Do proxy providers keep logs? What they record and why

Do proxy providers keep logs? What a proxy gateway records, what it cannot see over HTTPS, why "no logs" claims failed in court and how to read a policy.

Your client, a workstation with a sign-in page open, is cabled over HTTPS into a proxy gateway that routes on to the website, a browser window at example.com with a card that reads TLS end to end, ticked; a gold cable from the gateway feeds the provider logs server, whose screen shows one connection record with time, exit IP, host:443 and bytes each in its own colour and the page content padlocked, above three drive sleds for connection, usage and account records
Quick summary · TL;DR
  1. Every proxy provider keeps some logs. Billing per GB, handling abuse reports and answering legal process all need records, so the real question is which records and for how long.
  2. Over HTTPS a proxy sees the destination, not the content. A CONNECT tunnel names only the host and port; paths, headers, passwords and page content stay inside TLS.
  3. "No logs" claims have failed under court orders. Records from a web proxy service in 2011 and a VPN with a no-logs policy in 2017 both ended up in criminal cases.
  4. A good policy names its records. Look for the fields logged, the purpose, the rule that sets retention, the disclosure rule and your rights.

Do proxy providers keep logs? Yes. Every proxy provider keeps some logs, because a service that bills per GB, enforces acceptable-use terms and answers legal process cannot run without records. What differs is which records, how long they are kept and who can demand them. Over HTTPS a proxy sees where a connection goes and how much it carries, while the content stays encrypted.

A privacy-minded buyer reads “no logs” on one site and “we log connection metadata” on another and has no way to tell which one describes the gateway honestly. That gap is mostly marketing, and the protocol itself settles a large part of the question.

What do proxy providers keep in logs

Proxy logs fall into three buckets. Each one exists for a different reason, and a policy that lumps them together hides more than it explains.

Connection logs. One line per connection or session: timestamp, the client’s source IP, the exit IP used, the destination host and port, the result and the duration. Squid, the open-source caching proxy, writes exactly this by default: its native access log records the time, elapsed milliseconds, client address, result code, bytes, method and URL of every request, per the Squid LogFormat documentation. Any commercial proxy gateway can write the same kind of line for every connection.

Usage logs. Byte counts per login, per port or per order. Selling per GB needs a meter, and a meter is a usage log by definition. Without it there is no invoice and no top-up warning.

Account records. Email, billing details, the logins issued, support tickets and, where the provider verifies identity, the outcome of that check. These exist at every paid service, proxy or not.

Why every proxy keeps some logs

Four jobs force records into existence, whatever the marketing page says.

Billing needs a meter. A per-GB plan without byte counts cannot charge, and a per-IP plan still has to know which login holds which address.

Abuse handling needs connection records. When a target site or a network operator reports an attack from an exit IP at a given minute, the provider has to find the account behind it to enforce its own terms. Without those records the report goes nowhere, and the abuse keeps running from the same exits.

Security needs records too. Credential stuffing against the gateway, a leaked login used from five countries at once and a traffic spike from a compromised customer server each show up only in logs.

Law is the fourth reason, and it varies by country. Some governments set a minimum period for keeping network logs.

So the honest answer to “do proxy providers keep logs” is always yes, and the useful follow-up is which of the three buckets a provider keeps, for how long, and under what rules it hands them over.

What a proxy can see over HTTPS

When a client sends HTTPS traffic through an HTTP proxy, it opens a tunnel with the CONNECT method. RFC 9110 (June 2022) defines the CONNECT request target as only the host and port of the destination, for example example.com:443. After the proxy answers 2xx, it forwards bytes in both directions without reading them. The TLS session runs end to end between the client and the website.

So over HTTPS the proxy can record the destination host and port, the time, the duration and the bytes in each direction. It cannot read the path, the query string, the headers, cookies, form fields, passwords or page content. Those travel inside TLS.

SOCKS5 works the same way at a lower layer. RFC 1928 (March 1996) has the client send the destination as an IP address or a domain name plus a port, and the proxy relays the stream from there.

Two cases change the picture.

Plain HTTP targets. A request for an http:// URL travels to the proxy in the clear, with the full URL, headers and body. Anything sent to an unencrypted site is readable by the proxy, and by every network along the way.

TLS interception. Corporate filtering proxies decrypt HTTPS by installing their own root certificate on employees’ machines. A commercial proxy can only do that if the customer installs and trusts its certificate. No legitimate proxy setup needs one.

Encrypted Client Hello barely changes what the proxy sees. RFC 9849 (March 2026) encrypts the server name inside the TLS handshake so networks along the path cannot read it, but a CONNECT tunnel still names its destination host to the proxy in the request line. ECH hides the destination from the Wi-Fi operator and the ISP between the client and the proxy, while the proxy still reads it. ECH narrows what the proxy learns in one case only, a SOCKS5 client that sends just an IP address. Without ECH the proxy could still read the host name from the unencrypted ClientHello, and with ECH it sees the IP and port alone.

“No logs” claims in court

Three cases show how “no logs” holds up, two of them under a valid legal order.

In September 2011 the FBI arrested a suspect in the LulzSec attack on Sony Pictures. According to The Register (26 September 2011), the UK web proxy and VPN service he used handed over records of his activity in response to a court order. The service said it complied only because a court required it.

In October 2017 a federal cyberstalking complaint in Massachusetts relied on records from a VPN provider whose privacy policy said it kept no logs. As The Register reported (8 October 2017), those records tied the suspect’s home and work IP addresses to the same accounts.

Logging can also start without any court. In September 2013 the VPN service Proxy.sh, which advertised no logging, announced it had captured traffic on one US server to identify a user accused of harassment, with no legal order involved, as The Hacker News reported. Such a capture reads plain HTTP in full, while HTTPS traffic shows only hosts, timing and byte counts.

