[
  {
    "slug": "anonexch",
    "name": "AnonExch",
    "homepage": "https://anonexch.io",
    "category": "aggregator",
    "privacyScore": 100,
    "transparencyScore": 97,
    "overallScore": 10,
    "grade": "A",
    "confidence": "medium",
    "lastScanAt": "2026-09-06T22:42:57+00:00",
    "scan": {
      "status": "complete",
      "corpusHash": "2b066c9423fdf162da8262c745814568d1b8f16ccf6511d073b45e9ac44b36fa",
      "summary": "AnonExch refuses to run identity checks or AML screening at any amount, and holds no funds it could freeze. A swap that fails is refunded automatically minus the network fee. Swap records are deleted 24 hours after completion, support emails after 90 days.",
      "kycLevel": 0,
      "kycRationale": "The terms state outright that there is no identity-verification programme and that one will never be introduced, listing every document and detail the service will not ask for, at any amount and at any stage including refunds and API use. Section 2 is explicitly excluded from the clause allowing the terms to be changed, and the service states it runs no AML screening, no chain-analysis scoring and no address blocklist.",
      "kycPolicyMd": "Nothing triggers identity verification here: the terms say there is no KYC step, no AML questionnaire and no source-of-funds request at any amount or stage. A swap asks only for a destination address and an optional refund address, and merchant accounts ask only for an email and password with no business documents. Refunds are never conditioned on identity, documents or a source-of-funds explanation, and the service says it removes any routing partner that starts demanding identity documents.",
      "components": [
        {
          "label": "Baseline",
          "points": 50,
          "dimension": "privacy"
        },
        {
          "label": "Guaranteed no KYC",
          "points": 25,
          "dimension": "privacy"
        },
        {
          "label": "Has Onion or I2P URLs",
          "points": 5,
          "dimension": "privacy"
        },
        {
          "label": "Accepts Monero",
          "points": 5,
          "dimension": "privacy"
        },
        {
          "label": "No KYC after AML check",
          "points": 5,
          "dimension": "privacy"
        },
        {
          "label": "Refunds do not require KYC",
          "points": 5,
          "dimension": "privacy"
        },
        {
          "label": "Identity-free registration",
          "points": 10,
          "dimension": "privacy"
        },
        {
          "label": "Personal info is not verified",
          "points": 9,
          "dimension": "privacy"
        },
        {
          "label": "Strict no-log policy",
          "points": 5,
          "dimension": "privacy"
        },
        {
          "label": "No registration needed",
          "points": 5,
          "dimension": "privacy"
        },
        {
          "label": "Token-based login",
          "points": 1,
          "dimension": "privacy"
        },
        {
          "label": "Split-trust architecture",
          "points": 3,
          "dimension": "privacy"
        },
        {
          "label": "Non-custodial wallet",
          "points": 3,
          "dimension": "privacy"
        },
        {
          "label": "Baseline",
          "points": 50,
          "dimension": "transparency"
        },
        {
          "label": "Verified",
          "points": 10,
          "dimension": "transparency"
        },
        {
          "label": "Mature service",
          "points": 5,
          "dimension": "transparency"
        },
        {
          "label": "No KYC after AML check",
          "points": 10,
          "dimension": "transparency"
        },
        {
          "label": "Refunds do not require KYC",
          "points": 5,
          "dimension": "transparency"
        },
        {
          "label": "Refunds without KYC on AML flag",
          "points": 1,
          "dimension": "transparency"
        },
        {
          "label": "Strict no-log policy",
          "points": 3,
          "dimension": "transparency"
        },
        {
          "label": "Split-trust architecture",
          "points": 1,
          "dimension": "transparency"
        },
        {
          "label": "Non-custodial wallet",
          "points": 5,
          "dimension": "transparency"
        },
        {
          "label": "Aggregator provides guarantees",
          "points": 4,
          "dimension": "transparency"
        },
        {
          "label": "Non-custodial protocol",
          "points": 3,
          "dimension": "transparency"
        }
      ],
      "unanswered": [],
      "signals": [
        {
          "id": 203,
          "slug": "may-require-kyc-sof-by-policy",
          "stance": "absent",
          "rationale": "The service states it runs no identity-verification programme and will not introduce one, and asks for no source-of-funds or source-of-wealth information at any point.",
          "quote": "AnonExch operates no identity-verification programme, and will not introduce one. There is no KYC step, no AML questionnaire, and no source-of-funds or source-of-wealth request at any point in using this service.",
          "sourceUrl": "https://anonexch.io/terms"
        },
        {
          "id": 207,
          "slug": "kyc-depends-on-partners",
          "stance": "absent",
          "rationale": "The service states that being no-KYC is a condition for a provider to stay in its routing set, and that a provider demanding documents is removed.",
