BiliFix Privacy Policy
Last Updated: September 2026
Controlling Language Notice: This Privacy Policy is provided in multiple languages for informational convenience. In the event of any conflict, discrepancy, or inconsistency between a translated version and this English version, the English version shall govern and prevail.
1. Service Overview, Maintainers & Independent Status
BiliFix (accessible via vxbilibili.com, vxb23.tv, and associated subdomains; collectively, the “Service”) is an independent, non-commercial technical utility maintained by individual software developers and community contributors (the “maintainers,” “we,” “us,” or “our”). Its primary purpose is to resolve link unfurling failures and generate rich embed preview cards for Bilibili URLs across social messaging platforms (such as Discord and Telegram), with optional multilingual metadata translation and streaming media relay.
BiliFix is an independent project and is not affiliated with, sponsored by, authorized by, endorsed by, or in any way officially connected with Bilibili Inc., or any of its subsidiaries or affiliates. All Bilibili trademarks, service marks, logos, and trade names are the property of their respective owners, and their reference here is strictly for technical compatibility and nominative fair use.
2. Data Minimization & Account-Free Architecture
The Service is architected strictly around the principle of data minimization (GDPR Art. 5(1)(c)) and does not solicit, collect, or store direct personal data or personally identifiable information (PII):
- No Registration or Accounts: The Service operates entirely without user registration, accounts, passwords, or membership tiers.
- No Direct Personal Identifiers: We never request, collect, or store real names, email addresses, telephone numbers, physical addresses, government identification, or payment/financial credentials.
- Open, Frictionless Access: All link conversion, preview card generation, and redirection features are freely accessible without user authentication, login gates, or persistent personal profiles.
3. Technical Telemetry, Server Logs & Data Retention
To maintain infrastructure stability, monitor bandwidth capacity, and defend against malicious traffic or denial-of-service (DDoS) attacks, our systems process limited technical connection telemetry under strict retention schedules:
- Request Telemetry: Request timestamps, destination hostnames, requested HTTP paths, HTTP methods, and response status codes.
- Client Classification: Application-level metrics record broad User-Agent categories (e.g.,
DiscordBot,TelegramBot) rather than granular browser versions or operating system device fingerprints. - Coarse Geographic Region: High-level, two-letter country or regional codes (e.g.,
US,TW, provided by Cloudflare). We do not collect or store precise GPS or coordinate-level location data. - Referrer: Standard HTTP
Refererheaders, if transmitted by the client or calling application.
Technical connection telemetry is managed under strict data retention and disposal schedules:
- Origin Server Transient Logs: Temporary web server access logs (containing connection timestamps, client IP addresses, and requested URIs) exist strictly within an ephemeral, first-in-first-out (FIFO) rolling buffer. These logs are maintained exclusively for real-time traffic diagnostics and active troubleshooting, and are automatically overwritten or purged within a maximum of 48 hours. We do not export, aggregate, or archive these logs in long-term storage.
- Cloudflare Edge Logs: All inbound requests pass through Cloudflare’s reverse proxy and DDoS protection network. Edge connection processing and threat mitigation are governed independently under the Cloudflare Privacy Policy. The maintainers make no representations regarding, and do not manage, export, or control, Cloudflare’s internal data handling practices or retention schedules.
- Application Analytics Database: Our internal, de-identified metrics database does not collect or store any IP addresses (full, truncated, or cryptographically hashed IP strings are strictly excluded). Aggregated usage metrics are retained for up to 90 days and automatically purged via daily maintenance jobs.
Lawful Basis for Processing. Transient connection telemetry is processed under the legal basis of Legitimate Interests pursuant to GDPR Article 6(1)(f)—specifically, to ensure network security, maintain system uptime, and prevent abusive bot traffic (as recognized in GDPR Recital 49). Cross-border routing and edge caching are handled in compliance with Cloudflare’s global infrastructure.
4. Cookies & Local Storage
The Service does not deploy commercial advertising cookies, third-party behavioral trackers (such as Google Analytics or Meta Pixel), or remote client-side error telemetry SDKs (such as Sentry). Consequently, no cookie consent banner is required under the EU ePrivacy Directive (Directive 2002/58/EC).
Client-side data storage is strictly confined to essential technical security and functional user preferences:
- Strictly Necessary Security Cookies (Cloudflare): Network traffic routed through Cloudflare may be issued strictly necessary technical security cookies (such as
__cf_bmor similar security tokens) to detect automated bot abuse and mitigate anomalous traffic. Their deployment is governed independently by the Cloudflare Privacy Policy; BiliFix does not read, access, or control these security tokens. - Client-Side Functional Preferences (
localStorage): We use standard browserlocalStoragesolely on your local device to persist functional user interface preferences:dark-mode: Stores your preferred visual theme (dark or light mode).bilifix-converter-lang: Remembers the target translation language selected in the URL converter interface.lang-check-completed: Records whether you have acknowledged or dismissed the language suggestion prompt.
All localStorage key-value pairs remain entirely on your local machine, are never transmitted or synchronized to our servers, and can be cleared at any time via your browser settings.
