Ethical mobile proxy use: where we draw the line in 2026
Ethical mobile proxy use: where we draw the line in 2026
We turn down work most months. Usually it is credential stuffing dressed up as “account recovery”, occasionally it is someone who wants a few hundred ports to register accounts in bulk on a platform that plainly forbids it. We say no, and not because we are precious about it. A provider whose IPs get burned on that kind of traffic has a worse product for everyone else the following week.
This is the guide the rest of our posts point at when they mention responsible use. It is written from the infrastructure side, so it is about what we can actually see and control, rather than a legal opinion.
Where the IP comes from is the first ethical question
Most of the “is this ethical” argument in the proxy industry is really an argument about sourcing, and it gets skipped because the answer is uncomfortable for a large part of the market.
A residential proxy pool has to get its addresses from somewhere. Overwhelmingly that means consumer devices, and consumer devices join those pools through an SDK bundled into a free app or VPN. The user technically agreed, in the sense that a consent screen existed. Whether a person installing a free flashlight app understood that their home connection would carry a stranger’s commercial traffic is a different question, and it is the one the industry mostly avoids.
Our answer to that question is structural rather than a policy. Every IP we sell comes from a SIM card we bought, in a modem we own, in a rack we pay for, on a Singtel, StarHub, M1 or Circles plan in our own name. There is no third-party device owner in the chain, so there is no consent problem to hand-wave about. The tradeoff is that this is expensive and it caps how fast we can grow, which is why we sell one port at $40 rather than thousands of rotating residential IPs at a lower price.
Call that a different business model rather than a moral position. Ours has its own failure modes and plenty of them. But it does mean the sourcing question has a clean answer here, and it is worth asking any provider you buy from to give theirs.
What platform terms actually say, and what people pretend they say
Almost every major platform prohibits automated access and multiple accounts in its terms. That is not ambiguous and it is not a grey area, whatever the forum consensus says.
What is genuinely unsettled is the legal weight of a terms-of-service breach, which varies by jurisdiction and by what else you did. Scraping public data has been litigated repeatedly and the outcomes are not consistent. Running many accounts on a consumer platform is a contract question in most places and not a criminal one, right up until it touches fraud, another person’s credentials, or protected data.
The distinction that matters operationally is a simple one. Are you reading something anyone can see, or are you acting as someone you are not?
Reading public pages at a sane rate is the low-risk end. Price checks, SERP positions, ad libraries, public profiles. You may still be breaching a ToS, and you should know that you are, but nobody is harmed and the failure mode is a blocked IP.
Acting as a person who did not authorise you is the other end, and no proxy makes that acceptable. Logging into accounts you were not given, using someone else’s identity documents, taking over a page because you gained access to an email. We do not want that traffic, and a carrier IP does not launder it.
Most real work sits in the middle: an agency running its own clients’ accounts, a seller with several legitimate storefronts, a QA team testing an app from a market they do not live in. That work is fine by us, and it is most of what our ports do.
The things we say no to
Being specific here is more useful than a values statement.
- Credential stuffing and account takeover, in any framing. This is the most common request we refuse.
- Bulk fake account registration on platforms that forbid it. Registering accounts for yourself is one thing; farming them to sell is another.
- Anything touching SMS verification for accounts that are not yours. Our ports carry data, and we do not rent numbers for this reason.
- Scraping personal data at scale. Public and personal are not the same category, and PDPA is not something to find out about afterwards.
- Ad fraud, click fraud, and impression farming. Beyond the ethics, it puts carrier ranges on blocklists that our other customers then inherit.
- Anything aimed at Singapore government or banking systems. The Computer Misuse Act is real, we are a Singapore company, and this is not a line we are curious about.
If you are unsure whether your use case fits, ask before you buy. We would rather have the awkward conversation up front than issue a refund and clean up an IP afterwards.
Rate is an ethics question, not just a technical one
This gets treated as a performance tuning detail and it should not be.
An IP hammering a site at machine speed imposes real cost on whoever runs it, and on a small site that cost is not trivial. Pulling a page every few seconds from a company with a CDN is background noise. The same rate against an independent shop is a meaningful share of their bill.
Read robots.txt. It carries little legal weight in most places, and it is still the only mechanism a site owner has to state what they want. Ignoring it means you have decided your convenience outranks their stated preference.
Cache what you already fetched. A surprising amount of scraping traffic is the same pages repeatedly because nobody built a cache.
Identify yourself where you reasonably can. A user agent with contact details in it means an annoyed operator can email you instead of blocking the whole range.
What to have in place before you scale
If you are moving from a handful of profiles to a real operation, the useful things to be able to answer are practical:
Which accounts are you authorised to operate, and can you show it? For an agency that means something in writing from the client, not a verbal handoff.
What data are you collecting, and does any of it identify a person? If yes, you have data protection obligations regardless of how you collected it, and in Singapore that means PDPA.
What happens when you are wrong? Have a way to stop a job quickly and a person who owns that decision.
Have you actually read the terms of the platform you are working against, rather than assuming they match the last one?
None of that is legal advice, and I am not qualified to give any. If your operation is large enough that a mistake would hurt, pay a lawyer in your jurisdiction. The point of the list is that these are answerable questions, and the operations that get into trouble are usually the ones that never asked them.
The short version
We sell infrastructure, and infrastructure is neutral in the way a van is neutral. What we can control is where our IPs come from, who we sell to, and what we refuse. What you control is what you point them at.
If your work is reading public information at a reasonable rate, or operating accounts you are genuinely entitled to operate, you are in the space this product was built for. If it depends on being someone you are not, buy from someone else.