          "quote": "every one of them is no-KYC: not imposing identity verification on the swaps we route is the condition for being in our routing set, and a provider that starts demanding identity documents from users routed through AnonExch is removed from it",
          "sourceUrl": "https://anonexch.io/terms"
        },
        {
          "id": 208,
          "slug": "may-freeze-or-seize-funds",
          "stance": "absent",
          "rationale": "The service states it does not freeze, hold, seize or claw back user funds.",
          "quote": "We do not freeze, hold, seize, or claw back user funds, and we do not condition access to the service on identity, approval, or attestation.",
          "sourceUrl": "https://anonexch.io/terms"
        },
        {
          "id": 211,
          "slug": "transaction-monitoring",
          "stance": "absent",
          "rationale": "The service states it does not screen or score deposits and keeps no address blocklist.",
          "quote": "AnonExch runs no AML screening, no chain-analysis scoring, and no address blocklist. We do not assign your deposit a risk rating, we do not check it against sanctions or watchlists, and we do not refuse, delay, or reprice a swap because of where the coins came from.",
          "sourceUrl": "https://anonexch.io/terms"
        },
        {
          "id": 239,
          "slug": "data-sharing",
          "stance": "absent",
          "rationale": "The service states it has never sold, rented or shared user data with a third party for any purpose and will not do so.",
          "quote": "We do not profile visitors, and we have never sold, rented, or shared user data with a third party for marketing, analytics, scoring, or any other purpose — nor will we.",
          "sourceUrl": "https://anonexch.io/terms"
        },
        {
          "id": 272,
          "slug": "custodial-wallet",
          "stance": "absent",
          "rationale": "The service states no balance is ever held for the user and there is no wallet to freeze.",
          "quote": "Funds move directly between your wallet and the exchange leg — AnonExch never holds a balance for you. There is no wallet to freeze and no withdrawal to approve.",
          "sourceUrl": "https://anonexch.io/privacy"
        },
        {
          "id": 276,
          "slug": "may-suspend-your-account",
          "stance": "absent",
          "rationale": "The service states there is no account to suspend and no balance to lock.",
          "quote": "There is no account for us to suspend and no balance for us to lock.",
          "sourceUrl": "https://anonexch.io/terms"
        },
        {
          "id": 281,
          "slug": "additional-fees-for-high-risk-transactions",
          "stance": "absent",
          "rationale": "The service states it applies no surcharge for transactions considered high risk and has no such category.",
          "quote": "We charge no surcharge on transactions deemed “high risk” — there is no such category here.",
          "sourceUrl": "https://anonexch.io/terms"
        },
        {
          "id": 290,
          "slug": "some-countries-are-restricted",
          "stance": "absent",
          "rationale": "The service states it keeps no list of restricted persons and does not ask you to declare your jurisdiction or residence.",
          "quote": "We do not require you to attest to your jurisdiction, your residence, or your status, and we maintain no list of restricted persons.",
          "sourceUrl": "https://anonexch.io/terms"
        },
        {
          "id": 201,
          "slug": "refunds-do-not-require-kyc",
          "stance": "present",
          "rationale": "The terms state that no refund is ever conditioned on identity verification, personal information, documents or a source-of-funds explanation.",
          "quote": "A refund is never conditioned on identity verification, personal information, documents, or a source-of-funds explanation. This applies to every refund, whatever caused it.",
          "sourceUrl": "https://anonexch.io/terms"
        },
        {
          "id": 215,
          "slug": "third-party-liquidity",
          "stance": "present",
          "rationale": "Swaps are settled by independent exchange providers, each a separate operator with its own terms.",
          "quote": "Swaps settle through independent exchange providers. Each is a separate operator with its own terms",
          "sourceUrl": "https://anonexch.io/terms"
        },
        {
          "id": 230,
          "slug": "identity-free-registration",
          "stance": "present",
          "rationale": "Merchants can open a partner account with only an email address and a password, with no business or personal verification.",
          "quote": "Businesses accepting crypto through AnonExch create a partner account with an email address and a password. That is the entire onboarding. We ask for no business verification of any kind",
          "sourceUrl": "https://anonexch.io/terms"
        },
        {
          "id": 231,
          "slug": "personal-info-not-verified",
          "stance": "present",
          "rationale": "The service states it does not check anything you enter against a name, registry or watchlist, and that a merchant email is never verified against a real person.",
          "quote": "We also do not verify the information you do give us. A destination address is an address; a refund address is an address. Nothing you enter is checked against a name, a registry, or a watchlist, because we hold no identity to check it against.",
          "sourceUrl": "https://anonexch.io/terms"
        },
        {
          "id": 233,
          "slug": "no-registration-needed",
          "stance": "present",
