Cookie Policy
dkuvpn sets one cookie. It keeps you signed in, and there is nothing else — no advertising, no third-party script, and no analytics running in your browser on any page.
Last updated 16 August 2026
What we do not set
Each line below was checked against the code rather than assumed. None of the following appears on any page of this site:
- Analytics running in your browser — no Google Analytics, no Plausible, no counter script, no session recording. How many people visited is worked out afterwards from the web server's own log, which puts nothing on the page and is described in the Privacy Policy.
- Advertising and retargeting. Nothing about you is sold to an advertiser, because nothing is collected that could be sold.
- A tag manager, or a tracking pixel of any sort — no invisible image, iframe or beacon. Every image on the site is a file served from this domain.
- Third-party script. Every script this site serves comes from this origin.
- Cross-site tracking. dkuvpn_session is a first-party cookie, and there is no third-party cookie here for anyone to follow you with.
- Fingerprinting. Nothing reads your fonts, canvas, screen or device list to assemble an identifier.
- localStorage, sessionStorage or IndexedDB. The site writes nothing else to browser storage at all.
Three browser settings are read, and naming them is what keeps the list above honest. Every page asks whether you have switched on “reduce motion”, which stops the globe turning and shortens every transition on the site; “reduce transparency”, which turns the navigation bar solid; and “increase contrast”, which strengthens a few of the colours. Each answer decides how a page looks, and nothing more. None of the three is stored and none is sent anywhere.
Marzban's own admin console is served at /admin for whoever administers the service. That is a separate application and whatever it keeps in a browser is its own; nothing in a student's use of dkuvpn goes near it.
Fonts, which are usually the leak
This site is set in EB Garamond. On most sites a font like that is fetched from fonts.googleapis.com, which means your browser makes a request to Google — carrying your IP address — before the first word is drawn. Not here. The font is downloaded once when the site is built and served from this domain along with everything else, so your browser never contacts Google. Chinese text is set in the CJK font already on your device and is not downloaded at all.
The reason is practical as much as principled: fonts.googleapis.com is not reachable from mainland China, and a site that waits on it is a site that does not load where its students are.
Your language is in the address, not a cookie
Every page lives under /en or /zh. Arrive without one and the site reads the Accept-Language header your browser already sends on every request, picks the nearer of the two, and redirects you once. Nothing about that is stored: no cookie is set, and switching language is a link rather than a preference we remember for you.
What happens when you leave this site
Two things here take you somewhere else, and once you are there this policy stops applying.
- Paying. The buy buttons open Gumroad's checkout in a new tab. Gumroad is the merchant of record, handles the card details this site never sees, and sets its own cookies under its own policy. All that travels with you is what is in the link: the plan you picked, and your netid, so the payment can find your account.
- The setup guides. The install buttons point at the App Store, at Happ's own site, or, on Windows, at GitHub, where its installer is published. Those are third-party sites with their own cookies and their own policies. The guides link to them and do nothing more.
Every response from this site carries Referrer-Policy: same-origin, so when one of those links opens, the site at the other end is not told which page you came from.
The VPN connection is not a cookie
Clearing cookies signs you out of this website. It does nothing to the connection. Your subscription link lives in your VPN client, the client reaches the exit servers itself, and none of it passes through this browser or touches its cookies — so a cleared browser keeps connecting, right up until the next time you want to look at your dashboard.
The reverse holds too: nothing about your browsing runs through a cookie. What the proxy panel holds against your account is a running total of bytes used, an expiry date and a data limit — the Privacy Policy lists the rest of that account in full. Not a list of the sites you opened, the addresses you reached, or the names you looked up.
Everything that is not a cookie
This page covers browser storage and nothing more. What the service knows about you — the Duke address you sign in with, the sign-in codes and how briefly they are kept, the IP address counted against the rate limit, the record of what you paid for, and what the proxy panel stores against your account — is set out in the Privacy Policy. The rest of the arrangement is in the Terms.
Changes, and how to reach us
Every version of this page is dated. If it changes, the date at the top changes with it, and any change to what is kept in your browser — a new cookie, or an existing one doing something new — is stated plainly here rather than folded into a paragraph. The date is the announcement: there is no mailing list, and we will not email you about a policy.
Anything on this page that is unclear, or wrong, goes to support@dkuvpn.com. If you find a cookie on this site that this document does not list, say so — that is either a bug in the site or a bug in this page, and both get fixed.