Skip to main content
AVOID.NET
← AVOID.NET

Privacy

This site indexes risk. Its readers deserve to know exactly what it records about them — and what it is built not to record.

No cookies, no accounts required, no third parties for readers

Reading AVOID.NET sets no tracking cookies and requires no account. There is no Google Analytics, no advertising pixel, no session replay, and no third-party analytics service. Nothing about your visit is shared with anyone.

Signing in — which is optional, and only needed to submit evidence or track a request — sets an authentication cookie. That is a login session, not analytics.

How visitors are counted

To know how many people read the site, each request is reduced to a single irreversible value: a SHA-256 hash of your IP address, your browser’s user-agent string, the current UTC date, and a server-side secret. Your IP address itself is never written to the database.

That value changes every day, on purpose. Because the date is part of what is hashed, the identifier for a given person today cannot be linked to the identifier for the same person yesterday. The site can therefore count how many distinct people visited on a given day, and it cannot build a history of what any individual has read over time. That limit is structural rather than a policy promise — the data to reconstruct such a history is never created, so there is nothing to hand over, leak, or subpoena.

The direct cost of that design is that AVOID.NET does not know who its returning readers are, and will not be able to tell you. That is the intended trade.

Separately, the site records which paths were visited and which referring domain sent the visit. Those records carry no visitor identifier of any kind — they cannot be tied back to a person or grouped into a session.

If you submit evidence or request an investigation

Submissions and investigation requests store a salted hash of your IP address. Unlike the visitor counter above, this one does not rotate: it is what enforces rate limits and lets a moderator see that ten submissions came from one source. If you are signed in, your account is recorded instead and your chosen handle may be shown on the page you contributed to.

What you submit is published once a moderator accepts it. Until then it is visible only to moderators and to signed-in readers of that page. Moderators include an automated moderation agent, which reads submissions to decide clear-cut cases. Do not submit anything you are not willing to have published, and consider whether you need the protection of a tool built for anonymity before sending evidence about someone dangerous.

The one third party. When you open the evidence form, it may load Cloudflare Turnstile, a bot check. Cloudflare processes your IP address and browser signals to tell people from bots, under its own privacy policy. It sets no advertising cookies and loads only on the form, never when you are just reading.

Children

AVOID.NET is a reference site about financial risk, written for adults. It is not directed at children under 13, and it does not knowingly collect personal information from them. If you believe a child has signed in or submitted something, get in touch using the route below and it will be removed.

Retention

Daily visitor counts are aggregate rows keyed by day, and the per-day identifiers in them are meaningless once the day has passed. Contribution records persist as long as the contribution does, because they are part of the audit trail that makes the site checkable.

Getting in touch

To ask what is held about a contribution you made, or to have one withdrawn, email avoiddotnet@gmail.com. To report content on the site, see Report content; the rules for contributors are the contributor terms (coming soon). Corrections to published investigations follow the documented review process and are anchored on-chain like any other editorial decision.