Proxly

Privacy Policy

Effective date: 30 May 2026 · Last updated: 30 May 2026

This policy describes what data the Proxly Android app (com.shafayat.proxly) processes on your device, what it sends off your device, and the choices you have. Proxly is developed and operated by Shafayat Hossain Khan ("we", "us"). If anything here is unclear, email shafayathossainkhan@gmail.com.

The short version

1. What Proxly is, technically

Proxly uses Android's VpnService API to capture your device's network traffic into a local TUN interface. The traffic is processed on your device — by a native networking layer and a local TLS termination ("man-in-the-middle") engine — to show you connections, hostnames, and the contents of HTTPS sessions you have explicitly chosen to inspect.

Proxly is not a privacy VPN. It does not route your traffic through a remote server, and it does not hide your IP address. All inspection happens on the device itself.

2. What stays on your device

The following are read or generated locally and are never transmitted to us or to any third party by Proxly:

Uninstalling the app removes this data. Android's standard "Clear data" action in the app's settings also clears it.

3. What we send off your device

3.1 Firebase Analytics

Proxly uses Google Firebase Analytics to understand how the app is used so we can prioritise fixes and features. Each event we send is a short name and a small bag of parameters. The events we currently send include: app screens viewed, the VPN/firewall being toggled, the time-range and data-source filter you choose on the Apps screen, the onboarding steps you complete, and similar interaction counts.

Firebase automatically attaches a pseudonymous instance identifier (the Firebase Installation ID), your device's coarse country (derived from your IP address, which is then discarded for analytics purposes), the device model, and the operating system version. We do not collect your name, your phone number, your email address, your precise location, or your IP address for analytics purposes.

3.2 Firebase Crashlytics

When Proxly crashes or hits a non-fatal error, Crashlytics sends a stack trace along with the device model and OS version so we can reproduce and fix the issue. Crash reports do not contain captured traffic, intercepted bodies, blocked domains, or the list of apps on your device.

3.3 Blocked-domain telemetry (opt-in)

If — and only if — you turn on the Help improve Proxly's blocklists toggle in Settings, the app sends two extra fields with the blocked domain added, blocked domain removed, and domain blocked at runtime events: the domain string you blocked and the package name of the app you blocked it from. We use this aggregate data to design better default blocklists.

This setting is off by default. Turning it off stops the domain and package fields from being attached to any future event. Past events already sent cannot be unsent; you can request deletion using the contact details below.

4. Third-party services we rely on

We do not sell or rent your personal data to anyone, and we do not share it with advertisers.

5. How long we keep data

6. Your rights

Depending on where you live, you may have the right to access, correct, port, or delete the data tied to your install, and to withdraw consent where we relied on it. To exercise any of these rights, email shafayathossainkhan@gmail.com with "Proxly privacy request" in the subject. We will respond within 30 days.

EU / UK users (GDPR): our legal basis for general usage and crash analytics is our legitimate interest in operating and improving the app. Our legal basis for the optional blocked-domain telemetry is your explicit consent, which you can withdraw at any time in Settings.

California users (CCPA / CPRA): we do not sell or share personal information as those terms are defined under California law. You have the right to know what personal information we have and the right to request its deletion.

7. Children

Proxly is not directed at children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect data from children. If you believe a child has used the app, contact us and we will delete any associated data.

8. Security

Captured flows, stored bodies, and the Proxly root key live in the app's private storage, which Android protects from other apps on the device. Data sent to Firebase is transmitted over TLS. No system is perfectly secure, but we apply the standard protections expected of an Android app handling sensitive on-device data.

9. Changes to this policy

If we make a material change, we will update the "Last updated" date at the top of this page and, where the change concerns a new data collection, surface a notice in the app before the change takes effect.

10. Contact

Shafayat Hossain Khan
shafayathossainkhan@gmail.com