<mdr>
    <title>Privacy Policy of YZY proxy</title>
    <in-page-title>Privacy Policy of YZY proxy</in-page-title>
</mdr>

# YZY PROXY
## PRIVACY POLICY AND DATA PROCESSING DISCLOSURE STATEMENT

---

### PREAMBLE

WHEREAS the operator of the network relay service marketed under the trade name "YZY Proxy" (hereinafter, the "Service," "Service Provider," "we," "us," or "our," as context requires) maintains and administers certain proxy relay infrastructure for the routing of User network traffic; and

WHEREAS any natural or legal person who initiates, maintains, or attempts a connection to the Service (hereinafter, the "User," "you," or "your") is, by virtue of such connection, deemed to have read, comprehended, and irrevocably accepted the entirety of the terms, conditions, disclosures, and representations contained in this Privacy Policy and Data Processing Disclosure Statement (this "Policy"); and

WHEREAS the Service Provider operates the Service using private, purpose-built software, and has elected instead to make certain operational representations, concerning data handling, network architecture, and recurring outbound-connection verification, publicly available, in furtherance of the principle that such representations ought to be as transparent and falsifiable as their nature permits;

NOW, THEREFORE, the Service Provider hereby sets forth the following terms.

---

### ARTICLE I: DEFINITIONS

**1.1 "Connection Metadata"** means any transient technical parameter (including but not limited to source port, cipher suite negotiated, or packet timing) generated solely as an artifact of the TCP/IP or transport-layer handshake, which is processed exclusively in volatile memory and is not, under any circumstance addressed by this Policy, written to persistent storage.

**1.2 "Node"** means any individual relay endpoint, virtual private server, or exit point operated or leased by the Service Provider for the purpose of forwarding User traffic, encompassing both Relay Nodes and Exit Nodes as that distinction is described in Article V.

**1.3 "Personal Data"** means any information that identifies, or could reasonably be used to identify, a natural person. The Service Provider's position, as elaborated in Article II, is that it does not collect Personal Data in the ordinary operation of the Service.

**1.4 "Quality Auditor"** means the automated system, referenced in Article IV, that performs the Audit and publishes the resulting network-classification flags for each active Node. The Quality Auditor evaluates network traffic classification only. It does not evaluate, audit, or verify the Service Provider's data-handling or privacy practices.

**1.5 "Audit"** means the recurring technical verification performed by the Quality Auditor, confirming that a Node's outbound connection, as accessed via the subscription link, presents as ordinary residential traffic and is not classified as proxy, VPN, or datacenter traffic by third-party detection sources.

---

### ARTICLE II: NO-LOGS REPRESENTATION

**2.1** The Service Provider represents that the Service does NOT, in the course of ordinary operation, create, retain, or transmit to any third party any of the following categories of data in connection with an identifiable User session:

&nbsp;&nbsp;(a) source IP address of the User, beyond the instant required to route a single packet;
&nbsp;&nbsp;(b) destination addresses visited by the User;
&nbsp;&nbsp;(c) timestamps of connection initiation or termination;
&nbsp;&nbsp;(d) duration of any session;
&nbsp;&nbsp;(e) bandwidth consumed, disaggregated by individual User;
&nbsp;&nbsp;(f) DNS queries issued by the User through the Service.

**2.2** This representation reflects the Service Provider's own operational practice. The software being private, as clarified in Article III, this representation is not independently verifiable by the User through source-code review or through any other mechanism described in this Policy, including the Quality Auditor described in Article IV, which addresses a separate and unrelated matter.

---

### ARTICLE III: PROPRIETARY SOFTWARE; NO SOURCE DISCLOSURE

**3.1** The software governing Node behavior, traffic handling, and the Service's no-logs implementation is private, purpose-built software belonging to the Service Provider. It is not published, licensed, open-sourced, or otherwise disclosed, in whole or in part, to the User or to the public. No public repository, code link, or build artifact exists, or will be made to exist, for independent inspection.

