Privacy Policy
Last updated: 30 September 2026
Doxxedify corp, a Delaware corporation
1. Our Commitment
Doxxedify.com was built from the ground up with a single purpose: to protect the privacy and freedom of our users. This is not a marketing statement. It is an engineering decision embedded in every layer of our infrastructure.
We operate a fully vertical technology stack. We do not rely on third-party services for any core function of the platform. Every component, from our DNS resolvers to our authentication system, from our human verification to our network routing, is designed, built, and operated in-house by Doxxedify.com engineers. This means no third party touches your network traffic or your communications, because no third party is involved in operating the network. Payment processing is the one exception, and it is described in Section 2.
2. Vertical Infrastructure: No Third Parties
Unlike other privacy services that depend on external vendors, Doxxedify.com owns and operates:
- Our own autonomous network – We operate our own BGP-peered network across 20+ global points of presence. Your traffic never passes through a third-party VPN provider.
- Our own DNS infrastructure – We wrote our own DNS resolver from scratch in Go. We do not use BIND, Unbound, or any public DNS software. Our DNS servers are custom-built, purpose-designed, and run on our own anycast network.
- Our own human verification (DOXX POW) – We do not use Google reCAPTCHA, Cloudflare Turnstile, hCaptcha, or any third-party verification service. Our proof-of-work system runs entirely on our servers with zero external API calls.
- Our own authentication system – Token-based, no passwords, no email required. No Auth0, no Firebase, no Okta. Globally isolated private authentication infrastructure built in-house.
- Our own monitoring and statistics – No Google Analytics, no Mixpanel, no Datadog, no Sentry. Our real-time monitoring system is custom-built and stores data only in volatile memory.
- Our own certificate infrastructure – Self-signed certificates with client-side pinning for transport security, eliminating dependency on public certificate authorities for core VPN operations.
- Our own encrypted mesh network – All Doxxedify.com servers are interconnected via a private WireGuard mesh backbone. User-to-user traffic travels entirely over this encrypted mesh and never exits to the public internet.
The only external service involvement is payment processing. Plans and add-ons are purchased on the Doxxedify.com website and processed by Stripe, Inc. Stripe receives the information needed to process a charge. Doxxedify.com never sees or stores card numbers. We store only a billing reference needed to renew your plan, and we hold it separately from the network. Payment records are never associated with network activity. Apple and Google distribute our apps and do not process payments for the Service.
3. No-Logs Policy
We do not collect, store, monitor, or log:
- Browsing history or website visits
- DNS queries or resolutions
- Connection timestamps, duration, or frequency
- Real IP addresses (source IPs are never stored; see Section 7)
- Bandwidth usage per user
- VPN session metadata
- Any content of your communications
- Call records, message logs, or communications metadata from P2P Comms. Calls, video calls, chat, voice memos, and file transfers travel directly between devices, so no provider-held record of them can exist on our side
- User agent strings or device fingerprints
We have no ability to associate network activity with any individual user. This is not a policy choice. It is an architectural reality. The systems are not built to capture this data.
4. What We Collect
We collect the minimum data necessary to operate the Service:
- Account token: A randomly generated authentication string. No email address, no username, and no password is required to create an account.
- VPN tunnel configuration: WireGuard public keys and internally assigned VPN IP addresses. These are internal network addresses used for routing, not your real IP address.
- Feature preferences: Your settings such as Smart Blocking configuration, firewall rules, web privacy preferences, and covert communications options.
- Optional recovery information: If you voluntarily provide an email address or phone number for account recovery, it is stored. Most users do not provide this.
- Recovery codes: Stored as one-way cryptographic hashes. The original codes cannot be recovered from storage.
- Subscription data: A billing reference from our payment processor, your plan, and your subscription status are stored for plan, device, and seat management. This data is held separately from the network and is not linked to network activity.
- Terms of Service acceptance: A record that you accepted the terms, and when. No IP address or device information is recorded.
- Custom DNS domains: If you register a .doxx domain on the parallel internet, the domain name and ownership are stored.
5. Security Dashboard & Statistics (Opt-In Only)
If you choose to enable security statistics, the following data is processed to power your real-time security dashboard:
- Blocked domain names and security events are held in volatile RAM (server memory) only. This data is never written to disk and is permanently lost if the statistics server restarts or is interrupted.
- Data is organized into time-series buckets (1-second through 6-hour windows) for your dashboard visualizations.
- All data is keyed to a tokenized tunnel reference, not to your identity.
- This data is available only to your authenticated session via an encrypted WebSocket connection.
- It is not shared with any third party or used for any purpose other than displaying your personal security dashboard.
- If you enable bandwidth statistics, upload and download byte counts are processed in the same volatile, in-memory manner described above.
6. Diagnostic Data (Opt-In Only)
Diagnostics are off by default. If you choose to help us debug a problem, you can turn on diagnostic reporting in the app. When enabled, the app sends the following to servers we operate: application logs, crash reports, tunnel and connection diagnostics such as handshake results, transport in use, latency and error codes, device model, operating system version, and app version.
7. IP Address Handling
Doxxedify.com does not store real IP addresses anywhere in our systems.
- TOS acceptance: No IP address or user agent is recorded.
- Human verification (DOXX POW): A one-way SHA-256 hash of your IP is temporarily stored for abuse prevention. This hash cannot be reversed to obtain your actual IP address. Challenge data expires and is automatically deleted within one hour.
- VPN tunnel IPs: The IP addresses stored in your tunnel configuration are internally assigned VPN addresses (e.g., 10.x.x.x), not your real public IP address.
- Server logs: We do not log client IP addresses in application logs.
