How the scores work

Every listing is scored from what its own documents say: the privacy policy, the terms, the cookie policy, the subprocessor list. A bot reads them, names the facts it can quote, and the score is arithmetic over the facts that survive a check against the crawled text. Nothing here is an impression.

Why the model never gives a score

The problem with asking a model “how private is this service, 1 to 10” is that it answers. It gives a different answer to the same documents on a different day, and no reader can tell which run they are looking at. So the model is never asked for a number. It is asked which clauses exist, and made to quote each one. Every quote is then checked against the crawled text, and anything that cannot be found is thrown away. The score is arithmetic over what survives, so the same clauses always produce the same number.

  • A claim about a service always has a clause behind it, and the clause links to the page it was found on.
  • A service cannot argue its way out of a detected change: change detection is a text diff with no model involved.
  • Points can change without re-reading anything. Evidence and arithmetic are kept apart.
  • A bad model run costs findings, never correctness. The worst case is a service scored on less evidence than it deserved.

Privacy, 0–100

What using the service costs someone who does not want to be identified. The scale is kycnot.me’s, to the point.

50  baseline
  + KYC level                 0..4 → +25, +10, −5, −15, −25
  + Monero accepted           +5
  + onion or I2P address      +5
  + privacy points of every attribute
  clamped to 0–100

Trust, 0–100

How far the listing can be relied on: what the site knows about the service, and what its terms establish.

50  baseline
  + the listing’s standing    verified +10, approved +5, a scam −50
  − recently approved         −10 for the first 15 days
  − terms cannot be read      −3
  ± age                       under a year −4, under three months −10 more, two years or more +5
  + registered company        +2
  + trust points of every attribute
  clamped to 0–100

Overall, 0–10

(privacy × 0.6 + trust × 0.4) / 10, rounded to the nearest whole number as kycnot.me rounds it, with a letter grade from the same blend: A from 85, B from 70, C from 55, D from 40, F below. A service marked as a scam is capped at 3 however the rest adds up.

Confidence

Every scan carries a confidence of low, medium or high, from how many documents were read and how many claims were quotable. It is not a measure of whether the score is right, but of how much document there was to be right about.

Where the attributes come from

The bot reads a service’s terms and names the attributes their clauses establish, quoting each; a quote that is not in the crawled text is thrown away. Moderators assign attributes too, from what a suggestion said or what they know, and both count once. A moderator can also decline a finding until the documents change.

Reviews and suggestions

Anyone can post a review or suggest a service, without an account. Both are held until a moderator has read them. A suggestion becomes a listing only after the bot has read the service’s documents; the level and the scores come from those documents, never from the form.

An account, if you want one, is a login key we generate and you keep: no email, no password, nothing to recover. It lets you post reviews under a name and follow what became of your suggestions. Verified accounts publish reviews without waiting for a moderator. The only cookie this site ever sets is the session of someone who logged in.

The catalog

Every attribute, with what it is worth: kycnot.me’s catalog and kycnot.me’s points. The model never sees these numbers, so it cannot optimise a total instead of reading the document.

