This translation is provided for convenience. If wording differs, consult the Simplified Chinese original. Your rights under applicable law are unaffected. Simplified Chinese original
English
Last updated and effective: September 29, 2026
1. Scope and operator
MeowSec Tech LLC (“we”, “us”) operates SakuraCat. This Policy covers our website, account and subscription services, server nodes, and the SakuraCat iOS / iPadOS client we provide that links to this Policy (the “App”). It explains our processing of personal information and your rights.
When you use the Windows, macOS, Android or Linux version of the SakuraCat client we provide, this Policy also applies to account and server services.
This notice does not substitute for separately required consent. Processing requiring consent should be explained beforehand with appropriate choices. Withholding necessary information may prevent the requested function from working; unrelated optional information should not be a condition of access.
2. Information we process
2.1 Accounts, subscriptions and transactions
- Registration and verification: Email, password and applicable verification or invitation codes, for account creation, authentication, recovery and abuse prevention. The App does not save account passwords on device. Servers store password hashes, not plaintext. Password changes use the old password for verification and the new password to update the hash.
- Account and subscription records: User ID, email, plan, expiry, traffic allowance and usage, subscription tokens and URLs, for authentication and delivery. Subscription URLs and connection credentials grant access and should not be shared publicly.
- Usage and transactions: Uploaded and downloaded byte counts and daily totals for metering; orders, payment status, balances and rebates for transactions and service administration. Byte counts do not themselves contain browsing content. Website transaction records are distinct from card details directly collected in the App.
- Referrals: Codes, referral counts, rebate rates and amounts. An inviter sees corresponding order amounts and rebates without your email when you register with their code; these transactions may still be associated with the referral relationship.
2.2 Operations, security and website visits
The App does not actively report device models. Account APIs and connection services process request or connection times, source IPs, connection status, traffic amounts, app and operating system versions, errors and anomalies for delivery, troubleshooting and security.
Necessary destination IP addresses, domains or ports may be recorded during troubleshooting or a security incident. These can reveal destinations, so we do not promise a completely log-free service in every circumstance. Processing is limited to the specific issue's necessary scope and duration, not advertising profiles or selling browsing records. This is consistent with Section 6 of our Terms.
Public and account website visits also involve IPs, request paths, times and browser information. These website records differ from records of other sites visited over the VPN.
2.3 VPN, DNS and network checks
- Forwarding: After connection, the App's iOS Network Extension VPN extension processes and forwards data according to selected nodes and routing rules. This requires source and destination addresses, credentials and transmitted data. Direct-connection rules may bypass the VPN node. The App does not separately collect and upload tunnel contents for product analytics or advertising.
- DNS: Depending on configuration, public DNS services resolve some domains and system-check domains; others are resolved through nodes. Resolvers receive queried domains and the request source IP, depending on routing. Remote resolution does not mean domains never leave the device.
- Latency: Requests through nodes to Google's
http://www.gstatic.com/generate_204check connectivity and latency without attaching SakuraCat account data; recipients still receive network information such as the node exit IP. - IP location: The App uses ip-api.com with api.ip.sb as a fallback to display approximate exit location. Disconnected requests may expose your actual public IP; connected requests reveal the exit IP actually used. Countries, cities and IP-derived coordinates are not GPS locations. Results are displayed on device and not sent to our account server, but third parties still receive the IP.
- Dedicated IPv6: Supporting routes assign dedicated IPv6 exit addresses for forwarding. Destination services can see this network identifier. A dedicated address does not provide anonymity or prevent platform security checks.
2.4 Submissions and permissions
Ticket subjects, messages and replies, and chat, attachments and logs you send to support, are used to handle requests. Submit only necessary details, excluding passwords, subscription tokens, complete subscription URLs and unrelated information.
The App does not request GPS, Contacts, Photos, Camera, Microphone or Health permissions, read IDFA, integrate advertising, behavioral analytics or automatic crash-reporting SDKs, or track across apps or websites for advertising. IP-derived location still involves processing network information. The client described here does not directly collect card details; website checkout explains payment processing.
3. Purposes and grounds
We process information for authentication, subscriptions and nodes, metering, transactions and rebates, support, necessary service notices, troubleshooting, abuse prevention and legal duties. We do not sell personal information or use it for advertising, advertising profiles or data brokerage.
