The proxy/VPN machines were designed to be disposable (to potentially cycle IP addresses for various reasons) and to record a minimum of information. It would have required non-trivial effort to make it so that we could do a pen-tap on just one individual given that they could end up on a different server each time. Additionally, I believe that the proxy/VPN machines had no information on the user's identity, just the device's identity (devices were given unique, derived identities when they were created; we could work that information backwards to some degree of accuracy with enough effort, precisely for LE purposes).
I don’t always use a proxy or VPN, but when I do, I trust what my former employer wrote precisely because I know what we didn’t do then, and didn’t believe would be right for us to do. Nothing I have heard from the SurfEasy team since suggests that this has changed.
If the courts or intelligence services tell them to capture a username's data, or access to specific websites from all users, they will do it.
If the choice is between keep quiet and do it, or potentially get shutdown or arrested, you have to assume that almost everyone will do as they are told.
Isn't it worse if word gets out that you deliberately evade legal compliance frameworks? When a bank is found to be skirting regulations around money laundering, the reaction is not typically 'good on them, standing up for our rights against the man!'.
Doesn't it then bring us to where we are with all other matters - wiretaps, breaking into a home with a search warrant?
Law enforcement has to get suspicion of a crime, probable cause, a warrant or what have you and be subject to all the assorted checks and balances the justice system has evolved.
That's vastly different to having all internet activity tied to an IP/account/person in vast, ever increasing, NSA/GCHQ/lots of other databases then going on a big back trawl every time a name comes up.