**3.2** Accordingly, the representations made in Article II and elsewhere in this Policy concerning the Service's internal operation rest on the Service Provider's own assurance and are not capable of confirmation through source-code review. The Audit performed by the Quality Auditor, described in Article IV, addresses a separate and unrelated matter, namely the network classification of outbound traffic, and does not verify or otherwise bear upon the data-handling representations made elsewhere in this Policy.

**3.3** A vulnerability, security flaw, or discrepancy observed in the live operation of the Service, notwithstanding the absence of public source code, may be reported to **proxy@yzyworks.com**.

---

### ARTICLE IV: OUTBOUND CONNECTION QUALITY AUDIT

**4.1** The Service Provider operates an automated system named the Quality Auditor, which performs a recurring Audit of each active Node, verifying that the VLESS XHTTP/TCP outbound connection reachable through the subscription link presents, to third-party network classification sources, as ordinary residential traffic, rather than as traffic identifiable as proxy, VPN, datacenter, or anonymizer in nature.

**4.2** The Audit is executed automatically by the Quality Auditor, without manual initiation, on a weekly schedule at 10:00 UTC. The Service Provider does not warrant execution at the precise minute in every instance, but represents that the Audit will execute no less frequently than once every seven (7) calendar days.

**4.3** Results of the Audit are published by the Quality Auditor at **https://github.com/yzyworks-com/QualityAudits/actions**, disclosing, for each active Node, at minimum:

&nbsp;&nbsp;(a) the abuse-confidence score reported by third-party abuse-reporting databases (e.g., AbuseIPDB or a functional equivalent) for the Node's egress IP address;
&nbsp;&nbsp;(b) any "proxy," "VPN," or "anonymizer" classification flag asserted by commercial IP-intelligence or fraud-scoring providers against the Node's egress IP address;
&nbsp;&nbsp;(c) the date the Node's egress IP address was last rotated or replaced, where rotation occurs;
&nbsp;&nbsp;(d) the Node's ownership classification (Owned Node or Leased Node, as defined in Article VI).

**4.4** The Quality Auditor does not control, and cannot guarantee the accuracy of, third-party abuse or reputation databases. Its published output reflects a Node's standing with such databases as of the time of last run, and is provided so that the User may form an independent judgment, rather than relying on the Service Provider's characterization of Node trustworthiness.

**4.5** A Node flagged by a third-party reputation database, or by a given Audit, is not, solely by virtue of that flag, presumed by the Service Provider to have been involved in abuse; commercial reputation scoring is known to produce false positives, particularly against shared infrastructure.

**4.6** The Quality Auditor addresses only the network-classification matters enumerated in Section 4.3. It does not evaluate, audit, or verify the Service Provider's data-handling practices, including the no-logs representation of Article II, which remain addressed solely by Articles II and III.

---

### ARTICLE V: NETWORK ARCHITECTURE AND DATA NECESSARILY PROCESSED IN TRANSIT

**5.1** A connection initiated by the User through the subscription link is routed in two stages: first to a **"Relay Node,"** and from the Relay Node to an **"Exit Node,"** before onward transmission to the User's intended destination. This separation is maintained so that no single stage holds the complete picture of both the User's originating connection and the destination being reached.

**5.2** Relay Nodes and Exit Nodes are each instances of "Node" as defined in Article I, and are accordingly both subject, without distinction, to the no-logs representation of Article II, the Audit of Article IV, and the ownership classification of Article VI.

**5.3** A Node, whether functioning as a Relay Node or an Exit Node, may be hosted on infrastructure presenting either a residential-class or a datacenter-class IP address, including IP addresses that are, by the nature of the hosting arrangement, publicly exposed and attributable to a known datacenter range. The applicable IP classification for each active Node, together with its Audit result, is disclosed by the Quality Auditor referenced in Article IV.

