Privacy Policy
Revision dated September 28, 2026
1. Who we are and what this policy covers
ProxysVPN (in Russian, ПроксисВпнович; the “Service”, “we”) is a VPN service. This policy explains what data the Service handles, why, for how long, who else processes it and how you can have it deleted.
It covers the website proxysvpn.com and its reserve addresses, the Telegram bots @proxysvpn_bot and @proxysvpn_support_bot, the Telegram Mini App, the ProxysVPN apps and our VPN servers. Other VPN apps that you may use with the Service have privacy policies of their own.
If you do not agree with this policy, please do not use the Service.
2. Your VPN activity: our commitment
We do not sell, rent, use or disclose to third parties any data about your VPN activity or data collected through our apps, for any purpose. Our service providers (section 6) process data only on our instructions and only to run the Service.
We ourselves use such data only to provide and protect the Service, as this policy describes.
To carry your traffic, a VPN server necessarily sees your IP address and the addresses of the sites and services you connect to. The server software reads only what it needs to route a connection: its destination, and the domain name and protocol type at the start of the connection (this is how BitTorrent is blocked, as the Terms of Service say). Beyond that we do not examine the content of your traffic, and we do not use any of this to build a profile of you or for advertising.
For each access link the servers keep its device key, the ID of the account it belongs to (for an account created by email the ID contains the email address, for one created through Telegram it is the Telegram ID), its access period, the volume of traffic and the time of the last connection, and some servers also keep the IP addresses the link connects from. We use this to count traffic where a location has a monthly allowance, to notice a link shared among many devices, to find faults and to stop abuse. When you delete a device or your account, we remove it from the VPN servers together with these records.
The server software can also write a technical connection log (time, IP address and destination). We use it only to find faults and to stop abuse.
3. What data we keep
The table lists every kind of data we keep: where it comes from, why we need it, how long we keep it and who else processes it. The providers are described in section 6.
| Data | Source | Purpose | How long | Who else processes it |
|---|---|---|---|---|
| Account created by email: email address, password (stored only as a one-way hash), account ID | Source: Website | Purpose: Signing in, service messages, restoring access | How long: While the account exists | Who else processes it: Vercel, Upstash; Resend sends the emails; payment providers (the email address and the account ID, section 6); the VPN servers (the account ID, section 2) |
| Account created through Telegram: Telegram user ID, username and first name | Source: Telegram bot; signing in with Telegram on the website | Purpose: Signing in and working with you in the bot | How long: While the account exists | Who else processes it: Telegram, Vercel, Upstash; payment providers (the account ID, section 6); the VPN servers (the account ID, section 2) |
| Service data: balance, plan and paid periods, your devices and the names you give them, invitations and referral bonuses, language and currency | Source: Website, bot | Purpose: Providing the Service and billing for it | How long: While the account exists | Who else processes it: Vercel, Upstash |
| Access keys of each device: the random token in the access (subscription) link and the random device key by which the VPN servers recognise the device | Source: Created by us for each device | Purpose: Delivering connection settings to your VPN app and letting the device connect | How long: Until the device or the account is deleted | Who else processes it: Vercel, Upstash; the VPN servers (the device key); the support assistant (the link, section 11) |
| Install ID: a random identifier that the ProxysVPN app creates on first launch (not a hardware identifier); some other VPN apps send an identifier of their own | Source: App | Purpose: Keeping one access link on one device | How long: Up to 1 year from the first connection; deleted earlier when you reset the device link or delete the account | Who else processes it: Vercel, Upstash |
| Name, version and platform of the app that downloads the settings (User-Agent), and the time of the last download | Source: App or another VPN app | Purpose: Support (knowing which app you use), spotting outdated settings and telling you about them, and service messages about your access (for example, that it stopped while your app is still trying to connect); never for advertising | How long: 60 days from the last download | Who else processes it: Vercel, Upstash; the support assistant (section 11); Telegram, in the summary of your account the support team sees when you write to the support bot |
| Data on the VPN servers, for each access link: the device key, the account ID (containing the email address for an account created by email, the Telegram ID for one created through Telegram), the access period, traffic volume and time of the last connection; on some servers, the IP addresses the link connects from | Source: VPN servers | Purpose: Traffic allowances, spotting shared links, faults and abuse (section 2) | How long: Until the device or the account is deleted; copies in server backups for up to 14 days | Who else processes it: The hosting companies that rent us the servers (section 6). Whether a location’s monthly allowance is used up is also kept in our database (Vercel, Upstash) and shown to the support assistant (section 11) and, when you write to the support bot, to the support team in Telegram |
