Skip to content

Legal

All legal documentation, operator details, liability, data policy, and architectural disclosures — in one place.


Service Operator

Field Value
Legal form Individual Entrepreneur (ИП / sole proprietor)
Name IP Sakhno Roman Alexandrovich
INN (Tax ID) 614104707933
OGRNIP (Business ID) 323237500434312
Website dix.su
General email admin@dix.su
Data / privacy email dixsu@itdid.ru
Abuse email abuse@dix.su

MCC Code

MCC 4816 — "Computer Network Services" — the same code used by ngrok and Cloudflare Tunnel. No telecommunications license is required.

Jurisdiction

Russian Federation. Disputes are handled by courts at the Operator's location.

Law Subject
152-FZ Personal Data (primary)
149-FZ Information, IT and Information Protection
436-FZ Protection of Children from Harmful Information
187-FZ Anti-piracy law
Criminal Code Art. 242, 242.1, 242.2 CSAM
Criminal Code Art. 280, 205.2 Extremism
Criminal Code Art. 159 Fraud
Criminal Code Art. 273 Malware

Data protection supervisory authority: Roskomnadzor (rkn.gov.ru).


Document RU EN
Terms of Service dix.su/terms dix.su/en/terms
Privacy Policy dix.su/privacy dix.su/en/privacy
Acceptable Use Policy dix.su/aup dix.su/en/aup
Data Deletion dix.su/data-deletion

Document hierarchy

The Terms of Service is the primary document. The Privacy Policy and AUP are integral parts of it. In case of conflict, the latest version of the respective document takes precedence.


Technical Intermediary Position

dix.su acts as a technical intermediary (similar to a hosting provider or CDN). The Operator provides network infrastructure and has no access to the content of resources published through the tunnel. Full responsibility for content rests with the user (ToS §3.2).


Liability and Refunds

Liability Caps by Plan

Plan Operator liability cap
SIMPLE (free) 0 ₽ — access is provided free of charge
VIP ≤ amount paid for the current 30-day billing period
PRO ≤ amount paid for the current 30-day billing period
PERS ≤ amount paid for the current 30-day billing period
GLAVA ≤ amount paid for the current 30-day billing period

Refund Policy

Situation Resolution
Voluntary cancellation mid-period No refund. Plan remains active until end of paid period.
Account blocked for ToS / AUP violation No refund.
Service outage caused by Operator > 24 consecutive hours On request to admin@dix.su — proportional plan extension.
Full service shutdown Refund for unused portion of period — within 30 days of notice.

Resale prohibition

Resale, sublease, or commercial transfer of access to the infrastructure to third parties without the Operator's written consent is prohibited (AUP §4.2). For B2B integration or white-label enquiries, contact admin@dix.su.


Personal Data

What We Collect

Data Required Source
Email Required Form / OAuth providers
Name, avatar, bio Optional Profile / OAuth
Phone number Optional Profile
Ethereum wallet address Optional MetaMask in profile
OAuth identifiers When signing in via social account Google, GitHub, VK, Facebook, Yandex, Telegram
IP address, User-Agent Automatically Server logs
Tunnel data (IP, timestamps) Automatically when using tunnels Proxy service

Retention Periods

Data Retention
Account data (email, profile) Until deletion or 3 years of inactivity
IP addresses and tunnel logs 30 days, then auto-deleted
Deleted account data 30-day recovery buffer, then destroyed

Cross-border Data Transfer

User data is stored on servers in the Russian Federation. When signing in through a foreign OAuth provider, cross-border transfer occurs with the user's consent (152-FZ Art. 12):

Provider Data transferred Country
Google (Google LLC) Email, name, avatar USA
GitHub (Microsoft) Email, login, avatar USA
Facebook (Meta) Email, name, avatar USA
VK (VK Online Technologies) Name, avatar, VK ID Russia
Yandex ID Email, login, avatar Russia
Telegram (Telegram Messenger) Name, avatar, Telegram ID UAE

GDPR / International Users

For users from EU/EEA: the service complies with core GDPR requirements — cookie consent banner, English versions of all legal documents, rights to access, rectify, and delete data. Users are notified by email of material policy changes.

