On this page 9 sections
This policy explains what DinoLink stores about you, why, and how you can verify any of it. We’ve tried to write it in language a regular person can read in five minutes, because most privacy policies are designed not to be read at all.
DinoLink is operated from the Republic of Seychelles. The company is not bound by mutual legal-assistance treaties with the Russian Federation, the People’s Republic of China, or the Five Eyes alliance.
What we don’t keep
DinoLink does not store, log, or retain:
- Connection timestamps (when you connected or disconnected)
- Source IP addresses (the address your device used to reach us)
- DNS queries (which domains you looked up)
- Destination domains or URLs (which sites your traffic was bound for)
- Traffic content (the data inside the tunnel)
- Bandwidth records per user (we measure aggregate server load, not per-account usage history)
If a court, a regulator, or a law-enforcement agency asked us to produce any of the items above, we would not be able to. Our servers run in RAM only — they wipe on every reboot. There is no log file on disk to copy. This is a property of the system, not a promise we ask you to take on faith.
What still exists
To run a service that doesn’t fall over, we keep the minimum operational data necessary:
- Account state: your email address (or, for crypto-paid accounts, a randomly generated account ID), authentication credentials, and the locale you prefer.
- Billing state: whether each payment succeeded or failed, the rail it came in on (USDT, SBP, Mir, card), and the amount. Crypto payments carry no card identity. Card payments carry only the last four digits of the card and the issuer.
- Wallet and data balance: how much credit you have on your account and how many gigabytes are in your data balance. These exist because the product is pay-as-you-go and the balance is yours to spend.
- Aggregate server health metrics: server load, capacity headroom, error rates. These are not joined to user identity.
None of the above tells us where you went on the internet, when you went there, or what you did when you arrived.
Your rights
You can ask us, at any time, to:
- Export the data we hold about your account
- Delete your account and the data associated with it
- Correct any data that’s wrong
- Withdraw consent (and stop using the service)
Send requests from the email on file to the support address at the bottom of this policy. We respond within seven days.
If you pay with USDT or another anonymous rail, we may not be able to verify that a deletion request is from the account owner. In that case we’ll ask you to authenticate from the DinoLink client app instead.
Cookies and analytics on the website
The DinoLink marketing website (dinolink.io) uses no third-party analytics, no advertising cookies, and no behavioural fingerprinting. We host the static assets ourselves.
We do use one technical cookie to remember your language preference between visits. You can clear it at any time and nothing else breaks.
The DinoLink client apps (Android, iOS, Windows, macOS, Linux) communicate only with DinoLink-operated servers. They do not embed Google Analytics, Facebook SDKs, Mixpanel, or any other third-party telemetry.
How to verify
You don’t have to take our word for any of this.
- Network inspection: run a packet capture on your own device or router while connected through DinoLink. You’ll see encrypted traffic flowing to a DinoLink endpoint and nothing legible past it.
- RAM-only servers: our servers hold no persistent disk for session data, so there is no stored log to seize or hand over. A power cycle wipes everything in volatile memory.
Children
DinoLink is not intended for use by anyone under the age of 16. We do not knowingly collect data from children. If you believe a minor has registered an account, contact us and we’ll close it.
Changes to this policy
Material changes to this policy will be announced at least 30 days before they take effect, via email to the address on file and a notice on the website. The “last updated” date at the top of this page always reflects the current version.
Substantive changes (those that would weaken your privacy or expand what we collect) require your active consent before they apply to you. The previous version of this policy continues to govern your data until you accept the new one.
Governing law and jurisdiction
This policy is governed by the laws of the Republic of Seychelles. Any dispute that can’t be resolved by correspondence will be heard in the courts of the Republic of Seychelles. This does not affect statutory rights you may have under the law of the country in which you reside.
Contact
For privacy questions, data requests, or to report a concern:
For other questions about the service, see our terms of service or write to [email protected].