Home / Compare / IN THEIR OWN WORDS

In their
own words

A homepage is a claim. A privacy policy is the document a lawyer, a court or a subpoena reads. Below, the same company's two documents, side by side, quoted verbatim, with the URL under each pair and the date we checked. Read the grey line. That is the one that binds.

How to read this

The orange line is what the provider says where customers look. The grey line is what the same provider says in its terms, its privacy policy, or its own page source. Nothing inside quotation marks is paraphrased. Each pair was copied from the live page and re-checked by hand on 5 September 2026.

Why it matters

Nobody serves a subpoena on a homepage. The privacy policy and the terms are what a court, a payment processor and an abuse desk actually hold a provider to. When those documents say more is collected, logged or handed over than the banner admits, the documents win. Every time.

If a page changes

Tell us. A corrected page gets its pair removed or re-dated here the same week. We would rather this page be short than stale.

FlokiNET FlokiNET ehf, Iceland · full comparison
They say

“FlokiNET does not collect any personal information about you when you visit our website.”

Their own policy says

“FlokiNET collects and logs your IP address, the time and duration of your visit, the time and duration of the pages you view on our website (where applicable) and information about your computer system, such as your browser type and operating system, whenever you access or use a FlokiNET service.”

Both sentences are in the same document.

flokinet.is/privacy-policy/

They say

“We do not require any personal details or identification. Any valid email address is enough information to be a customer.”

Their own policy says

“For higher payment amounts (for example, dedicated servers), we may request additional customer verification details. [...] we may require that the PayPal email address matches the email address registered in our billing system.”

flokinet.is/
billing.flokinet.is/index.php?rp=/knowledgebase/58/PayPal-payments.html

Privex Privex Inc., Belize · full comparison
They say

“We do NOT share your order details with any third parties.”

Their own policy says

“In some rare cases, for specific products, we may be required to share some, or all of your personal details with one or more third parties in-order to provide the service.”

Same page, a few paragraphs apart.

www.privex.io/privacy/

They say

“Privex also does not accept any forms of fiat payments to ensure our customers' privacy.”

Their own policy says

“we can accept payments via domestic / international bank transfer so long as you're paying at LEAST $100 / EUR100 / GBP100 or equivalent currency.”

www.privex.io/articles/why-use-privex/
www.privex.io/articles/pay-bank-transfer/

They say

“For most of our services, we'll give you a full refund if you contact us within 14 days of purchase”

Their own policy says

“We offer a 7 day refund policy for VPS's and dedicated servers.”

www.privex.io/about/
pay.privex.io/order/

OrangeWebsite IceNetworks Ltd., Iceland · full comparison
They say

“Upon signing up with us, you will only be asked to provide your email address. We don't store your name, billing address or credit card information anywhere in our databases.”

Their own policy says

“Personal Information you give us depends on the type of service, support, or sale inquiry, and may include your name, address, telephone number, fax number and email address, dates of service provided, types of service provided, payment history, manner of payment, amount of payments, date of payments, domain name.”

www.orangewebsite.com/company/secure-hosting
www.orangewebsite.com/docs/privacy-policy.php

They say

“We accept Bitcoin and other cryptocurrencies for anonymous payments.”

Their own policy says

“We provide payment providers for cryptocurrency which are BitPay and Coinpayment. These providers reserve the right to request KYC (Know your customer). [...] We will setup your account after we have received payment and we have screened the order(s) in case of fraud.”

www.orangewebsite.com/
www.orangewebsite.com/docs/tos.php

BitLaunch Liber Systems Limited, England · full comparison
They say

“Recently, however, we took the additional step of completely removing analytics from our site. As a result, we don't run a single tracker or keep cookies.”

Their own record says

“The homepage source loads Intercom: window.intercomSettings = { app_id: "j1jbxoh8" }. Intercom is a third-party chat and messaging service that sets its own cookies.”

Not a quote from a policy: this one is in the HTML of bitlaunch.io itself.

help.bitlaunch.io/en/articles/4847100-privacy
bitlaunch.io/

They say

“All payments are final. There are no refunds or withdrawals”

Their own policy says

“You may have a legal right to change your mind within 14 days and receive a refund.”

bitlaunch.io/terms.html
bitlaunch.io/legal/fullterms/

They say

“Across the site and our VPS servers, we only store the data that is absolutely necessary to keep our service running. We only keep this information for exactly as long as we need it, and we don't share it with anybody else.”

Their own policy says

“We resell services from a selection of third parties. You must abide by the terms, rules and policies of the following third parties where the Services you order from us involve our resale of services from them”

help.bitlaunch.io/en/articles/4847100-privacy
bitlaunch.io/legal/fullterms/

They say

“Trusted by 100,000+ customers since 2017.”

Their own policy says

“Liber Systems Limited, company number 11405895: incorporated on 8 June 2018.”

