Back to proxyma.ai

Privacy Policy

The short version: When you run Proxyma yourself (the desktop app, or a server you host), your files, search queries and conversations stay on your own infrastructure, except what goes to a cloud AI provider you configure (section 3.6, which also covers web search and external AI assistants) and what you send us as feedback or an answer rating (section 3.7). Proxyma Community is free and requires no purchase or account. If you buy a Personal or Professional license, Lemon Squeezy emails you the key; we do not store your name, email address or payment data. We run three services ourselves: the license server, the opt-in diagnostics and feedback server, and the Enterprise sandbox at enterprise-demo.proxyma.ai. The sandbox is writable: what you add there can be seen by other visitors, is sent to the cloud AI service in the United States we use for it, and is deleted every night (section 3.8).

1. Who We Are

Proxyma is developed and maintained by:

Le Sy Hau
Individual software developer
237/3 Hoa Binh Street
Phu Thanh Ward, Ho Chi Minh City
Vietnam
Email: contact@proxyma.ai

We are an individual person, not a registered company, and the data controller for the limited personal data described in this policy.

As we are based in Vietnam, Vietnam's Law on Personal Data Protection (Law No. 91/2025/QH15) and its implementing Decree No. 356/2025/ND-CP apply to our processing. If you are in the European Economic Area or the United Kingdom, the GDPR and UK GDPR apply as well. This policy is written to satisfy all of them; where they differ, we apply whichever gives you the stronger protection.

2. The Privacy-First Design of Proxyma

Proxyma indexes and searches your documents on your own infrastructure. All document processing, vector embedding, keyword indexing and AI conversations happen on the machine or server running Proxyma. When that machine is yours, none of this data is transmitted to or stored on any server we operate, except feedback and answer ratings sent to us from inside Proxyma (section 3.7) and diagnostics if you turn them on (section 3.3). This is a core design principle, not an optional setting.

The exception is a cloud AI provider you configure yourself (section 3.6). The Enterprise sandbox is ours rather than yours, and it does accept what you type (section 3.8). The rest of this policy describes the limited cases where personal data flows.

3. What Data We Collect and Why

3.1 Purchase and licensing

Proxyma Community is free. The Personal and Professional tiers are a one-time purchase per installation, processed by Lemon Squeezy (Lemon Squeezy LLC) as Merchant of Record. When your purchase completes, Lemon Squeezy emails you a license key and notifies an automated function of ours, which issues the license that key activates. That function processes your name and email address only in transit to create the key, and stores neither on any server we operate. It keeps two things: the Lemon Squeezy order number and the license key Lemon Squeezy emailed you, stored with the license it issued, so that the license can be matched to its purchase, for example to revoke it after a refund. Your name, email address, billing details and payment information remain under Lemon Squeezy's control at all times; see lemonsqueezy.com/privacy. Enterprise licensing is negotiated directly; contact contact@proxyma.ai for pricing.

Legal basis under GDPR: performance of a contract (Article 6(1)(b)).

3.2 License validation

Proxyma verifies your license's signature locally, using a public cryptographic key bundled with the software. That check never leaves your machine.

Only paid tiers and the free trial contact our license server, in these ways. Activating a license sends the license key, a random identifier for that installation, your computer's name and the edition (desktop or server); the license server does not store the computer name or the edition. We store when the installation first and last activated. After that, Proxyma re-checks the license in the background roughly every six hours, sending only the signed license (which carries its order number and tier) and that installation identifier. This is what makes a refunded or revoked license stop working.

The free trial. When a new installation of Proxyma Desktop or Proxyma Home Server first starts, it asks our license server for its 30-day trial of Professional, sending a random identifier for that installation and a one-way hash of your operating system's own identifier (Windows' MachineGuid, or Linux's machine-id; for Home Server, the host computer's). The identifier itself is never sent: it is combined with a fixed Proxyma prefix and hashed with SHA-256 on your computer, and the hash cannot be turned back into it. The license server keeps the hash with the trial license it issued, so that each computer receives one trial, and uses it for nothing else. The trial license is labeled with the first characters of that hash. During the trial, the license is re-checked as described above; once it has ended, an installation without a paid license makes no further calls to the license server.

