Network sourcing standards
This document sets out the standards under which WebGears Services d.o.o. (the “Company“) sources and operates the Proxy Network behind the CyberYozh Data Services. Ethics is built into how we run our platform. Open-source code is just the starting point; how data is collected and how proxies are sourced matters just as much. These are the standards we follow in practice, not statements on a page. This document is binding on us and on the partners who supply our network, and it should be read together with our Terms of Service, Use Policy, Customer Verification Policy, Restricted Targets Policy, Privacy Policy, Cookie Policy and Payment and Refund policy.
1. Scope and How This Fits the Platform
1.1 CyberYozh Data has two sides. Our open-source tools — the self-hostable Scraper engine and the Yozh Crawler, which walks a site from a start URL, streams the pages it discovers and fetches each one through the Scraper over HTTP — are code you can run yourself. Separately, we operate an ethically-sourced Proxy Network that routes requests for Clients who buy proxy traffic or managed scraping.
1.2 This Policy governs the Proxy Network specifically: where its IP addresses come from, how the people and infrastructure behind them participate, and how we vet both our suppliers and our Clients. It reflects the second of our three pillars — Transparent proxy network — and connects to the other two, Ethical data collection (the Scraper and crawler) and Fast abuse response (Section 9).
1.3 If you self-host our open-source tools and route requests through your own infrastructure rather than our network, this Policy does not restrict you — but your own sourcing and use remain your responsibility, and our Terms of Service and Use Policy still apply.
2. Residential and Datacenter Sourcing at a High Level
2.1 Our network is built from two types of IP addresses. Datacenter IPs come from infrastructure we own, lease or obtain from ISP and hosting providers under commercial contracts. Residential IPs come only from real devices whose owners have chosen to participate as peers, through a disclosed software development kit (“SDK“) or application.
2.2 Residential participation is never automatic. A device becomes part of the network only after its owner opts in, and only on the terms described in Sections 3 to 6. We do not build residential capacity from botnets, malware, hijacked routers or any other source that bypasses the device owner’s knowledge and consent.
3. Informed Consent and Opt-In of Peers
3.1 A peer joins the residential network only after seeing a clear consent screen, written in plain language, that explains what participation means and that their device may be used to route traffic. There is no silent enrollment and no pre-ticked default.
3.2 The application or SDK that offers participation must present the choice in a clear, native interface with an accessible settings menu, so a peer can see their status and change it at any time.
4. Fair Compensation and Value Exchange
4.1 Every peer, or the host application they use, receives a clear and disclosed benefit in return for participating — for example an ad-free experience, premium features or a comparable value exchange. Participation is a fair trade, not something taken without return.
4.2 The nature of the benefit is disclosed before opt-in, so the peer understands what they receive in exchange for their bandwidth.
5. Right to Withdraw
5.1 Opting out is simple and always available. A peer can withdraw from the network in a couple of clicks through the same application, and no ongoing enrollment or reason is required.
5.2 When a peer withdraws, participation stops. We do not continue routing traffic through a device once its owner has opted out.
6. No Malware, No Hidden Bundling, No Device Harm
6.1 The residential SDK is disclosed openly and must be safely downloadable. It is not bundled secretly with unrelated software and is designed not to be classified as a potentially unwanted application by antivirus vendors.
6.2 On the peer’s device we keep our footprint minimal. Where applicable we route traffic only while the device is idle, we do not degrade its performance, we touch only the data essential to function as a proxy, and we do not modify a peer’s own traffic in transit.
6.3 We never knowingly use IP addresses sourced from botnets, malware, trojans or compromised devices, or obtained without the device owner’s awareness. This prohibition is absolute. Recent industry incidents have shown that a label such as “ethically sourced” means nothing without verifiable, auditable practice behind it, which is why we state this refusal explicitly rather than assume it.
7. Vetting and KYC of Supply Partners
7.1 Partners who supply residential capacity are vetted before onboarding and are contractually required to obtain and document the informed consent and awareness of the end users behind their IPs, in line with Sections 3 to 6.
7.2 If a partner falls below these standards, we suspend and terminate the relationship and remove the affected supply from the network.
8. Vetting and KYC of Clients
8.1 Sourcing standards work in both directions. Before granting access to proxy traffic or managed scraping, we verify Client identity and review the declared use case. The authoritative identity-verification and know-your-customer requirements are defined in our Customer Verification Policy, which governs this vetting; this section defers to that Policy rather than restating its steps.
8.2 Access is limited to permitted uses as set out in the Use Policy. Where a declared or observed use case is prohibited or high-risk, we may decline, restrict or revoke access.
9. Auditing, Monitoring and Enforcement
9.1 We audit supply partners on a periodic basis and monitor the network on an ongoing basis for signs of unethical or prohibited behavior, and we reserve the right to audit supply and demand at any time.
9.2 Enforcement is fast, in keeping with our Fast abuse response pillar. Accounts or supply involved in suspicious or prohibited activity can lose access immediately, and every abuse report we receive is investigated individually. Reports can be sent to abuse@cyberyozh.com, and we acknowledge them within one business day.
10. Data Privacy, Governance and Changes
10.1 We minimize the personal data we collect from network participants and handle it as described in our Privacy Policy. Our network is designed to align with GDPR and CCPA principles; where we design to a standard rather than hold a formal certification, we say so plainly.
10.2 This Policy is owned by the Company, WebGears Services d.o.o., registration number 22038745, with a legal address at Jurija Gagarina 231/329, Novi Beograd, Beograd, Serbia. We may update it from time to time; changes take effect on publication.
11. Contact and Reporting
11.1 To report abuse, misuse of the network or a sourcing concern, email abuse@cyberyozh.com, and we will acknowledge your report within one business day. For general help, contact support@cyberyozh.com or help@cyberyozh.com, or reach us on Telegram at @CyberYozh_support_bot. You can find our tools and documentation at cyberyozh.com and manage your account at app.cyberyozh.com.
12. Related policies
This Policy works together with the other documents in our Legal Center: