Privacy Policy

twinsproxy.com and the Twins Proxy service (together, the "Service") are owned and operated by Techies365 LLC, 30 N Gould St, Sheridan, WY 82801, USA. Techies365 LLC can be contacted at [email protected].

1. Purpose

The purpose of this Privacy Policy is to inform users of the Service of: (1) the personal data we collect; (2) how we use it; (3) who has access to it; (4) how long we keep it; and (5) the rights you have over it. This policy applies in addition to our Terms of Service. By using the Service you consent to the collection, use, and retention of data as described here. We collect as little as we can, and we never sell personal data.

2. Personal data we collect

We only collect data that helps us operate the Service. We will not collect additional data beyond what is listed below without notifying you first.

Account information. Your first and last name, email address, workspace name, and a cryptographic hash of your password (we never store the password itself). If you enable two-factor authentication, we store your TOTP secret encrypted at rest; if you add a passkey, we store only its public key — the private key never leaves your device.

Billing information. Payments are processed by Stripe. We store your Stripe customer and subscription identifiers, your plan, and your add-ons; your card number never touches our servers. Stripe's own privacy policy applies to payment data.

Service configuration. The domains, origins, nodes, and DNS provider credentials you configure. DNS provider API tokens and similar secrets are encrypted with AES-256-GCM before storage and are decrypted only to perform the DNS operations you have authorized.

Usage and security data. Sign-in events and security-relevant actions (with the acting user, IP address, and timestamp), per-domain traffic counters (request counts and bytes transferred) used for plan metering, and standard server logs.

Traffic through your masked domains. The Service proxies requests from your visitors to your configured origin. We record aggregate counts and bytes for metering; we do not build profiles of your visitors, and we do not sell or share visitor data.

Abuse reports. If someone files a report at /abuse, we collect the reporter's name, email address, the reported domain, their description, and any evidence attachment they provide, solely to investigate the complaint.

3. How we use personal data

We use the data above only to operate the Service: provisioning domains and certificates, routing traffic, metering plans, billing, preventing abuse and fraud (including bot checks at signup), account notifications (email verification, password reset, renewal reminders, security notices), support, and keeping the Service secure. We do not use your data for advertising, and we will not use it beyond what this policy discloses.

4. Who we share personal data with

Within our organization. Data is accessible only to members of our team who reasonably need it to operate the Service or handle your requests.

Service providers. We share data with the third parties we rely on to run the Service, each receiving only what it needs for its purpose:

Stripe — payment processing (name, email, payment details you enter on Stripe's pages).
Certificate authorities (Let's Encrypt, and optionally ZeroSSL or Google Trust Services) — certificate issuance; your domain names appear in public Certificate Transparency logs, which is inherent to publicly trusted HTTPS certificates.
Cloudflare — network delivery, bot protection (Turnstile), and — if you connect it — DNS automation.
Your DNS provider (Cloudflare, Route 53, GoDaddy, DigitalOcean) — only when you connect one, and only the record operations you authorize.
Our email delivery provider — transactional email (your address and the message content).
Google Safe Browsing — abuse screening. We submit the domain names you add and the origin URLs you configure so they can be checked against Google's malware and phishing lists. We do not send visitor traffic, request contents, or personal data.
Our hosting providers — the infrastructure the Service runs on.

Other disclosures. We will not sell or otherwise share your data with third parties, except: if the law requires it; if it is required for a legal proceeding; to prove or protect our legal rights; or to a buyer or prospective buyer of the company in the event of a sale, merger, or similar transaction (in which case this policy continues to apply to your data). If you follow links from the Service to other sites, their privacy practices are their own — we have no control over them.

5. How long we store personal data

Account data is kept while your account is active. Beyond that, we delete automatically on a schedule:

Audit events (including IP address and browser user-agent) — 12 months.
Provisioning and diagnostic events — 90 days.
Traffic totals used for billing — 24 months.
Expired sessions — 7 days after expiry.
Password-reset, email-verification, and two-factor codes — 24 hours after expiry.
Abuse report attachments — 90 days after the report is closed; the report itself, 24 months.

Deleting your account. You can delete your workspace yourself from Settings. Your domains stop serving immediately and your DNS provider credentials are destroyed at once; the remaining data is permanently deleted after 30 days, and you can cancel during that window. Cancelling restores your account and data, but not the domains, which you would need to add again.

After deletion we keep one record of the workspace name, plan, and payment-provider identifiers, with your email address stored only as an irreversible hash — this is the legal, billing, and tax exception noted below, and it is what lets us answer a tax or legal enquiry without retaining your personal data. Invoices themselves are held by our payment provider. Domain names in public Certificate Transparency logs cannot be removed by anyone, including us.

6. How we protect personal data

All traffic to the Service is encrypted in transit with TLS. Secrets are hashed (passwords, session tokens, API keys) or encrypted at rest with AES-256-GCM (DNS credentials, TOTP secrets). Access to production systems is restricted, and destructive administrator actions require fresh two-factor verification. While we take all reasonable precautions, no Internet service can guarantee absolute security; if we learn of a breach affecting your personal data, we will notify you without undue delay.

7. International data transfers

The Service is operated from infrastructure in the United States and Europe, and personal data is processed in the United States. Where we transfer personal data internationally, we protect it as described in this policy and comply with applicable legal requirements for international transfers, including using appropriate safeguards for data originating in the EEA, UK, and Switzerland.

8. Your rights

You can access and update your profile in the dashboard, export your configuration via the API, and delete credentials, domains, or your entire account at any time. In addition, and depending on where you live, you have the right to: access the personal data we hold about you; have it corrected or deleted; receive it in a portable format; restrict or object to certain processing; and withdraw consent where processing is based on consent. If you are in the EEA, UK, or Switzerland, we process your data on the legal bases of contract performance (operating the Service you signed up for), legitimate interests (security, abuse prevention), and legal obligation (billing and tax records), and you also have the right to lodge a complaint with your local supervisory authority.

If you are a California resident, you additionally have the rights provided by the CCPA/CPRA, including the rights to know, delete, and correct; we do not sell or "share" personal information as those terms are defined in the CCPA, and we do not discriminate against you for exercising your rights.

Exporting your data. You can download a copy of your workspace at any time from Settings — it includes your profile, workspace, domains, origins, traffic totals, and activity log. For your safety it does not include secrets: DNS provider credentials, your two-factor secret, and certificate private keys stay encrypted and are exported only through their own dedicated, individually confirmed paths.

To exercise any of these rights, or to ask what data we hold about you, contact us at [email protected]. We respond within 30 days.

9. Cookies

We use a single, strictly necessary session cookie (twp_session) to keep you signed in, plus a local-storage preference for your theme. No advertising or cross-site tracking cookies, and no third-party analytics scripts.

10. Do Not Track

We do not track users across third-party websites, so there is nothing for a Do Not Track signal to disable — the Service behaves the same either way. We cannot control how third parties you reach through the Service respond to DNT signals.

11. Children

The Service is not directed at children, and we do not knowingly collect personal data from anyone under 16 years of age. If we learn that we have, we will delete it as soon as possible; a parent or guardian may contact us at the address below.

12. Modifications

We may amend this Privacy Policy to maintain compliance with the law and to reflect changes to the Service. When we do, we will update the "Last updated" date above, and for material changes we will notify you by email or in the dashboard before they take effect. We recommend reviewing this policy periodically.

13. Contact

For questions, concerns, or complaints about privacy, or to request access to or deletion of your data, contact us at [email protected] or by mail at:

Techies365 LLC (d/b/a Twins Proxy)
30 N Gould St
Sheridan, WY 82801, USA