Privacy Policy
Effective August 27, 2026
This Privacy Policy describes the information Masklabs US LLC ("Masklabs," "we," "us," "our") collects when you use our website, dashboard, API, and proxy network (the "Services"), why we collect it, and how we use it. It forms part of our Terms of Service. Masklabs operates the Services from the United States, and we and our service providers process your information primarily in the United States. Some providers, including our payment processors, process limited information in other countries, as described in Section 8.
1. Information We Collect
1.1 Account information. Upon registration, we collect your name, email address, and a hashed password.
1.2 Organization data. We record the Organizations to which you belong, your role in each (owner, admin, or member), and the invitations you send or receive.
1.3 Usage and bandwidth records. For each Credential created by your Organization, we record the quantity of bandwidth consumed and the time of consumption, to meter your usage accurately and present your usage history.
1.4 Payment metadata. When you pay for the Services, our payment processors handle your payment details directly. Stripe processes card payments, and Cryptomus processes cryptocurrency payments. We receive and store only payment metadata: the amount, the currency, a timestamp, a processor-issued reference, and, where we bill you by invoice, the invoice record. We do not receive or store your full card number, CVV, or bank account number.
For a cryptocurrency payment, the processor reports the paying wallet address, the transaction hash, and the network to us in order to confirm the payment. We do not store the paying wallet address or the transaction hash. They remain with the payment processor. The transaction itself is recorded on a public blockchain, where it is permanent and neither you nor Masklabs can remove it.
1.5 Support communications. If you contact us by email or otherwise, we retain a record of the correspondence to assist you and maintain a support history.
1.6 Technical and log data. We retain standard web and server logs for the dashboard and API, such as IP address, user agent, and request timestamps, for security, diagnostics, and abuse prevention.
1.7 Identity verification. Where identity or payment verification, commonly called "know your customer" or KYC, is required, our payment providers perform it under their own terms and privacy policies. Masklabs does not collect or store government identification documents. Information you provide for verification is held by the provider that collected it.
2. Your Proxied Traffic
Usage is metered by the volume of data transmitted through each Credential. Masklabs does not inspect, log, or retain the content of traffic routed through the Services. Usage records are limited to the quantity of bandwidth consumed and the time of consumption.
3. How We Use Information
We use the information described above to:
- Operate and bill the Services, which includes metering your usage and processing your payments
- Authenticate you and secure your account
- Send transactional email, such as receipts, security alerts, password resets, and service notices
- Respond to your support requests
- Detect and prevent fraud, abuse, and Acceptable Use Policy violations
- Comply with our legal obligations and enforce our agreements
- Maintain and improve the Services
We do not use your account information for advertising, and we do not sell it. We may create and use aggregated or de-identified information, which does not identify you, to operate and improve the Services. We do not attempt to re-identify de-identified information, except to test that it cannot be re-identified.
4. Cookies and Similar Technologies
We use two kinds of cookies. We do not use advertising cookies, and we do not sell or share your information.
4.1 Essential. Always active. They sign you in, protect against automated abuse, remember your choice under Section 4.3, and store display preferences.
4.2 Non-essential. Analytics, described in Section 5. Served from our own domain rather than a third-party tracking domain.
4.3 Your choice. In the European Economic Area and the United Kingdom, non-essential cookies stay off until you accept them. Elsewhere they are on and you can switch them off. The Cookie settings link in the footer changes your choice at any time.
5. Analytics and Error Diagnostics
We use PostHog to see how the Services are used and to find defects: page views, feature usage, device and browser type, an approximate location from your IP address, and recordings of how our pages are used. After you sign in this is tied to your account and Organization. Form fields, including passwords and proxy credentials, are masked in your browser and never reach us. Processing is in PostHog's United States region. None of it happens if you decline.
We also collect crash reports, from our own infrastructure and from PostHog. A report may include a stack trace, request metadata, and sometimes an account identifier, never payment card data or the content of proxied traffic. Reports from our own infrastructure are part of running the Services securely and are not covered by the choice in Section 4.3.