These calls never carry your documents, file names or paths, search queries, conversations, or anything about your hardware. The installation identifier is a random value generated on your device, not a hardware fingerprint, and the trial's hash is derived from the operating system's identifier, not from your hardware. On Proxyma Desktop and Proxyma Home Server, if the re-check cannot reach us, Proxyma works normally for 14 days, then limits itself to the free Community tier's features until it can check again. Nothing is deleted.

An installation with no license makes none of these calls, except asking for its trial every few hours until the license server grants it or answers that this computer has had its trial.

Legal basis under GDPR: performance of a contract (Article 6(1)(b)).

3.3 Optional diagnostics (opt-in only)

Proxyma can send us diagnostics to help improve the product. This is strictly opt-in and disabled by default. You can enable or disable it at any time with Send diagnostics to Proxyma in Settings → About → Privacy. See what would be sent, in the same place, shows the exact report before anything leaves your device, and Delete collected data removes what has been collected. The same setting also allows answer ratings to be sent (section 3.7).

Diagnostics are aggregates: how many times, and how long, operations such as indexing, search, guardrail checks, chat and AI provider calls took, grouped by connector type, a file type class (such as “pdf” or “office”), a file size range and the AI provider protocol (such as “Anthropic”), never the name you gave a provider or the model; how often syncs, AI provider calls and updates succeeded or failed, by error category; which kinds of warnings and errors occurred, identified only by where in Proxyma's own code they happened (up to 25 code locations, with line numbers) and the types of error involved; the hour and minute (UTC) an error first and last occurred; how long the app has been running and how long it took to start; how often each of Proxyma's own tools was used; which features are switched on, and how many sources of each type you have, with document counts given as ranges; and your operating system family, processor architecture, number of processor cores, a memory range and the Java version. Each report carries a random installation identifier generated on your device, the app version, the license tier and the edition.

Diagnostics do not include document content, file names or paths, web addresses, search queries, conversation content, the text of log or error messages, account details, the names you gave AI providers, API keys, or your computer’s name.

Diagnostics are collected only from the moment you turn the setting on, kept on your device first, and sent at most about once a day as a single report covering whole days (UTC). A report that cannot be delivered is retried; anything not delivered within 30 days is deleted from your device. Turning the setting off deletes everything collected and not yet sent.

Proxyma Enterprise Server, and any installation under an Enterprise license, never sends diagnostics, regardless of this setting; diagnostics cannot be turned on there.

Legal basis under GDPR: consent (Article 6(1)(a)). You may withdraw consent at any time by turning off Send diagnostics to Proxyma in Settings.

3.4 This website (proxyma.ai)

The proxyma.ai website sets no cookies and uses no analytics. Its only browser storage is two localStorage entries. proxyma-mode holds one of the words system, light, gray or black so your chosen appearance survives to your next visit; it is written only if you use the appearance menu, and you can clear it on the Cookie Policy page. proxyma.locale holds the language you chose, such as en or vi; it is written only if you use the language switcher. When a page shows prices, it asks license.proxyma.ai, our license server, from your browser whether a sale is running; that request carries no cookie and no identifier of yours. We log no IP addresses or browsing data beyond what Cloudflare retains as the CDN and DNS provider for this website.

Cloudflare acts as a data processor for the website, for license.proxyma.ai and telemetry.proxyma.ai, and for the Enterprise sandbox described in section 3.8; see cloudflare.com/privacypolicy.

Legal basis under GDPR: our legitimate interest (Article 6(1)(f)) in operating this website.

3.5 Support and email contact

If you contact us at contact@proxyma.ai, your email address and message content are processed to respond to you. They reach no one but us and the email provider that hosts our mailbox (section 5).

Legal basis under GDPR: legitimate interest (Article 6(1)(f)).

3.6 AI providers you configure yourself

Proxyma comes with no AI provider configured, and sends no document content to any provider until you set one up. A model you run on your own hardware, for example with Ollama, keeps that content on your infrastructure. If you configure a cloud AI provider instead (currently Anthropic, Google Gemini, Azure OpenAI, or any service offering an OpenAI-compatible interface, for example OpenAI, DeepSeek or Mistral), what the assistant works with is sent to that provider: your question, the excerpts it retrieves, and any page, issue or file it opens to answer. If you choose a cloud embedding model, or turn on the knowledge graph with a cloud model, the text of the documents being indexed is sent to that provider as well. A cloud vision model used for OCR receives the pages of scanned documents being indexed. None of it passes through us.