          "rationale": "Swapping needs no account, no sign-up and no password; only a destination address and an optional refund address.",
          "quote": "Swapping on AnonExch requires no account and no registration. A swap needs one thing from you: the destination address the funds should arrive at, plus an optional refund address we strongly recommend you set. There is no sign-up form, no password, no email confirmation, and no profile.",
          "sourceUrl": "https://anonexch.io/terms"
        },
        {
          "id": 234,
          "slug": "token-based-login",
          "stance": "present",
          "rationale": "Each swap is accessed through its own unguessable link, which the terms call the only credential; API access uses a secret key instead of an identity.",
          "quote": "Each swap is reachable through its own unguessable link. That link is the only credential involved — keep it private, and treat it the way you would treat a receipt you do not want read.",
          "sourceUrl": "https://anonexch.io/terms"
        },
        {
          "id": 248,
          "slug": "api-available",
          "stance": "present",
          "rationale": "The terms cover a payment gateway API, and API access is granted by secret key.",
          "quote": "These terms apply to the AnonExch website, its Tor hidden service, the Android application, the payment gateway API, and hosted payment links.",
          "sourceUrl": "https://anonexch.io/terms"
        },
        {
          "id": 250,
          "slug": "mobile-app-available",
          "stance": "present",
          "rationale": "The terms list an Android application among the covered products.",
          "quote": "These terms apply to the AnonExch website, its Tor hidden service, the Android application, the payment gateway API, and hosted payment links.",
          "sourceUrl": "https://anonexch.io/terms"
        },
        {
          "id": 292,
          "slug": "non-custodial-protocol",
          "stance": "present",
          "rationale": "Funds move from your wallet to the exchange provider and then to your address; the service states no balance exists in an AnonExch wallet.",
          "quote": "AnonExch never holds your funds. Your deposit goes from your wallet to the exchange provider handling the swap, and the output goes from that provider to the address you specified. At no point does a balance exist in an AnonExch wallet with your name — or your session — attached to it.",
          "sourceUrl": "https://anonexch.io/terms"
        }
      ],
      "highlights": [
        {
          "title": "Refund deductions",
          "content": "If a swap cannot complete, they send your deposit back to your refund address automatically and take the on-chain network fee out of it.",
          "rating": "neutral",
          "topic": "refunds",
          "evidence": "If a swap cannot complete, your deposit is returned automatically to the refund address you provided, less the on-chain network fee required to send it.",
          "source_url": "https://anonexch.io/terms"
        },
        {
          "title": "Deletion schedule",
          "content": "They delete the swap record 24 hours after the swap finishes, and within 7 days if it never settles. Support email threads are kept for 90 days after the last message.",
          "rating": "positive",
          "topic": "logging",
          "evidence": "Deleted automatically 24 hours after the swap reaches its final state. An order that never settles at all is deleted within 7 days regardless.",
          "source_url": "https://anonexch.io/terms"
        },
        {
          "title": "No IP logging",
          "content": "They say they store only the pair, amount and addresses for a swap, and do not log IP addresses against swaps.",
          "rating": "positive",
          "topic": "logging",
          "evidence": "We store only what processing a swap requires: the pair, the amount, and the addresses involved. IP addresses are not logged against swaps. Once a swap finalizes, its data is purged.",
          "source_url": "https://anonexch.io/privacy"
        },
        {
          "title": "No identity relay",
          "content": "They state they will never pass on an identity request from an exchange provider or anyone else, and will not act as a middleman for a verification process.",
          "rating": "positive",
          "topic": "verification",
          "evidence": "We will never forward an identity request to you, from a provider or anyone else. You will not be asked for documents by AnonExch on a provider's behalf, and we will not act as an intermediary for any verification process.",
          "source_url": "https://anonexch.io/terms"
        },
        {
          "title": "No third-party scripts",
          "content": "The site loads no third-party analytics, ad pixels or external CDNs; every asset and API request comes from their own servers.",
          "rating": "positive",
          "topic": "dataSharing",
          "evidence": "The site carries no third-party scripts, no advertising or tracking pixels, no external CDNs, and no fingerprinting. Every asset and API request is served from our own origin.",
          "source_url": "https://anonexch.io/terms"
        },
        {
          "title": "Split routing",
          "content": "In the default Private mode they route the swap so no single exchange party sees both the sending and receiving side, breaking the on-chain link between the two.",
          "rating": "positive",
          "topic": "other",
          "evidence": "The default Private mode goes further than a direct trade: the swap is routed so that no single exchange party ever sees both the sending side and the receiving side.",