5. Privacy-Preserving Link Redirection
The Service is engineered to safeguard user privacy when links are shared across social media and messaging platforms. When an end user clicks or navigates to a BiliFix link using a standard web browser—as distinguished from an automated platform crawler fetching metadata for preview card rendering—the Service operates strictly as an immediate pass-through conduit. The server issues an immediate HTTP redirection response (such as HTTP status codes 301, 302, or 307), seamlessly forwarding the client’s browser directly to the underlying content on the official Bilibili platform without interposing intermediate landing pages or executing tracking scripts.
To prevent cross-platform surveillance and downstream behavioral profiling, the Service automatically strips commercial tracking and analytics parameters prior to executing the redirection. Destination URLs are programmatically sanitized to remove known tracking query parameters (including spm_id_from, from_source, and share_source). By stripping these identifiers, BiliFix mitigates cross-site user tracking and precludes third parties from correlating individual browsing sessions across disparate services and communications channels.
6. Third-Party Services & External Links
To deliver its core features, the Service interacts with or provides outbound links to the following external third-party services:
- Cloudflare: Provides global reverse proxy delivery, content caching, and DDoS mitigation under the Cloudflare Privacy Policy.
- Bilibili (Official Platform): Embed metadata and media streams are retrieved dynamically from publicly accessible Bilibili endpoints. When you are redirected to Bilibili, your subsequent browsing session, cookies, and interactions are governed exclusively by Bilibili’s Terms of Service and Privacy Policy.
- Metadata Machine Translation (Google Translate): Public video titles and descriptions may be processed via automated Google Translate APIs to generate multilingual preview cards. Only public text strings are submitted for translation; no user IP addresses, client identifiers, or personal data are ever transmitted to Google.
- Community & Voluntary Support Portals: Outbound links to Ko-fi (for voluntary financial contributions) and Discord (for community discussion and technical support) are provided for user convenience. Any engagement on those platforms is subject to their respective terms and privacy policies.
7. Transient Technical Caching & Safe Harbor Notice
Stateless Technical Conduit & Non-Hosting Architecture. BiliFix operates strictly as an automated, stateless compatibility proxy and metadata conduit. The Service does not permanently host, archive, or redistribute copyrighted audio, video, or underlying media content. All video titles, thumbnails, uploader descriptions, and media streams are dynamically fetched from publicly accessible third-party endpoints strictly on demand, and all intellectual property rights remain the exclusive property of their respective copyright holders and the source platform.
Intermediate & Transient Technical Caching. To alleviate redundant bandwidth load on upstream servers and facilitate smooth preview playback in chat clients, the proxy may maintain an intermediate transit cache for up to seven (7) days, after which cached materials are automatically purged. This temporary intermediate storage operates solely as an automated technical process for the purpose of making subsequent transmissions more efficient to downstream users who request it. Such technical caching functions strictly within the safe harbor protections of intermediate and temporary system caching pursuant to Section 512(b) of the Digital Millennium Copyright Act (17 U.S.C. § 512(b)) and the mandatory exception for transient and incidental reproduction under Article 5(1) of EU Directive 2001/29/EC, and does not constitute a permanent media repository or secondary publication.
Content Takedown & Blacklist Requests. If you are a copyright owner, licensee, or authorized legal representative and wish to request the removal, disabling, or blacklisting of preview unfurling for specific content or URLs, please submit a written notice to [email protected]. Upon receipt of a bona fide request containing sufficient identification of the copyrighted material, the maintainers will promptly review and process the notice, expeditiously disabling preview generation and purging any associated transient cache entries.
8. Children’s Privacy
The Service is a general-audience technical utility and is not directed to children under the age of 13 (or under 16 where applicable by European Union member state law). We do not provide user registration forms or public submission portals, and we do not knowingly collect or solicit personal data from children or minors. If you have reason to believe that a minor has submitted personal information through any of our communication channels, please contact us at [email protected] so we can promptly delete such information.
9. Security, Policy Updates & Inquiries
Security & Threat Profile. Because the Service operates without user accounts, authentication credentials, or financial payment processing, we do not maintain sensitive user databases susceptible to credential compromise or identity theft. In the event of a significant infrastructure incident, service disruption, or scheduled maintenance, status announcements will be published in our official Discord community.
Data Subject Rights & Inquiries (GDPR Art. 11). Because BiliFix operates without user accounts and does not persist IP addresses in its analytics database, the maintainers have no technical means to link technical requests to any identifiable natural person. Pursuant to GDPR Article 11 (Processing which does not require identification), the maintainers are not obligated to maintain, acquire, or process additional personal data to identify individual users for the sole purpose of fulfilling data subject rights under Articles 15 through 22. Requests to blacklist or disable preview unfurling for specific content may be directed to our content takedown channel outlined in Section 7.
Policy Amendments. We may update this Privacy Policy from time to time to reflect technical enhancements, operational adjustments, or legal and regulatory developments. Any revisions will be published directly on this page with an updated “Last Updated” date. Your continued use of the Service following the posting of an updated version signifies your acknowledgment of the revised policy.
For privacy inquiries, feedback, or compliance matters, please reach out via our official communication channels:
- Email: [email protected]
- Community Support: Official Discord Community