§ Terms of Service · Last updated 2026-04-24

Terms of Service

Plain English. These terms tell you what you can expect from Oxshield and what we expect from you. By creating an account or using the service you accept them. If anything is unclear, email us (see §11) — we'd rather explain than hide behind words.

1. Who we are

Oxshield is operated by Oxshield Labs, currently a UAE-registered entity. We run a subscription VPN service. Oxshield servers are built on an open-source foundation (Outline by Google Jigsaw, Apache 2.0), with no modifications to the underlying encryption or traffic-handling protocol. A BVI subsidiary and Cayman Foundation structure is planned for the network phase — these terms will be updated at that time and users will be notified.

2. The service

Oxshield routes your internet traffic through an encrypted tunnel to a server of your choosing. The tunnel protects your traffic from local network observation and helps circumvent censorship. Server capacity is provided partly by Oxshield-operated servers and partly by community contributors who run their own. You pay a flat monthly subscription; the free tier is a limited demo, not a permanent product.

We do not promise the service will bypass every geo-restriction or unblock every streaming platform. We do not promise absolute availability. We run the service with reasonable effort and transparent status updates.

3. Your account

You create an account with an email address and password. You are responsible for keeping your password safe. If you enable two-factor authentication (recommended), you are responsible for keeping your authenticator app or recovery codes safe — we cannot recover them for you. We do not sell or share account emails.

A future release will offer anonymous account-number signup (no email required). When it ships, it will be optional and offered alongside the current email flow.

4. Acceptable use

You may use Oxshield for any lawful purpose, including accessing information or services that your local jurisdiction restricts. We defend that right — a VPN that won't let you read the news in your own country is pointless. But “lawful” is load-bearing: these terms and applicable law apply end-to-end, and you are responsible for your own conduct on the network.

You must be at least 16 years old to create an account, or the age of digital consent in your jurisdiction, whichever is higher.

4.1. Strictly prohibited activity

Any of the following results in immediate account termination, key revocation across all devices, and — where required by law — cooperation with the relevant authorities. There is no grace period and no refund.

  • Child Sexual Abuse Material (CSAM). Accessing, distributing, hosting, producing, or soliciting any material depicting minors in sexual contexts. Reports received at abuse@oxshield.io are escalated without delay to NCMEC, INHOPE, and the applicable national reporting authorities.
  • Terrorism, violent extremism, and incitement to violence — including coordination, financing, recruitment, or glorification.
  • Human trafficking, modern slavery, or exploitation in any form.
  • Distribution of malicious software — viruses, worms, ransomware, spyware, stalkerware, botnet command-and-control traffic, credential stealers, or any software designed to compromise third-party systems without authorization.
  • Fraud — including phishing, vishing, business email compromise, payment fraud, identity theft, romance scams, investment scams, and fake-support scams.
  • Unauthorized access to third-party systems — hacking, credential stuffing, SQL injection, brute-force attacks, exploitation of security vulnerabilities without authorization, or port scanning at scale. Legitimate security research is welcome via abuse@oxshield.io under coordinated disclosure — not by attacking our production or third parties.
  • Denial-of-service activity — DDoS, reflection attacks, amplification, or packet flooding against any target.
  • Unsolicited bulk communication — email spam, SMS pumping, mass fake-account registration on third-party services, or scraping protected resources at scale.
  • Trafficking in restricted goods — controlled substances, firearms, explosives, counterfeit currency, stolen goods, or any item whose sale or transfer is restricted under applicable law.
  • Financial crime — money laundering, terrorist financing, tax evasion, market manipulation, insider trading, securities fraud, or circumvention of economic sanctions (OFAC, EU, UK, UN, or other applicable regimes).
  • Serious crime — any activity constituting a serious criminal offense under the laws of your residence, our place of incorporation, or the jurisdiction where the traffic terminates.

4.2. Prohibited on the Oxshield network specifically

  • Attempting to compromise, reverse-engineer, or overload our infrastructure, other customers' traffic, or contributor servers.
  • Reselling, redistributing, or sharing your access credentials with third parties without written permission. One paid subscription covers reasonable use for one household (up to 5 devices on paid tiers).
  • Operating the service as an open proxy, a Tor exit node, or a relay for automated traffic at a scale that degrades other users' connectivity.
  • Knowingly running a contributor server on a VPS whose provider's terms prohibit VPN traffic. You are responsible for your upstream hosting agreement.
  • Using the free tier in bad faith — for example by cycling through disposable email addresses to exceed the data cap. Free-tier users identified as evading the cap will be blocked from re-signup.

4.3. Intellectual property and DMCA

Oxshield respects copyright. We process takedown notices received at abuse@oxshield.io in good faith, though as a connectivity provider our visibility into specific content is limited. A valid notice identifies the allegedly infringing material with enough detail for us to locate it, identifies the rights-holder (or authorized representative), and contains a good-faith statement of belief that the use is not authorized. Repeat infringers have their accounts terminated.

Running torrent / P2P traffic is permitted on our paid tiers within reason, subject to the IP-rights rules above. Community-contributor servers may be flagged by contributors as P2P-allowed or P2P-disallowed; we respect the contributor's preference.

4.4. Sanctions and export controls

You may not use Oxshield from, or on behalf of any entity located in, a country or territory subject to comprehensive US / EU / UK sanctions (currently Cuba, Iran, North Korea, Syria, and the Crimea, Donetsk, and Luhansk regions of Ukraine). You may not be listed on any applicable restricted-party list (OFAC SDN, EU CFSP, UK OFSI, UN Security Council consolidated list).

This restriction is consistent with — and does not contradict — the general licenses issued by OFAC and equivalent authorities permitting personal communications services to ordinary residents of sanctioned jurisdictions. Where those general licenses apply, we follow them. Where they do not, we follow the sanctions rules.

4.5. Enforcement and law enforcement cooperation

Reports of violations should go to abuse@oxshield.io. We act on confirmed reports within one working day — typically by immediate account termination, key revocation across all registered devices, and retention of the billing / authentication metadata that we are legally required to keep.

We cooperate with lawful legal process (subpoenas, MLATs, court orders) issued by authorities with proper jurisdiction. We challenge process we consider overbroad or improper. We cannot produce VPN traffic content that we do not log — we can confirm account existence, billing status, and last authentication timestamps, which is the scope of what we retain.

5. Contributor servers

You can run your own Oxshield server and register it with us. In exchange you receive free Premium access while your server meets the uptime threshold. Contributor servers are operated by their owners, not by us. We verify identity and server health during onboarding. We do not verify each server's underlying VPS provider's terms; you are responsible for your own hosting agreement. You may remove your server from the directory at any time.

6. Payment and refunds

Subscriptions are billed monthly, at a flat rate stated on the pricing page. Payments are processed by Polar (Polar Software Inc.), which acts as the merchant of record and handles any applicable VAT or sales tax.

If the service does not work for you in the first 14 days, email us for a full refund. After 14 days, cancellations stop future billing but do not refund the current period. There are no long-term contracts, no auto-renewal price hikes, and no multi-year lock-in plans by design.

7. Suspension and termination

You can close your account at any time from the dashboard. We may suspend or terminate your account for a material violation of §4 (acceptable use), a confirmed payment failure after reasonable retry, or where required by a lawful order from a competent authority. In all cases we will attempt to notify you at the email on file unless doing so would violate a legal order.

8. Limitation of liability

The service is provided as-is. To the extent permitted by applicable law, Oxshield Labs is not liable for indirect, consequential, or special damages; lost profits; or damages exceeding the amount you paid to us in the twelve months preceding the claim. Nothing in these terms limits liability for fraud, willful misconduct, or where limiting liability is prohibited by law.

9. Governing law and disputes

These terms are governed by the laws of the United Arab Emirates. Any dispute is resolved first by good-faith negotiation; if not resolved within 30 days, by the DIFC Courts in Dubai. When Oxshield transitions to the planned BVI subsidiary / Cayman Foundation structure, governing law will be updated accordingly and users will be notified in advance.

10. Changes to these terms

We may update these terms. Material changes will be announced by email and in the dashboard at least 14 days before they take effect. Minor edits (clarifications, typos) are published immediately with the "Last updated" date bumped.

11. Contact

Questions, complaints, or legal notices: hello@oxshield.io. DMCA takedown notices, abuse reports, or security disclosures: abuse@oxshield.io. Billing or technical support: support@oxshield.io. We read everything and respond within 5 working days.