          "source_url": "https://anonexch.io/privacy"
        },
        {
          "title": "Traffic filtering",
          "content": "They may refuse automated traffic that degrades the service, such as floods of API requests. They state this applies to traffic, not to funds already moving.",
          "rating": "neutral",
          "topic": "other",
          "evidence": "We may decline to serve automated traffic that is degrading the service for others, such as request floods against the API; that is an infrastructure measure applied to traffic, and it never touches funds already in flight.",
          "source_url": "https://anonexch.io/terms"
        }
      ],
      "warnings": [
        {
          "title": "Emailing support hands them data",
          "body_md": "Writing to support is the one way to give them information they would not otherwise hold. They keep the thread and delete it 90 days after the last message.",
          "severity": "info"
        },
        {
          "title": "Privacy limits they name themselves",
          "body_md": "They state that blockchains are public, that your own wallet habits such as address reuse can identify you, and that any website you visit sees your IP. They suggest Tor or a VPN if that matters to you.",
          "severity": "info"
        },
        {
          "title": "Third-party providers settle your swap",
          "body_md": "Independent exchange providers handle the actual swap, and each has its own terms. AnonExch states all of them are no-KYC and that any provider demanding documents is dropped, but the provider leg is still outside its control.",
          "severity": "info"
        },
        {
          "title": "No refund address means manual handling",
          "body_md": "If you did not set a refund address, the automatic return cannot happen and they send it by hand after you email support with your swap link and an address on the deposit's network.",
          "severity": "info"
        }
      ]
    }
  },
  {
    "slug": "mullvad",
    "name": "Mullvad",
    "homepage": "https://mullvad.net",
    "category": "VPN",
    "privacyScore": 83,
    "transparencyScore": 84,
    "overallScore": 8,
    "grade": "B",
    "confidence": "high",
    "lastScanAt": "2026-09-06T23:07:08+00:00",
    "scan": {
      "status": "complete",
      "corpusHash": "0b8c5b89a5a8acc4f4d0fcacf97d62c3a6fe98d1ea79f23e57c7ea357d64c67d",
      "summary": "Mullvad keeps payment records up to seven years under accounting law and passes payment and email data to Stripe, PayPal, its bank and its mail host. It stores no activity logs, IPs or connection times, and sign-up needs only a generated account number.",
      "kycLevel": 1,
      "kycRationale": "Nothing in the corpus mentions identity verification, KYC, source-of-funds checks, transaction screening or blocking. The sign-up flow explicitly asks for no personal information at all, and the privacy policy states that no automated decision making or profiling takes place.",
      "kycPolicyMd": "Nothing in these documents triggers an identity check: the service asks for no name, email or password and generates a random account number instead. The only identity exposure comes from the payment method you pick — card, PayPal, Swish and bank wire go through Stripe, PayPal or the bank SEB, which record who paid, while cash, Bitcoin, Bitcoin Cash and Monero go to wallets Mullvad hosts itself. The documents describe no situation in which the service demands documents or withholds your money.",
      "components": [
        {
          "label": "Baseline",
          "points": 50,
          "dimension": "privacy"
        },
        {
          "label": "No KYC mention",
          "points": 10,
          "dimension": "privacy"
        },
        {
          "label": "Has Onion or I2P URLs",
          "points": 5,
          "dimension": "privacy"
        },
        {
          "label": "Accepts Monero",
          "points": 5,
          "dimension": "privacy"
        },
        {
          "label": "Refunds may require KYC",
          "points": -3,
          "dimension": "privacy"
        },
        {
          "label": "Identity-free registration",
          "points": 10,
          "dimension": "privacy"
        },
        {
          "label": "Strict no-log policy",
          "points": 5,
          "dimension": "privacy"
        },
        {
          "label": "Token-based login",
          "points": 1,
          "dimension": "privacy"
        },
        {
          "label": "RAM-only infrastructure",
          "points": 3,
          "dimension": "privacy"
        },
        {
          "label": "Third-party payment processor",
          "points": -2,
          "dimension": "privacy"
        },
        {
          "label": "Account required",
          "points": -1,
          "dimension": "privacy"
        },
        {
          "label": "Baseline",
          "points": 50,
          "dimension": "transparency"
        },
        {
          "label": "Verified",
          "points": 10,
          "dimension": "transparency"
        },
        {
          "label": "Mature service",
          "points": 5,
          "dimension": "transparency"
        },
        {
          "label": "Legally registered",
          "points": 2,
          "dimension": "transparency"
        },
        {
          "label": "Refunds may require KYC",
          "points": -3,
          "dimension": "transparency"
        },
        {
          "label": "Strict no-log policy",
          "points": 3,
          "dimension": "transparency"
        },
        {
          "label": "RAM-only infrastructure",
          "points": 3,