AttributePrivacyTrust
KYC
No KYC after AML check
You can contact the service's support team to request a free AML score check before making a deposit, and a flagged deposit is returned without identity verification.
+5+10
Refunds do not require KYC
The refund process does not require the completion of a Know Your Customer procedure or the disclosure of personal information.
+5+5
Uses own liquidity
The service runs its own liquidity, so there is no third-party liquidity provider that could independently demand KYC or block funds.
+50
May require KYC/SOF by policy/law
The service may require identity verification, KYC or Source of Funds information, by its own policy or by law, at any time.
-6-4
Refunds may require KYC
KYC or personal information may be needed for a refund when funds are flagged for AML risk.
-3-3
KYC required for refund on AML flag
If a deposit is flagged by the AML system, the service requires identity verification before returning the funds.
-20
Risk-based refund on AML flag
Refund behaviour on AML flags depends on the transaction risk score. Low-risk deposits are returned; high-risk deposits may require KYC.
-40
KYC depends on partners
The service routes through partner providers whose KYC policies vary. The actual experience depends on which partner is used.
-50
May freeze or seize funds
Internal monitoring may freeze or seize funds flagged for suspicious activity, stolen or sanctioned sources.
0-3
Liquidity provider may block funds
Even if the service itself is permissive, the upstream liquidity provider can independently freeze funds and demand KYC or Source of Funds.
-1-1
SoF may be required for refunds
Source of Funds information is required to process a refund.
0-1
Transaction monitoring
Deposits are analysed for blacklisted or high-risk sources; flagged ones need verification.
-10
Some sellers may require KYC
P2P traders set their own rules, and some specify identity verification requirements.
-30
Soft KYC
No formal KYC, but personal information is needed for certain features or services.
-3-1
Refunds without KYC on AML flag
If a deposit is flagged by the AML system, the service returns the funds without demanding identity verification.
0+1
Third-Party Liquidity
Swaps are filled by outside liquidity providers, whose own rules can apply to a transaction.
00
Privacy
Identity-free registration
Users can create accounts without giving personal information such as a full name, address or phone number.
+100
Personal info is not verified
The service does not check personal information: temporary emails, disposable phone numbers or a made-up name and address work.
+90
Strict no-log policy
The service has a strict no-log policy: it does not collect or store any information about its users.
+5+3
No registration needed
Users can access and use the service without creating an account.
+50
Token-based login
Access is through a secret token rather than a username and personal details.
+10
Split-trust architecture
Two independent providers share the work so that no single party can de-anonymise a user.
+3+1
RAM-only infrastructure
Servers run from memory only, so nothing about users survives a reboot or a seizure. (Points not confirmed against the live site.)
+3+3
Peer to peer market
A marketplace where unknown people trade directly with one another rather than with the operator.
0+4
Phone number is required
A valid phone number is needed, verified by SMS or a call. Anonymous SMS services are often acceptable.
-40
Data sharing
Personal data may be shared with authorities or third-party providers for compliance.
-30
Refunds may need personal information
A refund request may require disclosing personal information such as a name or address.
-30
Usage can be detected on public blockchains
On transparent blockchains, use of the service may be publicly identifiable.
-20
In-person service
Physical presence is required: direct interaction with another individual.
-20
Third-party payment processor
Payments are handled through a third party such as Coinbase Commerce or CoinPayments, which sees them.
-2+1
Account required
An account has to be created to access and use the service.
-10
Email required
A valid email address is needed to create an account.
00
No JavaScript needed
The service does not require JavaScript to be enabled.
+10
JavaScript needed
The service does not work without JavaScript. (Points not confirmed against the live site.)
00
API available
An API is available for programmatic interaction with the service.
00
Telegram bot available
The service maintains a Telegram bot interface.
00
Mobile app available
The service can be used through a mobile app.
00
Trust
Atomic swaps
Two people exchange cryptocurrencies from different blockchains directly, without a middleman holding either side.
+3+8
Open source code
The source code of the service is publicly available and licensed as open source.
0+7
Escrow available
A trusted third party holds funds during a peer-to-peer transaction until both sides have delivered.
0+6
Non-custodial wallet
The user holds and manages the private keys; the service never has custody of the funds.
+3+5
Peer to peer network
A decentralised network in which individual computers connect directly rather than through the operator.
+2+5
Audited
The service has been audited by an independent third party.
0+5
Decentralized network
Data, control and decision-making are distributed across independent nodes rather than one operator.
0+5
Good customer support
Customer support is usually fast and helpful.
0+5
Uses hodl invoices
A hodl invoice holds a Lightning payment until the service delivers, like escrow on the Lightning Network.
0+5
Aggregator provides guarantees
If you do not receive your funds or encounter any issues, the aggregator service may reimburse you up to a specified guarantee, subject to the aggregator's terms. This may not apply to all of the aggregator's partners.
0+4
Source available code
The source code is publicly available but not under an open-source licence.
0+4
Hard KYC process
Known for a particularly difficult KYC process, with repeated and arbitrary requests for documents.
-3-6
Custodial wallet
The service manages the private keys and keeps custody of funds, which requires trusting it.
-3-5
Seller wallet is custodial
The seller lacks control of the funds while a trade is open, common on P2P exchanges for dispute handling.
-3-3
Poor or no customer support
The service offers no support, or support that is inadequate, slow or unsatisfactory.
0-5
Service termination policy
The provider can terminate access at any time, without notice, at its discretion.
0-4
May suspend your account
The service reserves the right to suspend or limit access for violations or arrears.
0-4
Slow processing times
Users often experience slower-than-desired processing times.
0-4
Unclear refund policy
The refund policy is unclear or nonexistent.
0-4
No published policies
No published terms of service, AML policy or dispute framework: no protections at all.
0-3
No-refund policy
The service does not offer refunds.
0-3
Additional fees for high-risk transactions
The service may charge additional fees on transactions it flags as high risk.
0-2
Orders processed manually
Orders are processed by hand, so times depend on staff schedules.
0-2
Frontend policies vary
A decentralised protocol whose access, privacy and legal terms vary by the third-party frontend used.
0-1
Hybrid infrastructure
A mix of self-owned hardware and rented servers; the risks of rented infrastructure apply to part of it.
0-1
Third party infrastructure
Entirely on rented servers, so the infrastructure operator is an additional party to trust.
0-1
Currently in beta
The service is in a pre-release phase and may have bugs or missing features.
0-1
Source code is private
The source code is not public, so it cannot be reviewed or audited.
0-1
Partially open source code
Some components are open source; others remain proprietary.
0+2
Basic customer support
Customer support is average: questions are answered and problems fixed in reasonable time.
0+1
Some countries are restricted
Availability varies by jurisdiction or logistics; some countries cannot use the service.
00
Defends against takedown requests
The provider evaluates takedown complaints rather than suspending on receipt.
0+2
Non-custodial protocol
The protocol never takes custody of the user's funds during an exchange.
0+3

Limits

  • Readings are machine-generated. They are a starting point, not legal advice.
  • A service is scored on what it writes down. A policy can be honest and alarming or dishonest and reassuring, and this reads only the text.
  • Documents behind a login, in a PDF, or rendered by JavaScript the crawler cannot get past are not read.
  • The point weights are a judgement call, one number each, published above.

The site

This site is HTML and CSS first. Filters, sorting, the menu, the review form and every other part work with JavaScript switched off; a small script, when allowed to run, keeps the address bar in step with the filters and searches as you type. There is no tracker, no account required, and no cookie unless you log in. Fonts are served from here, not from a third party. The full dataset is published as JSON.