Last updated: 01-July-2026
Short version: we collect as little as we can get away with, we don’t sell anything about you, and we don’t run ad trackers. You can read this whole site without telling us who you are. If you email us, we’ll have your email, because that’s how email works.
The longer version is below. It’s written in plain English on purpose. A privacy policy nobody can read isn’t much of a promise.
Who we are
Dark Web Decoded publishes darkwebdecoded.com, an educational site about the dark web, anonymity tools, and online privacy.
If you want to talk to us about any of this, we’re at [email protected].
For the legal folks: we’re the data controller for the information described here. We’re based in Arizona, US.
Why we care about this more than most sites do
We write about privacy. Half our readers are here because they’re worried about being tracked. It would be pretty embarrassing to run a surveillance operation on them while doing it.
So the rule we work to is: if we don’t need it, we don’t collect it. That’s it. That’s the policy. Everything below is just the details.
What we actually collect
When you just read the site
Almost nothing about you personally.
Our web host records standard server logs when a page loads: IP address, browser and device type, the page you asked for, the page you came from, and the time. Every web server on earth does this. We use it to keep the site online, spot attacks, and fix things that break.
Logs are kept for 7 days, then deleted.
Analytics
We don’t run analytics at all. We genuinely have no idea who reads this site, and we’ve made our peace with that.
When you use the contact form
You give us: your message, and whatever you put in the email and name fields.
The name field is optional and we mean that. You don’t need to use a real one.
When you email us
We get your email address, whatever your mail provider puts in the headers, and what you wrote. Nothing we can do about that part. It’s email.
If you’d rather we couldn’t read it in transit, our PGP key is at here. Use it. We won’t think you’re paranoid.
Cookies
We use one cookie, and only if you’ve dismissed a banner or set a preference, so the site remembers. That’s a functional cookie and it doesn’t tell us anything about you.
We don’t run advertising cookies, we don’t run social media pixels, and we don’t have a Facebook Like button quietly reporting your visit to Menlo Park.
If you’re using something that blocks cookies, the site will work fine.
Comments
If we ever turn comments on, you’ll be able to post with a name and an email. The email stays private and is only there so we can reply. Your comment and your chosen name are public, obviously, since that’s what a comment is.
Newsletter
If you sign up, we keep your email address and the fact that you signed up. We send you articles. We don’t send you anything else, and we don’t hand your address to anyone. Every email has an unsubscribe link and it works on the first click.
What we don’t do
Worth spelling out:
- We don’t sell your data. Not to advertisers, not to brokers, not to anyone.
- We don’t share it with third parties except the boring infrastructure ones listed below.
- We don’t build profiles on readers or try to work out who you are.
- We don’t run behavioural advertising.
- We don’t try to deanonymise anyone. Obviously. Given the subject matter, we feel like this one needs saying out loud.
How long we keep things
- Server logs: 7 days, then gone.
- Contact form messages and emails: until the conversation is finished and there’s no reason to keep it. Usually a few months. We clear the inbox out periodically.
- Newsletter signups: until you unsubscribe.
- Analytics: aggregate numbers only, kept indefinitely, and there’s nothing personal in them.
If you want your message deleted sooner, ask and we’ll do it.
Your rights
Depending on where you live (and definitely if you’re in the UK or EU under GDPR, or California under CCPA), you have the right to:
- ask what we hold about you
- get a copy of it
- have it corrected
- have it deleted
- object to us processing it
- take it elsewhere in a portable format
- complain to your data protection regulator if we’ve messed up
To use any of these, email [email protected]. We’ll respond within 30 days and we won’t make you jump through hoops.
Fair warning: for most readers the honest answer to “what do you hold about me” is “nothing, we have no idea who you are.” That’s the point.
We’re not going to ask you to prove your identity by sending us a photo of your passport. That would be a slightly absurd thing for us to demand, given everything else on this page.
Legal basis for processing
- Server logs and security: legitimate interest in keeping the site running and not getting knocked over.
- Contact form and email: your consent, and our legitimate interest in replying to you.
- Newsletter: your consent, which you can pull back any time.
- Analytics: consent if it’s cookie-based, legitimate interest if it’s the anonymous kind.
Where your data goes
Some of our providers are outside the UK/EU, mostly in the US. Where that happens, transfers are covered by standard contractual clauses or an equivalent mechanism. In practice there’s very little data to transfer, which is the best safeguard there is.
Kids
The site is for adults. We don’t knowingly collect anything from anyone under 16. If you think we have, email us and we’ll delete it.
Other people’s sites
We link out to news outlets, court records, research papers, and documentation. Once you click, you’re on their turf and their privacy policy applies, not ours. Some of them track far more aggressively than we do.
And to say the thing we say on every page: we don’t link to dark web sites, and we’re not affiliated with anyone operating on one.
If something goes wrong
If we ever have a breach that puts you at risk, we’ll tell the regulator within 72 hours and we’ll tell you. We won’t sit on it, we won’t call it an “incident,” and we won’t bury it in a Friday afternoon blog post.
Changes to this policy
We’ll update this when things change, and we’ll change the date at the top. If it’s a significant change, we’ll say so on the site rather than hoping you don’t notice.
Talk to us
Questions, requests, or you think we’ve got something wrong here:
[email protected] PGP: here
If you’re in the UK or EU and we’ve handled your data badly, you can complain to your national data protection authority. We’d rather you came to us first, but it’s your call.