          "dimension": "transparency"
        },
        {
          "label": "Third-party payment processor",
          "points": 1,
          "dimension": "transparency"
        },
        {
          "label": "Open source code",
          "points": 7,
          "dimension": "transparency"
        },
        {
          "label": "Audited",
          "points": 5,
          "dimension": "transparency"
        },
        {
          "label": "Basic customer support",
          "points": 1,
          "dimension": "transparency"
        }
      ],
      "unanswered": [],
      "signals": [
        {
          "id": 245,
          "slug": "email-required",
          "stance": "absent",
          "rationale": "No email address is asked for when creating an account.",
          "quote": "When you sign up for Mullvad, we do not ask for any personal information – no username, no password, no email address.",
          "sourceUrl": "https://mullvad.net/help/no-logging-data-policy/"
        },
        {
          "id": 230,
          "slug": "identity-free-registration",
          "stance": "present",
          "rationale": "Creating an account requires no personal details of any kind.",
          "quote": "When you sign up for Mullvad, we do not ask for any personal information – no username, no password, no email address.",
          "sourceUrl": "https://mullvad.net/help/no-logging-data-policy/"
        },
        {
          "id": 234,
          "slug": "token-based-login",
          "stance": "present",
          "rationale": "Access to the service is through a randomly generated account number, not a username and personal details.",
          "quote": "Instead, a random account number is generated, a so-called numbered account. This number is the only identifier a person needs in order to use a Mullvad account.",
          "sourceUrl": "https://mullvad.net/help/no-logging-data-policy/"
        },
        {
          "id": 243,
          "slug": "third-party-payment-processor",
          "stance": "present",
          "rationale": "Card, PayPal, Swish and bank wire payments run through Stripe, PayPal and the bank SEB, which record the payment.",
          "quote": "For credit card, PayPal, Swish, and bank wire, we do use third parties: Stripe, PayPal, and our bank SEB (which handles both Swish and bank wire). These kinds of companies log everything.",
          "sourceUrl": "https://mullvad.net/help/no-logging-data-policy/"
        },
        {
          "id": 244,
          "slug": "account-required",
          "stance": "present",
          "rationale": "You need a numbered account to use the VPN, although you can create as many as you like.",
          "quote": "Anyone at anytime can create as many numbered accounts as they wish on our website. An account can be used by multiple people or by someone other than the person who initially generated it.",
          "sourceUrl": "https://mullvad.net/help/no-logging-data-policy/"
        },
        {
          "id": 250,
          "slug": "mobile-app-available",
          "stance": "present",
          "rationale": "The documents describe Android and iOS apps, including in-app purchases and an Android split tunneling feature.",
          "quote": "If the split tunneling feature is used on Android, then the app queries the system for a list of all installed applications in order to let the user choose which apps should communicate outside the VPN tunnel.",
          "sourceUrl": "https://mullvad.net/help/no-logging-data-policy/"
        },
        {
          "id": 265,
          "slug": "audited",
          "stance": "present",
          "rationale": "The policy references an infrastructure audit carried out by the external security firm Cure53 and a finding resolved from it.",
          "quote": "This was a way of resolving [MUL-03-002 WP2 from our Infrastructure Audit](https://mullvad.net/blog/2021/1/20/no-pii-or-privacy-leaks-found-cure53s-infrastructure-audit/) in 2020.",
          "sourceUrl": "https://mullvad.net/help/no-logging-data-policy/"
        }
      ],
      "highlights": [
        {
          "title": "Seven-year records",
          "content": "Swedish accounting law forces Mullvad to keep certain payment data for seven years after the end of the fiscal year before it deletes it.",
          "rating": "negative",
          "topic": "logging",
          "evidence": "Certain payment data must be kept for the statutory retention period described in applicable local laws such as the Swedish Accounting Act (some information must be stored for seven years from the end of the fiscal year).",
          "source_url": "https://mullvad.net/en/help/privacy-policy"
        },
        {
          "title": "Monero hash kept",
          "content": "Mullvad deletes most crypto payment details after 20 days, but keeps the Monero transaction hash longer to stop double-crediting.",
          "rating": "neutral",
          "topic": "logging",
          "evidence": "For Monero payments we store the transaction hash, or tx_hash. This is stored beyond 20 days in order to prevent double-crediting.",
          "source_url": "https://mullvad.net/help/no-logging-data-policy/"
        },
        {
          "title": "Own crypto nodes",
          "content": "Mullvad runs its own full node and self-hosted wallet for each supported cryptocurrency, so no outside payment processor sees crypto payments.",
          "rating": "positive",
          "topic": "custody",
          "evidence": "We run our own full node for each currency and we self-host all wallets. No third parties are involved.",
          "source_url": "https://mullvad.net/help/no-logging-data-policy/"
        },
        {
