Privacy Policy

Updated: August 28, 2026

This policy explains how VineaVPN ("Vinea", "we", or "us") handles data when you use our browser extension, website, account, payment, and proxy services.

1. Account and sign-in data

You may create an account with an email address and password or use Google sign-in. For email sign-in, the email address and password are sent to the VineaVPN API over HTTPS for authentication. The extension does not write the account password to its local storage.

Google sign-in requests the openid, email, and profile scopes through Google OAuth and the browser Identity API. Google may provide an ID token, access token, email address, display name, and profile image. The extension sends the ID token needed to verify your identity to the VineaVPN API, which then issues a VineaVPN access token.

After sign-in, the extension stores the email address, VineaVPN account token, refresh token, and a local user record in the current browser profile. This keeps you signed in and lets the extension retrieve your subscription and proxy servers.

2. Subscription, usage, and payment data

To display and enforce a plan, we process the account ID, product or plan, subscription status, expiry date, bandwidth used, and bandwidth allowance. The extension may cache the current subscription, available servers, and selected server locally.

When you purchase a subscription or data package, we process the order number, product, amount, payment method, and payment status. WeChat Pay or Alipay handles the payment account, authorization, and other information required by that provider. The extension does not read or store your payment password or bank card number.

3. Proxy connections and routing data

When the proxy is enabled, browser traffic matching the current mode and domain rules is sent to the selected VineaVPN proxy server. Establishing the connection requires the server address and port plus service-assigned proxy credentials. The extension stores those credentials in the current browser profile and supplies them when the proxy server requests authentication.

During an active connection, the proxy service must process the source IP address, destination hostname or IP address, connection time, and transferred data volume to establish and route the connection and calculate plan usage. We do not use this routing data to create a per-user browsing history or for targeted advertising. The account service stores bandwidth totals rather than a website list generated by the extension.

4. Extension storage and permissions

The extension uses extension-page local storage and chrome.storage.local. It does not use Chrome Sync for this data. Stored items may include account tokens, subscription and server data, proxy credentials, language, proxy mode, domain rules, selected server, window size, and message preferences.

The proxy permission controls browser proxy settings. The webRequest and webRequestAuthProvider permissions answer proxy authentication challenges. Identity is used for Google sign-in, storage saves extension state, and contextMenus lets you add or remove a domain rule from the page menu. The context-menu feature reads the current page address only after you choose one of those actions and stores only the normalized domain.

Signing out turns off the proxy and removes account tokens, proxy credentials, the current subscription, and server cache. Preferences without account credentials, such as language, proxy mode, domain rules, and window size, remain for the next use. Uninstalling the extension or clearing its data removes local storage.

5. Website data and analytics

Our website may use Google Analytics 4 and Cloudflare services to understand page visits, diagnose errors, protect the site, and measure performance. These services may process the page URL, referrer, browser and device information, approximate location derived from the IP address, timestamps, and cookie or similar identifiers. Your IP address is necessarily transmitted when your browser connects to these providers. Their handling of data is governed by their own terms and privacy policies.

VineaVPN extension version 1.0.8 does not load Google Tag Manager or Google Analytics 4 and does not send extension-open, sign-in, proxy-connection, plan-selection, payment, or other extension usage events to GA4. Website analytics does not receive proxy browsing traffic from the extension.

6. How we use data

  • Authenticate users and maintain account sessions.
  • Provide proxy routing, server selection, and domain rules.
  • Display and enforce subscription and bandwidth limits.
  • Process orders, reconcile payments, and answer support requests.
  • Protect the service, prevent abuse, and diagnose failures.
  • Measure and improve website reliability and performance.

7. Recipients and sharing

  • VineaVPN APIs, proxy servers, and infrastructure providers: process account, subscription, proxy authentication, connection, and bandwidth-total data to provide the service.
  • Google: processes Google OAuth sign-in. The extension initializes Firebase Messaging to receive service messages; Firebase may process message content and the browser or device information needed for delivery. Google Analytics may process website analytics.
  • WeChat Pay or Alipay: processes a payment when you choose the corresponding method.
  • Cloudflare and hosting or CDN providers: deliver and protect the website and service infrastructure.
  • Legal and security recipients: may receive relevant data when required by law or when needed to investigate fraud and protect users or the service.

We do not sell personal data handled by the extension or use proxy traffic for targeted advertising.

8. Storage and retention

Extension data remains in the current browser profile until you sign out, clear extension data, or uninstall the extension, as described above. Server-side account, subscription, bandwidth-total, and order records are kept while needed to provide the account and service, complete transactions, answer disputes, prevent fraud, and meet applicable legal or accounting requirements. After an account is closed, data that is no longer needed is deleted or de-identified. Data in backups is removed as those backups are overwritten in the normal backup cycle.

Website analytics retention follows our configured settings and the provider's controls. Security and access records may be kept for the period needed to investigate incidents and protect the service.

9. Security and international processing

Account and subscription requests between the extension and the VineaVPN API use HTTPS. Access is limited according to operational need. Because proxy servers and service providers may operate in several countries or regions, data may be processed outside your place of residence. No network transmission or storage method is completely risk-free.

10. Access, correction, and deletion

You can sign out to remove account and proxy-authentication data from the extension, or remove all local content by clearing extension data or uninstalling it. To access, correct, or request deletion of server-side account data, email [email protected]. We may need to verify your identity and may retain records that are still required for the purposes described above.

11. Children

VineaVPN is not intended for children under 18. If you believe a child has provided personal data to us, contact us so we can review and remove it where required.

12. Policy changes and contact

If our data, purposes, or recipients change, we will update this policy and the revision date. Questions or privacy requests can be sent to:

[email protected]