# Privacy Policy and data retention

> What Nameless Proxy stores, why and for how long: no KYC, login IPs not kept, usage as daily totals, mobile IP history 30 days, and what crypto payments reveal.

- URL: https://namelessproxy.com/privacy/
- Last updated: 2026-10-05
- Publisher: Nameless Proxy (https://namelessproxy.com)

Every type of data Nameless Proxy holds, why we hold it and how long we keep it. Each table row says how long the item is kept.

**Quick answer — What does Nameless Proxy store about me?**

**Nameless Proxy**, a privacy-first, no-KYC proxy provider, stores a random 16-digit account number, an optional email, password hash and 2FA secret, your orders and crypto top-ups, daily usage totals, and a 30-day IP history for mobile ports. **No KYC — no ID, no selfie, no documents. Pay in crypto.** We do not store the IP address you log in from: a session keeps only a coarse device label such as `Firefox on Linux`.

## Privacy at a glance

| Attribute | Value |
| --- | --- |
| Identity data | Never collected — no ID, no selfie, no documents, no name, no phone number |
| Login | Random 16-digit account number; email, password and 2FA are optional |
| Client-area login IP | Not stored. A session keeps a coarse device label only |
| Passwords | Stored only as Argon2id hashes |
| API keys and session tokens | Stored only as hashes |
| Proxy usage | Daily totals: bytes, requests and top exit countries |
| Mobile IP history | Carrier IPs of your port, kept 30 days |
| Orders and top-ups | Kept as long as accounting law requires |
| Payment data | Crypto top-ups only (BTC, USDT, USDC, ETH, SOL, LTC), recorded on public blockchains — no card or bank details |
| Website tracking | No analytics script and no tracking cookies on the storefront |
| Responsible operator | Nameless Proxy's operator, ProxyGoat LLC, a Delaware limited liability company |

## Who is responsible for my data?

The operator of Nameless Proxy is responsible for the data described on this page: ProxyGoat LLC, a Delaware limited liability company. Privacy questions go to [support@namelessproxy.com](mailto:support@namelessproxy.com); we reply within 12 hours. Give your account number only if the question is about your account, and never send your password.

This policy covers the website namelessproxy.com, the client area, the API at namelessproxy.com/api and the proxy gateway `gw.namelessproxy.com`.

## What does Nameless Proxy store, and for how long?

The four tables below list each type of data our systems keep, grouped by purpose. Read the retention column this way:

- **Until you delete your account** means the data is erased when you delete the account.
- **As long as US accounting and tax law requires** applies to the order, top-up and payout records of ProxyGoat LLC.

### Account and login data

| Data | Why we keep it | How long | Notes |
| --- | --- | --- | --- |
| Account number (16 digits) | It is your login and identifies your account | As long as the account exists; erased when you delete the account | Created by a secure random generator; never derived from your identity |
| Email address (optional) | Sending your account number if you lose it; receipts and reminders you choose | Until you remove it or delete your account | A new email must be verified again. Product-news emails are off by default |
| Password (optional) | Protecting logins | Until you remove it or delete your account | Stored only as an Argon2id hash. Changing it logs out your other sessions |
| Two-factor (TOTP) secret (optional) | Second login factor | Until you delete your account | You can switch 2FA off at any time. The 10 recovery codes are shown to you once |
| Account settings: language, email choices, referral code, status, balance, creation date | Running your account | As long as the account exists; erased when you delete the account | Deleting the account forfeits the remaining balance |
| Login sessions: token hash, device label, start and last-seen times | Listing your active sessions so you can revoke them | Until you log out, revoke the session or it expires; deleting the account revokes all of them. Ended sessions leave your session list, and no login IP is ever stored | No IP address. The device label is coarse, for example `Firefox on Linux` |
| IP address at account creation | Limiting how many accounts one address can create | Only during the rate-limit window; not logged beyond it | Account creation is limited to 5 new accounts per hour per IP |