Connection logs kept for a few days, or a session table that maps an exit IP to an account, are enough to answer a subpoena. A policy that names those records and the rules for disclosing them gives a buyer something to check.

RAM-only servers, a common answer from VPN services, change where connection logs live and how fast they disappear. Per-GB services still write byte counts to billing records, because the invoice depends on them.

Log retention and the law

How long do proxy providers keep logs? It depends on where they operate and what the records are for.

In the EU and the UK, the GDPR’s storage limitation principle in Article 5(1)(e) (Regulation 2016/679, adopted April 2016) requires personal data to be kept “for no longer than is necessary” for its purpose. Connection logs that contain customer IP addresses are personal data. Article 5 sets no fixed number of days, so each provider has to set and justify its own period.

Other countries set a minimum instead. China’s Cybersecurity Law, in force since June 2017, obliges network operators under Article 21 to keep network logs for at least six months, as summarised by Protiviti. India’s CERT-In directions of 28 April 2022 go further: service providers must keep logs of their ICT systems for a rolling 180 days, and VPN, VPS and cloud providers must keep subscriber records for five years. Where a provider operates therefore matters as much as its policy text.

The United States sets no general minimum for proxy or VPN logs, but it can freeze what exists. Under 18 U.S.C. 2703(f) a government request obliges a provider to preserve records it already holds for 90 days, extendable by another 90, while investigators obtain a court order or subpoena. No court has to approve the preservation request itself.

Legal requests sit on top everywhere. Under a subpoena or court order, a provider can only hand over what it still holds, and a policy should say when and how it responds.

How to read a proxy privacy policy

Five minutes with a provider’s privacy page answers most of the question. Clear policies cover six points.

  1. Named records. It lists what is logged (timestamps, volumes, IPs, destinations) instead of saying “minimal data”.
  2. Stated purpose. Each record has a reason next to it: billing, abuse, security or law.
  3. Retention rule. What decides how long records are kept is written down.
  4. Legal requests. It names when data is disclosed (legal process, fraud, abuse) and limits it to what the request requires.
  5. No resale. Data is not sold and not used for advertising profiles.
  6. Your rights. There is a contact address and a response time for requests to see, correct, export or delete your data.

proxymint’s privacy policy is an example of the named-records approach. It says the service logs connection and usage metadata, “including timestamps, volumes, the IP addresses involved, and the destinations your sessions reach”, to run the service, bill and keep the network safe. Retention follows the same purpose: as long as needed to run the service and keep the network safe, and as the law requires. Disclosure happens on valid legal process or to address fraud, security issues and terms violations, and covers only what a request lawfully requires. proxymint does not sell data, builds no advertising profiles, and answers GDPR requests to see, correct, delete or export data within 30 days. The terms of service set the acceptable-use rules those records enforce.

How to limit what a proxy records

Some exposure is in the buyer’s own hands, whichever provider carries the traffic.

  • Use HTTPS targets only. Over CONNECT the proxy sees a host name and a port. Over plain HTTP it sees everything.
  • Keep the proxy scheme http://, socks5:// or socks5h://. The tunnel to the website is still TLS. Set the proxy up as the proxy setup guide describes and leave certificate checks on.
  • Decide where DNS resolves. With curl, socks5h:// sends the host name to the proxy for resolution and socks5:// resolves it locally, so the local resolver sees every lookup. Pick one on purpose.
  • Separate jobs by login. One login or order per project keeps usage records apart and makes any abuse report easy to scope.

For the category itself, rotating residential proxies suit public data collection, price monitoring and ad verification from home connections, with a new IP per request, a 5 to 60 minute timer or a sticky session set on the order. The residential proxy guide explains how those exits work, and types of proxies compares every category on fit.

Choosing a provider with clear logging

For public data collection, ad verification or price monitoring, “do proxy providers keep logs” has a short answer, yes, and the decision rests on four answers a privacy page should give in plain words: which records, for what purpose, under which retention rule and when they are disclosed. A metered service that promises no records at all is making a claim to test against its own billing. On the buyer’s side, HTTPS targets, normal certificate checks and a deliberate DNS choice keep paths, content and credentials out of any proxy’s logs.

Frequently asked questions

Yes. Every proxy provider keeps some records, because metering traffic for billing, handling abuse reports and answering legal requests all need them. Providers differ in which records they keep (connection, usage or account data), how long they keep them and when they disclose them.

It depends on the protocol. Over HTTPS the proxy sees the destination host and port, the timing and the byte counts, while paths, headers, cookies and content stay encrypted. Requests to plain HTTP sites pass through the proxy fully readable.

Yes, through records. The website sees the exit IP, and the provider's connection and account records can link that exit IP and time to an account. When a valid legal order arrives, that chain can be followed back to the customer.

It is a marketing term for a proxy service that claims to keep no records of customer activity. Any service that bills by traffic or acts on abuse reports keeps at least usage and account records, so the claim is best read as a statement about connection logs and tested against the full privacy policy.

Not through a normal CONNECT tunnel or SOCKS5 connection, because the password travels inside TLS between the browser and the website. It becomes readable only if the customer installs a root certificate from the proxy or turns off certificate checks.

There is no single period. Under the GDPR, personal data such as connection logs may be kept no longer than necessary for its purpose, while China's Cybersecurity Law requires network logs to be kept for at least six months and India's CERT-In directions require 180 days. Each provider's privacy policy should state the rule it follows.

They can be compelled to. A subpoena or court order obliges a provider to hand over the records it still holds, and published cases from 2011 and 2017 show proxy and VPN records used in criminal investigations. In the US a preservation request can freeze existing records for 90 days, renewable once, before the order arrives. A clear policy says when the provider discloses data and that it discloses only what a valid request requires.