Privacy Policy
This Privacy Policy explains how MONI TECHNOLOGY CO., LTD. ("Moni Technology", "we", "us", or "our") handles information in connection with the Moni Proxy mobile and desktop applications and the moniproxy.com website (together, the "Service"). We have built Moni Proxy to be local-first: the core of the product runs entirely on your device, and we collect as little information as possible.
This policy is written to comply with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and the privacy requirements of the Apple App Store and Google Play.
1. Who we are (Data Controller)
The data controller responsible for your information is MONI TECHNOLOGY CO., LTD., the developer and publisher of Moni Proxy. You can reach us at any time at [email protected] for any privacy-related request.
2. Local-First Architecture & Summary
Moni Proxy works as a local proxy that runs inside your own device. When you enable inspection, the app shows you the content of the HTTP and HTTPS requests your device makes so you can debug them. This inspection happens entirely on your device.
- We do not collect your traffic. Captured requests and responses — including URLs, headers, query parameters, cookies, authorization tokens, and request/response bodies — are never logged, uploaded, transmitted, or stored on our servers.
- We do not sell or share your personal information for advertising or any other purpose, as those terms are defined under the CCPA/CPRA.
- No advertising or tracking SDKs are embedded in the app.
3. Information We Process
We process only the limited categories of data described below.
- Data that stays on your device (we never receive it): captured sessions, pinned/favorite endpoints, rules (Map Local, rewrite, breakpoints, DNS overrides, block lists), scripts, Compose workspaces, app settings, and the locally generated certificate. This data lives in your operating system's app sandbox and is removed when you delete the app.
- Purchase & subscription data: when you buy Moni Proxy Pro, the transaction is processed by Apple or Google. We receive only the limited purchase and entitlement information their billing systems return (for example, a product identifier and whether a purchase is active). We do not receive your full payment card details.
- Desktop license data: if you buy a desktop license on our website, our payment provider processes your email address and payment to deliver and validate your license key. License verification in the apps is performed with a local signature check and does not phone home on every launch.
- Support communications: if you email us, we receive your email address and the contents of your message so we can respond.
- Diagnostics (optional): the operating system's own crash reporter (Apple / Google Play) may share anonymous, aggregated crash diagnostics with us only if you have enabled that sharing in your OS settings. These reports do not contain your captured network content.
4. How We Use Information & Legal Bases (GDPR)
We use the limited data above to: provide and maintain the Service; validate purchases and unlock Pro features; deliver and verify desktop license keys; respond to support requests; and detect, prevent, and address technical issues or abuse. Where GDPR applies, our legal bases are: performance of a contract (providing the app and your purchases), legitimate interests (keeping the Service secure and working), and consent (optional diagnostics), which you may withdraw at any time.
5. Payments & Third-Party Processors
We do not use any third-party analytics or advertising providers. The only third parties that process data on our behalf are the payment platforms required to sell the app:
- Apple App Store and Google Play process in-app purchases and subscriptions under their own privacy policies.
- Our desktop checkout provider processes website purchases of desktop license keys under its own privacy policy.
These providers act as independent controllers or processors for the payment data they handle; please review their privacy policies for details.
6. The Local Certificate
To let you view the content of HTTPS requests, the app helps you install and trust a Certificate Authority (CA) that is generated uniquely on your own device. Because the certificate is created locally and its private key never leaves your device, it cannot be used by anyone else to view your traffic. You can remove or stop trusting this certificate at any time in your operating system settings, and you should only keep it installed while you are actively using Moni Proxy.
7. Data Retention
Because captured data never reaches us, its retention is fully under your control on your device — the free tier retains session history for the last 7 days and Pro retains it until you delete it. Purchase and license records are retained only as long as necessary to provide the Service, honor entitlements (including lifetime purchases), and meet legal, tax, and accounting obligations. Support emails are retained only as long as needed to assist you.
8. Your Privacy Rights (GDPR & CCPA/CPRA)
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information; to restrict or object to certain processing; to withdraw consent; and, under the CCPA/CPRA, to opt out of the "sale" or "sharing" of personal information (note: we do not sell or share it) and not to be discriminated against for exercising your rights.
To exercise any of these rights, email [email protected]. We will respond within the timeframe required by applicable law. Most on-device data can be erased immediately by you (see Section 9). You also have the right to lodge a complaint with your local data protection authority.
9. How to Delete Your Data
- On-device data: clear sessions and rules inside the app, or uninstall the app to remove all locally stored data, including the locally generated certificate material managed by the app.
- Purchase records: subscriptions are managed and cancelled through your Apple or Google account; we cannot delete records Apple or Google are required to keep.
- Account-level deletion request: email [email protected] and we will delete the limited data we hold about you (such as support correspondence and, where permitted, license records).
10. Children's Privacy
Moni Proxy is a developer tool intended for professional and technical users. It is not directed to children, and we do not knowingly collect personal information from children under 13 (or under the minimum age required by your jurisdiction, such as 16 in parts of the EU). If you believe a child has provided us with personal information, contact us and we will delete it.
11. International Data Transfers
We are based in Vietnam, and our payment processors may operate globally. Where personal information (such as purchase or support data) is transferred internationally, we and our processors rely on appropriate safeguards, such as the relevant standard contractual clauses, where required by law.
12. Security
We apply reasonable technical and organizational measures to protect the limited information we process. However, no method of transmission or storage is completely secure. Because Moni Proxy installs a trusted certificate on your device, you are responsible for protecting your device with a passcode or biometric lock to prevent unauthorized physical access.
13. Changes to this Policy
We may update this Privacy Policy to reflect changes to the Service or legal requirements. We will post the updated version here and revise the "Last Updated" date. Material changes will be communicated through the app or website where appropriate.
14. Contact Us
For any questions, requests, or complaints regarding this Privacy Policy or your personal information, contact MONI TECHNOLOGY CO., LTD. at [email protected].