Terms of Service
dkuvpn is run by students, for students at Duke Kunshan. It is not a Duke service. These terms say who may use it, what it does, and what it will not promise.
Last updated 12 August 2026
Accepting these terms
Signing in is how you accept these terms, and it is also what creates your account. There is no box to tick and no separate contract. If you do not accept them, do not sign in; if you already have, stop using the service and write to us about whatever time is left.
This page, the Privacy Policy, the Refund Policy and the Cookie Policy are one document in four parts. Where one of the others describes something more exactly than this page does, the more exact statement is the one that applies.
Throughout, we means the students who run dkuvpn, and you means the person whose Duke address is on the account.
This is not a Duke service
dkuvpn is not operated by, endorsed by, or affiliated with Duke Kunshan University or Duke University. It is a student project run for other students. Neither institution is answerable for it.
The site is set in EB Garamond, uses Duke Navy and Duke Royal Blue, and carries DKU's mark as its browser tab icon. That says who the service is for — students at DKU — and nothing else. It is not a claim that either university built it, reviewed it, or agreed to it.
What that decides in practice is where a problem goes. Neither university's IT desk can see this service, restore an account or return a payment. We can, at support@dkuvpn.com.
Who can use it
You need a working email address on a domain the service allows — duke.edu is the primary one, and the sign-in page names what it accepts. You type the address, a six-digit code is emailed to it, and the part before the @ becomes your netid. The code lasts 10 minutes and works once.
The netid is the account. There is no second identifier anywhere in this service, so one netid is one account: signing in with the same address always lands on the same account, and signing in with somebody else's address never gets you an account of your own — it opens theirs, and if they have never signed in it creates theirs and spends their free week. Do not do that.
- A netid is 3 to 32 characters of a–z, 0–9 and underscore, because that is what Marzban accepts as a username. An address no valid netid can be made from is refused at the form, with the reason, rather than failing further in.
- An allowed domain that is not the primary one is carried into the netid: ab999@dukekunshan.edu.cn becomes ab999_dukekunshan. Two domains can hold the same local part and two different people, and those two must never land on one account.
- If an account already exists under your netid but belongs to a different Marzban administrator, sign-in fails and asks you to write to us. The code was not wrong; that account is simply not ours to open.
Keep control of the address. It is the only proof of who you are here, so an address you have lost access to is an account you have lost access to.
What the service is, and what it is not
dkuvpn is an account on a Marzban panel and a subscription link. You paste the link into a proxy client — Happ, which the setup guides go through step by step — and the client carries your traffic out through one of the exits the service offers. Today those are Durham, Iowa, Seoul, Tokyo, Bangkok and Singapore.
That is the whole product. Your dashboard shows your netid and the account's status, the subscription link, how much time is left, and the traffic counted against the account so far — against a data limit, where one has been set.
What it is not:
- Anonymity. Your traffic leaves from an address that belongs to this service and is shared with other students, so a site sees that address rather than yours — along with everything else you hand it: your login, your cookies, your account.
- Protection against a determined adversary. The tunnel is encrypted, which is not the same as being safe from someone who can watch both ends of it, or who has your device in their hands. Do not lean on it where being wrong about that would be serious.
- A promise that any particular site loads. Plenty of services refuse addresses they believe belong to proxies, and one that turns an exit away has made its own decision. There is nothing on this side to fix.
- Access you do not otherwise have. An exit in Durham is not the university network and carries none of its entitlements; it will not open a journal your own account cannot open.
Your subscription link is a credential
The link on your dashboard is the account. Nothing stands between holding it and using it — no code, no second factor — which is why the dashboard says, directly under the link, to treat it like a password.
Sharing the link, selling it, or running one account for several people breaches these terms. The first consequence needs no enforcement at all: whoever holds it spends your days and your traffic, and everything done through it is done as you.