| Your IP address when you use the website or when an app downloads its settings; the website’s technical logs of requests and errors, which may also contain your account ID | Source: Website | Purpose: Protection against password guessing and abuse; limiting sign-up bonuses per address; choosing which prices to show at sign-up (only the country is read, it is not stored); finding faults | How long: Counters from 1 minute to 24 hours, not linked to your account; request logs of the hosting provider under its rules | Who else processes it: Vercel; our proxy server in Russia for some reserve addresses of the website |
| How you found us: campaign tags (utm), referral code, the site that linked to us (domain only), the first page and the time of the visit | Source: The website’s “attr” cookie; the link that opened the bot | Purpose: Understanding which channels bring new customers | How long: The cookie lives 30 days; a copy made at sign-up is kept while the account exists | Who else processes it: Vercel, Upstash |
| Payments: amount, date, payment method and payment ID. We never receive card numbers | Source: Payment providers | Purpose: Crediting payments, refunds and disputes | How long: Payment history: while the account exists; payment orders: up to 180 days; refund records: up to 1 year | Who else processes it: The payment provider you choose; Vercel, Upstash |
| Chat with the support assistant: your messages, attached images and, if you have an account, a summary of it | Source: Website, Telegram Mini App, support bot | Purpose: Answering your request | How long: 180 days from the last message; in the personal account you can delete it earlier with the “Clear” button | Who else processes it: OpenRouter and the language-model provider (section 11); Vercel, Upstash |
| Requests to the support team: messages to the support bot with your Telegram name and username, and letters to the support address. For the operators the bot adds a summary of your account: balance, email address, devices with their app and the time it last downloaded the settings, whether a location’s allowance is used up, recent payments | Source: Support bot, email | Purpose: Answering your request | How long: Support bot: our records 180 days from the last message; copies of the messages and the summary stay in the support team’s working chat in Telegram until an operator deletes them, also after the account is deleted. Letters: until they are no longer needed for your request, or deleted at your request | Who else processes it: Telegram, Vercel, Upstash; OpenRouter and the language-model provider when the assistant answers in the bot (section 11); Cloudflare forwards letters to our mailbox |
| Marketing: whether you turned off offers in the bot; the answer you pick when the bot asks why you stopped using the Service; the email address of your account for occasional newsletters | Source: Bot, website | Purpose: Occasional news and offers | How long: While the account exists or until you unsubscribe; the answer about why you stopped: up to 1 year | Who else processes it: Telegram; Resend for email newsletters |
| Website statistics: pages viewed, clicks, browser and device type, approximate location by IP address; sign-up events with campaign tags | Source: Pages of the website | Purpose: Traffic statistics and counting sign-ups | How long: Under the rules of the analytics services | Who else processes it: Yandex (Metrika), Vercel (Web Analytics); see section 10 |
| “Helpful / not helpful” votes under guides, with a random ID kept in your browser | Source: Website | Purpose: Improving the guides | How long: 180 days | Who else processes it: Vercel, Upstash |
We do not ask for passport data, document scans, phone numbers, your contacts, precise location or card details.
4. The ProxysVPN apps
The ProxysVPN apps connect your device to our VPN servers. In addition to what is described above:
- On first launch the app creates a random install ID. It is not derived from your hardware and carries no information about your device. The app sends it when it downloads your settings, so that one access link works on one device.
- Requests from the app to our website carry the app’s name and version, the operating system (for example, iOS or macOS) and whether the app was installed from the App Store — no device model or serial numbers.
- The apps contain no advertising, analytics or crash-reporting code and do not track you across other apps or websites. If you allow your device to share analytics with app developers, Apple may pass us crash reports under its own rules.
- The app’s technical log stays on your device. It leaves the device only if you send a report to support yourself.
- DNS. By default the app resolves site names through the VPN server, by asking Cloudflare (1.1.1.1) or Google Public DNS (8.8.8.8), so these resolvers see the server’s address rather than yours. When Russian sites are routed around the VPN, their names may be resolved directly from your network, by Yandex public DNS or by your system resolver. Where the app offers the choice, you can switch to your system resolver or enter your own.
