Privacy Policy
Last Updated: September 9, 2026
Controlling Language Notice: This Privacy Policy is provided in multiple languages as a convenience. In the event of any conflict, discrepancy, or inconsistency between a translated version and the Traditional Chinese (zh-TW) version, the Traditional Chinese version shall govern and control.
1. Nature of the Service & Non-Affiliation Notice
BiliFix (accessible via vxbilibili.com, vxb23.tv, and associated subdomains; collectively, the “Service”) is a non-commercial technical utility maintained by independent software developers and community contributors (the “maintainers,” “we,” “us,” or “our”). Its primary purpose is to resolve link unfurling failures and generate rich embed previews for Bilibili URLs across messaging platforms (such as Discord and Telegram), with optional multilingual metadata translation and streaming media relay.
The Service is an independent project and is not affiliated with, sponsored by, authorized by, endorsed by, or in any way officially connected with Bilibili Inc. or any of its subsidiaries or affiliates. All Bilibili trademarks, service marks, logos, and trade names are the property of their respective owners, and any reference to them is strictly for technical compatibility and nominative fair use.
2. Data Minimization & Account-Free Architecture
The Service is architected strictly around the principle of data minimization and does not solicit, collect, or store personally identifiable information (PII) or direct personal identifiers:
- No Registration or Accounts: The Service operates entirely without user registration, accounts, passwords, or membership tiers.
- No Direct Personal Identifiers: We never request, collect, or store real names, email addresses, phone numbers, physical addresses, government-issued IDs, or payment and financial details.
- Open, Frictionless Access: All link conversion, preview generation, and redirection features are freely accessible without an account, and we do not create, track, or maintain user profiles.
3. Technical Telemetry, Server Logs & Data Retention
To maintain infrastructure stability, monitor bandwidth consumption, and defend against malicious traffic or denial-of-service attacks, our systems process limited technical connection data:
- Request Telemetry: Request timestamps, destination hostnames, requested targets (paths and query parameters), HTTP methods, and response status codes.
- Client Classification: Application-level metrics record broad User-Agent categories (e.g.,
DiscordBot,TelegramBot) rather than granular browser versions or operating system device fingerprints. - Coarse Geographic Data: High-level, two-letter country or region codes (e.g.,
US,TW, provided via Cloudflare headers). We do not collect or store precise GPS coordinates or granular location data. - HTTP Referer: Standard HTTP Referer headers (if transmitted by the client), used strictly to detect and prevent abnormal or unauthorized requests, without associating this information with any individual identity.
This technical data is governed by strict retention and deletion schedules:
- Origin Server Transient Logs: Temporary web server access logs (recording connection timestamps, client IP addresses, and requested URLs) serve strictly as a transient operational buffer and are retained for a maximum of 48 hours.
- Cloudflare Edge Logs: All inbound requests pass through Cloudflare’s reverse proxy and DDoS protection network. Edge connection processing and threat mitigation are governed independently under the Cloudflare Privacy Policy. The maintainers make no representations regarding, and do not manage, export, or control, Cloudflare’s internal data handling practices or retention schedules.
- Application Analytics Database: Our internal, de-identified metrics database does not collect or store any IP addresses (full, truncated, or cryptographically hashed IP addresses are strictly excluded). Aggregated usage metrics are retained for up to 90 days and automatically purged via daily maintenance jobs.
Transient connection data is processed based on our legitimate interest in maintaining system and network availability, ensuring stability, and defending against malicious attacks. Cross-border data routing and edge caching are handled across Cloudflare’s global infrastructure.
4. Cookies & Local Storage
The Service does not use commercial advertising cookies, third-party behavioral trackers (such as Google Analytics or Meta Pixel), or client-side error monitoring SDKs (such as Sentry).
Client-side data storage is strictly confined to essential technical security and functional user preferences:
- Strictly Necessary Security Cookies (Cloudflare): Traffic routed through Cloudflare may receive strictly necessary technical security cookies (such as
__cf_bmor similar security tokens) to detect automated bot abuse and mitigate anomalous traffic. Their deployment is governed independently by the Cloudflare Privacy Policy. - Client-Side Functional Preferences (
localStorage): We use standard browserlocalStoragesolely on your local device to persist functional user interface preferences:dark-mode: Stores your preferred visual theme (dark or light mode).bilifix-converter-lang: Remembers the target translation language selected in the URL converter interface.lang-check-completed: Records whether you have acknowledged or dismissed the language suggestion prompt.
