Legal
Privacy policy
How Birdie Proxies collects, uses and protects information about you when you use the dashboard and the proxy service.
Last updated 6 September 2026
Who we are
The service is operated by Birdie Technologies. We are the data controller for the personal data described here. Questions about this policy or your data go to [email protected], or open a support conversation from the dashboard.
What we collect
We keep what the service needs to work, and no more:
- Account details. Your email address, your chosen username (which is also your proxy username) and a salted hash of your password. We never store the password itself.
- Sign-in sessions. For each sign-in we record the time, the IP address and a short description of the browser or device, so you can see and end sessions from your account page.
- Two-factor authentication. If you turn it on, the authenticator secret is stored encrypted, together with hashes of your recovery codes.
- Orders. What you bought, when, the amount, and the payment reference from our payment processor. Card numbers go directly to Stripe and never reach our servers.
- Proxy usage. The bandwidth used through your proxies and the destination hostnames of requests, as reported by the proxy network. This is what powers your statistics page and your balance. We do not log the content of your requests.
- Support conversations. Messages you send us, including free-trial requests, and our replies.
- Giveaway plays. When you take a shot in the daily game, the outcome and any prize credited.
- Account activity. A log of significant events on your account, such as sign-ins, password and two-factor changes, proxy key resets, orders and support activity, with the time and IP address. It exists so we can investigate problems and abuse.
- Technical logs. Request metadata such as IP address and timestamps, used for rate limiting and to keep bots and abuse out. These are short-lived.
Why we use it
We process this data to provide the service you signed up for (our contract with you), to run the business sensibly (our legitimate interests in security, fraud prevention, support and improving the product), and to meet legal obligations such as keeping tax records. We do not sell personal data and we do not use it for advertising.
The proxy network
Proxies are provided over a network operated by an upstream provider. When you connect through a proxy, the upstream provider sees your proxy username and the traffic you send through it, and reports usage back to us. Your proxy username does not include your email address or name. The upstream provider processes this data under its own terms and privacy policy.
Who we share it with
- Stripe, which handles card payments and issues invoices. Stripe receives your email, the order amount and your billing country for VAT.
- The upstream proxy provider, which receives your proxy username and the bandwidth allocated to it.
- Hosting and infrastructure providers that run the dashboard and database, under contracts that restrict them to processing on our behalf.
- Authorities, where the law requires it or to protect the rights and safety of others.
Some of these providers are outside the United Kingdom and the European Economic Area. Where that is the case, transfers rely on adequacy decisions or standard contractual clauses.
How long we keep it
- Account details: while your account exists, then deleted within 30 days of closure.
- Sign-in sessions: removed when they expire or when you end them, and in any case within 90 days.
- Orders and invoices: six years, as tax law requires.
- Proxy usage statistics: up to 12 months.
- Support conversations: two years after the last message.
- Account activity log: two years, except records of payments and credits, which are kept with the orders.
- Technical logs: up to 30 days.
How we protect it
Passwords are hashed with a modern key-derivation function, authenticator secrets are encrypted at rest, and the database enforces row-level security so an account can only ever read its own rows. Connections use TLS. Two-factor authentication is available to every account, and you can review and end sessions at any time.
Cookies
We use only the cookies needed to keep you signed in: a session cookie for your account, a short-lived cookie during two-factor sign-in, and a separate cookie for operator access. They are HttpOnly and are not used for tracking. We do not run analytics or advertising cookies.
Your rights
You can ask for a copy of your data, have it corrected or deleted, restrict or object to how we use it, and receive it in a portable format. Most of this you can do yourself from the account page; for anything else, write to [email protected] and we will respond within one month. If you are unhappy with how we handle your data you can complain to your data protection authority; in the United Kingdom that is the Information Commissioner's Office.
Age
The service is for adults. We do not knowingly collect data from anyone under 18, and we close accounts we discover belong to minors.
Changes
When this policy changes we update the date at the top. For material changes we will tell you by email or with a notice in the dashboard before they take effect.
