The short version. ProxyTool routes your traffic to proxy servers you choose. That traffic does not pass through our servers, and we do not log, inspect or store the content of your connections, the pages you open or the files you transfer. What we do store is what an account needs: your email, your subscription, and which devices your licence runs on. Everything beyond that is optional, off by default, and described below.
1. Who we are and what this policy covers
This privacy policy is provided by the organization that operates ProxyTool:
ProxyTool
Straße der Jugend 18
14974 Ludwigsfelde, Germany
Website: https://proxytool.app
Phone: +49 160 8801818
Privacy contact: privacy@proxytool.app
It covers the ProxyTool applications for Android, iOS, macOS, Linux and Windows, the ProxyTool web dashboard at proxytool.app, and the ProxyTool website. Wherever this policy says “the app”, it means the ProxyTool client on any of those platforms. Where a platform behaves differently, that difference is stated explicitly.
Some ProxyTool clients are still in development. A platform is covered by this policy from the day its client is published, and the data practices described here apply identically across platforms because every client talks to the same backend.
2. What ProxyTool never does
These are commitments, not aspirations. They hold on every platform:
- We do not read your traffic. The app forwards connections to the proxy servers you configure. The content of those connections — websites, messages, files, credentials — never reaches ProxyTool servers and is never written to our systems.
- We do not sell personal data, and we do not share it with data brokers or advertising networks.
- Data from the tunnel stays out of everything else. ProxyTool routes traffic on your device, and we do not sell, disclose to any third party, or use for any purpose of our own the data that this routing produces — not for advertising, not for profiling, not for training models, not for measuring anything beyond the feature you asked for. The only exception is the fleet telemetry in section 4.4: it exists solely so that the organisation that manages your device can see its own proxy usage, it is off unless that organisation switches it on, it is never available to personal accounts, and it is deleted after 48 hours.
- We do not inject, replace or manipulate ads or any other content in your traffic, and we do not use your connection as an exit node for anyone else.
- We do not read your contacts, messages, photos, calendar, microphone, camera or precise location. The apps do not request those permissions.
- We do not collect an inventory of the apps installed on your device. Application names are only ever processed for the apps you add to a routing rule, plus — if fleet telemetry is switched on — the apps that actually generated proxied traffic.
3. How routing works, and what it means for your data
ProxyTool is a proxy client. It decides which application's traffic goes through which proxy, and hands that traffic to a proxy server operated by your provider or by you. ProxyTool does not operate the proxy servers and has no visibility into what passes through them.
Per platform
- Android: the app uses Android's
VpnService to create a local tunnel interface. This is the only mechanism Android offers for routing another app's traffic. The tunnel exists on your device; ProxyTool is not the endpoint. Traffic leaves the device to the proxy endpoint you configured. Android shows a system consent dialog before the tunnel starts, and the app explains what it does before that dialog appears.
- iOS: the app uses Apple's Network Extension framework for the same purpose, subject to the same system-level consent.
- Windows: traffic is redirected locally through the Windows Filtering Platform.
- macOS and Linux: traffic is redirected locally through a transparent proxy layer.
In each case the redirection happens on your device. Connection metadata used to make routing decisions — destination host, port, and the process that opened the connection — is evaluated locally and discarded. It is only transmitted if a fleet administrator has switched on telemetry for a managed device, which is described in section 4.4.
On encryption: connections between the app and ProxyTool's own services always use TLS 1.2 or higher. The encryption of your proxied traffic depends on the proxy protocol and provider you choose: HTTPS and SOCKS5-over-TLS endpoints are encrypted between your device and the proxy, plain SOCKS5 is not. Traffic that is already encrypted end to end (HTTPS websites, for instance) stays encrypted regardless of the proxy protocol. The app tells you which protocol a profile uses.
4. What we collect
4.1 Account data
Created when you register, required to have an account at all:
- Email address, and a display name if you set one
- A hashed password (only if you use password sign-in) and, if you enable it, two-factor secrets and backup codes
- Session records: an authentication token, the browser or client user agent, expiry, and for web sessions the IP address the session was created from
- Account creation and update timestamps
4.2 Device and licence data
Sent by the app when you sign in, so a licence can be tied to a device and your device limit can be enforced:
- A device identifier. The app derives it on your device from stable system characteristics and hashes it with SHA-256 before sending. We receive the hash only; it cannot be turned back into a hardware serial number, and we do not receive advertising identifiers.
- Device name (your device's hostname), platform and operating system version
- App version and the timestamp your device was last seen
4.3 Managed device data (business plans only)
If your device is enrolled in an organisation's fleet by an administrator, the app additionally reports, roughly once a minute: which configuration profile is active, the proxy entries in it (label, host, port, type), how many proxies and chains are configured, and the version of the policy currently applied. This is what makes central configuration possible. It does not include traffic.