Three other things can leave your machine without a cloud provider. When the assistant searches the web, the search words it chooses, which can be drawn from your question, are sent to DuckDuckGo, or to Google if you have configured a Google search key; when it opens a web page, that page's site receives the request. And if you connect an external AI assistant in Settings → AI Assistants, that assistant receives the search results and excerpts it asks Proxyma for, and handles them under its own provider's terms. And if you turn on Show a space fact on the empty chat (Settings → About → Display), Proxyma checks the fact's source page at NASA, ESA, HubbleSite or Wikipedia from your installation, which shows your network address to that site.

That provider acts as a subprocessor for those requests and handles the data under its own privacy policy, which we encourage you to read before configuring it. This happens only with a provider you have actively set up, never with a model you run on your own hardware.

3.7 Feedback you send us from inside Proxyma

Proxyma has a feedback form, and a thumbs-up and thumbs-down under each answer. Using either is entirely optional, and what you send reaches us rather than staying on your machine.

The feedback form sends nothing unless you fill it in and press Send.

Rating an answer sends that answer and the question it replies to, exactly as written, which can include text quoted from your documents. A rating is sent to us only when Send diagnostics to Proxyma is turned on in Settings → About → Privacy, the same setting as the telemetry in section 3.3, and never from an installation under an Enterprise license. On Proxyma Enterprise Server, only a super administrator can change that setting, and only the super administrator's own ratings are sent. Taking back a thumbs-up or thumbs-down does not recall a rating already sent.

Feedback is always anonymous. No account, username or user ID is attached, and no setting changes that. We receive your rating, what you wrote, and some technical context about the installation: the edition (desktop or server), the version, the license tier and an installation identifier. That identifier is a random value generated once and stored in the installation’s own data folder, so that several reports from one installation can be recognized as related. Feedback and diagnostics from one installation carry the same installation identifier. It is not derived from your hardware, username or network, and deleting it makes the installation a new, unlinkable one.

In the feedback form, the following are included only if you choose them: you type in an email address and pick files yourself, and the log file and the conversation each have a box of their own that starts unticked:

  • Your email address — only if you type one in, and used only to reply to you. Leave it blank and the submission stays completely anonymous.
  • Files you attach — screenshots or any other file you pick. File names of attachments are sent with them.
  • Your latest log file — the most recent part of the installation’s log. It can contain file and folder names, connector names, error messages, settings and the words of searches from that machine, but not the contents of your documents.
  • The conversation, when you send feedback about a specific answer — the messages exactly as written, which can include text quoted from your documents. This is the most sensitive thing the form can send, and the form never includes it unless you tick that box. A rating, described above, always includes the rated answer and its question.

A copy of the submission also stays in your installation, so a server administrator can still read feedback sent from their deployment.

Legal basis under GDPR: our legitimate interest in improving the product (Article 6(1)(f)), and your consent (Article 6(1)(a)) for the optional attachments, your email address and answer ratings. You can ask us to delete a submission at any time by writing to contact@proxyma.ai. Because feedback is anonymous, we may need you to tell us roughly when you sent it, or to write from the address you gave, so we can find it.

3.8 The Enterprise sandbox (enterprise-demo.proxyma.ai)

We host a Proxyma Enterprise Server deployment at enterprise-demo.proxyma.ai, so people can try accounts, roles and administration without installing anything. It runs on hardware we operate ourselves in Vietnam, not on a third-party cloud platform, and is reached through Cloudflare, which provides DNS, TLS and DDoS protection in front of it. It is writable. It is free, and has no guarantee of availability.

Accounts. You sign in with one of three shared accounts, whose password is published on the sign-in page: Super admin, which can view everything and change nothing; Admin, which manages users and guardrails; and Member. Or you register an account of your own with an email address and a password; you must be 16 or older to do so. We send no email to that address and do not check that it is yours, and anyone who signs in as the Admin or the Super admin can see it, so use a made-up address.