The second line is the Companies House record, not a BitLaunch page.

bitlaunch.io/
find-and-update.company-information.service.gov.uk/company/11405895

Skhron Skhron OU, Estonia · full comparison
They say

“self-hosted, non-custodial payment processor - no middlemen, no third-party tracking, no seized funds”

Their own policy says

“Operator uses Stripe for payment services. Stripe collects identifying information about the devices that connect to Operators' websites.”

The promise is about their crypto rail; the policy is about their websites. A visitor reads both on the same site.

skhron.eu/
skhron.eu/legal/privacy-policy

They say

“we simply never see your IP address”

Their own policy says

“This technical information includes Internet Protocol (IP) addresses, browser information, and the preceding and succeeding websites you have visited”

The first sentence is their Tor FAQ, and over Tor it is true. The second is what their cookies collect the rest of the time.

skhron.eu/services
skhron.eu/legal/privacy-policy

They say

“No KYC is required to order or use our services”

Their own policy says

“Operator may collect certain contact information from you, such as your first and last name, organization name, country, city, state, zip code, email address, and phone number.”

Not verifying an identity is not the same as not collecting one.

skhron.eu/
skhron.eu/legal/privacy-policy

Njalla Njalla SRL, "based in Costa Rica" (their about page) · full comparison
They say

“We brag about not telling who our customers are.”

Their own policy says

“Njalla reserves the right to provide relevant authorities, governmental bodies, courts or other similar institutions with any information mentioned under section 6.1 above about you in case of violation of section 4.2 above.”

njal.la/about/
njal.la/tos/

They say

“All the data we have about clients are displayed in the logged in pages.”

Their own policy says

“All the data we have about clients are displayed in the logged in pages.”

Whatever is on those pages is what clause 6.2 lets them hand over.

njal.la/tos/

1984 Hosting 1984 ehf., Iceland · full comparison
They say

“All logging is sent to /dev/null and DNS queries are made on the same server.”

Their own policy says

“1984 collects and logs your IP address, the time and duration of your visit, the time and duration of the pages on our website that you view (where applicable) and information about your computer system, such as your browser type and operating system, whenever a 1984 service is accessed.”

The first line is the VPS product page. The second is their GDPR page.

www.1984.hosting/product/vps/
1984.hosting/GDPR/

They say

“We do not use cookies to track visitors.”

Their own policy says

“1984 uses web beacons to count the number of times that its advertisements and web-based e-mail content are viewed.”

Cookie policy versus GDPR page, same company.

1984.hosting/cookiepolicy/
1984.hosting/GDPR/

They say

“1984 will always do everything within its legal power to inform our customers of any inquiries from any authorities, lawyers or courts into the customer's affairs that we may become aware of.”

Their own policy says

“1984 may release the information it collects to third parties when 1984 believes that it is appropriate to comply with the law, to enforce its' legal rights, to protect the rights and safety of others, or to assist with industry efforts to control fraud, spam or other undesirable conduct.”

"When 1984 believes that it is appropriate" is a lower bar than a court order.

1984.hosting/about/
1984.hosting/GDPR/

is*hosting WEBRAIN OU, Estonia · full comparison
They say

“All transactions (including initial registrations) on the blockchain are anonymous, fully protecting your financial and personal information.”

Their own policy says

“KYC verification is conducted on a selective basis. The decision is made based on our internal risk assessment system [...] Payment method characteristics [...] Government-issued photo identification (passport, national ID, driver's license) [...] Proof of address dated within 90 days [...] Biometric selfie verification [...] Source of funds documentation”

Their blog sells crypto as anonymity. Their KYC policy lists the payment method as a trigger for asking for your passport and a selfie.

blog.ishosting.com/en/buy-vps-with-btc
my.ishosting.com/en/kyc-policy

They say

“Our VPN network has a strict policy against storing logs of users' online activity, which enhances privacy and security.”

Their own policy says

“computer-related information (browser type you used, your Internet Protocol address, last URL visited, and the date and time of day of your login) [...] we may retain and use PI for such periods of time as required or permitted by law or best business practices”

ishosting.com/en/vpn
ishosting.com/en/privacy-policy

They say

“We do not store your documents”

Their own policy says

“Customer Verification Records | 5 years after account closure | Regulatory compliance and AML requirements”

Help centre versus the KYC policy's own retention table.

help.ishosting.com/en/why-do-i-need-to-complete-kyc
my.ishosting.com/en/kyc-policy

IncogNET IncogNET LLC, Wyoming, USA · full comparison
They say

“Anonymous registration, no tracking, no invasive data collection.”

Their own policy says

“We may log IP addresses associated with new customer orders and account sign-ups, as well as standard webserver access logs generated when users interact with our website or service panels.”

incognet.io/
incognet.io/privacy

They say

“We don't need to know who you are and cannot share what we do not know.”

Their own policy says

“Card payments are processed through PayPal. [...] If we are presented with a valid and legally binding order requiring disclosure of customer information, we may be required to comply.”

PayPal knows exactly who you are.

incognet.io/free-speech-webhosting
incognet.io/privacy

They say

“We don't police your opinions or voice.”