**5.4** A distinct entry within the subscription link, including configurations consumed by v2rayTun or functionally equivalent client software, does not necessarily correspond to a distinct, physically separate Node. Multiple entries may instead reflect differing Server Name Indication (SNI) values, differing Relay Node assignments, or other routing-layer distinctions presented through a single underlying Exit Node, or a shared set of Exit Nodes.

**5.5** Notwithstanding Article II, the User acknowledges that the technical function of multi-hop proxy relay inherently requires the momentary processing of packet headers and encrypted payload, at each stage described in Section 5.1, for the sole purpose of forwarding such packets toward their intended destination.

**5.6** Such processing, at the Relay Node and at the Exit Node alike:

&nbsp;&nbsp;(a) occurs exclusively in volatile memory (RAM);
&nbsp;&nbsp;(b) is not copied, mirrored, or written to disk, swap, or any non-volatile medium;
&nbsp;&nbsp;(c) is discarded immediately upon completion of the forwarding operation or upon teardown of the underlying connection, whichever occurs first.

**5.7** The Service Provider cannot decrypt payload content protected by end-to-end encryption negotiated between the User's own client and the User's intended destination, and accordingly cannot, and does not, inspect such content at either stage.

---

### ARTICLE VI: INFRASTRUCTURE OWNERSHIP AND SUBPROCESSORS

**6.1** Nodes fall into one or both of the following categories, the proportion of which may vary from time to time without affecting the validity of this Policy:

&nbsp;&nbsp;(a) **"Owned Nodes"**, meaning physical hardware owned outright by the Service Provider, over which no third-party hosting provider holds physical or hypervisor-level access;
&nbsp;&nbsp;(b) **"Leased Nodes"**, meaning virtual or dedicated infrastructure leased from third-party hosting or virtual-private-server providers, where the underlying hardware remains the property of, and may be physically accessed by, that provider.

**6.2** With respect to Leased Nodes, the relevant third-party provider may, under its own independent policies, retain records relating to the lease of infrastructure (e.g., billing records) and may possess physical or hypervisor-level access to hardware. This Article does not, by its terms, extend to Owned Nodes, no such third party being present in that case.

**6.3** The Service Provider selects third-party providers for Leased Nodes with the no-logs posture of Article II in mind, but cannot extend Article II's representations to the unilateral policies of such providers, and makes no representation as to their data retention practices beyond what is disclosed in their respective public policies.

**6.4** The current classification of each active Node (Owned or Leased) is disclosed by the Quality Auditor referenced in Article IV, Section 4.3(d).

---

### ARTICLE VII: RESPONSE TO LEGAL PROCESS

**7.1** Because the Service Provider does not retain the categories of data enumerated in Article II, the Service Provider has no responsive User-identifying connection records to produce in response to a request, subpoena, or order, however issued.

**7.2** Nothing in this Article shall be construed as a representation that the Service Provider will resist, challenge, or decline to acknowledge legal process validly served upon it. The Service Provider can only disclose what it has; per Article II, it has, in the ordinary course, very little.

---

### ARTICLE VIII: ACCEPTABLE USE

**8.1** The User shall not employ the Service for any purpose unlawful under the law applicable to the User, including but not limited to:

&nbsp;&nbsp;(a) the transmission of malicious code;
&nbsp;&nbsp;(b) the facilitation of unauthorized access to third-party systems;
&nbsp;&nbsp;(c) the transmission of threats of violence, including but not limited to bomb threats, threats against persons, or threats against critical infrastructure;
&nbsp;&nbsp;(d) the distribution of material the possession or distribution of which is itself unlawful.

**8.2** Nothing in Article II's no-logs representation shall be construed as an undertaking by the Service Provider to shield a User from the consequences of conduct prohibited under Section 8.1.