So do not post it, do not paste it into a group chat, and do not pass it to a friend when what you could pass them is the fact that their own first week is free. If it has already got out, write to us — the link can be revoked and a new one issued from the panel, and the old one stops working the moment it is.
Acceptable use
The list is short. Every line is on it because a few servers, paid for a month at a time, cannot absorb the alternative.
- Nothing illegal under the law that applies to you, and nothing that makes this service a route into somebody else's systems.
- No attacks: no port scanning, no brute forcing, no denial of service, no intrusion attempts.
- No spam, and no bulk unsolicited mail of any kind over the connection.
- No sharing, reselling, renting or reassigning your account, in whole or in part.
- No using this to get around Duke's or DKU's acceptable-use policies. Those bind you whichever route your traffic takes, and a proxy is not an exception to them.
- No going at the service itself: do not work around the sign-in limits (3 codes per netid per 15 minutes, 10 per IP address per hour, 5 tries per code), do not request codes for addresses that are not yours, and do not probe the panel or the payment endpoint.
- Nothing that gets an exit shut down. A sustained run of abuse complaints costs a server, and the server is lost for everyone who was using it rather than only for whoever caused it.
Breaking any of these is grounds for disabling the account. Coursework, ordinary browsing, video calls and streaming are not on this list and are not what it is aimed at.
The law where you are
Complying with the law that applies to you is yours to do. We run a proxy; we are not anybody's lawyer, and nothing on this page is legal advice.
In mainland China, using a VPN that has not been authorised by the relevant authorities is restricted under PRC law. Whether to use dkuvpn there is your decision and your risk. We do not encourage anyone to break any law, and we cannot carry the consequences of one on your behalf.
It is also half the reason nothing here promises uninterrupted service. A connection whose job is to cross a national filter cannot honestly be guaranteed by anyone, and a document that guaranteed it would be worth less than one that says this.
Duke's and DKU's own policies apply to you on their own terms. Nothing here overrides them, and nothing here stands between you and them.
Availability
Best effort, run by students around their own coursework. No uptime figure is quoted here, because none could be honoured.
The reasons a connection stops working, commonest first:
- Network conditions between you and the exit. The common one, and usually minutes rather than hours.
- Blocking or interference aimed at the protocol or at an exit's address. An exit that has been blocked may not come back, and the fix is normally a different exit.
- Maintenance on a server or on the panel. Usually short and usually unannounced: there is no status page and no announcement list, because the only mail this service sends anyone is a sign-in code.
- An exit going away for good. The six named above are what is offered today, not a set we undertake to keep.
- Your own account — time run out, or a data limit if one has been set on it. The dashboard shows both, and both are visible long before they bite.
The service itself can stop. It is run by students who graduate, on servers paid for a month at a time, and nothing here undertakes that it runs for any particular length of time. If it is going to close, the notice goes on this site, because there is no announcement list to send one down. Time you paid for and cannot use is then a refund question: the Refund Policy covers it.
When it stops, try another exit, then the setup guides, then write to us. Whether an outage was long enough to be worth money back is a question for the Refund Policy.
Paying for time
The first week is free. A netid signing in for the first time has a one-week account provisioned automatically, and nothing is asked for in exchange. It does not turn into a subscription, because there is no subscription for it to turn into.
After that, time is bought a length at a time:
- Month — $4.95 for 30 days
- Session (2 months) — $8.95 for 60 days
- Semester (4 months) — $14.95 for 120 days
- Year (12 months) — $29.95 for 365 days
All prices are in US dollars. Every purchase is one-off: nothing renews, no card is stored, and there is no subscription to cancel. Checkout happens on gumroad.com in a new tab, so this site never sees your card details — Gumroad is the merchant of record, and the payment itself is on its terms.
Time stacks. A purchase counts from whatever is left on the account rather than from the day you paid, so buying early never burns days you already have. An account with no expiry at all is left alone rather than given one, so paying can never shorten an account.
