This policy describes what data the Proxly Android app
(com.shafayat.proxly) processes on your device, what it sends
off your device, and the choices you have. Proxly is developed and operated
by Shafayat Hossain Khan ("we", "us"). If anything here is unclear, email
shafayathossainkhan@gmail.com.
Proxly uses Android's VpnService API to capture your device's
network traffic into a local TUN interface. The traffic is processed on
your device — by a native networking layer and a local TLS termination
("man-in-the-middle") engine — to show you connections, hostnames, and the
contents of HTTPS sessions you have explicitly chosen to inspect.
Proxly is not a privacy VPN. It does not route your traffic through a remote server, and it does not hide your IP address. All inspection happens on the device itself.
The following are read or generated locally and are never transmitted to us or to any third party by Proxly:
PackageManager, used to display the per-app usage and firewall screens.NetworkStatsManager (granted by the Usage access permission you approved).Proxly uses Google Firebase Analytics to understand how the app is used so we can prioritise fixes and features. Each event we send is a short name and a small bag of parameters. The events we currently send include: app screens viewed, the VPN/firewall being toggled, the time-range and data-source filter you choose on the Apps screen, the onboarding steps you complete, and similar interaction counts.
Firebase automatically attaches a pseudonymous instance identifier (the Firebase Installation ID), your device's coarse country (derived from your IP address, which is then discarded for analytics purposes), the device model, and the operating system version. We do not collect your name, your phone number, your email address, your precise location, or your IP address for analytics purposes.
When Proxly crashes or hits a non-fatal error, Crashlytics sends a stack trace along with the device model and OS version so we can reproduce and fix the issue. Crash reports do not contain captured traffic, intercepted bodies, blocked domains, or the list of apps on your device.
If — and only if — you turn on the Help improve Proxly's blocklists toggle in Settings, the app sends two extra fields with the blocked domain added, blocked domain removed, and domain blocked at runtime events: the domain string you blocked and the package name of the app you blocked it from. We use this aggregate data to design better default blocklists.
This setting is off by default. Turning it off stops the domain and package fields from being attached to any future event. Past events already sent cannot be unsent; you can request deletion using the contact details below.
We do not sell or rent your personal data to anyone, and we do not share it with advertisers.
Depending on where you live, you may have the right to access, correct, port, or delete the data tied to your install, and to withdraw consent where we relied on it. To exercise any of these rights, email shafayathossainkhan@gmail.com with "Proxly privacy request" in the subject. We will respond within 30 days.
EU / UK users (GDPR): our legal basis for general usage and crash analytics is our legitimate interest in operating and improving the app. Our legal basis for the optional blocked-domain telemetry is your explicit consent, which you can withdraw at any time in Settings.
California users (CCPA / CPRA): we do not sell or share personal information as those terms are defined under California law. You have the right to know what personal information we have and the right to request its deletion.
Proxly is not directed at children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect data from children. If you believe a child has used the app, contact us and we will delete any associated data.
Captured flows, stored bodies, and the Proxly root key live in the app's private storage, which Android protects from other apps on the device. Data sent to Firebase is transmitted over TLS. No system is perfectly secure, but we apply the standard protections expected of an Android app handling sensitive on-device data.
If we make a material change, we will update the "Last updated" date at the top of this page and, where the change concerns a new data collection, surface a notice in the app before the change takes effect.
Shafayat Hossain Khan
shafayathossainkhan@gmail.com