All localStorage entries remain entirely on your local device, are never transmitted or synchronized to our servers, and can be cleared at any time through your browser settings.
5. Privacy-Preserving Link Redirection
The Service is engineered to safeguard user privacy when links are shared across social media and messaging platforms. When users click or open Service links in messaging applications or on the web, the Service automatically redirects them to the official Bilibili destination page.
During redirection, the system automatically strips known tracking parameters embedded in the URL (such as share_source, vd_source, and trackid), protecting both link sharers and recipients from platform correlation and behavioral tracking.
6. Third-Party Services & External Links
To deliver its core features, the Service interacts with or provides outbound links to the following third-party services:
- Cloudflare: Provides DNS resolution, global CDN acceleration, caching, and security protection under the Cloudflare Privacy Policy.
- Bilibili (Official Platform): Embed metadata and media streams are retrieved dynamically from publicly accessible Bilibili endpoints. When you are redirected to the official Bilibili website, your subsequent interactions are governed by Bilibili’s Terms of Service, Privacy Policy, and related policies.
- Metadata Machine Translation (Google Translate): Public video titles and descriptions may be processed via automated Google Translate APIs to generate multilingual previews. The Service transmits public video metadata strictly server-to-server and never transmits user IP addresses, client identifiers, or other personal data to Google.
- Community & Support Links: Outbound links to Ko-fi (for voluntary donations) and Discord (for community support) are provided for user convenience. Any interactions on those platforms are governed by their respective terms and privacy policies.
7. Transient Technical Caching & Intellectual Property Notice
The Service acts solely as a metadata proxy and format adapter, and does not permanently host or store any original audio or video files.
Temporary Technical Caching. To reduce redundant load on upstream servers and accelerate preview playback, the Service may temporarily cache media streams for up to seven (7) days, after which cached files are automatically purged. This automated caching exists solely to facilitate transient network transmission and does not constitute a permanent repository or archive of audiovisual content.
Intellectual Property Ownership. All video titles, thumbnails, uploader descriptions, and media streams are dynamically fetched from publicly accessible third-party endpoints strictly on demand, and all intellectual property rights remain the exclusive property of their respective copyright holders and the source platform.
Content Takedown & Blocking Requests. If you are a copyright owner, licensee, or authorized legal representative and wish to request the removal, disabling, or blocking of preview generation for specific content or URLs, please submit a written notice to [email protected]. Upon receipt of a bona fide request containing sufficient identification of the copyrighted material, the maintainers will promptly review the notice, disable preview generation, and purge any associated cache entries.
8. Children’s Privacy
The Service is an account-free technical utility with no forms or interfaces for submitting personal information, and does not knowingly collect or solicit personal information from children or minors.
9. Information Security, Data Subject Rights & Policy Amendments
Security Architecture & Incident Notifications. Because the Service operates without user accounts, authentication credentials, or payment processing, we do not maintain sensitive user databases susceptible to credential compromise or identity theft. In the event of a significant infrastructure incident, service disruption, or scheduled maintenance, status announcements will be published in our official Discord community.
Data Subject Rights. Because the Service operates without user accounts, our routine operations neither require nor enable us to identify specific individuals. If you wish to exercise rights of access or deletion regarding transient connection logs, your request must be submitted within 48 hours of the connection (before logs are routinely overwritten and purged) along with objective technical details sufficient to locate the record—namely, the originating IP address, exact requested URL, and connection timestamp accurate to the minute. These technical parameters are required for us to locate, verify, and delete the relevant log entries.
Policy Amendments. We may update this Privacy Policy from time to time to reflect technical enhancements, operational adjustments, or legal and regulatory developments. Any revisions will be published directly on this page with an updated “Last Updated” date. Your continued use of the Service after an updated policy is posted signifies your acknowledgment and acceptance of the revised policy.
10. Contact Information
If you have questions, feedback, or legal inquiries regarding this Privacy Policy, please contact us through our official channels:
- Email: [email protected]
- Community Support: Official Discord Community