Legal document

Privacy Policy

Last updated: August 2026

When providing cross-border network acceleration, account management, and subscription services, BiliVPN processes only the data needed to operate the service, complete orders, and respond to support requests. This policy explains the data categories, purposes, retention practices, and controls available to users.

Data Collected and Processing Purposes

No email address is required for registration; a username and password are sufficient. As a result, this service does not collect a registration email. Account details are used to identify accounts, verify sign-in status, preserve subscription benefits, and handle service requests submitted by users. Passwords are processed in the form required for authentication and are not displayed on pages as readable text.

Order records include the selected subscription, payment status, transaction result, activation time, traffic usage, and benefit changes. These records are used to deliver purchased services, verify payments, calculate monthly subscription traffic resets, and handle refunds or order disputes. Usage analytics may include page visits, referring pages, browser type, device category, and approximate region. This information helps assess site operation, identify errors, and improve content structure; analytics are not used to build profiles of the content users access.

To enforce plan allowances, the system needs to retain each account’s used traffic and remaining benefits. This measurement data is used only for subscription delivery, usage display, and troubleshooting, and does not include user transmission content.

No-Logs Principles and Connection Data

BiliVPN does not record which websites users access through international routes. It does not retain visited pages, search content, downloaded content, communication content, or DNS query content, nor does it create personal browsing histories from such data. Account usage statistics and order status required to operate the service are not browsing-content logs.

The system does not create long-term records of connection activity. To keep routes available, limit abuse, or diagnose issues reported by users, servers may briefly process necessary technical status data during operation; this status is not used to reconstruct browsing activity. Diagnostic information attached to a support ticket is used only to handle that request and is deleted or de-identified as needed after the issue is resolved, disputes are settled, or related security needs end.

Cookies and Local Storage

The website may use Cookies or browser local storage to retain sign-in status, interface language, session credentials, and necessary security markers, allowing selected settings to persist between pages. The user panel also stores authentication information locally to identify the current session and provide account functions.

Identifiers needed for usage analytics are used only to aggregate page usage and distinguish consecutive visits. Users can clear Cookies and local storage through browser settings; after clearing them, sign-in status, language preferences, and some interface settings may need to be established again. Disabling necessary storage may prevent the user panel from maintaining sign-in status, but it does not affect access to public policy and information pages.

Payment Processing and Data Retention

BiliVPN supports Alipay, WeChat Pay, and USDT. Payments are processed by the relevant third-party payment service. Payment account details submitted to the payment provider are managed by that provider under its own rules. This service receives the transaction status, order identifier, and result information needed to complete an order, but does not directly store complete credentials for third-party payment accounts.

Account details and active subscription records are generally retained while an account remains active so that services can continue to be provided. Order, refund, and dispute records are retained for as long as needed to complete transactions, reconcile finances, conduct security reviews, or resolve disputes. Usage analytics are retained for aggregated analysis, with efforts made to reduce their association with specific accounts. Once processing purposes are met, data is deleted, de-identified, or retained only to the extent required by applicable rules.

If third-party services participate in payment or infrastructure processing, data is transferred only to the extent necessary to perform the corresponding function. Third parties are independently responsible for data they obtain, and their retention and deletion practices are governed by their respective service policies.

Account Deletion and Policy Updates

Users can sign in to the user panel to view account and order information. To correct account details, delete an account, or object to data processing, users can submit a request through the support ticket portal in the user panel. Account control may need to be verified before a deletion request is processed; after verification, data that is no longer needed will be deleted. Records related to unfinished orders, refunds, disputes, security incidents, or necessary retention obligations will be cleared after the relevant matter ends.

This policy may be updated when service features, data processing practices, or applicable requirements change. The updated text will be published on this page, and the last-updated month at the top will be changed accordingly. Significant changes affecting data purposes or user rights will be communicated in a manner suited to the current service format. Users are encouraged to review the latest version before continuing to use the service; updates do not alter data processing disclosures that were clearly made before the update.