### Payments and billing

| Data | Why we keep it | How long | Notes |
| --- | --- | --- | --- |
| Orders: plan, quantity, price, chosen country, carrier or city, dates | Delivering what you paid for; accounting; support | As long as US accounting and tax law requires | Kept after account deletion, detached from your email |
| Crypto top-ups: coin, network, deposit address, unique amount, exchange rate, on-chain transaction, confirmations, dates | Crediting each top-up to your prepaid balance | As long as US accounting and tax law requires | Kept after account deletion, detached from your email. Top-ups are transactions on public blockchains, where anyone can look them up |
| Balance ledger: top-ups, purchases, refunds and credits | Showing your balance history; accounting | As long as the account exists; entries tied to orders and top-ups are kept as long as US accounting and tax law requires | Each entry links to its order or top-up |
| Referral-payout details: coin, network, the address you give, the on-chain payout | Sending you the payment | As long as US accounting and tax law requires | Use a separate receiving address if you want to keep payments apart |
| Idempotency keys on orders, top-ups and payouts | Stopping a retried request from charging you twice | 24 hours | Replaying the same key returns the first response instead of a new charge |

### Proxy services and usage

| Data | Why we keep it | How long | Notes |
| --- | --- | --- | --- |
| Residential subscriptions and sub-users: labels, proxy usernames and passwords, traffic caps and counters | Providing and billing the proxies | While the service exists; after it ends, only the order record is kept | Proxy passwords are stored so the client area can show them. Reset one at any time; the old one stops within 60 seconds |
| Mobile ports: country, carrier, city, current IP, rotation settings, proxy credentials | Providing the port | While the port exists; after it ends, only the order record is kept, and the port's IP history ages out after 30 days | The current IP is the carrier's IP, not yours |
| Mobile IP history: carrier IPs assigned to your port, start and end times, what triggered each change | Letting you check past IPs; support | 30 days | Triggers are manual, link, timer, relocation or carrier |
| Usage statistics: bytes and requests per day, per subscription, sub-user or port; top 10 exit countries for residential traffic | Traffic counters, billing and your usage charts | As long as the account exists; erased when you delete the account | Stored as daily totals, not as a request-by-request history |
| API keys: name, prefix, scopes, creation and last-use times | Programmatic access, including the mobile rotation link | Active until you revoke the key; deleting the account revokes all keys. A revoked key stops working at once; keys are stored only as hashes | The full key is shown once; we store only a SHA-256 hash of it |
| IP whitelist: addresses or ranges you add, with labels | Letting those addresses use the proxies without a password | Until you remove the entry or delete the account | These are addresses you choose to give us, such as a server's |
| Gateway connection data: the IP that connects to the gateway, the destination host, byte counts | Authentication, routing, the Acceptable Use blocklist and traffic counting | Your account keeps daily totals only. Gateway operational logs are used only to run the network and handle abuse reports, and are kept no longer than needed for that | Upstream partner networks and carriers may log connection metadata under their own policies |

### Support, referrals and websites

| Data | Why we keep it | How long | Notes |
| --- | --- | --- | --- |
| Support tickets: subject, category, messages, linked order or top-up | Answering you | As long as the account exists; erased when you delete the account | Plain text only. Never send passwords, 2FA codes or private keys |
| Emails to support@ and abuse@ | Answering you; handling abuse reports | As long as needed to answer you and close the case | You can write from any address |
| Referral data: the referral code an account came from, commissions | Paying referral commissions | As long as the referring account exists; commission records as long as US accounting and tax law requires | A referrer sees commissions, never which account was referred |
| Website server logs (namelessproxy.com) | Serving and protecting the website | Only as long as needed to serve and protect the website | The storefront loads no analytics script and sets no tracking cookies |
| Client-area browser storage: session token, interface language, referral code from a link | Keeping you logged in; remembering your language; crediting a referral | Session token: until you log out. Language and referral code: until you clear your browser storage | Kept on your device, not on our servers. No cookies |

## What does Nameless Proxy never collect?

We never ask for the following, and our systems have no field to store it:

- your name, postal address or phone number;
- an ID document, a selfie or company documents;
- card or bank details, because payment is crypto only;
- the IP address you use to log in to the client area.

The account form has no required field at all. You can create an account, pay in crypto and use proxies without giving us your name or any document. That is what we mean by **No KYC — no ID, no selfie, no documents. Pay in crypto.** Read more on [no-KYC proxies](https://namelessproxy.com/no-kyc-proxies/).

## Who else can see data about me?

Some parties outside Nameless Proxy see parts of your activity. We list them so you can plan for it.