8. Connection State
We maintain a record of whether your VPN tunnel is currently active and which server it is connected to. This is operational data used for load balancing and service health, not a connection log. Only the current state is stored; no history of connections is maintained.
9. Cookies & Web Tracking
The Doxxedify.com portal uses session cookies for authentication only. We do not use:
- Analytics trackers of any kind
- Advertising pixels or retargeting tags
- Third-party scripts that phone home to external servers
- Fingerprinting libraries
- Any form of cross-site tracking
Checkout pages are hosted by our payment processor and are the only pages where a third party's code runs. They are described in Section 2. No payment processor code runs inside the Doxxedify.com apps.
10. What We Never Do
- We never sell, rent, license, or share user data with any third party.
- We never serve advertisements or participate in ad networks.
- We never use third-party analytics or monitoring services.
- We never inject content, headers, or tracking into your traffic.
- We never cooperate with data brokers.
- We never retain data beyond what is described in this policy.
- We never build interception capabilities, weaken our encryption, or add logging that targets a person or class of persons, in response to any request, from anyone.
11. Legal Requests
We may receive legal requests for user data. Because we do not log user activity, we have no traffic data, browsing history, DNS queries, or connection metadata to provide. Our architecture ensures we cannot produce records that do not exist. We will comply with valid legal process to the extent we are able, which in practice means confirming whether an account token exists and when it was created.
What process we require. Doxxedify corp is a Delaware corporation subject to United States legal process. We respond only to valid legal process issued by a court of competent jurisdiction and properly served on our registered agent. We do not act on informal requests or on orders served directly by foreign authorities; foreign requests must proceed through mutual legal assistance mechanisms, where they are tested against United States law. We review every demand for legal sufficiency and scope, and we challenge demands that are overbroad, improper, or unlawful.
User notification. Unless we are legally prohibited from doing so, our policy is to notify an affected user before any disclosure in response to legal process, so they may challenge it themselves. Where a nondisclosure order expires, our policy is to notify the user once it does.
Transparency report. We publish a transparency report at doxxedify.com/transparency, updated at least twice per year and promptly after any notable legal event, describing in aggregate the legal demands we receive, from which jurisdictions, what was sought, and what was produced. Where we are lawfully permitted to publish a request and our response in full, we do.
12. Takedown Requests, Copyright, and Abuse
For traffic that transits our network, Doxxedify.com acts as a conduit: we transmit our users' communications without selecting, modifying, or storing their content. There is no transited content on our servers to take down. Notices concerning content on third-party websites should be directed to the party hosting that content.
Where Doxxedify.com operates name and address infrastructure, such as domains that resolve inside the parallel internet or leased IP addresses, we act on valid complaints at the level we control: a name, an address lease, or a token's access may be suspended or terminated for violations of our Terms of Service, including under our repeat-infringer policy, without our being able to identify the person behind the token. Reserved brand names are blocked across all our top-level domains.
Copyright notices under the DMCA may be sent to our designated agent at legal@doxxedify.com [register the designated agent with the U.S. Copyright Office and insert the registered details here]. Network abuse, including malware distribution, phishing infrastructure, or denial-of-service activity, may be reported to abuse@doxxedify.com. We investigate every report against the resources we control. What we cannot do, for anyone, is identify a user, produce their history, or monitor their traffic: the capability does not exist.
13. Your Privacy Rights
Where privacy laws such as the EU and UK GDPR or the California Consumer Privacy Act grant you rights over personal data, we honor them for the data we actually hold, described in Section 4. For most of what those laws contemplate, our honest answer is that the right cannot be exercised because the data cannot be linked to you: we cannot produce, correct, or delete a person's browsing history, connection records, or communications because no such records exist or can be tied to an identity. We do not sell or share personal information, we do not process it for targeted advertising, and we do not profile users. To exercise rights over the data we do hold, or to delete your account and all associated data, contact legal@doxxedify.com or use in-app account deletion.
Data breach notification. In the event of a breach affecting the data described in Section 4, we will notify affected users and regulators as required by applicable law. The categories of data that could ever be affected are limited to that inventory, which is why it is short.
14. Data Retention
- Account data: Retained while your account is active. Upon account deletion, all associated data is permanently removed from our database cluster across all nodes.
- DOXX POW data: Expires and is automatically deleted within one hour.
- Security dashboard data: Exists only in volatile RAM. Lost permanently on server restart. Not recoverable.
- Diagnostic data: Collected only while you have opted in. Deleted within [30] days of receipt, or sooner once your report is resolved.
15. Children's Privacy
The Service is not directed at children under 13. We do not knowingly collect data from children under 13.
16. Changes to This Policy
We may update this Privacy Policy periodically. The effective date at the top indicates the most recent version. Continued use of the Service after changes constitutes acceptance.
17. Verification
This privacy policy was verified against the Doxxedify.com production codebase, database schema, and server infrastructure by an independent AI code audit (Claude Opus 4.6, Anthropic) on February 7, 2026. The audit reviewed the database schema, all APIs and source code, the DNS resolver, the statistics server, and the human verification system to confirm that the statements in this policy accurately reflect the system's actual data handling practices. Sections added after that date [Sections 11 additions, 12, and 13] are pending the same verification and counsel review; this note will be updated when the next audit completes. The payment processing statements in Sections 1, 2, 4, and 9 and the diagnostic data section (Section 6) reflect the move to website billing and the opt-in diagnostics feature, and are pending the same verification.
18. Contact
For questions about this Privacy Policy, please contact us at: legal@doxxedify.com
For abuse reports: abuse@doxxedify.com
Legal process is accepted only by service on our registered agent.