          "title": "Support mail erased",
          "content": "Emails and problem reports you send are permanently erased 70 days after the case closes, including from sent items, trash and archives.",
          "rating": "positive",
          "topic": "logging",
          "evidence": "After 70 days, all emails/problem reports sent to our support address are automatically, permanently erased (from inbox, deleted items, sent items, trash, and archives).",
          "source_url": "https://mullvad.net/en/help/privacy-policy"
        },
        {
          "title": "Data stays in EU",
          "content": "Mullvad states it stores and processes personal data only within the EU/EEA and makes no transfer to a third country.",
          "rating": "positive",
          "topic": "dataSharing",
          "evidence": "No. We only store and process your personal data within the EU/EEA.",
          "source_url": "https://mullvad.net/en/help/privacy-policy"
        },
        {
          "title": "No profiling",
          "content": "The privacy policy states that no automated decision making or profiling is applied to you.",
          "rating": "positive",
          "topic": "verification",
          "evidence": "No automated decision making (including profiling) takes place.",
          "source_url": "https://mullvad.net/en/help/privacy-policy"
        },
        {
          "title": "Web server logs",
          "content": "Web server access logs are kept for up to 5 minutes without IP addresses, after which only aggregate request counts remain.",
          "rating": "positive",
          "topic": "logging",
          "evidence": "We store Nginx access logs for up to 5 minutes in the following format (which does not contain IPs): $server_name [$time_local] $request $status",
          "source_url": "https://mullvad.net/help/no-logging-data-policy/"
        }
      ],
      "warnings": [
        {
          "title": "Your payment method decides your anonymity",
          "body_md": "Cash, Bitcoin, Bitcoin Cash and Monero go to wallets Mullvad hosts itself. Card, PayPal, Swish and bank wire go through Stripe, PayPal or the bank SEB, which log the payment and link it to you.",
          "severity": "warning"
        },
        {
          "title": "Bank wire exposes your account number",
          "body_md": "If you pay by bank wire, your Mullvad account number ends up in the message field of the bank transaction, tying your bank identity to that account.",
          "severity": "warning"
        },
        {
          "title": "Mullvad may not be able to answer a data request",
          "body_md": "Mullvad says it usually cannot hand you a copy of your data because it stores almost nothing and cannot identify you from payment data. Exercising your GDPR rights can also cut off support that needs that data, such as issuing a refund or recovering a lost account.",
          "severity": "info"
        }
      ]
    }
  },
  {
    "slug": "servers-guru",
    "name": "Servers Guru",
    "homepage": "https://servers.guru",
    "category": "hosting",
    "privacyScore": 70,
    "transparencyScore": 54,
    "overallScore": 6,
    "grade": "C",
    "confidence": "high",
    "lastScanAt": "2026-09-06T23:26:26+00:00",
    "scan": {
      "status": "complete",
      "corpusHash": "739c9beec55761891f6e74ddd874f06ce8b385beb0eb5962cc7e34ffdfb2ac8a",
      "summary": "Servers Guru can remove any account without notice and refuses refunds, including to banned customers. Wallet credits cannot be turned back into crypto. It notifies law enforcement of criminal offences. Signup needs only an email; the name is optional and unverified.",
      "kycLevel": 2,
      "kycRationale": "Nothing in the terms, privacy policy or FAQ asks for identity documents, and the privacy policy states that the only data collected is an email address with an optional, unverified name. However, the terms commit the operator to notifying law enforcement when it believes a violation is a criminal offence and to fully cooperating with authorities in child abuse material cases, which is disclosure at authority level rather than routine identity checks.",
      "kycPolicyMd": "Nothing triggers an identity check here: you sign up with an email address, and the name you give is optional, can be inaccurate, and is never verified. If you pay by credit card, the card's identity reaches Servers Guru; crypto payments avoid that. If they decide you broke the rules they can restrict, suspend or delete the account and issue no refund, and they notify law enforcement when they consider the violation a criminal offence.",
      "components": [
        {
          "label": "Baseline",
          "points": 50,
          "dimension": "privacy"
        },
        {
          "label": "Rare KYC",
          "points": -5,
          "dimension": "privacy"
        },
        {
          "label": "Has Onion or I2P URLs",
          "points": 5,
          "dimension": "privacy"
        },
        {
          "label": "Accepts Monero",
          "points": 5,
          "dimension": "privacy"
        },
        {
          "label": "Identity-free registration",
          "points": 10,
          "dimension": "privacy"
        },
        {
          "label": "Personal info is not verified",
          "points": 9,
          "dimension": "privacy"
        },
        {
          "label": "Data sharing",
          "points": -3,
          "dimension": "privacy"
        },
        {
          "label": "Account required",
          "points": -1,
          "dimension": "privacy"
        },
        {
          "label": "Baseline",
          "points": 50,
          "dimension": "transparency"
        },
