Setting Up a Local HTTP Proxy on Android with Termux & Privoxy (No Root)

13 min read Learn step‑by‑step how to install Termux, configure Privoxy as a local HTTP proxy on Android, route traffic through it, and troubleshoot common issues—all without rooting. October 08, 2026 20:00 How to Set Up a Local HTTP Proxy on Android with Termux & Privoxy (No Root)

Before you start

Running a local HTTP proxy on Android lets you filter, cache, or modify web traffic without installing a system‑wide VPN or rooting the device. This guide assumes you have a fairly recent Android version (7.0+), a stable Wi‑Fi connection, and at least 200 MB of free storage for Termux and its packages.

What you’ll need:

  • Google Play Store or F‑Droid access to install Termux.
  • A Wi‑Fi network (cellular data can be used, but the proxy setup differs slightly).
  • Basic comfort with a Linux‑style command line.

Safety note: The proxy runs entirely in user space, so it cannot alter system files. However, routing all traffic through a local proxy may expose you to privacy risks if the proxy configuration is left open to other apps. Keep the proxy port blocked by a firewall when not in use.

Step 1 – Install Termux and update its package repository

  1. Open the Play Store (or F‑Droid) and search for Termux. Install the official app.
  2. Launch Termux. The first launch will populate a minimal Linux environment.
  3. Update the package list and upgrade existing packages:
    pkg update && pkg upgrade -y

    This may take a few minutes; allow the process to complete.

  4. Install the nano editor (optional but handy for editing config files):
    pkg install nano -y

If you see a warning about storage permissions, grant Termux access via Settings > Apps > Termux > Permissions > Storage. Without this, Privoxy will not be able to write its log file.

Step 2 – Install Privoxy

  1. Privoxy is available in the Termux community repository. Install it with:
    pkg install privoxy -y
  2. Verify the installation by checking the version:
    privoxy --version

    You should see something like Privoxy 3.0.33 printed.

Privoxy runs as a user‑space HTTP proxy on a configurable port (default 8118). It does not require root privileges, which makes it ideal for our purpose.

Step 3 – Configure Privoxy for local use

  1. Open the default configuration file with nano:
    nano $PREFIX/etc/privoxy/config
  2. Locate the line that starts with listen-address. By default it reads listen-address 127.0.0.1:8118. This is already suitable for a local proxy, but you can change the port if another app is using 8118.

    Why this matters: The proxy must bind to 127.0.0.1 so that only the Android device itself can reach it. Binding to 0.0.0.0 would expose the proxy to the local network, which is a security risk.

  3. Optional: Enable logging for troubleshooting. Find the line logfile /var/log/privoxy/logfile and uncomment it (remove the leading #). Ensure the directory exists:
    mkdir -p $PREFIX/var/log/privoxy
  4. Save the file (Ctrl+O, Enter) and exit nano (Ctrl+X).

At this point Privoxy is ready to run, but we’ll add a small wrapper script to keep it alive when the screen turns off.

Step 4 – Create a start‑up script

  1. Create a script called start‑privoxy.sh in your home directory:
    nano ~/start-privoxy.sh
  2. Paste the following content:
    #!/data/data/com.termux/files/usr/bin/sh
    # Prevent the device from sleeping while Privoxy runs
    termux-wake-lock
    # Start Privoxy in the background
    privoxy $PREFIX/etc/privoxy/config &
    # Keep the script alive so Termux does not close the session
    wait
  3. Make the script executable:
    chmod +x ~/start-privoxy.sh
  4. Run the script:
    ~/start-privoxy.sh

    You should see no output; Privoxy is now listening on the port you configured.

Note: The termux-wake-lock command keeps the CPU awake, preventing Android from killing the process when the screen turns off. If you prefer the proxy to stop when you’re not actively using the device, omit that line.

Step 5 – Point Android’s Wi‑Fi proxy to the local server

  1. Open Settings > Network & internet > Wi‑Fi (wording may vary by manufacturer).
  2. Long‑press your active Wi‑Fi network and select Modify network (or the gear icon).
  3. Expand Advanced options and locate Proxy.
    • Set the proxy to Manual.
    • Enter 127.0.0.1 as the Proxy hostname.
    • Enter the port you chose in Step 3 (default 8118) as the Proxy port.
    • Leave the Bypass proxy for field empty unless you need to exclude local addresses.
  4. Save the changes and reconnect to the Wi‑Fi network.

