Legal
Privacy Policy
Last updated: 2026-08-24
1. Who we are
Basil Proxies is operated by Basil Solutions, ul. Popiełuszki 13, 20-052 Lublin, Poland (VAT 9461073473). For GDPR purposes, we're the data controller for the personal data described here.
2. What we collect
- Account info — name, email, and a hashed password (never stored in plain text).
- Discord info, if you connect it — your Discord user ID, username, and avatar.
- Preferences — language, timezone, and currency.
- A country, inferred from your signup IP — we don't store anything more precise than that.
- Usage totals — how much bandwidth you've used, by product, as periodic snapshots.
- Connection records on part of our residential network — for each request, the domain you connected to, how much data it used, how long it took, and whether it succeeded. You can see this yourself on the statistics page in your dashboard; we use it for support and for handling abuse reports. We never store the content of your traffic, and our other proxy products don't record destinations at all.
- Payment identifiers — Stripe handles your card and billing address directly; we keep only what's needed to match a payment to your account.
- Security records — the IP address used at signup, login, and sensitive actions like enabling two-factor authentication, so we can flag unfamiliar logins to you.
4. How we use it
To run your account and deliver the service, process payments and issue tax-compliant invoices, keep your account secure, credit referrals correctly, and email you about your account or orders.
6. How long we keep it
We keep your account data for as long as your account is active. We don't currently run an automatic deletion schedule for historical activity or login records — if you close your account and want us to delete what we hold, email us and we'll do it by hand. Invoicing records are kept as long as Polish tax law requires.
The connection records described above sit with the network partner that operates that pool, not in our own database, and we can only query roughly the last 30 days of them.
7. Your rights
Under GDPR, you can ask us to show you what we hold on you, correct anything that's wrong, delete your data, or export it in a portable format. Email [email protected] — we don't have automatic self-service for this yet, so a real person handles it directly.
8. Security
We encrypt sensitive credentials, like two-factor recovery codes and proxy keys, at rest, and passwords are always stored as a hash, never in plain text. No system is perfectly secure, but we take reasonable steps to protect what we hold.
9. Children
The Service isn't for anyone under 18. We don't knowingly collect data from anyone under that age.
10. Changes to this policy
We may update this policy from time to time. Changes take effect when we post the new version here with an updated date above.
11. Contact
Questions about this policy or your data: [email protected].