Data Handling Rules

Privacy Policy

This policy explains how Bibi VPN handles data while operating its website, user panel, and subscription services, along with the controls available to users.

Last updated: August 2026

Data Collected and Processing Purposes

Creating a Bibi VPN account does not require an email address. A username and password are enough to create an account. The service processes usernames and authentication credentials to identify accounts, maintain signed-in sessions, prevent unauthorized account actions, and provide subscription management features. Authentication credentials are used only for account verification and are not used to analyze network access preferences.

When a subscription is purchased or adjusted, the system stores order items, the amount due, payment status, subscription status, and necessary transaction identifiers. This information is used to deliver the service, verify payments, process refunds, resolve order disputes, and maintain account records. To enforce traffic rules, the system also processes account traffic usage, traffic reset status, and subscription validity.

When you visit the website or user panel, the service may process page visit records, referring pages, browser type, device category, interface language, and basic error information. These usage statistics help verify that pages work properly, improve content structure, and investigate unusual requests. They are not used to build profiles of the international websites users visit.

No-Logs Principles and Connection Data

Bibi VPN does not record which websites users visit, retain browsing content, search queries, transmitted content, or in-app activity, or create browsing histories that could be used to reconstruct an individual's network activity.

When a network connection is established, the server may temporarily process operational data required for identity checks, route assignment, traffic accounting, and fault control. This data is used only to maintain the current service session. It is not retained as browsing content and does not form a long-term connection history. After the connection ends, operational data is not used to analyze specific destinations.

When users voluntarily submit troubleshooting materials, those materials may include the client environment, selected route, and error messages. They are used only to address the related issue and are managed separately from regular network connections. Review the materials before sending them to avoid including personal information unrelated to troubleshooting.

Cookies and Local Storage

The website and user panel may use cookies or browser local storage to save sign-in sessions, interface language, necessary security states, and preferences actively selected by users. These mechanisms keep users signed in, restore page state, and reduce repeated setup. They are not used to store the content of websites users visit.

Usage statistics tools may also set necessary identifiers to distinguish consecutive visits and calculate page usage. Users can clear cookies and local storage through browser settings. After clearing them, an account may be signed out and interface preferences may return to their defaults. Restricting necessary storage may affect sign-in and subscription management features.

Third-Party Payments and Data Sharing

Bibi VPN supports Alipay, WeChat Pay, and USDT. Payments are handled by the relevant third-party payment services, which may collect information required to complete transactions under their own rules. The service generally receives order status, transaction identifiers, and payment results to confirm whether a subscription can be delivered.

Bibi VPN does not store through this website the complete payment credentials that third-party payment services ask users to submit directly. When using a payment service, users should also review the provider's privacy rules. Account data is not provided to unrelated third parties except where necessary to deliver subscriptions, process orders, maintain security, or meet applicable obligations.

Data Retention and Deletion

Account details and subscription status are retained while an account is in use so users can sign in and manage the service. Order records are retained as needed for transaction verification, refund processing, dispute resolution, and applicable obligations. Usage statistics and error records are kept only to the extent needed to maintain the website, analyze overall use, or handle security incidents.

Users can request deletion of their account and data directly associated with it through the ticket entry in the user panel. After receiving a request, account control will first be verified, followed by processing of data eligible for deletion. Records that must be retained for incomplete orders, refund disputes, security investigations, or applicable obligations will be cleared after the relevant purpose ends. Aggregated information or statistics that can no longer be linked to a specific account are outside the scope of account deletion.

Policy Updates and User Choices

This policy may be updated when service features, data handling practices, or applicable requirements change. Updated versions will be published on this page, and the last-updated date at the top will be revised. Important changes involving data use or user rights will be highlighted in an appropriate location on the website or user panel.

Before continuing to use the service, users can review the updated policy. If they object to a new handling practice, they can stop using the relevant feature and submit a request through a user panel ticket to access, correct, or delete data. Bibi VPN will process the request based on account status, its scope, and applicable obligations.

Start Free