Privacy Policy
Last updated 15 August 2026
The short version. We do not log the destinations or contents of your traffic. We keep the minimum needed to bill you accurately and run the network: your account email, billing metadata, and per-gigabyte usage totals. We do not sell data to anyone.
The part most providers leave out. We are not the only party your traffic passes through. The upstream networks that carry it keep their own connection records, which can include destination IP addresses, for 30 days before automatic deletion. We do not receive those records and cannot delete them — but you should know they exist. See Upstream networks below.
This policy explains how VeilSocks ("we", "us") handles personal data in connection with veilsocks.com and the proxy service. For the purposes of the GDPR, we are the data controller for the personal data described below.
What we collect
Account data
- The email address you register with.
- Proxy credentials we issue to you.
- Support correspondence you send us by email or Telegram.
Billing metadata
- Payment amount, currency, timestamp, and method (card or cryptocurrency).
- A transaction reference from our payment processor.
- Your balance and its history.
Card numbers never reach our servers. Card payments are handled by our payment processor, which collects billing details directly under its own privacy policy. Cryptocurrency top-ups require no personal billing details at all.
Usage data
- Bandwidth consumed, measured per gigabyte and attributed to your account.
- Which product type and geography a session used (for example, "US mobile").
- Session start and end times, and the volume transferred.
- Operational signals needed to keep the pool healthy, such as aggregate error rates.
What we deliberately do not collect
We do not record the destination hosts, URLs, or IP addresses you connect to through the proxy, and we do not inspect, store, or analyse the contents of your traffic. There is no browsing history attached to your account, because we never create one.
This is a design decision, not just a policy statement: the per-GB billing that charges you counts bytes, not destinations. A practical consequence is that if you ask us what you visited, or a third party demands it, we cannot produce it — we do not have it.
Upstream networks
What we do not collect is only half the picture, and the half that most proxy providers describe. Here is the other half.
Your traffic reaches the internet through mobile carriers and upstream infrastructure providers that we do not own. Those networks keep their own connection records, which can include destination IP addresses and timestamps. That logging happens at their layer, under their retention policies and the law of their jurisdiction.
Retention: 30 days. Our upstream provider states that these connection records are held for 30 days and then deleted automatically from their systems. That period is set by them, not by us, and they could change it — we will update this page if we are told it has changed.
What this means in practice:
- We do not receive, store, or have access to those records at any point.
- We cannot delete them early, extend them, or turn the logging off.
- Within that 30-day window, an upstream provider can be compelled by legal process in its own jurisdiction, independently of us. After it, there is nothing left for them to produce.
- No proxy service can honestly promise otherwise. Any provider claiming that absolutely no record of your connections exists anywhere is describing something they do not control.
We state this plainly because a privacy promise you cannot verify is worth nothing. If your threat model requires that no party anywhere retains connection metadata, a commercial proxy — ours or anyone else's — is not the right tool.
Why we process it, and on what basis
- To provide the service — issuing credentials, routing traffic, billing usage per GB. Basis: performance of our contract with you (GDPR Article 6(1)(b)).
- To bill you — processing payments and maintaining balances. Basis: contract (Article 6(1)(b)), and legal obligation for financial records (Article 6(1)(c)).
- To support you — answering your messages. Basis: contract (Article 6(1)(b)) and our legitimate interest in running a usable service (Article 6(1)(f)).
- To protect the network — investigating abuse reports and enforcing our acceptable-use rules. Basis: our legitimate interest in network integrity (Article 6(1)(f)), and legal obligation where we must act (Article 6(1)(c)).
Who we share it with
We do not sell personal data, and we do not share it for advertising. We share only with:
- Our payment processor, to take payment and handle disputes.
- Our hosting provider, which stores the systems this data lives on.
- Upstream carriers and network partners, to the extent needed to provision the IPs you use.
- Authorities, where we receive valid legal process — limited to what we actually hold, which does not include traffic contents or destinations.
Each of these acts as a processor or subprocessor bound by a written agreement that restricts them to processing data on our instructions and requires confidentiality. They may not use your data for their own purposes.
How long we keep it
- Account data — while your account is open, and up to 12 months after you close it.
- Billing records — as long as tax and accounting law requires, typically 7 years.
- Usage totals — 12 months, then deleted or aggregated beyond attribution to you.
- Support messages — 24 months.
Cookies and analytics
This site sets no advertising cookies and sends nothing to an advertising network.
We do measure traffic, using Umami — analytics software we run on our own server. It is served from this domain, stores its data on our infrastructure, and sets no cookies at all. It records the page visited, the referring site, any campaign parameters in the link, and coarse details such as browser, operating system, device type and country. It does not fingerprint you, does not follow you to other websites, and no third party receives that data.
The customer dashboard at app.veilsocks.com uses a strictly necessary session cookie to keep you signed in. That is functional, not tracking, and it is not used to profile you.
Fonts and scripts are served from our own domains rather than a public CDN, so ordinary browsing here makes no third-party requests.
Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you, and receive a copy.
- Correct data that is inaccurate.
- Delete your data, subject to records we must legally retain.
- Object to or restrict certain processing.
- Receive your data in a portable format.
- Withdraw consent where processing relies on it.
If you are in the EU or UK, these rights come from the GDPR, and you may also complain to your local supervisory authority. If you are a California resident, the CCPA gives you rights of access, deletion, and correction, plus the right to opt out of "sale" or "sharing" of personal information — we do neither, so there is nothing to opt out of. We will not discriminate against you for exercising any of these rights.
To exercise a right, email support@veilsocks.com from your account address. We respond within 30 days.
Security
Traffic to this site and to the customer dashboard is encrypted with TLS. Access to billing and account systems is restricted to people who need it. No system is perfectly secure, and we cannot guarantee absolute security — but the strongest protection here is structural: the most sensitive data, your browsing activity, is never collected by us in the first place. That protection stops at our boundary; see Upstream networks.
International transfers
Our infrastructure is hosted in the United States, and our network spans 190+ countries. If you are outside the US, using the service involves transferring your account and billing data to the US. Where required, we rely on appropriate safeguards such as the European Commission's standard contractual clauses.
Children
The service is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.
Changes
We may update this policy. The "last updated" date will change, and material changes will be announced on this page before taking effect.
Contact
- Email — support@veilsocks.com
- Telegram — @veilsocks
- Entity — VeilSocks