        {
          "label": "Verified",
          "points": 10,
          "dimension": "transparency"
        },
        {
          "label": "Mature service",
          "points": 5,
          "dimension": "transparency"
        },
        {
          "label": "Legally registered",
          "points": 2,
          "dimension": "transparency"
        },
        {
          "label": "Service termination policy",
          "points": -4,
          "dimension": "transparency"
        },
        {
          "label": "May suspend your account",
          "points": -4,
          "dimension": "transparency"
        },
        {
          "label": "No-refund policy",
          "points": -3,
          "dimension": "transparency"
        },
        {
          "label": "Hybrid infrastructure",
          "points": -1,
          "dimension": "transparency"
        },
        {
          "label": "Source code is private",
          "points": -1,
          "dimension": "transparency"
        }
      ],
      "unanswered": [],
      "signals": [
        {
          "id": 230,
          "slug": "identity-free-registration",
          "stance": "present",
          "rationale": "The privacy policy states the only personal data wanted is a working email address, and the name you give is optional and can be inaccurate.",
          "quote": "We do not want your personal informations beside a working email address",
          "sourceUrl": "https://servers.guru/privacy-policy/"
        },
        {
          "id": 231,
          "slug": "personal-info-not-verified",
          "stance": "present",
          "rationale": "The service says it will never verify the name you submit, and the FAQ allows temporary email addresses.",
          "quote": "Submitting your name is completely optional and do not need to be accurate, we will never ask your to verify this information.",
          "sourceUrl": "https://servers.guru/privacy-policy/"
        },
        {
          "id": 239,
          "slug": "data-sharing",
          "stance": "present",
          "rationale": "The terms commit the operator to informing law enforcement and cooperating with them in certain cases.",
          "quote": "Servers.guru is required by law to notify law enforcement agencies and fully cooperate with them when it becomes aware of the presence of child pornography on, or being transmitted through, its services.",
          "sourceUrl": "https://servers.guru/terms-conditions"
        },
        {
          "id": 244,
          "slug": "account-required",
          "stance": "present",
          "rationale": "Services are managed through an account tied to the email listed in the operator's database, and cancellation is done in the customer panel.",
          "quote": "The legal ownership of your websites and accounts managed through the Servers.guru platform, operated by us, shall be vested in the individual or organization whose email is listed in the Servers.guru database as the owner.",
          "sourceUrl": "https://servers.guru/terms-conditions"
        },
        {
          "id": 245,
          "slug": "email-required",
          "stance": "present",
          "rationale": "An email address is the one piece of information required, and it is used for billing and account notices.",
          "quote": "You can use a temporary email addresses but you should make sure you can always access that inbox as this address will be used to notify you about important informations regarding your VPS or your account, as well as outstanding invoices and other billing related communications.",
          "sourceUrl": "https://servers.guru/faq"
        },
        {
          "id": 249,
          "slug": "telegram-bot-available",
          "stance": "present",
          "rationale": "The FAQ lists a Telegram bot as a support contact channel.",
          "quote": "You can also contact us on [Telegram](https://t.me/serversguru_bot), [Matrix](https://matrix.to/#/@servers.guru:matrix.servers.guru), Session",
          "sourceUrl": "https://servers.guru/faq"
        },
        {
          "id": 275,
          "slug": "service-termination-policy",
          "stance": "present",
          "rationale": "The operator reserves the right to end access at any time, for any reason, with or without notice.",
          "quote": "Servers.guru reserves the right to remove any account without prior notice and to refuse service to anyone at any time.",
          "sourceUrl": "https://servers.guru/terms-conditions"
        },
        {
          "id": 276,
          "slug": "may-suspend-your-account",
          "stance": "present",
          "rationale": "Accounts in arrears are suspended automatically, and access can be restricted during an investigation.",
          "quote": "Accounts that are past due will be automatically suspended.",
          "sourceUrl": "https://servers.guru/terms-conditions"
        },
        {
          "id": 280,
          "slug": "no-refund-policy",
          "stance": "present",
          "rationale": "The billing section states a no-refund policy for anything not caused by the operator itself.",
          "quote": "Servers.Guru has a no-refund policy for issues not resulting from its direct involvement or negligence.",
          "sourceUrl": "https://servers.guru/terms-conditions"
        },
        {
          "id": 284,
          "slug": "hybrid-infrastructure",
          "stance": "present",
          "rationale": "The FAQ says the company owns no datacenters and uses a mix of colocated hardware and rented dedicated servers.",
          "quote": "Currently we do not own the datacenters we are using. We are colocating in datacenters, or deploying our own virtualization solution on rented dedicated servers depending on locations.",
