A Windscribe setup guide for BitTorrent Classic on Windows. This is not a guide for BitTorrent Web, which runs in the browser and does not expose the settings below.
If you just want the safe setup and would rather not learn every networking term on the first read, follow these seven steps. The rest of the guide explains each one in more detail and adds optional extras you can ignore for now.
That is the whole safe path. Everything below is detail and optional refinement.
A few facts that will save you a support ticket:
With BitTorrent Classic, the order of operations matters more than any in-client setting, because your safety net is the Windscribe app, not the client. Set up the VPN before the client ever opens.
A word on why the Firewall, and not a "kill switch": a kill switch is reactive. It only cuts your connection after it notices the VPN dropped, and in that gap, packets can still escape over your real IP. Windscribe's Firewall is proactive. With Always On selected, the Always-On Firewall is designed to block traffic outside the VPN tunnel, including if the app exits, crashes, or the computer restarts. In the trade this is called failing closed. For torrents you leave running unattended, that property is the entire point.
The correct sequence, which mirrors Windscribe's own torrent best-practice guidance:


There is less to configure here than you might expect, and that is by design: the VPN app is doing the protecting.
Options > Preferences > Connection. You will see a Proxy Server section with a Type dropdown (SOCKS4, SOCKS5, HTTP, HTTP Connect). Leave it set to (none). Windscribe no longer runs hosted SOCKS5 proxy servers, so there are no Windscribe proxy credentials to enter here. For a Windscribe setup, the supported path is the VPN app plus the Always-On Firewall, not an in-client proxy. Only touch this section if you run your own separate proxy, which is outside the scope of this guide.

BitTorrent Classic's Options > Preferences > Connection panel, Proxy Type set to (none)
Some torrent clients let you lock the client to a specific network adapter so it refuses to send traffic whenever the VPN interface is down. Clients like qBittorrent expose this directly, and where a client supports it, binding to the VPN interface is a good extra layer. If you do not see a clear adapter/interface binding option in BitTorrent Classic, rely on Windscribe's Always-On Firewall instead.
Optional advanced section: only use this if you care about seeding performance or connectability. It is not required for privacy, and beginners can skip it entirely. Port forwarding can help with inbound connections, connectability, and seeding ratios, but it is optional. Here is what Windscribe offers, by plan:
One hard rule regardless of plan: do not buy a Residential Static IP for torrenting. Residential Static IPs are not peer-to-peer enabled, so seeding through one will not work. If you want a Static IP for seeding, use a Datacenter Static IP in a peer-to-peer-enabled location.
If you do reserve a port, pick a fixed listening port in BitTorrent Classic (it lives in the same Options > Preferences > Connection panel as the proxy settings), and disable the option that randomizes the port on startup. Use that listening port as the internal port when you create the Windscribe port forward; Windscribe will then show you the external port that peers actually connect to. While you are in that panel, turn off UPnP and NAT-PMP so the client does not try to map a different port on its own.

Disable "Randomize port each time BitTorrent starts" before creating a port forward
A browser leak test proves nothing about your torrent client, because the client and the browser can take different routes. Verify the client directly.
If the torrent checker shows the Windscribe IP and your real address appears nowhere, BitTorrent Classic is routing through Windscribe as intended.
If the client connects but specific trackers refuse to, check R.O.B.E.R.T., Windscribe's server-side domain blocker for ads, trackers, malware, and custom rules. The standard blocklists toggle in the desktop app, but the fuller controls and custom rules live in your account at My Account > R.O.B.E.R.T.. If an aggressive blocklist is catching a legitimate tracker domain, add that domain as a whitelist rule there and restart the client.
No. Peer-to-peer traffic is disabled on free servers. You will need Full Pro, or a Build-a-Plan that includes the locations you intend to torrent on.
No. Windscribe retired its hosted SOCKS5 proxy servers, so there are no Windscribe proxy credentials to enter. Leave the proxy type set to (none) and let the VPN app plus the Always-On Firewall do the work. The only reason to touch that panel is if you run your own separate proxy.
It makes you more private, not invisible. Windscribe replaces your real IP with the VPN server's IP and encrypts the traffic your ISP can see, which is what stops casual logging of your address. That is privacy, not a cloak of invisibility, and it is not a license to ignore the law where you live.
No. Port forwarding is not a privacy feature; it only helps with inbound connections and seeding. If you want it, ephemeral port forwarding is a Pro-only feature (Build-a-Plan and free accounts do not get it), and permanent forwarding requires a purchased Static IP.
Any peer-to-peer-enabled location. Most paid locations allow peer-to-peer, just avoid any server marked with the crossed-out P2P icon in the app, and do not use a Residential Static IP, since those are not peer-to-peer enabled.
Three usual suspects, in order: you opened BitTorrent Classic before the VPN finished connecting, you are on a server that does not allow peer-to-peer, or R.O.B.E.R.T. may be blocking a tracker domain. Reconnect and wait for CONNECTED, confirm the location allows peer-to-peer traffic, then check your R.O.B.E.R.T. rules in My Account.
Peer-to-peer needs a paid plan, so grab Full Pro or build the plan that fits your locations, connect to a peer-to-peer-enabled server, and get back to downloading your entirely legal Linux distros.