Privacy Policy
What RyoProxy collects, why, how long it is kept, and the rights you have over it.
Legal documents are published in English only. Translations elsewhere on this site are provided for convenience; the English text governs.
1. Scope
This policy explains what RyoProxy collects when you use this website and the operator dashboard, and how that data is handled. It does not cover the traffic that passes through routers you operate β that infrastructure is under your control.
2. Data we collect
- Account data: email address, password hash, role, and β if you link one β your Telegram account identifier.
- Session data: access and refresh tokens stored in HttpOnly cookies, session records, and the IP address used to sign in.
- Operational data: agent identifiers, router configuration state, PPPoE interface names, proxy port assignments, WireGuard peer metadata and IP-check results.
- Security data: failed authentication attempts and blocked IP addresses, kept to enforce graduated blocking.
- Support data: anything you send us on Telegram.
3. What we do not collect
We do not record the contents of traffic routed through your proxies, tunnels or VPN peers. The control plane stores configuration and status, not payloads.
4. Purpose and legal basis
- Performing the contract: operating your account, agents and infrastructure.
- Legitimate interest: protecting the platform against abuse, credential stuffing and automated attacks.
- Legal obligation: retaining billing records where the law requires it.
5. Retention
- IP observation and verdict history: 90 days, then deleted automatically.
- Expired tokens and revoked sessions: removed by a scheduled cleanup service.
- Account and billing records: kept while the account is active and for as long as tax or accounting rules require afterwards.
6. Sharing
We do not sell personal data. Data is shared only with the processors needed to run the service β hosting, payment processing and the reputation providers used by IP checking β and only to the extent required for those functions.
7. Security
- Router and proxy credentials are encrypted at rest.
- Authentication uses short-lived JWT access tokens with refresh tokens in HttpOnly cookies, protected by CSRF tokens and a CORS allowlist.
- Repeated failed attempts trigger graduated IP blocking.
- Agents connect outbound only; routers are never required to expose an inbound management port to the internet.
8. Your rights
You may request access, correction, export or deletion of your personal data, and you may revoke any active session yourself from the dashboard. Reach us on Telegram at @RyoProxy_Support and we will respond within 30 days.
9. Self-hosted deployments
If you run the platform on your own infrastructure, you are the data controller for everything it stores. This policy then describes only the data handled by this website and by any support channel you use.
10. Changes
Material changes are published on this page with a new revision date. Continuing to use the service after that date means you accept the revised policy.