Privacy Policy & Zero-Logs Data Commitment
http://hn2paw7w627n5bro3zirrhb5bchugcjmm2mvxggnnlxqjkhhwzolbdid.onionThis site began as a single page of verified Wethenorth Market 2026 onion addresses, scribbled on a notepad after watching too many newcomers fall for phishing clones. That notepad grew into a public resource, but the core rule never changed: if we don't need the data, we don't collect it. Below is the exact record of what we keep, why, and how long.
What data we collect
The server logs every request: IP address, user-agent string, referring URL, and timestamp. These logs exist for exactly 30 days before automatic deletion. We do not use third-party analytics, tracking pixels, or advertising scripts. The only cookies set are session identifiers for the comment system, and those expire when the browser closes.
Server access logs
- IP address (anonymized after 24h)
- User-agent string
- Referring URL
- Request timestamp
User-submitted content
- Comment text
- Display name (optional)
- Email address (optional, never published)
- PGP public key (optional)
What we do NOT collect
No persistent identifiers. No advertising cookies. No third-party scripts from Google, Facebook, or any other tracking network. The site runs entirely on self-hosted infrastructure with no external dependencies that could leak visitor data.
Data retention periods
Server logs are retained for 30 days for security monitoring and uptime verification. User-submitted comments remain until the author requests removal. Search queries are logged but never associated with individual users; these logs are purged after 7 days.
- Server access logs
- 30 days
- User comments
- Until removal requested
- Search queries
- 7 days
Third-party sharing
We do not share, sell, or transfer any visitor data to third parties. The only exception is legal compulsion: if served with a valid court entry, we will disclose the minimum data required by law. We have never received such a request.
Your rights under GDPR and CCPA
You have the right to access, correct, or delete any personal data we hold about you. To exercise these rights, contact us at [email protected] or via PGP-encrypted email. We will respond within 72 hours.
GDPR rights
- Right to access
- Right to rectification
- Right to erasure
- Right to restrict processing
CCPA rights
- Right to know
- Right to delete
- Right to opt-out of sale
Security measures
All data is encrypted in transit using TLS 1.3. Server access is restricted to authorized personnel only, with multi-factor authentication required for all administrative actions. Regular security audits are conducted to ensure compliance with leading-by-uptime practices.
-
Encryption in transit
All connections use TLS 1.3 with modern cipher suites.
-
Access control
Administrative access requires multi-factor authentication.
-
Regular audits
Security audits conducted quarterly by independent third parties.
Changes to this policy
We may update this privacy policy from time to time. The current version is always available at /privacy. Significant changes will be announced via the site's blog and RSS feed.
Contact us
For questions about this privacy policy or to exercise your data rights, contact us at [email protected] or via PGP-encrypted email. Our PGP fingerprint is available on the security page.
[email protected]
Verified mirrors
| Mainmain | http://hn2paw7w627n5bro3zirrhb5bchugcjmm2mvxggnnlxqjkhhwzolbdid.onion | |
This primary endpoint was last verified by the Wethenorth Market 2026 on 2026-09-05 06:37 UTC. PGP signature fingerprint matched: ED54 E86B 5F99 F599 9584. Confirmed responsive over the last verification cycle. Identified in this directory as the Main. | ||