          "sourceUrl": "https://servers.guru/faq"
        }
      ],
      "highlights": [
        {
          "title": "Credits are locked in",
          "content": "Money you top up into the wallet can only be spent on Servers Guru services. They will not convert it back into cryptocurrency or any other currency.",
          "rating": "negative",
          "topic": "refunds",
          "evidence": "Credits deposited into a customer's wallet are exclusively designated for the renewal of open invoices issued by Servers.guru or for the procurement of new services from Servers.Guru. It is not possible to convert these credits back into cryptocurrencies or any other form of currency.",
          "source_url": "https://servers.guru/terms-conditions"
        },
        {
          "title": "Banned means no money back",
          "content": "If they ban you for breaking the terms, you get no refund, and they give no credit for downtime caused by a rules-based shutdown.",
          "rating": "negative",
          "topic": "refunds",
          "evidence": "Servers.guru does not issue credits for outages incurred through service disablement resulting from TOS violations. Servers.Guru does not issue refunds for banned customers due to TOS violations.",
          "source_url": "https://servers.guru/terms-conditions"
        },
        {
          "title": "Data deleted on expiry",
          "content": "If you miss a renewal, they terminate the service automatically after the due date. That cannot be undone and they keep no backups of terminated services.",
          "rating": "negative",
          "topic": "other",
          "evidence": "In the absence of renewal, services will be automatically terminated following the due date by the platform. This action is irreversible, and backups of terminated services are not retained to uphold privacy.",
          "source_url": "https://servers.guru/terms-conditions"
        },
        {
          "title": "Police notified",
          "content": "If they judge a violation to be a criminal offence, they inform law enforcement. They decide alone what counts as a violation.",
          "rating": "negative",
          "topic": "dataSharing",
          "evidence": "If such violation is a criminal offense, Servers.guru will notify the appropriate law enforcement authorities of such violation.",
          "source_url": "https://servers.guru/terms-conditions"
        },
        {
          "title": "Card reveals identity",
          "content": "Paying by credit card hands Servers Guru the identity attached to that card. They point to cryptocurrency, and Monero in particular, as the way to avoid this.",
          "rating": "neutral",
          "topic": "verification",
          "evidence": "Customers who choose to pay with Credit Card expose themselves to share the identity tied to their Credit Card with Servers.Guru. We encourage crypto-currency payments and especially Monero in order to minimize the leak of personal informations to Servers.Guru.",
          "source_url": "https://servers.guru/privacy-policy/"
        },
        {
          "title": "Contact form scanned",
          "content": "Messages sent through the contact form pass through hCaptcha, an outside anti-spam service, so that third party sees the submission.",
          "rating": "neutral",
          "topic": "dataSharing",
          "evidence": "The contact form is checked through an external automated privacy respecting spam detection service (Hcaptcha).",
          "source_url": "https://servers.guru/privacy-policy/"
        },
        {
          "title": "You can delete your data",
          "content": "You can view, edit or delete your personal information yourself, and request an export or erasure, except for data they say they must keep for administrative, legal or security reasons.",
          "rating": "positive",
          "topic": "logging",
          "evidence": "You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.",
          "source_url": "https://servers.guru/privacy-policy/"
        }
      ],
      "warnings": [
        {
          "title": "Prepaid balance is one-way",
          "body_md": "Anything you load into the wallet stays there as service credit. Servers Guru states it will not pay it back in cryptocurrency or any other currency.",
          "severity": "alert"
        },
        {
          "title": "They alone decide what breaks the rules",
          "body_md": "The terms make Servers Guru the sole arbiter of what counts as a violation, and grounds for deactivating an account. Spamming alone carries a minimum fine of US$500 plus immediate suspension.",
          "severity": "alert"
        },
        {
          "title": "Crypto mining banned on some plans",
          "body_md": "Mining, farming, plotting, running nodes, storing blockchain data and trading crypto are prohibited on ARM VPS, Cloud servers and Webhosting. They are allowed on regular and unmetered VPS.",
          "severity": "info"
        },
        {
          "title": "Terms change without notice",
          "body_md": "The operator can change the terms at any time with no prior notice, and the new version takes effect the moment it is posted. Continuing to use the service counts as accepting it.",
          "severity": "warning"
        },
        {
          "title": "Backups are your job",
          "body_md": "Servers Guru states it is in no way responsible for managing or backing up your data, even though it sells an optional daily backup add-on holding 7 days of copies.",
          "severity": "info"
        }
      ]
    }
  }
]