What you add is shared. Everything you add is stored on that machine and can be seen and used by other visitors: chat messages and conversations, uploaded files, sources such as websites you have it crawl, connections and the credentials in them, skills, key accounts, and user accounts, including the email address an account was registered with. This is especially true under a shared account, where everyone who signs in as it sees the same things you do. Do not enter real credentials, confidential data or anyone else's personal data. The sign-in page and a banner on every screen of the sandbox say the same.

It is sent to an AI provider. Chat, and the indexing of what you add, send content to a third-party AI provider we configure for the sandbox, a cloud AI service in the United States: your messages with the excerpts retrieved for them, and the text of files and sources being indexed. That provider acts as our subprocessor and handles this content under its own privacy policy. Spending on chat is capped. When the assistant searches the web or opens a page, the requests described in section 3.6 are made from the sandbox.

Everything is deleted every night. An automatic reset empties the sandbox's database and data directory, then puts back the configuration and example content we prepared for it, which contain nothing any visitor added. We do not back up anything visitors add. Apart from that prepared copy, the only thing the reset keeps is the installation identifier the sandbox uses to activate its own license (section 3.2), which says nothing about any visitor. Content already sent to the AI provider is kept under that provider's policy, not ours. To remove something sooner, delete it in the sandbox, or write to contact@proxyma.ai.

Feedback sent from the sandbox reaches us as section 3.7 describes.

Signing in sets session cookies, and starting a conversation sets one more; the Cookie Policy lists them. The network address of each request is used in memory to limit how many requests one address may make.

Legal basis under GDPR: our legitimate interest (Article 6(1)(f)) in letting people evaluate Proxyma Enterprise Server, and in keeping the sandbox available by limiting requests per network address and capping what it spends.

4. Data Retention

Data How long we keep it
Order data from Lemon Squeezy webhook (name, email) Not retained — processed in transit only to generate the license key
Lemon Squeezy order number, stored with the license it created As long as the license exists
License device registry (license key, random installation identifier) As long as the license exists. Releasing a device in Settings → License → Release deletes its entry immediately. A refunded or revoked license stops working, but its remaining entries are kept as the record of which devices it was used on; write to us and we will delete them
Free trial record (one-way hash of the operating system's identifier, and the trial license issued for it) For as long as we offer the free trial, so that each computer receives one. It identifies no person; write to us and we will delete it, after which that computer could start another trial
Telemetry and diagnostics reports (if you opted in) 12 months from receipt, then deleted. Diagnostics not yet sent are kept on your device for at most 30 days
Feedback: conversation transcripts (including a rated answer and its question) and attachments 90 days, then deleted
Feedback: rating, comment, version and contact address 2 years, then deleted
Support email correspondence 3 years after the last contact
Enterprise sandbox: everything visitors add (accounts, conversations, files, sources, connections, skills, key accounts) Until the next nightly reset, then deleted; not backed up. Content already sent to the sandbox's AI provider is kept under that provider's policy

5. Data Sharing

We do not sell or rent your personal data to anyone. Data flows only through these parties:

  • Lemon Squeezy (Lemon Squeezy LLC) — Merchant of Record and data controller for Personal, Professional and applicable Enterprise purchase and billing data. We keep no copy of this data beyond the order number and license key stored with your license (section 3.1).
  • Cloudflare, Inc. — DNS, CDN, DDoS protection and TLS termination for the proxyma.ai website, the license server (license.proxyma.ai), the diagnostics and feedback server (telemetry.proxyma.ai) and the Enterprise sandbox. Traffic to all of them passes through Cloudflare's edge network before reaching us.
  • An AI provider — subprocessor for individual requests. In the software you run, this is a provider you configure, and there is none by default (section 3.6). The Enterprise sandbox is the exception: it sends chat and indexing content to an AI provider we configure for it, a cloud AI service in the United States (section 3.8).
  • GitHub, Inc. — hosts Proxyma's releases. Proxyma Desktop and Home Server check it for updates, when they start and once a day by default (Settings → Updates), and download updates from it; like any web request, this shows your network address to GitHub. No license, document or usage data is sent.
  • The web search engine (DuckDuckGo, or Google if you configure a Google search key) — receives the words of the assistant's web searches and your network address (section 3.6).
  • The sites of space facts (NASA, ESA, HubbleSite, Wikipedia) — only while Show a space fact on the empty chat is on, receive your network address when Proxyma checks a fact's source page (section 3.6).
  • The email provider that hosts contact@proxyma.ai — receives the messages you send us, including rights requests.