4.4 Fleet telemetry — optional, off by default
Organisations can switch on telemetry for a managed device to see how proxy capacity is being used. It is disabled by default, it is switched on per device from the web dashboard, and while it is off the app sends nothing of the sort and our API rejects such data outright. Personal accounts that are not part of an organisation cannot enable it at all.
When an administrator has enabled it, the app reports in batches:
- Aggregate counters: active and total connections, bytes sent and received, proxied versus direct volume, connection errors
- Protocol breakdown and proxy health: per-protocol counts, per-proxy quality, error rates and throughput
- Application names of the top traffic-producing apps, with their traffic volume
- Domain names contacted through the proxy, with a category, traffic volume, request count and the app that requested them
- Security events: for connections that were blocked or flagged, the process name, destination hostname, destination IP, port, reason and action taken
This is real usage data about the person at the device, which is why it is off by default, visible to that organisation only, and deleted automatically after 48 hours. Administrators can wipe it at any time. If your employer enrols your device, they are responsible for informing you under the applicable employment and data protection rules; ProxyTool acts as a processor for that data.
What never leaves the device, even with telemetry on: the content of connections, the live per-connection list shown in the app's monitor, your local session history (stored encrypted on the device), and TLS/JA3 fingerprints, which are computed and displayed locally only.
4.5 Diagnostic logs — only when you send them
If you hit a problem, the app can package its local log files and send them to support. This happens only when you trigger it. The package can contain hostnames, proxy configuration fragments, process identifiers and error traces, and is attached to your email address so we can answer you. Diagnostic logs are deleted after 90 days.
4.6 Subscription and billing data
Plan, status, quantity, billing period, invoice history and your Stripe customer reference. Payment is handled entirely by Stripe: we never receive or store card numbers, CVVs or bank details.
If you subscribe inside the iOS app instead, Apple is the merchant and handles the payment. We never see your Apple ID or your payment details. What we receive from Apple is the transaction and the identifier of the product you bought, plus an opaque token that we generate ourselves so we can attach that subscription to your ProxyTool account. Cancelling and refunding such a subscription happens in your Apple account settings, because only Apple can do it.
4.7 Support and communication
If you open a ticket or write to us, we store your email address, name, and the content of the exchange in order to answer it. The live chat on our website is provided by Crisp.
4.8 Website and product analytics
On our website and in the web dashboard we use PostHog to understand which pages and features are used. It is opt-in: nothing is captured until you accept the cookie banner, and you can decline. Conversion events for advertising are sent to Google Ads under the same consent. The apps themselves contain no advertising or attribution SDKs.
4.9 Bot protection
Sign-in and registration are protected by Cloudflare Turnstile, which receives your IP address and a challenge token to distinguish humans from automated attacks.
4.10 AI assistant
If you use the AI assistant in the dashboard, the message you write — and any screenshot you attach — is sent to Google's Gemini API to generate the answer. Credentials detected in the text are redacted before sending. Do not paste anything into the assistant you would not want processed by a third-party model. The assistant is optional and never runs on its own.
4.11 Proxy marketplace
If you buy proxy bandwidth through ProxyTool, we create an account for you with the provider (currently Evomi) and transmit your email address and a generated username for that purpose. Your usage volume with that provider is read back to display your balance.
4.12 Referrals
If you arrive through a referral link, we store the referral code, the accounts on both sides and the IP address the referral was claimed from, in order to detect self-referral fraud.
5. Data safety summary
The same information in the format used by app store data safety labels. “Shared” means transferred to a third party that is not acting purely as our processor.
| Data type | Collected | Shared | Purpose | Optional |
| Email address, name | Yes | No | Account management, developer communications | Required |
| Password (hashed), 2FA secrets | Yes | No | Authentication, security | Required |
| Purchase history, payment reference | Yes | No | Billing (processed by Stripe, or by Apple if you subscribe in the iOS app) | Required for paid plans |
| Device identifier (irreversible hash) | Yes | No | App functionality, licence enforcement, fraud prevention | Required |
| Device name, OS and app version | Yes | No | App functionality, support | Required |
| App activity: proxy configuration metadata | Managed devices only | No | Central device management | Business plans |
| App activity: app names, domains, security events | Only if telemetry is enabled | No | Fleet analytics for the organisation | Optional, off by default |
| Diagnostic logs | Only when you send them | No | Support and troubleshooting | Optional |
| IP address | Yes, transiently | Cloudflare | Bot protection, rate limiting, referral fraud | Required |
| Web analytics | Only with consent | PostHog, Google Ads | Analytics, marketing measurement | Optional |
| AI assistant messages | Only when used | Google (Gemini) | Answering your request | Optional |
| Traffic content, full URLs, page-level browsing history | Never collected. Only the domain names listed above, and only while telemetry is enabled. |
| Contacts, messages, photos, location, calendar | Never collected. |
All data is encrypted in transit. You can request deletion of all of it — see section 10.
