

We may update this policy. The "last updated" date will change, and material changes will be announced on this page before taking effect.

Contact