Why this document is strict
Many of our exits are real people's internet connections, shared with consent and for compensation. When traffic through those addresses causes harm, the harm lands on a household, on an upstream network partner, and on every other customer whose success rate depends on the pool staying clean. So this policy is not boilerplate, and it is enforced the way it is written. We vet customers before granting credentials, we monitor connection metadata for abuse patterns, and we terminate for violations without a second warning where the line crossed is a bright one.
If your use case sits anywhere near an edge described here, ask us before you buy. You will get a straight answer, and "no" is one of the answers we give.
Prohibited uses
The following may never run through the network. This list is illustrative, not exhaustive; conduct of the same character is treated the same way.
- Unauthorized access and account abuse. Credential stuffing, credential testing, account takeover, brute-force attacks, session hijacking, and access to any system or account you are not authorized to use. Managing accounts you own or operate with the owner's authorization is fine; testing other people's logins is not, in any quantity, for any reason.
- Fraud. Payment and card fraud, chargeback abuse, affiliate fraud, click and impression fraud, fake account creation, review and engagement manipulation, identity fraud, and evasion of anti-fraud controls. This includes automated purchasing designed to evade per-customer limits for resale.
- Attacks on availability. Denial of service in any form, load testing systems you do not own or lack written authorization to test, and any traffic pattern whose purpose is to degrade a service rather than read from it.
- Security probing of third parties. Port scanning, vulnerability scanning, exploit delivery and penetration testing against systems you do not own, unless you hold written authorization from the system owner and have cleared the engagement with us first.
- Malware and phishing. Distribution of malicious software, command-and-control traffic, phishing pages and lures, and infrastructure for any of these.
- Child sexual abuse material. Zero tolerance. Accessing, distributing or facilitating CSAM results in immediate termination and a report to the competent authorities. This is the one category where we do not wait for certainty before acting.
- Targeting individuals. Stalking, harassment, doxxing, and surveillance of private individuals. Collecting public business information is a use case; following a person is not.
- Spam. Sending unsolicited bulk messages of any kind, email, DMs, comments, form submissions, or creating accounts and infrastructure whose purpose is to send them.
- Sanctions and export violations. Use by or for the benefit of sanctioned parties, or in violation of applicable export controls.
- Anything illegal in the jurisdiction the traffic originates from, exits in, or targets.
Rules for data collection
Most of our customers collect data from the web, and this policy is written to keep exactly that use case sustainable. The rules:
- Collect what is public. Scraping publicly accessible pages is the intended use of this network. Circumventing authentication to reach data that requires an account you were not granted is not collection, it is intrusion, and it falls under prohibited uses above.
- Keep sources alive. Pace your collection so the source does not feel it. Traffic that materially degrades a target's service is treated as an attack on availability regardless of intent, and "we needed the data faster" is not a defense we accept.
- Own your legal basis for personal data. If what you collect includes personal data, the obligations of GDPR and equivalent laws sit with you as the party determining purpose and means. We will not assess your compliance for you, and we will act on credible complaints that you have none.
- Honor your own contracts. If you are bound by a target's terms through an account or agreement, routing around your own obligations through our exits does not launder them. That dispute is yours; do not make it the pool's.
Network rules
- Outbound SMTP on port 25 is blocked network-wide, permanently. It has no legitimate use through residential exits and one abusive use that burns them. Transactional mail belongs on your mail provider, not on a proxy.
- Exits are for outbound requests. Hosting services, accepting inbound connections, or maintaining long-lived tunnels through an exit is not permitted.
- Reselling or sharing access requires our written agreement first. We vet the customers on our network; anonymous sublease defeats the control that keeps the pool usable.
Enforcement
We monitor connection metadata, timestamps, bytes, destination hosts, exit assignments, for patterns of abuse. We do not inspect the content of your traffic and cannot see inside TLS. Enforcement decisions come from metadata, complaints and blocklist signals.
Bright-line violations, the fraud, attack, CSAM and spam categories above, end the account immediately, without refund of traffic already consumed and with unused purchased traffic refunded only where the law requires it. Ambiguous cases get a human conversation first: a named contact, the pattern we saw, and a chance to explain or fix it. We honor valid legal process, and we cooperate with upstream partners' abuse procedures because their trust is part of what you are buying.
Reporting abuse
If you believe our network was used against you, report it through the contact form under "Abuse report" with the IP address, a timestamp with timezone, and whatever evidence you can share. A human reads every report, acknowledges within one business day, and tells you the outcome where the law lets us.
Changes
We update this policy as the abuse landscape changes. Material changes are announced to account holders by email before they take effect. The version on this page is the one in force.