Gizlilik Politikası
Last updated: September 24, 2026
This policy describes how data is processed when you use the Evil VPN website, account area, the Telegram bot @evil_vpnbot, the app in Telegram, and Evil VPN client apps for Android, macOS and Windows.
1. What we collect
- Telegram ID — account identifier for managing your subscription
- Name and username — as displayed in Telegram (optional)
- Interface language — for bot localization
- Transaction data — payment confirmation, selected plan, date
- UTM tags — referral source for aggregated analytics
- Email — if you linked it for signing in on the website and in the apps
- Login sessions — client type (web, Android, macOS, Windows), login time and IP address for account sign-in; needed so you can view and end sessions. This is account login data, not browsing history or VPN traffic data
- Subscription devices — name of the VPN app and platform of devices that downloaded the key; needed to enforce the device limit
2. What we do NOT collect
- History of visited websites and DNS requests
- Incoming and outgoing traffic
- IP addresses and times of your connections to VPN servers
- Bank card numbers and details — they are entered on the payment partner's side
3. How data is used
- Activating and managing your subscription
- Subscription expiration notifications in Telegram and by email
- Technical support in Telegram and by email
- Aggregated statistics without personal data
4. Sharing data with third parties
We do not sell data or share it for advertising. To operate the service, some data is processed by partners — only to the extent needed for their task:
- Payment partners (Platega — SBP, card, cryptocurrency; Heleket — cryptocurrency; Telegram — Stars): amount, plan, order number, and payment status. You enter card details with the partner; we do not receive them
- Telegram: bot and app messages in Telegram
- Hosting and email: servers on which the service runs, and the email service for login codes
- As required by law — to the extent provided by applicable law
5. Data retention
Account and payment data are stored while the account is active and are deleted at your request. One-time login codes are valid for several minutes. You can end and delete login sessions and the device list yourself in your account area.
6. Security
Data is transmitted only over an encrypted connection (HTTPS), access to the database is restricted, and app login tokens are stored in the device's secure storage.
7. Your rights
- Request access to your data
- Demand correction of inaccuracies
- Request deletion ("right to be forgotten")
- Opt out of marketing notifications
Contact us via @evil_vpnbot or at support@evilvpn.io.
8. Cookies
The website and account area do not use advertising or analytics cookies. Only technical settings (theme, language) and the account login token are stored in the browser — in the browser's local storage.
9. Policy changes
The current version is always available on this page. We will notify you of material changes in the Telegram channel.