← back to blog

What your proxy provider can actually see

mobile-proxy logging privacy singapore operations

What your proxy provider can actually see

One connection through my farm writes one row to disk. Roughly this shape:

2026-08-04T14:07:22+08  port 8241  line m1-07  src 118.x.x.x
dst api.example.com:443  up 41KB  down 2.9MB  ok  238s

Nine fields. It sits there for thirty days and then it is deleted.

Most arguments about proxy privacy would finish early if sellers just published that row. Instead you get “zero logs” set in a large font, and a buyer who has no way of knowing whether a destination column exists at all.

I run the hardware. The SIMs are registered to my company, the modems sit on shelves in my house, and I hold root on the machines writing that row. So this is my own setup, not a guess about somebody else’s.

The destination column is not optional

People assume encryption hides where they are going. Encryption starts after the proxy has been told where to go.

An http proxy gets a request that opens with CONNECT, then the hostname, then the port, in plain text, because that is the only way it can dial out on your behalf. SOCKS5 does the same handshake in a different byte layout, and your client hands over either a name or a raw address.

Suppose your client only ever passes raw addresses. The TLS handshake that follows still carries the hostname in the clear, in the SNI field of the first message your machine sends. Anything sitting in the flow reads it without effort. Encrypted ClientHello removes that on the slice of the web that has switched it on, mostly behind one large CDN, and everywhere else the name is right there.

So a provider does not get to choose whether the destination is visible. The only decision is whether it gets written down.

Where the visibility stops

Once the tunnel is up I am relaying encrypted bytes and nothing else.

No path, no headers, no cookies, no session token, no request body, no response. The row above tells me a port talked to a hostname for two hundred and thirty eight seconds and moved about three megabytes. It cannot tell me which endpoint, which account, or what came back.

Getting past that needs a certificate my box controls and your machine trusting it. Corporate networks do this every day, and it starts with something installed on the client. Nothing gets installed on your client by buying a proxy.

Port 80 is the exception, and it deserves a sentence of its own. Plain http means the request line, the headers and the body pass through in the open. Most of the web moved on years ago. Plenty of the small JSON endpoints people scrape did not, and if your job hits one of those, every hop between you and it can read the entire exchange.

Visible and stored are separate questions

Nothing technical stops me running a capture on my own machine and watching hostnames scroll past live.

Sit with that for a second, because it is true of every provider on earth and no policy page changes it. A privacy claim from a proxy seller is a statement about behaviour made by somebody with full capability. You are trusting a person, and it is worth being clear that is what you are doing.

Which is why a field list beats a slogan. A field list can be tested against how the business actually behaves when something goes wrong.

Billing needs the byte columns

A customer on a 200GB plan needs a counter he can argue with.

Last time one of my lines came back over cap, the customer was certain the number was wrong. With a monthly total and nothing else I would have had “trust me” as my only answer, which is a bad answer when the number costs him money. We walked the connection rows, found a retry loop refetching the same product page a few hundred times a day, and he fixed the loop instead of paying me more.

A provider who stores nothing cannot do that. He can send you an invoice and a shrug.

Abuse complaints need the destination column

The SIMs are in my company’s name. When traffic a carrier objects to leaves one of my lines, the complaint arrives at my door, and “I have no idea who was on it” is not a thing you say to a telco holding your entire inventory.

One landed nineteen days after the event. I looked up which port was live on that line at that minute, checked which account owned the port, replied with the destination host and the time, and the line stayed on.

That is the full extent of the capability: which customer, going where, when. The content was encrypted at the time and it does not exist now.

I do not enjoy that this column is there. It protects the farm rather than the buyer, and I would rather say that than describe it as a security feature.

A dead line needs the whole row

Somebody messages me saying his line is down. There are four candidates and they look identical from his side.

The modem lost its bearer. The carrier moved the address block under it. His credentials are wrong. Or the site at the far end is refusing him and he has read that as an outage.

The connection log separates them in about thirty seconds. A wall of refusals aimed at one hostname means the site said no. Nothing arriving at all means his traffic never reached me. Connections opening and dying in under a second means my radio. Strip the log out and all four become guesswork, with the customer waiting through it.

Retention, in numbers

Connection rows live thirty days, then they go.

Hourly usage counters live one year, because people ask about last quarter when they are planning budgets.

Invoice totals live five years, because Singapore requires business records kept that long and I do not get a vote.

The account record lives as long as the account does, which is the one nobody thinks to ask about even though it holds the email address.

Thirty days is the number to press any provider on. Carrier complaints show up weeks late. Debugging needs days. Past a month those rows have stopped being useful to me and become a liability sitting on a disk.

What a zero logs page is really telling you

A provider running real infrastructure who writes nothing down cannot bill accurately by usage, cannot answer a carrier notice, and cannot tell a customer why his line stopped. If a seller offers all of those and claims no records, one of the claims is decorative.

The answer worth trusting is duller. Field list, duration per class, who internally can read it, what makes it leave the company. Anyone who has genuinely thought about it can write that in four lines. Anyone who has not reaches for the word “strict”.

I am the smallest observer in your chain

My carrier sees the same metadata one layer out, plus the tower and the SIM identity, held under their rules for their reasons.

The site you connected to has your request in full, because you sent it to them deliberately.

And whoever took your payment has your name or your wallet address, which identifies you far harder than a hostname and a byte count. If you paid me by card, that record on its own beats everything in my logs combined.

A proxy takes one observer out of the picture, the network you would otherwise have left from. The room stays crowded.

Eleven days when my policy was wrong

Rebuilding logging on one box, I turned on a verbose mode to check the field format, confirmed it looked right, and left it on. It ran about eleven days writing full request lines for any plain http passing through.

Almost nothing goes over plain http, so the file stayed small and most of it was health check traffic from my own monitoring. I deleted it and changed the default so verbose has to be set per run and dies with the process.

Still, for eleven days what I said I did and what I did were two different things, and I found it while looking at disk usage for an unrelated reason. Nobody audits me. I audit myself, unevenly, when something else prompts it. If you need a provider who can prove this class of claim, you want one paying for an external audit, and I do not.

The questions to ask

Which fields do you write per connection. How long does each class survive. Who outside your team can reach the boxes. What happens when a carrier or a law enforcement request arrives, and will you tell me it happened.

Then the one people skip: is this line shared with anyone else right now. On a shared pool your connections sit interleaved with four other customers on the same address, and untangling them afterwards is guesswork for all five of you.

How quickly the answer comes back tells you as much as the answer. Somebody who runs the hardware knows the field list from memory. Somebody reselling another company’s pool has to ask upstream, and often never finds out. If you want lines where the person answering that question is the one who wrote the logging, that is what I run.

Get new guides and videos first — join the Telegram channel.

ready to try Singapore mobile proxies?

24-hour free trial. no credit card required.

start free trial
message me on telegram