- Connectivity checks. To find out whether your network works at all, the app may briefly connect to Cloudflare (1.1.1.1) and Google (8.8.8.8); these connections carry no information about your account. The app also checks that our website and servers respond.
- To download your settings, the app contacts our website or, if it is unreachable, one of the website’s reserve addresses (section 7).
The VPN permission you grant lets the app route your device’s traffic through our servers; the app uses it for nothing else.
5. How we use data
We use data only to:
- provide the Service: create access links, deliver settings, count usage and charge for it;
- answer your requests to support;
- take payments through the provider you choose;
- protect the Service and other users from fraud and abuse;
- tell you about your account, your balance and the state of the Service;
- send news and offers: in the bot at most once a week (turn them off with the “No more offers” button under such a message or with the /offers command) and occasionally by email, with an unsubscribe link in every letter.
We do not sell data and do not use it for advertising profiles. We disclose data to public authorities only when a binding legal requirement obliges us to, and only the data it covers.
6. Service providers and other services
Our service providers process data only on our instructions, only to the extent their task requires and with protection at least equal to this policy:
- Vercel Inc. (USA): hosting of the website, its API and our bots, and cookie-free visit statistics; it handles every request to the website.
- Upstash, Inc. (USA): our database of account, service, payment and support records.
- Resend, Inc. (USA): sending emails, that is, sign-in codes, service letters and newsletters.
- Cloudflare, Inc. (USA): the DNS of our domains; it receives letters sent to our addresses and forwards them to our mailbox.
- Hosting companies that rent us servers for the VPN and for the website’s reserve proxy. We do not name them, so as not to make it easier to block our servers. The servers are located in: Finland, France, Germany, Kazakhstan, Netherlands, Poland, Russia, Sweden, Türkiye, United Kingdom, and United States.
The following services are independent: they receive data because you use them or because the task requires it, and they process it under their own privacy policies:
- Telegram (UAE): our bots, the Mini App and signing in with Telegram; everything you send to the bots passes through Telegram.
- Payment providers: YooKassa, Cashera, Enot and lava.top (cards and fast payments), NOWPayments and CryptoBot (cryptocurrency). We pass them the amount and an order number. All of them except Cashera also receive your account ID, sometimes inside the order number: for an account created by email the ID contains your email address, for one created through Telegram it is your Telegram ID. YooKassa, Enot and lava.top also receive the email address of your account, if it has one, for the receipt. What you enter on their payment page (card or wallet details) goes to them, not to us.
- OpenRouter, Inc. (USA) and the language-model provider it passes the request to (currently xAI or Google, USA): answers of the support assistant (section 11). They may keep requests under their own terms.
- Yandex (Russia): Yandex Metrika web analytics on the public pages of the website (section 10).
- DNS resolvers of Cloudflare, Google and Yandex, used by the apps as described in section 4.
7. Where data is processed
The website, the database and email run on servers of Vercel, Upstash and Resend in the European Union and the USA. The VPN servers are located in: Finland, France, Germany, Kazakhstan, Netherlands, Poland, Russia, Sweden, Türkiye, United Kingdom, and United States. Some reserve addresses of the website pass through our own proxy server in Russia, which forwards requests to Vercel. Yandex Metrika processes data in Russia; Telegram and the payment providers process data where they operate.
Data-protection law in these countries may differ from the law of your country. Wherever the data is, we protect it as this policy describes.
8. How long we keep data, and deleting your account
The period for each kind of data is in the table in section 3.
When your account is deleted, we remove its devices from the VPN servers and delete the account, its devices, balance and settings from our database at once. What support may still need for an open request (the support chat, the payment history, the traces of your apps) is deleted automatically 7 days later.
A few records stay longer, each for its own reason: a one-way hash of the account ID with the time of deletion (180 days, so that a late payment is not credited to a deleted account); records of refunds (up to 1 year); the promo codes the account has used and the personal offers made to it (up to 1 year, against abuse); records of payment orders (up to 180 days) and of credited payments (up to 90 days), so that a late payment or a refund can be matched; records of requests in the support bot (180 days from the last message) and their copies in the support team’s working chat in Telegram (until an operator deletes them); and a ban from support, if one was imposed. These records carry the account ID, which for an account created by email contains the email address. Other technical records that name the account, such as rate limits and marks against sending a message twice, expire on their own within 180 days at most. Payment providers keep their own records of your payments under their rules.