- **Upstream partner networks and mobile carriers.** Your traffic exits through established partner networks and carrier networks. They may log connection metadata under their own policies, and we cannot control that.
- **The websites you visit.** They see the proxy's IP address, not yours. They do see whatever your browser or script sends them, such as cookies and logins.
- **Public blockchains.** Every top-up in BTC, USDT, USDC, ETH, SOL, LTC is recorded on a public blockchain. The crypto payments section below explains what that means.
- **No card network or bank.** Top-ups go straight to the deposit addresses shown on the top-up screen.
- **Email providers.** If you save an email, our messages to you pass through email providers.
- **Authorities with a valid legal request.** See the law-enforcement section below.

The storefront runs no advertising or analytics trackers.

## What can the proxy see about my traffic?

For HTTPS sites, the proxy sees the destination host and port, not the content. An HTTP proxy carries HTTPS with the CONNECT method: it opens a tunnel and forwards encrypted bytes it cannot read (RFC 9110). Plain HTTP requests, by contrast, pass through in readable form.

- Use HTTPS targets whenever you can.
- With SOCKS5, the username and password travel in cleartext (RFC 1929). On a network you do not trust, use IP whitelisting instead of a password, and reset proxy passwords you think have leaked.
- The gateway checks each destination against the blocked categories of the [Acceptable Use Policy](https://namelessproxy.com/acceptable-use/) and counts bytes for billing.

The upstream network that carries your request has the same view of host, port and volume. For a wider comparison of proxies, VPNs and Tor, read [proxies for personal privacy](https://namelessproxy.com/use-cases/personal-privacy/).

## What do my crypto payments reveal?

Every coin we accept runs on a public blockchain, so a top-up is visible there like any other transaction:

- **Bitcoin (on-chain only):** every transaction is public and permanent, so anyone can see the history of an address (Bitcoin.org).
- **Ethereum, USDT, USDC, Litecoin and Solana:** these also run on public ledgers. Stablecoins (USDT, USDC) keep a stable dollar value, but their transfers are just as public.

Our top-up records store the on-chain transaction and a block-explorer link. We never ask who you are, so these records point to a random account number, not to a name or a document. To keep proxy payments apart from the rest of your crypto activity, use a separate wallet for top-ups.

## How does Nameless Proxy answer law-enforcement requests?

We can only hand over what we hold, and the tables above are the complete list. We answer valid legal requests from competent authorities under the law that applies to the operator (ProxyGoat LLC, a Delaware limited liability company).

A valid request could reach the following, where it exists for the account concerned:

- the account number, the email if one was saved, and account settings;
- orders and top-ups with their on-chain transactions;
- daily usage totals and the last 30 days of mobile IP history;
- whitelisted IPs, API-key details and support messages.

No request can reach data we never collect: identity documents, selfies, names, phone numbers, card data, or the IP addresses used to log in to the client area. Authorities can send requests to [abuse@namelessproxy.com](mailto:abuse@namelessproxy.com); see [report abuse](https://namelessproxy.com/abuse/).

## Does the website use cookies?

No. The storefront at namelessproxy.com sets no tracking cookies and loads no analytics script. Its one script opens the mobile menu, powers the copy buttons, and passes a referral code or campaign tag (`?ref=`, `utm_`) from the address bar to the checkout links.

The client area uses no cookies either. It keeps your session token, your interface language and, if you arrived through a referral link, the referral code in your browser's local storage. Logging out deletes the session token from the browser. If analytics are ever added, this page will say so before they go live.

## How can I see, change or delete my data?

Most of your data is in the client area, and you control it there:

- **See:** account details, active sessions, orders, top-ups, the balance ledger, daily usage and mobile IP history.
- **Change:** add, change or remove your email; set, change or remove your password; switch 2FA on or off; choose which emails you get.
- **Remove:** log out other sessions, revoke API keys, delete sub-users and remove whitelisted IPs.
- **Delete everything:** delete the account. You re-type the account number, plus your password and 2FA code if they are set.

Account deletion stops every service, forfeits the remaining balance, revokes all sessions and API keys, and deletes your email, password hash and 2FA secret. Order and top-up records stay only as long as accounting law requires, detached from your email. For anything else, write to [support@namelessproxy.com](mailto:support@namelessproxy.com).

