QuellVPN · Legal document

Privacy Policy

Effective from 05.09.2026 Version 1.0 Applies to bot @quell_vpn_bot Jurisdiction: Russia
Table of contents
  1. 01Who we are
  2. 02Data we collect
  3. 03Data we don’t collect
  4. 04Why we need it
  5. 05Storage & protection
  6. 06Who receives it
  7. 07Retention & deletion
  8. 08Your rights
  9. 09Children
  10. 10Policy changes
  11. 11Contacts

§01Who we are and what this document covers

QuellVPN (hereinafter — the “Service”, “we”) provides access to VPN servers through the Telegram bot @quell_vpn_bot. The Service is administered by an individual (hereinafter — the “Operator”) with no intermediaries: you interact with the bot, and requests are handled by the Operator personally or by a limited circle of administrators.

This document explains what data the Service collects when you use the bot, why it is needed, and how it is handled. It applies to any user who has started the bot with /start, purchased a plan, added a device, or contacted support.

By using the bot, you agree to the terms described below and to the Terms of Service, which governs the terms of access itself.

The Operator provides services in the territory of the Russian Federation and processes personal data in accordance with Russian law, including Federal Law No. 152-FZ “On Personal Data”, to the extent applicable to its activities.

§02What data we collect

We collect only what is needed to issue you a working VPN key, track your traffic limit, and respond to support requests. Full list below.

CategoryWhat exactlySource
Telegram profileTelegram ID, username, name, chosen interface languageProvided by Telegram on first /start
Subscription & paymentswhich plan was purchased, renewal date, payment method (card / SBP via YooKassa), payment amount and IDGenerated when a plan is purchased
Devicesthe device name you enter yourself (“iPhone”, “Laptop”) and the connection key (client UUID) for a specific serverGenerated when a device is added
Traffic usagetotal data transferred in the current paid period, in bytes — just a number, not the contentRead from Xray counters on the server
Support requeststhe text of messages you send in a ticket, and its statusYou write it yourself in the bot dialogue
Referral programwho referred whom, and bonuses credited, if you take part in the programGenerated when you follow a referral link

§03Data we do not collect

Zero traffic-logging principle

The tunnel runs on the VLESS + Reality protocol: the server opens an encrypted connection disguised as a request to an ordinary website. We deliberately do not enable logging of traffic content, visited addresses, or DNS requests on our servers — the Reality architecture itself does not involve decryption on our side.

The only thing read from server counters is the total volume of megabytes transferred, to track the plan’s traffic limit (see §02). We do not know which sites you visited through the VPN, and we do not store request history.

We also do not request: passport data, bank card numbers (card/SBP payment is processed on the payment provider’s side, bypassing us), real-time geolocation, or access to contacts or messages outside the dialogue with the bot.

§04Why we need this data

Grant access
Telegram ID and plan data are needed to know who to create a VLESS key for, and on which server.
Enforce the traffic limit
100 GB per paid period (see Terms of Service, §04) — without a usage counter there would be nothing to check the limit against.
Show status in your account
how many days are left, how many devices are connected, how much traffic has been used.
Respond to support
ticket history is kept so we do not have to ask for context again on a repeat request.
Notify you of important events
subscription ending, traffic limit exceeded, an admin’s reply — sent by the same bot.

We do not use this data for advertising, do not sell it, and do not share it with analytics networks.

§05Storage and protection

Data is stored in the Service’s database and is accessible only to the Operator and the administrators specified in the system. Technically sensitive secrets — SSH access to servers and Reality’s private encryption keys — are not stored in plain form; they are encrypted (Fernet), kept separate from the rest of the data, and used for nothing other than maintaining the server infrastructure.

The connection key (client UUID) issued to you personally is stored in plain form — the same way it appears in your link/QR code for setting up the VPN client: it is your own access identifier, not an infrastructure secret.

§06Who receives the data

We do not sell or share data with third parties for marketing purposes. Limited sharing happens only where technically necessary for the Service to work:

  • Telegram — the platform the bot runs on; it receives the same data it would from using any other bot.
  • YooKassa — the payment provider processing card and SBP payments; card data goes directly to it, bypassing the Service.
  • VPN server providers (virtual server rental) — see the fact of a connection and traffic volume at their infrastructure level, but do not directly process Service users’ personal data.

Data may be disclosed if directly required by law — for example, upon an official request from an authorized government body.

§07Retention period and deletion

Account data is stored for as long as you use the Service. The traffic usage counter resets on every subscription renewal (see Terms of Service, §04) — it is not a history, it is a measure of the current period.

You can request deletion of your account and related data through support (see §11). Once confirmed, we delete the profile, device keys, and support correspondence, except for records we are legally required to keep longer (e.g. payment records).

§08Your rights

  • Find out what data we hold about you — we will send you an export on request via support.
  • Ask us to correct inaccurate data (e.g. a device’s display name).
  • Request full deletion of your account and data (see §07).
  • Withdraw consent to processing — this is equivalent to ending your use of the Service, since access technically does not work without a baseline set of data.

§09Children

The Service is not intended for people under the age at which their country’s law allows entering into agreements like this one independently. We do not knowingly collect children’s data and will delete an account if we learn it was created in violation of this condition.

§10Changes to this policy

We may update this document — for example, when adding a new payment method or server. The date in the document header (“Effective from…”) always reflects the current version. Material changes that expand the data we collect are additionally announced via a message in the bot.

§11Contacts

For any questions about personal data — the fastest way to reach us is the “Help” section in the bot itself.