**8.3** In furtherance of Section 8.1, the Service Provider may, at its discretion, restrict outbound access from some or all Nodes to particular destinations or ports where such destinations or ports are commonly associated with the conduct described in Section 8.1, for example financial-services platforms such as PayPal, where access via proxy infrastructure is frequently associated with fraud, or the Simple Mail Transfer Protocol port (TCP/25), where access via proxy infrastructure is frequently associated with unsolicited bulk email. Such restrictions may vary by Node, by time, and without prior notice, and do not constitute a representation that any particular destination or port will remain reachable or unreachable at any given time.

---

### ARTICLE IX: SECURITY MEASURES

**9.1** Transport between the User's client and the Node is secured using modern transport-layer encryption with traffic-obfuscation characteristics designed to resist protocol fingerprinting.

**9.2** No security measure is represented as absolute. The User is encouraged to maintain independent operational security practices appropriate to the User's own threat model.

---

### ARTICLE X: AMENDMENT

**10.1** The Service Provider may amend this Policy from time to time. Material amendments shall be reflected by an updated Version number at the head of this document, published at **https://yzyworks.com/mdr?source=/yzyproxy/PrivacyPolicy.md**.

**10.2** Continued use of the Service following publication of an amended Policy constitutes acceptance of the amended terms by the User.

---

### ARTICLE XI: SEVERABILITY AND INTERPRETATION

**11.1** If any provision of this Policy is held invalid or unenforceable by a court or tribunal of competent jurisdiction, such provision shall be severed, and the remaining provisions shall continue in full force and effect.

**11.2** Headings are for convenience of reference only and shall not affect the interpretation of this Policy.

---

### ARTICLE XII: REGISTRATION AND PAYMENT

**12.1** Registration for the Service is anonymous. Consistent with Article II, the Service Provider does not require the User to submit any Personal Data, including name, government-issued identifier, billing address, or device identifier, as a condition of obtaining or maintaining access to the Service.

**12.2** Fees for the Service are denominated and settled in digital-asset form, namely: (a) Toncoin (TON); (b) Tether USD (USDT) issued on the TON network; or (c) Tether USD (USDT) issued on the TRC-20 (Tron) network, at a price quoted directly by the Service Provider on a per-transaction basis. The Service Provider does not accept fiat currency, card payments, or any payment rail that would require the collection of Personal Data as a condition of processing.

**12.3** Because TON-network and TRC-20-network assets are not interoperable and are received at distinct wallet addresses, the User shall confirm, through the channel described in Section 12.5(a), which network a given payment is to be sent on before transmitting funds. The Service Provider accepts no liability for funds sent on a network other than the one confirmed for that transaction.

**12.4** Price quotations and payment (wallet) details are not published as a static, unauthenticated list. They are communicated solely through the verification channels enumerated in Section 12.5, in order to reduce exposure to impersonation and payment-redirection fraud.

**12.5** Communication for the purpose of arranging payment shall proceed in the following order of precedence:

&nbsp;&nbsp;(a) Email, at **proxy@yzyworks.com**, which the Service Provider treats as the primary and preferred channel of first contact, and through which a User must first establish contact. Correspondence from this address is authenticated using a published OpenPGP key; the User should verify the cryptographic signature of, and may request OpenPGP-encrypted correspondence to, that key, using OpenPGP-capable email client software such as the end-to-end encryption built into Mozilla Thunderbird, before treating the content of any such correspondence as authoritative. Correspondence purporting to originate from this address that cannot be verified against the published key shall not be treated as authentic;
&nbsp;&nbsp;(b) only after such initial contact has been made and verified via Section 12.5(a), the Service Provider may, at its discretion, continue or supplement communication through Telegram or Signal, identifiers for which will themselves be disclosed only through the Section 12.5(a) channel.

**12.6** The User should treat any unsolicited contact purporting to originate from the Service Provider via Telegram, Signal, or any channel other than the address in Section 12.5(a), without prior email confirmation, as unverified.

**12.7** The Service Provider accepts no liability for funds sent to a wallet address not directly confirmed by the Service Provider through the channel described in Section 12.5(a).

