We own the network. Here’s how we run it.
Owning the network means owning the responsibility that comes with it.
7.5M+ Residential IPs
active monthly
150+ countries
USA, Germany, France, etc.
Prices dropped 3x
in last 12 months
Every customer is verified
Identity
Government ID or business registration for all accounts
Use case
Every customer describes their intended use. We review before activation.
Business entity
Enterprise accounts require company verification and a named contact.
Ongoing monitoring
Accounts with unusual traffic patterns are flagged for review within 24 hours.

What gets rejected:
We decline accounts where the stated use case involves credential stuffing, ad fraud, DDoS, spam, scraping of personal data without legal basis, or any activity that violates our Acceptable Use Policy.
Not every proxy provider does this. We do, because we own the IPs, abuse on our network is abuse of our infrastructure, not someone else’s.
How we prevent misuse
Owning the network means we see everything that runs through it. That’s a responsibility.
Real-time monitoring
Automated traffic analysis flags patterns associated with credential stuffing, brute-force attacks, and spam.
Dedicated abuse team reviews flagged accounts within 4 hours during business hours, 12 hours off-hours.
Accounts confirmed abusing the network are suspended immediately and permanently.
Reporting abuse
Anyone can report suspected abuse at abuse@geonode.com. We investigate every report within 24 hours and respond with an outcome.
Abuse response timeline
We've suspended paying customers for policy violations. Revenue isn't worth the network.
DDoS, credential stuffing
High-volume abuse patterns
Policy edge cases
What data we collect. What we don't.
What we collect
Account information (name, email, company, billing)
Usage metadata (bandwidth consumed, connection timestamps, target domains at aggregate level)
Payment information (processed by Stripe - we never store card numbers)
What we do NOT collect
Content of proxied requests or responses
Target page content, scraped data, or downloaded files
Individual URL-level logs beyond aggregate domain statistics
IP-to-user mapping retained beyond 30 days (required for abuse investigation only)
Data retention
Account data: Duration of account + 12 months post-deletion
Abuse investigation logs: 31 days, then purged
Payment records: As required by tax law (~7 years)
Your rights (GDPR, CCPA, and equivalents)
Request a copy of all data we hold on you
Request deletion of your account and associated data
Opt out of non-essential communications
Where IP comes from
Our sourcing principles
Clear, informed consent from any device contributing to the network
Regular audits of IP source quality and consent compliance
We do not purchase traffic from apps that bury proxy consent in Terms of Service.
FAQ
Common reporters include: site owners noticing unusual traffic patterns, law enforcement (we cooperate with valid legal requests), security researchers, and our own internal monitoring systems.
We don't require a verified identity to file a report. We do verify the claim before taking action.
What we store:
- Account information (name, email, company, billing)
- Usage metadata (bandwidth consumed, connection timestamps, target domains at aggregate level)
- Payment information (processed by Stripe – we never store card numbers)
What we do not store:
- The content of your proxied requests or responses
- The pages or data you scrape
- Individual URL-level logs beyond aggregate domain statistics
Several competitors run data marketplace businesses alongside their proxy networks. Their incentive is to retain your data. We sell access, not your output.
Specifically:
- Lawful basis: Legitimate interest for operational data, contractual necessity for service delivery
- Data subject rights: Request a copy, request deletion, or opt out of non-essential communications — contact privacy@geonode.com
- Data Processing Agreement (DPA): Available on request
- Sub-processor list: Published and updated quarterly
- Data residency: EU and US options available for enterprise plans
- Retention: Account data deleted within 12 months of account closure; usage metadata retained on a rolling 90-day basis
We also comply with CCPA (California), LGPD (Brazil), and PDPA (South Africa).
Repocket users explicitly opt in to share spare residential bandwidth in exchange for monthly payouts. Zenshield users opt in for free VPN service; their spare bandwidth becomes part of our pool while they're not using the device. Both apps:
- Show the consent screen before any bandwidth is shared
- Allow opt-out at any time
- Pay users for the bandwidth they contribute
- Publish the legal basis for the network's operation
We do not source IPs from:
- Browser extensions that harvest bandwidth without clear user consent
- Apps that bury proxy consent in Terms of Service
- Bundled SDK models where proxy participation is hidden in unrelated apps
Our 2.5M pool is smaller than some competitors' 100M+ pools because we reject these sourcing methods. Every IP in our pool is clean.