Time normally lands about a minute after payment, when Gumroad tells us the sale happened. That notice is the only thing that grants it, and where it cannot reach us Gumroad tries four times over roughly seventy minutes before giving up — so if a couple of hours have passed and your expiry has not moved, send us the receipt and it will be applied by hand. Do not pay a second time.
Refunds, partial refunds and chargebacks — and what reversing a sale does to the days on your account — are set out in the Refund Policy.
Suspension and disabling
An administrator can disable an account that breaches these terms. Where a warning is possible you get one first, written by hand from support@dkuvpn.com — the service itself only ever sends sign-in codes. Where the breach is doing damage while we type — a link handed round a year group, an attack running out of an exit — the account goes off first and that mail follows.
A payment landing on a disabled account does not re-enable it. Applying time writes the new expiry date and deliberately never touches an account's status, so buying more time after a suspension buys days on an account that still will not connect. Write to us before you buy, not after.
Disabling is not deleting. The account, its expiry and its traffic total stay exactly where they were, so a suspension that turns out to be a mistake is undone by switching it back on and costs you nothing.
If you think we got it wrong, say so at support@dkuvpn.com. There is no appeals procedure — there is nothing procedural here at all — but there is a person reading that mailbox, and being wrong about this is something we would rather find out.
Ending it yourself
Stop whenever you like. There is nothing to cancel because nothing recurs: stop using the link, let the days run down, and the account stops connecting on its own. Not using it is not charged for.
Signing out clears the single cookie this site sets, in that browser. It does not touch the account and it does not stop the subscription link, which is not tied to your session — a device you no longer control with the link still on it is a reason to ask for a new link, not a reason to sign out.
To have the account itself removed, ask; it is done by hand. Two things are worth knowing first. Days already bought are not paid back because you asked for the account to go — what is refundable, and when, is in the Refund Policy. And the payment ledger keeps its rows, netid included, because that record is what stops a reversed sale being granted a second time; the Privacy Policy says exactly what those rows hold.
No warranty, and the limit of what we owe
The service is provided as it is. There is no warranty of availability, of speed, or of fitness for any particular purpose, and none that a given site will load through it. Every reason for that is written plainly in the sections above rather than buried in this one.
If it fails, what we owe you is the money you paid for time you did not get, on the terms of the Refund Policy. We do not take on what follows from an outage: a deadline missed, a submission that would not upload, a call that dropped, an account somewhere else closed for connecting through a proxy. A service that charges $4.95 for a month cannot carry those, and writing otherwise here would not make it able to.
Nothing here tries to exclude what cannot lawfully be excluded, including our own fraud and harm caused deliberately or recklessly. Where a mandatory rule of the law that applies to you gives you a right, this document does not take it away.
Who you are dealing with
dkuvpn is run by students at Duke Kunshan for other students there. There is no company behind it, no office and no support rota — there is a mailbox and the people who read it.
That is why this document names no governing law and no arbitration forum. Writing one in would be claiming a legal structure that does not exist. Whatever law applies to you applies whether or not a page like this says so, and nothing here waives a right you hold under it.
So a complaint takes the short route: write, in your own words, and a person answers. A payment has a second route, because Gumroad took the money and runs its own dispute process — but read the Refund Policy first. It is the same money, it is faster, and a chargeback costs a service this size more than the sale was worth.
Contact and changes
Everything goes to support@dkuvpn.com: a connection that stopped working, an account that was disabled, a link that got out, a payment that never landed, or a question about this page. It is read by the students who run dkuvpn, between their own classes, and answered within one business day.
When this document changes, the date at the top of the page changes with it. There is no announcement list — the only mail this service sends anyone is a sign-in code — so this page is the notice, and it is worth re-reading when that date moves. Using the service after a change accepts the changed terms; if you do not accept them, stop using it and write to us about the time you have left.
A change never applies backwards to a purchase already made. The version published on the day you paid is the one that governs it.