Privacy Policy

Last updated: 01-July-2026

Short version: we collect as little as we can get away with, we don’t sell anything about you, and we don’t run ad trackers. You can read this whole site without telling us who you are. If you email us, we’ll have your email, because that’s how email works.

The longer version is below. It’s written in plain English on purpose. A privacy policy nobody can read isn’t much of a promise.

Who we are

Dark Web Decoded publishes darkwebdecoded.com, an educational site about the dark web, anonymity tools, and online privacy.

If you want to talk to us about any of this, we’re at [email protected].

For the legal folks: we’re the data controller for the information described here. We’re based in Arizona, US.

Why we care about this more than most sites do

We write about privacy. Half our readers are here because they’re worried about being tracked. It would be pretty embarrassing to run a surveillance operation on them while doing it.

So the rule we work to is: if we don’t need it, we don’t collect it. That’s it. That’s the policy. Everything below is just the details.

What we actually collect

When you just read the site

Almost nothing about you personally.

Our web host records standard server logs when a page loads: IP address, browser and device type, the page you asked for, the page you came from, and the time. Every web server on earth does this. We use it to keep the site online, spot attacks, and fix things that break.

 Logs are kept for 7 days, then deleted.

Analytics

We don’t run analytics at all. We genuinely have no idea who reads this site, and we’ve made our peace with that.

When you use the contact form

You give us: your message, and whatever you put in the email and name fields.

The name field is optional and we mean that. You don’t need to use a real one.

When you email us

We get your email address, whatever your mail provider puts in the headers, and what you wrote. Nothing we can do about that part. It’s email.

If you’d rather we couldn’t read it in transit, our PGP key is at here. Use it. We won’t think you’re paranoid.

Cookies

We use one cookie, and only if you’ve dismissed a banner or set a preference, so the site remembers. That’s a functional cookie and it doesn’t tell us anything about you.

We don’t run advertising cookies, we don’t run social media pixels, and we don’t have a Facebook Like button quietly reporting your visit to Menlo Park.

If you’re using something that blocks cookies, the site will work fine.

Comments

If we ever turn comments on, you’ll be able to post with a name and an email. The email stays private and is only there so we can reply. Your comment and your chosen name are public, obviously, since that’s what a comment is.

Newsletter

If you sign up, we keep your email address and the fact that you signed up. We send you articles. We don’t send you anything else, and we don’t hand your address to anyone. Every email has an unsubscribe link and it works on the first click.

What we don’t do

Worth spelling out:

  • We don’t sell your data. Not to advertisers, not to brokers, not to anyone.
  • We don’t share it with third parties except the boring infrastructure ones listed below.
  • We don’t build profiles on readers or try to work out who you are.
  • We don’t run behavioural advertising.
  • We don’t try to deanonymise anyone. Obviously. Given the subject matter, we feel like this one needs saying out loud.

How long we keep things

  • Server logs: 7 days, then gone.
  • Contact form messages and emails: until the conversation is finished and there’s no reason to keep it. Usually a few months. We clear the inbox out periodically.
  • Newsletter signups: until you unsubscribe.
  • Analytics: aggregate numbers only, kept indefinitely, and there’s nothing personal in them.

If you want your message deleted sooner, ask and we’ll do it.

Your rights

Depending on where you live (and definitely if you’re in the UK or EU under GDPR, or California under CCPA), you have the right to:

  • ask what we hold about you
  • get a copy of it
  • have it corrected
  • have it deleted
  • object to us processing it
  • take it elsewhere in a portable format
  • complain to your data protection regulator if we’ve messed up

To use any of these, email [email protected]. We’ll respond within 30 days and we won’t make you jump through hoops.

Fair warning: for most readers the honest answer to “what do you hold about me” is “nothing, we have no idea who you are.” That’s the point.

We’re not going to ask you to prove your identity by sending us a photo of your passport. That would be a slightly absurd thing for us to demand, given everything else on this page.

Legal basis for processing

  • Server logs and security: legitimate interest in keeping the site running and not getting knocked over.
  • Contact form and email: your consent, and our legitimate interest in replying to you.
  • Newsletter: your consent, which you can pull back any time.
  • Analytics: consent if it’s cookie-based, legitimate interest if it’s the anonymous kind.

Where your data goes

Some of our providers are outside the UK/EU, mostly in the US. Where that happens, transfers are covered by standard contractual clauses or an equivalent mechanism. In practice there’s very little data to transfer, which is the best safeguard there is.

Kids

The site is for adults. We don’t knowingly collect anything from anyone under 16. If you think we have, email us and we’ll delete it.

Other people’s sites

We link out to news outlets, court records, research papers, and documentation. Once you click, you’re on their turf and their privacy policy applies, not ours. Some of them track far more aggressively than we do.

And to say the thing we say on every page: we don’t link to dark web sites, and we’re not affiliated with anyone operating on one.

If something goes wrong

If we ever have a breach that puts you at risk, we’ll tell the regulator within 72 hours and we’ll tell you. We won’t sit on it, we won’t call it an “incident,” and we won’t bury it in a Friday afternoon blog post.

Changes to this policy

We’ll update this when things change, and we’ll change the date at the top. If it’s a significant change, we’ll say so on the site rather than hoping you don’t notice.

Talk to us

Questions, requests, or you think we’ve got something wrong here:

[email protected] PGP: here

If you’re in the UK or EU and we’ve handled your data badly, you can complain to your national data protection authority. We’d rather you came to us first, but it’s your call.