6. International Data Transfers

We are based in Vietnam. Because we do not store purchase data beyond an order number, the personal data we directly handle is limited to what sections 3.1 to 3.3, 3.5 and 3.7 describe: that order number and the license records, diagnostics if you opt in, support email you choose to send us, and feedback and answer ratings sent from inside Proxyma; and, until each nightly reset, what visitors add to the Enterprise sandbox (section 3.8). Lemon Squeezy, as sole data controller for all purchase data, handles international data transfers under its own transfer mechanisms.

The license server, the diagnostics and feedback server and the Enterprise sandbox run in Vietnam, on hardware we operate ourselves rather than on a third-party cloud platform. Each of them uses the network address of a request in memory to limit how many requests one address may make, and does not log it. Requests reach them through Cloudflare's global edge network, which terminates TLS and forwards them over an outbound tunnel, so traffic to them is processed in transit at the Cloudflare edge location nearest you. If you are in the EEA, the diagnostics and feedback you send us are transfers to Vietnam, and visiting the sandbox means your request reaches Vietnam; what you add to it is stored in Vietnam until the nightly reset, and what it sends to its AI provider, a cloud AI service in the United States, is a transfer to that provider. Configuring a cloud AI provider under section 3.6 does transfer personal data to that provider. As the safeguard, we rely on the European Commission's Standard Contractual Clauses, or the recipient's own approved transfer mechanism where it has one. Running Proxyma yourself with a local model avoids both transfers entirely.

7. Your Rights

Rights under GDPR (EEA users)

  • Access — request a copy of the personal data we hold about you
  • Rectification — request correction of inaccurate data
  • Erasure — request deletion of your personal data
  • Restriction — request that we limit how we use your data
  • Portability — receive your data in a structured, machine-readable format
  • Objection — object to processing based on legitimate interest
  • Withdraw consent — for diagnostics and answer ratings, turn off Send diagnostics to Proxyma at any time in Settings → About → Privacy
  • Complain to a supervisory authority — lodge a complaint with the data protection authority of the EEA country where you live or work, or where you believe the problem occurred. You are not obliged to contact us first

Rights under Vietnamese law

Vietnam's Law on Personal Data Protection gives you equivalent rights over the personal data we hold: to know what we process and why, to access, correct and have it deleted, to withdraw consent, to restrict or object to processing, to receive a copy, to complain, and to be told about a breach affecting your data. To exercise any of them, write to contact@proxyma.ai, or complain to the Ministry of Public Security's Department of Cybersecurity and High-Tech Crime Prevention (A05).

Wherever you are, you exercise any of these rights by writing to contact@proxyma.ai. It is free. Write from the email address you bought with, or include your license key or order number. For diagnostics or answer ratings, include your installation identifier (Settings → About → Privacy → See what would be sent) and roughly when you sent feedback. For a trial record, include the contents of the file machine-id in Proxyma's data folder (%LOCALAPPDATA%\proxyma on Windows, ~/.local/share/proxyma on Linux). We acknowledge your request within 2 working days and complete it within 10 days. If a service provider such as Lemon Squeezy has to act, or a request is unusually complex, we may extend once by up to 10 days and will tell you why before the first 10 days end. If we cannot delete something, we tell you what and why: we keep the record of a license for as long as the license exists, to honor the purchase, refunds and revocation, and Lemon Squeezy keeps its own records under its policy.

8. Security

We implement appropriate measures to protect the personal data we directly handle (license records, diagnostics, support email correspondence, feedback and answer ratings, and, until each nightly reset, what visitors add to the Enterprise sandbox). Because Proxyma processes your documents locally on your own device or server, the security of your document content depends entirely on your own infrastructure. The Enterprise sandbox is shared by design, so it is not a place for anything that has to stay confidential (section 3.8).

9. Children

Proxyma is not directed at individuals under 16. We do not knowingly collect personal data from children. If you believe we have inadvertently received data relating to a child, contact us and we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top changes whenever this policy does, including for material changes; compare it with the date you last read it to see whether anything has changed. We keep no mailing list and cannot notify you individually, because we hold no email address for you unless you have written to us.

11. Contact

Questions about this Privacy Policy: contact@proxyma.ai