Copies may remain in backups of our database and of the VPN servers until those backups are deleted; the VPN servers keep their backups for 14 days. Backups are used only to restore the Service after a failure. Messages you exchanged with our bots stay in your Telegram until you delete them there.
9. Your choices and rights
At any time you can:
- ask what data we hold about you and get a copy: write to support;
- ask us to correct inaccurate data;
- delete your account on the account deletion page or by asking support; this also withdraws your consent to the processing of your data;
- turn off news and offers with the “No more offers” button or the /offers command in the bot, or with the unsubscribe link in an email;
- delete the support chat with the “Clear” button and ask for a human operator instead of the assistant;
- block cookies and analytics in your browser; the website works without them.
If you ask support to delete your account, we do it within 30 days. You can also complain to the data-protection authority of your country.
10. Cookies and analytics
The website sets these cookies of its own:
- “sid” keeps you signed in: 1 hour, or 7 days if you tick “Remember for 7 days”;
- “tg_bind” ties a Telegram sign-in code to your browser for 10 minutes;
- “lang” remembers the language you chose: 1 year;
- “attr” remembers how you found us (section 3): 30 days.
Your browser’s storage also keeps the theme, the language, the random ID for guide votes and the campaign tags of your first visit; in the Telegram Mini App it keeps the sign-in for the current session.
On the public pages of the website we use Yandex Metrika. It does not run on the sign-in and registration pages, in the personal account, in the Telegram Mini App or on device connection pages. Where it runs, it sets its own cookies, records visits, clicks and scrolling and may record a replay of how the page was used (Webvisor). Yandex processes these data in Russia. We use them to see how people find us and how many of them sign up.
Vercel Web Analytics and Speed Insights count visits and measure page speed without cookies; they see the page address, the referring site, the browser, the device type and the country.
You can block these tools in your browser settings or with a content blocker; the website works without them.
11. Automated processing of support requests
Requests in the support chat are answered by an automated assistant: in the personal account on the website, in the Telegram Mini App and in the support bot after you press the ⚡ button. In the support bot the assistant may also answer a request that no operator has answered for a while. To prepare an answer, the text of your request, attached images and, if you have an account, a summary of it are sent to OpenRouter, which passes them to a language-model provider (currently xAI or Google).
The summary includes your balance and currency; your devices with their names, types, plans and terms, the app used on each and its access link (so that the assistant can give you the same link on a reserve address if our main address is blocked); when an app last downloaded the settings; whether a location’s monthly traffic allowance is used up; whether the account is linked to Telegram; recent top-ups (date, amount and method); and the result of an automatic connection check. Your email address, Telegram ID and password are not sent, and we do not have card details at all.
The conversation is kept for 180 days from the last message and is then deleted automatically. If you have an account, you see it in the personal account and can delete it earlier with the “Clear” button; otherwise ask support to delete it.
Conversations with the email address, the account ID and attached images removed are used to improve the assistant: to refine its rules and to check that it handles typical cases correctly.
You can ask for a human operator at any time: just say so in the chat. Do not send passwords, confirmation codes or card details to the chat; we never need them.
12. Security
Connections between your device and the website, the apps and the VPN servers are encrypted. Passwords are stored only as one-way hashes, access to data is limited to those who run the Service, and we keep the infrastructure up to date.
No transmission over the Internet is completely secure. We are not responsible for data lost, stolen or disclosed through the fault of third parties or through your own actions, such as a compromised device or shared credentials.
13. Changes to this policy
We may change this policy. The current revision is always published on this page with its date; continuing to use the Service after a new revision is published means you accept it. Revision history:
- September 28, 2026: the policy was rewritten. It now contains the commitment about VPN data, the full table of the data we keep with retention periods, the service providers and the countries where data is processed, a section on the apps, what happens when an account is deleted, and cookies and analytics described as they are.
- September 1, 2026: the section on automated processing of support requests was added.
14. Contacts
For any question about your data, write to our support bot @proxysvpn_support_bot or to support@proxysvpn.com.