Where applicable law allows, account, connection and metering data are necessary to perform the requested service. Legal obligations may require transaction or security records. Optional functions and other processing requiring consent depend on relevant notice and consent. Where legitimate interests can lawfully support service security, processing is necessary and takes your rights into account. Blanket continued-use language does not replace separately required permission.
4. Recipients and website technologies
The table distinguishes App and website contexts. Third parties may retain requests under their own policies. On-device display or the absence of advertising SDKs does not mean no third-party transmission occurs. Providers acting on our behalf are required to limit purposes and provide protection equivalent to this Policy.
| Recipient | Context | Information involved |
|---|---|---|
| Crisp (Crisp IM SAS, France) | App live chat loads when opened; website chat after selecting support | App chat sends email, language, plan, total / used / remaining traffic, expiry, reset date and messages. Public website pages do not read plan details, but loading chat sends IP, browser, session information and submissions. Privacy policy |
| ip-api.com / api.ip.sb | App exit IP location; the latter is a fallback | Request public IP; the primary service also receives language. ip-api terms; ip.sb website |
| Public DNS services | Domain resolution according to routing, possibly including server addresses at launch | Domains and source IP. Configuration includes Tencent DNSPod (119.29.29.29, 1.12.12.12, doh.pub), Alibaba Cloud DNS (223.5.5.5, dns.alidns.com), 360 (doh.360.cn), OneDNS (doh.onedns.net) and v.recipes |
| Google (gstatic.com) | Node connectivity and latency checks | Network information including node exit IP and time; no attached SakuraCat account data |
| Cloudflare | Website hosting, delivery and network security | Visitor IP, request path and time, browser and connection information. Privacy policy |
| Account infrastructure and transaction providers | Necessary hosting, verification email and website payment operations | Necessary account, email or transaction information; payment recipients depend on your selected checkout method |
| Inviters | Calculating and displaying rebates | Corresponding order amounts and rebate records, without email, as in Section 2.1 |
| Apple | App distribution, operating system and VPN framework | Apple's own processing follows its Privacy Policy |
Website language preference: The website reads your browser's language settings to choose a display language, without an IP-location lookup for this purpose. A manual choice is stored in this browser's local storage for future visits; choose “Use browser language” or clear website data to remove it. Language codes are not used for advertising tracking, and no text is sent to a third-party translation service.
Public website pages do not use advertising tracking scripts. Our chat code sends no Crisp request before you select support. Login and registration entry pages check candidate account sites, which may receive IPs, times and related request information. Account sessions and chat cookies or local storage support their respective functions. Closing chat does not necessarily clear a session. Clearing browser website data may require signing in again.
Websites in the App's system browser view still receive requests and may use cookies. Embedded browsing does not eliminate this processing. Independent services you choose to visit are responsible for their own processing.
We assess the basis of legally required disclosures and limit them to what the law requires. Broad rights-protection or business-transfer language does not justify selling information or unrestricted sharing. Operator or processing changes require applicable notice and other legal formalities.
5. On-device information
- Sign-in tokens: Stored in iOS Keychain and cleared by the App on sign-out.
- Offline cache: Recent subscriptions, node addresses and credentials are encrypted in the App Group container shared by the App and VPN extension for offline use, and cleared on sign-out or subscription invalidation.
- Configuration and preferences: Proxy configuration, credentials, rules, caches and core error logs may reside in the App Group container shared with the VPN extension. Preferences include node, proxy mode and appearance.
- Runtime logs: The latest 500 entries are held in memory, potentially including connection events, request addresses and errors, without automatic upload. A portion becomes support data only if you copy and send it. Remove sensitive details first. Core error logs on disk are separate.
- Chat web data: Embedded Crisp cookies and local data are cleared on sign-out. This does not erase records already sent to support servers.
Uninstalling normally removes installation-specific app data, not the server account. Keychain items, system VPN profiles or shared-container data may remain depending on the system and other extensions. Disconnect and sign out first, then check iOS VPN profiles and browser website data if cleanup is needed. Uninstalling cannot recall previously transmitted information.
6. Retention and deletion
Retention is based on purpose and applicable law, not indefinite potential usefulness.
