Last updated: September 2026
Privacy Policy
This page explains what data KimiVPN processes while delivering cross-border network acceleration, why that data is needed, and what is never recorded. The wording is kept plain, with no vague phrasing.
In one sentence: account and order data is used to activate plans, reset data allowances and process refunds; content-level records such as which sites were visited and connection logs are not retained by this service.
Data Collected and Why It Is Used
KimiVPN limits the data it processes to what is needed to deliver the service and handle refunds. It does not build user profiles and does not use data for advertising. Specifically:
- Account information: signing up requires only a username and a password, with no email address. Passwords are stored as irreversible hashes; this service does not keep plaintext passwords and cannot restore them.
- Subscription and usage: plan type, activation date and data used this month. Allowances reset monthly on the activation date, and mid-cycle upgrades are prorated by remaining days — both calculations rely on usage records.
- Order records: order number, amount, payment channel and payment status, used to activate plans, reconcile accounts and process the 7-day no-questions-asked refund.
- Ticket content: a problem description and any attached screenshots are created only when a user submits an issue.
- Visit statistics: aggregated data such as page paths, referrers and device types, used to judge which content is worth keeping; the results do not point to any specific individual.
Not Logged: What Is Never Recorded
This service holds an anonymous, no-log stance: it does not record which websites a user visits, does not store DNS query records, and does not build traceable links such as “account — destination address — timestamp”.
- Connection logs: the route side handles only the non-content data required to keep the service available, such as overall route load and error rates. It exists in aggregate form and is not stored long-term in association with an account.
- Browsing content: which sites were visited and what was viewed is neither recorded nor analyzed.
- Sharing with others: user data is not sold, rented or exchanged with third parties; it is not disclosed to third parties except where the law clearly requires it and the necessary procedures have been followed.
One point worth stating clearly: account and order data is still retained. This is the necessary balance between anonymous no-log operation and account reconciliation — without order records, neither allowance resets nor refunds could be carried out.
Cookies and Local Storage
This service uses browser local storage to keep basic functions working. It does not use third-party advertising cookies and does not perform cross-site tracking.
- Language preference: remembers the chosen interface language so the next visit opens directly in that language version.
- Sign-in state: the sign-in token is kept in browser local storage to maintain the session on that device; it becomes invalid immediately after signing out or clearing site data.
- Session and security: a small number of essential functional cookies, used to maintain the session and verify the origin of requests.
- How to clear: clear this site's data in your browser settings. You will need to sign in again afterwards; the account itself and any plan already purchased are unaffected.
Payment Handling
Payments are handled by third-party channels, and this service never touches full payment credentials. Supported methods are Alipay / WeChat / USDT.
- Data boundary: sensitive information such as card numbers and payment passwords is entered and verified on the payment channel's side; this service neither receives nor stores it.
- Data returned: the channel returns only the order number, amount and payment result, used to activate plans, process refunds and reconcile accounts.
- Refund dependency: the 7-day no-questions-asked refund needs the order and the payment receipt as proof, so these records must be retained during the refund window.
Retention PeriodsDeletion Methods
- Account information: retained while the account exists; after a closure request it is deleted, apart from necessary financial records.
- Order and payment records: must be retained during the 7-day no-questions-asked refund window; once that window ends they are still kept for as long as account reconciliation requires, and are not used for any other purpose afterwards.
- Connection level: no visit records that can be traced back to an individual are retained, consistent with “Not Logged: What Is Never Recorded” above.
- Access, correction and deletion: after signing in to the user panel you can change your password yourself; to close the account or delete data, submit a request through the ticket entry in the panel.
A closed account cannot be restored, so please confirm there are no pending orders or refund requests before submitting. Tickets keep a record of how they were handled, so both sides can check the request and the outcome.
Policy Updates and Contact
- How updates work: when this policy changes, the “Last updated” date at the top of this page is revised at the same time and a prominent notice is shown on the site; continuing to use this service means accepting the updated version.
- Contact: for questions about this policy, or to exercise your rights to access, correct or delete data, submit through the ticket entry in the user panel; the handling record is kept as well.
- What is never requested: this service does not ask for passwords, payment credentials or other sensitive information; sign-up does not require an email address, so there is no email verification step either.
Related links: User panel · Tickets; for more on accounts, subscriptions and refunds, see the Terms of Service.