Data Subject Rights


Tunnel Architecture and Data Security

dix.su is a centralised reverse-proxy tunnel (like ngrok or frp). The user's device establishes an outbound WebSocket connection to the server. There is no P2P connection between visitor and device.

Visitor → HTTPS → nginx (*.dix.su) → dixu_proxy → WebSocket → device_client → localhost:PORT

Two Tunnel Modes

Mode Address Where TLS terminates What the Operator sees
Public slug.dix.su On dix.su server (wildcard certificate) Technically — decrypted traffic (like any reverse proxy / CDN). The Operator does not monitor content.
Private E2E e2e-<token>.dix.su On the user's device (Let's Encrypt via DNS-01/ACME) Encrypted bytes only — blind relay. Private key never leaves the device.

Private E2E tunnel

When using private_mode, the Operator is technically unable to read the tunnel traffic. See Security for details.


Billing

Payment Methods

Method Status Notes
T-Bank (Tinkoff) — Russian cards ✅ Active Russian acquiring, Visa/MC/Mir
Lemon Squeezy — international cards 🔧 In progress Code ready; activation blocked by IBAN/routing requirement (Stripe Connect). Planned via Payoneer.

Billing period: 30 days. For payment questions, contact admin@dix.su within 14 days of the transaction.


Acceptable Use — Summary

Full text: dix.su/aup · dix.su/en/aup

Allowed Use Cases

Smart home, IP cameras, personal cloud (Nextcloud), media server (Jellyfin, Plex), personal website, Git repository, messengers, monitoring, password manager, development and testing, databases and APIs — anything running on your own hardware.

Absolute Prohibitions

  • CSAM — immediate block + report to law enforcement and NCMEC
  • Terrorism and extremism (as defined under Russian law)
  • Illegal content: drugs, illegal weapons, counterfeit goods, personal data leaks
  • Phishing, malware, DDoS, C2 servers
  • Spam and unsolicited mass mailings

Response Times for Complaints

Violation type Response time
CSAM, terrorism Immediately, 24/7
Phishing, malware Within 24 hours
Fraud, scam Within 48 hours
Other violations Within 72 hours

Violation of the rules is grounds for immediate account termination without prior notice and without a refund.


Contacts

Topic Contact
General questions, billing, technical issues admin@dix.su
Personal data, deletion requests, consent withdrawal dixsu@itdid.ru
Abuse complaints, harmful content abuse@dix.su
B2B, white-label, partnerships admin@dix.su

Frequently Asked Questions

Is dix.su liable for the content of tunnels?

No. dix.su is a technical intermediary: it provides network infrastructure but has no access to the content of resources published through the tunnel. All responsibility for content rests with the user (ToS §3.2). The position is equivalent to a hosting provider or CDN.

Can I resell tunnel access?

No. Resale, sublease, or commercial transfer of access without the Operator's written consent is prohibited (AUP §4.2). For B2B integration — admin@dix.su.

Is the service GDPR-compliant?

For EU/EEA users, core GDPR requirements are implemented: cookie consent banner, English versions of all documents, right to access and delete data, notification of policy changes. Primary regulator: 152-FZ (Russia). Supervisory authority: Roskomnadzor (rkn.gov.ru).

How do I delete my data?

Via dix.su/data-deletion or by request to dixsu@itdid.ru. After account deletion, data is retained for 30 days (recovery buffer), then destroyed.

Which court handles disputes?

Court at the Operator's location (Russia). Governing law: Russian Federation.

At dix.su/terms, dix.su/privacy, dix.su/aup and dix.su/data-deletion. English versions at /en/ prefix paths.