We are putting it in writing because the rest of the industry will not. This page is the policy, not the marketing version of the policy. If something here turns out to be wrong, we want to hear about it.
Every residential IP in our pool belongs to a participant who agreed, in plain language, to share idle bandwidth in exchange for something. Most often that is a paid product feature, a free tier of a paid offering, or a small monthly cash payment. The participant keeps full control. They opt in through our consent flow, they accept the terms, and they can revoke participation at any time with a one-tap toggle in settings.
We do not buy raw IP lists. We do not crawl public Wi-Fi. We do not touch compromised devices, malware bundles or any IP that cannot trace back to an explicit, on-device consent prompt we can show on demand. The whole pool is built and operated by us, end to end.
No malware-bundled SDKs. Period.
No dark patterns hiding the consent prompt.
No reselling IP ranges we did not source ourselves.
No routing participant traffic through illegal targets.
No targeting compromised devices, ever.
No selling participant identity, location or browsing data.
If a customer asks us to route a request that violates our acceptable use policy, the request is dropped and the account is reviewed. We would rather lose the revenue than burn the pool we built.
The following uses are explicitly forbidden on every plan, every protocol, every gateway. Violations lead to immediate account termination, forfeiture of any unused balance, cooperation with law enforcement where legally required, and permanent ban of the operator and any related accounts. No warnings, no second chances on these.
Any production, transmission, possession, hosting, indexing or scraping of sexual content involving minors. Reported to NCMEC and law enforcement on detection. There is no legitimate use case. We do not negotiate this.
No scraping or probing of any .gov, .mil, .gouv, .gob domain or any equivalent national / state / municipal portal. No targeting of court records systems, voter databases, or law enforcement tooling. Includes both attack and reconnaissance traffic.
No automated traffic against Stripe, PayPal, Adyen, Square, Plaid, Wise, Revolut, banks, card networks, central banks, brokerages or any payment-card data flow. Includes credential testing, BIN/CVV checking, account enumeration, and merchant-side scraping at checkout.
No traffic against hospital systems, EHR vendors, insurance member portals, public utilities (water, power, telecom carrier provisioning), transit operators or emergency services. Anything where downtime or data exposure can put real people at physical risk.
No use as command-and-control, no payload delivery, no exfiltration relay, no phishing-kit hosting reachability checks. Same rule for spam runs, smishing, and phishing-page deployment.
No flooding, no amplification, no Layer 7 attack traffic of any kind. The gateway will rate-limit and terminate before your script knows what hit it. Same for port scanning, vulnerability scanning of systems you do not own and have no written permission to test.
No traffic originating from, terminating in or otherwise serving entities listed under OFAC, EU, UK, UN or any equivalent sanctions program. We screen the standard lists and update on every published change.
No darknet market reachability, no firearms-without-license commerce, no fentanyl precursor sourcing, no human trafficking platforms. If the underlying product cannot be sold legally on a federally-incorporated US e-commerce site, it cannot be scraped from here either.
See abuse? Email [email protected] with timestamp, target hostname and observed traffic. We answer within hours, not days.
Compensation depends on the program a participant joined. Some get a paid product feature unlocked for free. Some get direct cash per gigabyte of idle bandwidth used. Some accumulate points redeemable for store credit. Whatever the format, the deal is disclosed in plain language before they join, not buried in a 40-page EULA.
Payments run on a recurring schedule with revenue transparency on the bandwidth we actually used. Underpayment is a fast track to having an integration retired. We have done this before.
Every request that flows through the network can be traced back to a customer account, a request ID and a timestamp. If a target reports abuse, fraud or content that violates our acceptable use policy, we can identify the customer who routed the request and shut the account down within hours.
We do not log the contents of customer traffic. We do log the metadata we need to investigate complaints and protect the pool: timestamps, target hostnames at the request edge, response codes and account identifiers. That is the bargain we make with the participants who power the network and with the targets they reach.
If you are a target site and you believe traffic from our network is hurting you, write to [email protected]. We answer in hours, not weeks, and we do not hide behind a ticketing wall.
Every consent flow is reviewed on a real device by our team. If a participant cannot reasonably understand what they are agreeing to, we revise the flow until they can.
Every participant gets a tangible benefit before bandwidth flows. No silent participation, no free-riding, no exception.
All client-side code that ships on our network runs through a sandboxed audit. We look for hidden persistence, kernel hooks and silent reinstall. Anything unusual is removed.
Network audits run quarterly. Devices and integrations that passed a year ago are not assumed to pass today.
Participants get a one-tap opt-out and we verify it works on every supported platform before any release.
Operators running scrapers in regulated industries reach out regularly with sourcing questionnaires. We answer them. The short version: we can produce the consent flow, the compensation structure and the abuse-response process on demand for every IP currently in the pool. We can show what has been retired and why. Under NDA we share the technical details of the consent system itself for compliance review.
We update this page when material changes happen. The last review was driven by an enterprise compliance team that pushed back on a vague answer we gave them. They were right. The page is clearer because of it.