**12.8** Following confirmation of payment, the subscription link, access credentials, and any other information required to use the Service shall be delivered to the User solely through the verified communication channel established in Section 12.5, and not through any other, unconfirmed channel.

**12.9** The Service Provider is under no obligation to issue a refund in any circumstance, including but not limited to dissatisfaction with the Service, a period of unavailability addressed under Article XIII, or a change in the User's own requirements.

**12.10** Where a refund is, notwithstanding Section 12.9, granted at the Service Provider's discretion, no communication purporting to approve, authorize, or confirm that refund is binding on the Service Provider unless it is received through, and cryptographically verifiable against, the OpenPGP-authenticated email channel described in Section 12.5(a). A purported refund approval received through Telegram, Signal, or any other channel, or through an email that cannot be so verified, is of no effect.

---

### ARTICLE XIII: SERVICE AVAILABILITY; STATUS DISCLOSURE

**13.1** The Service Provider does not warrant that the Service will be available, operable, or free of interruption at any given time. The Service is provided on a best-effort basis, and its operation may be affected by factors including, without limitation, infrastructure failure at a Node, action by a third-party hosting provider, network-level interference, or the outcome of an Audit under Article IV.

**13.2** The Service Provider is under no obligation to remediate, restore, or compensate the User for any period during which the Service is unavailable or degraded. The Service Provider's sole undertaking in connection with a known disruption is, at its discretion, to send the User a brief notice by email indicating that an issue has been identified.

**13.3** The Service publishes its own operational status, independent of any representation made to a particular User, by way of two HTTP response headers returned at **https://proxy.yzyworks.com/auditor-uptime-status**:

&nbsp;&nbsp;(a) a header named `status`, bearing the value `up` (the Service is fully operational) or `down` (the Service is not operational);
&nbsp;&nbsp;(b) a header named `notice`, bearing free-text commentary most recently entered by the Service Provider concerning the current operational situation, which may include a UTC timestamp (for example: "Service interruption identified; resolution in progress as of 06:01:43 UTC.").

**13.4** The User is encouraged to consult the headers described in Section 13.3 directly, including in connection with an apparent Audit failure under Article IV, before assuming that an interruption is specific to the User's own connection, configuration, or Node.

---

### ARTICLE XIV: NOTICES AND CONTACT

**14.1** Inquiries regarding this Policy or the Quality Auditor may be directed to: **proxy@yzyworks.com**.

**14.2** Security disclosures should be directed to the channel specified in Section 3.3. Payment-related inquiries are governed by Article XII.

---

### ARTICLE XV: TRADEMARK AND NON-AFFILIATION DISCLOSURE

**15.1** "YZY," "YZY Proxy," and any associated marks used in connection with the Service are used by the Service Provider as a trade name only. They do not constitute a registered trademark, a registered company name, or a legally incorporated entity in any jurisdiction, except to the extent the Service Provider has separately and explicitly registered them as such.

**15.2** The Service Provider and the Service are not affiliated with, endorsed by, sponsored by, or in any way officially connected to Ye (professionally known as Kanye West), Yeezy LLC, Yeezy Apparel LLC, or any of their respective affiliates, agents, or licensed brands. Any resemblance between the Service's trade name and the branding of any such party is coincidental and is not intended to imply association, endorsement, or sponsorship.

**15.3** Nothing in this Article shall be construed as a waiver of any rights the Service Provider may hold, or may later seek to register, in the name "YZY Proxy" as applied specifically to the Service.

---

*This document is a self-drafted template and does not constitute legal advice. If YZY Proxy will be offered to users in jurisdictions with specific data-protection regimes (GDPR, CCPA, etc.), have an attorney review it before publishing.*

---

**Document Reference:** YZY-PP-2026-01
**Version:** 2.1
**Governing Document Class:** Service Disclosure Instrument (Non-Negotiable Standard Terms)