Their own policy says

“We reserve the right to cancel, suspend, or terminate your service for any reason and without prior notice.”

incognet.io/
incognet.io/legalstuff

They say

“Warrant Canary”

Their own policy says

“Warrant Canaries are practically meaningless, but with that said we'll try to do better to keep this more up to date since the last update was almost a year ago.”

That is the canary text itself, dated August 3rd, 2025. It has not been updated in the thirteen months since.

incognet.io/warrant-canary

SporeStack United States · full comparison
They say

“We can't guarantee privacy, but we make it easier to stay private than some hosts.”

Their own policy says

“Logs are retained for 90 days. [...] If you give us the cryptocurrency used, transaction ID, and a subpoena, we can associate that payment with a token, and then show what servers are associated with the token.”

To their credit, both sentences are on their own site. Ninety days of logs and a payment-to-server link on subpoena is the product.

sporestack.com/
sporestack.com/law-enforcement.html

Kyun Kyun SRL, Romania · full comparison
They say

“Private, really private. When we say Kyun is private, we mean it. We don't collect or store anything we don't legitimately need”

Their own policy says

“We do not encrypt your drives [...] It is technically possible for us, or anyone else with access to the hypervisor running your VM, to dump the decryption keys from RAM, which would give the attacker full access to your unencrypted data.”

Privacy policy and general FAQ. Honest, and the opposite of the headline.

kyun.sh/
git.kyun.sh/kyun/docs/-/raw/master/privacypolicy%7CPrivacy%20Policy.md
git.kyun.sh/kyun/docs/-/raw/master/faqs%7CFAQs/general%7CGeneral%20FAQ.md

They say

“Information about law enforcement requests, court orders, subpoenas, and other legal process will be published separately in transparency reports, where legally permitted.”

Their own record says

“https://files.kyun.sh/transparency returns HTTP 404. No transparency report is linked anywhere on the site.”

The promise is in their warrant canary, dated 2026-08-19.

files.kyun.sh/canary.txt
files.kyun.sh/transparency

They say

“Get an automatic prorated refund when you delete or downgrade any service.”

Their own policy says

“XMR deposit refunds are not guaranteed and are only offered on a per-case basis.”

The refund lands in an internal balance. Getting Monero back out is discretionary.

kyun.sh/
git.kyun.sh/kyun/docs/-/raw/master/tos%7CTerms%20of%20Service.md

Webcare360 no legal entity named on its site
They say

“The information you supply us will not, under any circumstance, be sold, reused, rented, loaned, distributed, or otherwise disclosed to any third party.”

Their own policy says

“Upon receiving a valid legal order or abuse report, we may disclose relevant data (e.g. logs, user info) as required by law.”

webcare360.com/service-agreement/
webcare360.com/onshore-servers-terms-and-policy.html

They say

“A strict no-log policy that ensures no tracking or unnecessary data collection.”

Their own policy says

“we may disclose relevant data (e.g. logs, user info)”

A no-log policy has no logs to disclose.

webcare360.com/webcare360-data-security-framework/
webcare360.com/onshore-servers-terms-and-policy.html

They say

“Includes our DMCA Ignore option for full content flexibility from day one.”

Their own policy says

“WebCare360 has implemented a comprehensive policy for handling abuse.”

webcare360.com/
webcare360.com/service-agreement/

They say

“Adheres to GDPR, ISO 27001, and PCI-DSS standards.”

Their own record says

“https://webcare360.com/privacy-policy/ returns HTTP 404. The site has no privacy policy page.”

Checked 5 September 2026.

webcare360.com/webcare360-data-security-framework/
webcare360.com/privacy-policy/

Run it
on us.
Please.

We can take other people's pages apart like this because we are not worried about ours. Every claim we make in public is below, next to the exact place you verify it. Run the same test. Read our policy against our homepage, read the terms against the pricing page, pull the HTML. If you find a line that does not hold, tell us, and we fix it. Whatever it is, however small, however loud you want to be about it. That offer has no expiry.

No email, no name, no phone. A 32-character credential is the whole account.

Open the register page. There is no field to fill.

Check it →

No access logs. Visitors' IP addresses are not written anywhere.

Privacy policy, "What We Do Not Collect", and the PGP-signed warrant canary.

Check it →

No session cookie until you log in or open a form.

Load any public page with the developer tools open: no Set-Cookie header.

Check it →

Stripe learns an amount and an opaque customer record, never the order, plan or server.

Privacy policy, "Payment data".

Check it →

Blackbox: encrypted memory, no guest agent, disk encrypted inside your VM, measured boot.

Verify it yourself from inside the machine with the published tool.

Check it →

Abuse reports are read by a person. Nothing is suspended automatically.

Terms, "Abuse Reports".

Check it →

99.9% availability, in writing, with per-node uptime published live.

Terms, "Service Availability", and the status page.

Check it →

Read our
policy first.

It is short, it is the document that counts, and it says less than the homepage does, not more.

Privacy policy Warrant canary
Full comparisons 1984 Hosting _own-words-data BitLaunch FlokiNET IncogNET is*hosting Kyun Njalla OrangeWebsite Privex Skhron SporeStack