6. How We Protect Information
We maintain reasonable administrative, technical, and organizational measures designed to protect the information we hold against unauthorized access, loss, and misuse. No method of transmission or storage is entirely secure, and we therefore cannot guarantee absolute security.
7. Data Retention
We retain account, Organization, billing, and usage records for as long as your account is active, and thereafter for as long as necessary to meet accounting, tax, and legal obligations. Sign-in sessions and email verification tokens are retained only while valid and are removed once they expire. When you request deletion of your account (see Section 9), we delete or anonymize what we can while retaining the records we are legally required to keep, such as transaction records for tax purposes.
8. Sharing and Third Parties
We do not sell your personal information. We share it only with the service providers that help us operate Masklabs, each bound to use it solely for that purpose:
- Stripe and Cryptomus (operated by Xeltox Enterprises Ltd), for payment processing and related identity verification
- PostHog, for product analytics and error diagnostics
- AI service providers, for analyzing usage and supporting the Services. These providers may process account and usage data on our behalf and do not use it to train their models.
- Our infrastructure and hosting providers
- The mobile network operators that supply the IP addresses through which you connect
We may also disclose information where required by law, in response to a subpoena or other legal process, or to protect the rights, property, or safety of Masklabs, our customers, or the public, or to enforce our Terms of Service and Acceptable Use Policy. In connection with a merger, acquisition, or sale of assets, information may be transferred as part of that transaction and will remain subject to this Policy.
9. Your Choices and Rights
You may accept or decline non-essential cookies at any time using the Cookie settings link in the site footer, as described in Section 4.3.
You may delete your account at any time from your account settings in the dashboard. You may also access, correct, or request deletion of your personal information by writing to [email protected]. We will verify that you are the account holder and will respond within 45 days. Deleting your account ends your access to the dashboard and to your proxy Credentials; as noted in Section 7, we retain certain records where the law requires it.
We will not discriminate against you for exercising any of these rights. We will not deny you the Services, charge you a different price, or provide you a different level or quality of service because you made a privacy request.
10. Your California Privacy Rights
If you are a California resident, the California Consumer Privacy Act, as amended (the "CCPA"), gives you specific rights regarding your personal information. This Section supplements the rest of this Policy.
Categories we collect. In the preceding twelve months we have collected the following categories of personal information: identifiers, such as your name, email address, and account or Credential identifiers; commercial information, such as the plans and data you have purchased and your usage history; internet and network activity, such as the technical and log data described in Section 1.6 and the analytics described in Section 5; and payment metadata, described in Section 1.4. We do not collect the content of your proxied traffic, as stated in Section 2.
Sources. We collect this information from you directly, from your use of the Services, and from our payment processors.
Purposes. We use each category for the business purposes described in Section 3, such as operating and billing the Services, securing accounts, providing support, preventing fraud and abuse, and complying with law.
Disclosures. We disclose personal information to the service providers described in Section 8 for those business purposes. We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA.
Sensitive personal information. We do not use or disclose sensitive personal information for purposes that would give you a right to limit that use.
Your rights. Subject to the exceptions the CCPA provides, you have the right to know the categories and specific pieces of personal information we have collected about you, to request that we delete personal information we collected from you, to correct inaccurate personal information, and not to receive discriminatory treatment for exercising any of these rights.
How to exercise your rights. Submit a request by writing to [email protected], or use the account controls in the dashboard. We will verify that you are the person to whom the personal information relates, or an authorized agent acting on that person's behalf, and will respond within the time the CCPA allows. An authorized agent may submit a request on your behalf with your written permission and proof of their authority.
11. Children
The Services are not directed to anyone under 18, and we do not knowingly collect information from anyone under 18. If we learn that we have done so, we will delete it.
12. Changes to This Policy
We may update this Privacy Policy. Where a change is material, we will post the updated policy with a new effective date and, where the law requires, notify you by email.
13. Contact
Questions regarding this Policy or your data may be directed to [email protected], or by mail to:
Masklabs US LLC 1309 Coffeen Ave STE 1200 Sheridan, WY 82801