## How is my data protected?

We keep little data and store the sensitive parts in a form that cannot be read back:

- Passwords are hashed with Argon2id. API keys are stored as SHA-256 hashes. Session tokens carry at least 256 bits of entropy and are stored only as hashes.
- Login errors never say whether an account number exists, and the recovery form gives the same answer for every email.
- Account numbers come from a cryptographically secure random generator.
- Two-factor authentication (TOTP, 6-digit codes every 30 seconds) is available on every account.

No system is perfectly secure. Use a password manager, switch on 2FA, and keep your account number private.

## Which privacy laws apply?

The operator is ProxyGoat LLC, a Delaware limited liability company, so the law of the United States and of the State of Delaware is the starting point; the privacy laws of your own country may also apply. Whatever the jurisdiction, we follow data minimisation: personal data should be adequate, relevant and limited to what is necessary for the purpose, as GDPR Article 5(1)(c) puts it.

This page is not legal advice about your own duties. If you collect personal data through our proxies, for example while scraping, data-protection law applies to you as well.

## Changes to this policy

We update this page when the data we hold changes. The date at the top shows the current version.

## Privacy questions

### Does Nameless Proxy store my IP address?

Not when you log in to the client area: a session keeps only a coarse device label such as `Firefox on Linux`. Your IP is used briefly to rate-limit account creation and is not logged beyond that window. We do store IPs that you add to the whitelist yourself. The gateway sees the IP that connects to it; its operational logs are used only to run the network and handle abuse reports, and are kept no longer than needed for that.

### Can Nameless Proxy see which websites I visit?

The gateway sees destination hosts while it routes your traffic, because it applies the Acceptable Use blocklist. For HTTPS sites it cannot read the content. Your account stores traffic only as daily totals of bytes and requests, plus the top exit countries for residential traffic. Upstream partner networks may log connection metadata under their own policies.

### Do I have to give Nameless Proxy an email address?

No. An account needs nothing but its random 16-digit number. An email adds two things: recovery of a lost account number, and the messages you choose, such as payment receipts and expiry reminders. Product-news emails are off by default. You can remove the email at any time, and deleting the account erases it.

### What happens to my data when I delete my account?

Deletion stops every service, forfeits the remaining balance, revokes all sessions and API keys, and erases your email, password hash and 2FA secret. Order and top-up records are kept only as long as accounting law requires, detached from your email. Mobile IP history ages out after 30 days. Other records follow the periods in the tables above.

### Can other people see my crypto top-ups?

Yes, on the blockchain. Every coin we accept (BTC, USDT, USDC, ETH, SOL, LTC) runs on a public ledger, so anyone can look up a top-up transaction, and stablecoins are no exception. Our own record holds the amount, the coin and the on-chain transaction, linked to a random account number, not to a name or a document. A separate wallet for top-ups keeps proxy payments apart from your other activity.

### Can the person who referred me see my account?

No. A referrer sees one commission line per paid order of the accounts they referred, with the order total and product, but never which account placed it. Your account number, email, usage and proxy details are not shown to them. The referral code you arrived with is stored on your account so that the commission can be paid.

## Sources

1. [Some things you need to know (Bitcoin transactions are public)](https://bitcoin.org/en/you-need-to-know) — Bitcoin.org (2026-10-05)
2. [RFC 9110, HTTP Semantics, section 9.3.6 CONNECT](https://www.rfc-editor.org/rfc/rfc9110#name-connect) — RFC Editor (2026-10-05)
3. [RFC 1929, Username/Password Authentication for SOCKS V5](https://www.rfc-editor.org/rfc/rfc1929) — RFC Editor (2026-10-05)
4. [GDPR Article 5, Principles relating to processing of personal data](https://gdpr-info.eu/art-5-gdpr/) — gdpr-info.eu (2026-10-05)

**Privacy-first proxies, paid in crypto** No KYC — no ID, no selfie, no documents. Residential proxies from $0.53/GB, with a login that is just a number. [Get residential proxies — from $0.53/GB](https://namelessproxy.com/pricing/) · [Pay with crypto](https://namelessproxy.com/crypto-proxies/)

---

Nameless Proxy: Nameless Proxy is a privacy-first, no-KYC proxy provider: rotating residential and 4G/5G mobile proxies, account-number login, and payment in crypto (Bitcoin, USDT, USDC). Residential from $0.53/GB.