6. Why we process it, and on what legal basis
- Contract performance (GDPR Art. 6(1)(b)): creating and running your account, enforcing device limits, delivering the software, handling subscriptions and invoices, answering support requests.
- Legitimate interest (Art. 6(1)(f)): keeping the service secure, preventing fraud and licence abuse, diagnosing faults, and understanding aggregate product usage.
- Legal obligation (Art. 6(1)(c)): retaining invoices and accounting records under German tax law.
- Consent (Art. 6(1)(a)): website analytics and advertising measurement, sending diagnostic logs, using the AI assistant, and — for managed devices — enabling fleet telemetry. Consent can be withdrawn at any time with effect for the future.
7. Who else processes your data
We keep this list short on purpose. Each of these is bound by a data processing agreement.
Each of these is contractually required to protect your data to the same standard this policy sets out, to process it only on our documented instructions, and to use it for no purpose of their own. Where a provider is a controller in its own right — Apple and Stripe for the payment itself, Evomi for the proxy account you buy — their own policy applies to that part, and we have linked it above so you can read it.
Proxy providers you configure yourself receive your traffic directly, under their own terms and privacy policies. That relationship is between you and them.
8. International transfers
We are based in Germany and prefer EU processing where it is available. Some of the providers above are based in the United States. Those transfers are covered by the EU-US Data Privacy Framework or by Standard Contractual Clauses together with supplementary measures.
9. How long we keep it
- Fleet telemetry: automatically deleted after 48 hours
- Diagnostic logs: deleted after 90 days
- Device and licence records: until you remove the device or delete your account
- Account data: until you delete your account
- Support conversations: up to 24 months after the ticket is closed
- Invoices and accounting records: 10 years, because German tax law requires it — this is the one category that survives account deletion
10. Deleting your account and your data
You can delete your account yourself, and you do not need to ask us for permission or install anything to do it.
- In the web dashboard: Settings → Delete account. It takes effect immediately. The dashboard works in any browser, so you do not need the app installed.
- Without signing in: follow the instructions at proxytool.app/delete-account.
Deleting your account permanently removes your profile, sessions, licences, devices, fleet records, telemetry, diagnostic logs, support history and referral records. We do not freeze or deactivate accounts as a substitute for deletion. Invoices are the only exception and are retained for the statutory period described above; they are kept for tax purposes and are not used for anything else. Residual copies in encrypted backups are overwritten within 30 days.
11. Your rights
Under the GDPR you have the right to:
- Access — request a copy of your personal data
- Rectification — have inaccurate data corrected
- Erasure — have your data deleted
- Restriction and objection — limit or object to processing based on legitimate interest
- Portability — receive your data in a machine-readable format
- Withdraw consent — at any time, with effect for the future
Write to privacy@proxytool.app and we will answer within 30 days. You also have the right to lodge a complaint with a supervisory authority; ours is the Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg.
12. Security
- TLS 1.2 or higher for every connection between the apps, the website and our services
- Encryption at rest for the database and stored files
- Passwords stored only as salted hashes; device identifiers stored only as hashes
- Optional two-factor authentication on accounts
- Scoped, expiring tokens for app sessions, revocable per device
- Local session history on the device stored encrypted with the operating system's key store
- Rate limiting, bot protection and audit logging on sensitive endpoints
- Desktop releases are signed with an EV code signing certificate
13. Children
ProxyTool is a tool for professional use and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has created an account, write to privacy@proxytool.app and we will delete it.
14. Cookies and consent
The website and dashboard set strictly necessary cookies for authentication, session management and security. These are required for the service to work and are not used for tracking.
Analytics and advertising measurement — PostHog and Google Ads — only run after you accept them in the cookie banner. Declining costs you nothing: the service works identically either way. You can change your choice at any time by clearing the banner's stored preference in your browser. The ProxyTool apps do not use cookies or advertising identifiers.
15. Changes to this policy
When our data practices change, this policy changes with them before the change ships. Significant changes are announced by email or in the app. The date below always reflects the current version.
Questions? Ask a person: privacy@proxytool.app. If something in this policy does not match what you observe the app doing, tell us — that is a bug we want to hear about.
Last updated: September 11, 2026