Android will now send all HTTP (not HTTPS) traffic from apps that respect the system proxy through Privoxy. Most browsers, the Google Play Store, and many third‑party apps follow this setting.

Step 6 – Verify that traffic is flowing through Privoxy

  1. Open a web browser (Chrome, Firefox, etc.) and navigate to http://config.privoxy.org. This page is served by Privoxy itself and should display a configuration summary.

    If you see the Privoxy configuration page, the proxy is active.

  2. Alternatively, check the log file (if you enabled logging):
    tail -f $PREFIX/var/log/privoxy/logfile

    You should see entries like GET http://example.com/ ... appear as you browse.

Because Privoxy only handles plain HTTP, HTTPS sites will still connect directly unless you also install a TLS‑intercepting tool, which is beyond the scope of this no‑root guide.

Step 7 – Using the proxy with apps that ignore the system setting

Some apps (e.g., certain VPN clients or browsers that bundle their own networking stack) bypass Android’s proxy configuration. For those, you can use ProxyDroid‑style wrappers, but they typically require root. A practical workaround is to use adb reverse to forward traffic from the app’s local port to Privoxy, but this also needs a PC. In most everyday scenarios, the system proxy covers the majority of traffic you care about, such as web browsing and app updates.

Troubleshooting

Privoxy won’t start

  • Port conflict: If another app already uses port 8118, Privoxy will abort. Change the listen-address line to an unused port (e.g., 127.0.0.1:8888) and update the Android proxy settings accordingly.
  • Missing libraries: Run pkg install libandroid-glob if you encounter “cannot open shared object file” errors.
  • Termux session killed: Ensure you started Privoxy with the wrapper script that includes termux-wake-lock. You can also enable Termux:Boot (install the add‑on) and add ~/start-privoxy.sh to its ~/.termux/boot folder so the proxy restarts after a reboot.

No traffic appears in the log

  • Confirm the Android proxy is set to 127.0.0.1 and the correct port.
  • Check that the Wi‑Fi network you are on is the one you edited. Android stores proxy settings per‑network.
  • Some apps use HTTPS exclusively; they will not be logged unless you enable TLS‑interception (requires certificates and is not covered here).

Websites load slowly or fail

  • Privoxy’s default filtering can block certain scripts or ads that a site relies on. Open http://config.privoxy.org and disable aggressive filters under the Actions tab.
  • High latency may be caused by the device’s CPU throttling when the screen is off. Keep the wake lock active or manually start the proxy after you unlock the device.

Advanced tweaks (optional)

  • Content filtering: Add custom rules in $PREFIX/etc/privoxy/user.action to block trackers, strip cookies, or rewrite URLs.
  • Caching: Enable the built‑in cache by uncommenting enable-cache 0 (set to 1) in the config file. This can speed up repeated requests on low‑bandwidth connections.
  • Running as a background service: Install the Termux:Boot add‑on, then place the start script in ~/.termux/boot/start-privoxy.sh. The proxy will start automatically after each reboot.

When to stop the proxy

If you no longer need the proxy, simply kill the Privoxy process and remove the wake lock:

pkill privoxy
termux-wake-unlock

Remember to revert the Wi‑Fi proxy settings to None** to avoid apps trying to connect to a non‑existent local server.

Wrap‑up

By following these steps you have turned a regular Android device into a lightweight, user‑space HTTP proxy. The setup works entirely without root, respects Android’s security model, and can be toggled on or off with a single command. Use it to test web‑filtering rules, reduce data usage on metered connections, or simply gain more visibility into the HTTP traffic your apps generate.

Because everything runs in Termux, you can extend the setup with other command‑line tools—like mitmproxy for TLS interception (requires certificate installation) or tinyproxy for a minimal forward proxy. The foundation you built here is a solid, reproducible base for any future network‑debugging or privacy‑enhancing projects on Android.

User Comments (0)

Add Comment
We'll never share your email with anyone else.