- Accounts: Necessary records are retained while providing account service. Plan expiry is not deletion. After deletion, associated data no longer needed is deleted or irreversibly anonymized.
- Usage and transactions: Retained as needed for metering, reconciliation and relevant disputes. Legally required order and financial records have restricted purposes during the applicable period.
- Operational and security logs: Retained as necessary for troubleshooting, investigations and applicable duties. Destination diagnostics relate to specific incidents, not long-term advertising or profiling.
- Support: Retained for requests, follow-up and relevant disputes; processor deletion requests are coordinated as required.
- Backups and exceptions: Copies may be cleared through rotation. Legally retained or temporarily inseparable backup records should be isolated, access restricted, excluded from ordinary service and marketing, and deleted when the retention basis ends. Confirmed deletions should be reapplied after restoration.
Contact us for the basis and expected timeframe relevant to your records. Independent third-party request records also follow their policies. Section 5 covers device data.
7. Security
Authentication and subscription APIs use TLS; tokens are stored in the system Keychain and offline caches are encrypted. Backend and personal-information access is limited to authorized personnel and necessary duties.
VPN protection depends on protocols and routing; not every website request is end-to-end encrypted. Section 2.3's HTTP connectivity checks are outside the account API TLS statement. Destination services should protect communications using HTTPS or equivalent measures. Protect devices, passwords and subscription credentials; do not publish full logs.
No method guarantees absolute security. We investigate and remediate incidents and notify affected users and authorities as required by law.
8. Choices and rights
8.1 Access, correction and copies
View account, plan and usage data in App settings or the account center, and use the password change function. Contact Section 12 for other corrections, copies, restriction or objection, and applicable portability rights.
8.2 Account and associated data deletion
You can initiate deletion using the App's “Delete Account” function. Confirming in the App submits a deletion request. The account service processes requests through a daily scheduled task; deletion is not immediate. Signing in again before the account is actually deleted cancels the request. Submit a new request if you still want deletion. Do not sign in just to check its progress. Deletion covers the account and associated personal information no longer needed; legally retained records follow Section 6.
For progress or problems with deletion, contact SakuraCat support. Email is a backup assistance channel, not a replacement for in-app deletion.
Section 6 governs deleted-account data; our Terms govern refunds and transactions. If your payment channel supports recurring billing, confirm cancellation there; uninstalling alone does not show billing has stopped.
8.3 Withdrawal and stopping use
Disconnecting stops new traffic through the tunnel; sign-out clears relevant local authentication data. Not opening support avoids initiating a new Crisp session through that function. Sign-out, disconnection and uninstall do not erase existing server records or undo lawful completed processing.
Use Section 12 to withdraw optional consent. Withdrawal does not affect earlier lawful processing or necessary legal retention; the affected optional function may stop working.
8.4 Requests and complaints
We normally respond within 30 days after receipt and necessary identity verification, or sooner where law requires. This is not a promise that every backup or legal record is erased within 30 days. We explain extensions, refusals and retained records. Verification is proportionate and does not require your password.
You may complain to a competent data-protection authority. We do not discriminate against you for lawfully exercising privacy rights.
9. Children and minors
The Service is not directed to children under 13 or a higher legal minimum age. Users above that minimum who remain minors should obtain guardian permission where required. Contact us about children's information handled without required conditions; we will investigate and delete it or take other necessary legal measures.
10. International processing
Nodes may be in other countries or regions, and traffic follows actual routing. Account hosting and Section 4 providers may process data outside your location. A node's country does not identify where all account data is stored.
Protections differ between jurisdictions. International processing should meet applicable law, including required notice, separate consent and lawful transfer arrangements. Contact Section 12 for relevant storage regions, recipients and safeguards.
11. Updates
Updates and dates appear on this page. Material changes to purposes, data types, recipients or rights will be explained through appropriate App or account notices. Renewed consent will be requested before new processing where required; continued use does not automatically authorize new optional processing.
12. Contact
Entity responsible for personal-information processing: MeowSec Tech LLC.
- Privacy and service contact: SakuraCat support
- Website:
mysakuracat.com - Other channels: Settings → Tickets in the App, or tickets in the account center.
- Include “Privacy request” and the access, correction or deletion you need. Do not send passwords, complete subscription URLs or unrelated sensitive information.