Privacy Policy
Effective 1 January 2026
What NullVault collects, why, how long it is kept, and what you can ask us to do about it.
1. Who is responsible
NullVault is the data controller for the information described here. Contact for any privacy question or request.
2. What we collect
| Data | Why | Basis |
|---|---|---|
| Email address, display name | Account identity, service notices, password reset | Contract |
| Password hash (argon2id) | Authentication | Contract |
| Google account ID and verified email, if you use Google sign in | Authentication | Contract |
| Wallet ledger, orders, invoices | Billing, accounting, dispute handling | Contract, legal obligation |
| IP address, user agent, request metadata | Rate limiting, fraud and abuse prevention, security audit log | Legitimate interest |
| Proxy generation parameters (country, protocol, session mode, counts) | Support, abuse investigation, capacity planning | Legitimate interest |
What we do not collect
- Card numbers. Payments are handled entirely on the payment provider's hosted checkout. We receive a payment reference, an amount and a status, never the instrument.
- The content of your proxied traffic. It does not pass through this platform. Traffic is carried on the proxy network itself, and this application never sees it.
- No third party analytics product measures how you use the site.
- Visitor counting. We count how many distinct people load the site each day, on our own server. No script runs in your browser and no cookie is set for it. Your IP address and browser string are combined with a secret and the current date into a one way hash, which is added to a probabilistic counter and then discarded. The counter stores a fixed amount of data regardless of how many people visit, and the original values cannot be recovered from it. Because the date forms part of the hash, the same visitor produces a different value tomorrow, so nothing can be followed from one day to the next. We see totals and nothing else, there is no list of visitors, and no way to build one.
3. Cookies
We set one cookie of our own: a session cookie holding an opaque token, so you stay signed in. It is HttpOnly, Secure, SameSite=Lax and expires after 30 days. It is strictly necessary for the service to function.
Advertising. We run the Google Ads tag so we can tell which adverts lead to a purchase. It sets Google cookies in your browser and sends Google your IP address, the pages you open here and, where one is present, the click identifier from the advert you arrived through. It is measurement for our advertising and it is not necessary for the service to work. If you would rather not be counted, block googletagmanager.com in your browser or use any content blocker, and the site will work exactly as it does now.
Cloudflare Turnstile sets its own short lived storage to run the bot challenge. NOWPayments sets cookies on its own checkout pages, under its policy, not ours.
4. Who we share it with
We use these processors, and only for the purposes listed:
- Our network infrastructure partner, receives provisioning requests so a pool can be allocated to your order. It does not receive your identity: requests carry an internal order reference and nothing that identifies you.
- NOWPayments, cryptocurrency payments. Receives an order reference and an amount, not your identity.
- Cloudflare. CDN, DDoS protection and Turnstile. Sees request metadata including your IP.
- Google, for sign in if you choose it, and for advertising measurement through the Google Ads tag described above.
- Our email provider, delivers password reset messages.
We do not sell personal data, and we do not share it for anyone else's marketing.
We will disclose data where legally compelled. Where we are permitted to tell you, we will.
5. International transfers
Our processors operate globally, so your data may be processed outside your country. Where required, transfers rely on Standard Contractual Clauses or an adequacy decision. Ask us for the current list of subprocessors and their locations.
6. How long we keep it
- Account and billing records, for the life of the account, then as long as tax and accounting law requires (typically 6 to 7 years).
- Security audit log, 12 months.
- Expired sessions and reset tokens, purged 7 days after expiry.
- Generation parameters, 12 months.
7. How it is protected
- Passwords are hashed with argon2id and are not recoverable.
- Session tokens are stored only as hashes; the plaintext exists only in your cookie.
- Proxy credentials and API key secrets are encrypted at rest with AES-256-GCM under a key held separately from the database.
- All traffic is TLS encrypted end to end.
- Access to production data is limited to administrators and is audit logged.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing, to data portability, and to withdraw consent. Email and we will respond within 30 days.
Deleting your account removes your profile, services and credentials. Billing records are retained where the law requires it, reduced to the minimum needed.
9. Use of AI
This website was built with AI assistance. Parts of the site's code, its interface copy and its documentation were written with the help of a large language model, reviewed by a human before release. We are telling you because it is true and because you should be able to know how the thing you are trusting with your traffic was made.
What that does and does not mean for your data:
- No AI runs on this site. There is no model in the request path, no chat assistant, and no automated decision making. Nothing you type here is sent to a model.
- Your data was never training material. No customer record, email address, proxy credential, wallet balance or traffic log has been used to build, train, fine tune or prompt any model, and none will be.
- Support replies are written by a person. If you email us or message the Discord, a human reads it and a human answers it.
- Accuracy is our responsibility, not the tool's. Figures published on this site are sourced as described on the pages that carry them. Where a claim comes from our the network's published specification rather than from our own live measurement, we say so on the page that carries it.
If we ever introduce a feature that sends your data to a model, this section will say so before it ships, and the change will be announced under section 11.
10. Children
The service is not for anyone under 18. We do not knowingly collect data from children. If you believe we have, contact us and we will delete it.
11. Changes
Material changes will be announced by email or in the dashboard before they take effect. See also the Terms of Service and Acceptable Use Policy.