damned.wtf  /  legal

Privacy Policy

Last updated: March 17, 2026

This Privacy Policy and Legal Notice applies to all websites and pages operated under the Operator's domain, including damned.wtf and all its subpaths — /lol, /infosec, /tos, /privacy — and any related static pages the Operator may host. By accessing or using any part of this site, you agree to the terms set out below. If you do not agree, please do not use this site. This Privacy Policy, together with the Operator's Terms of Service, constitutes the complete and exclusive agreement between you and the Operator of damned.wtf — a single private individual — regarding your use of the Site.

Definitions

The same definitions from the Terms of Service §00 apply throughout this Privacy Policy. In particular:

  • "Operator" — the private individual who owns and controls the damned.wtf domain. This is a personal, non-commercial project with no registered legal entity.
  • "Site" — damned.wtf and all its subpaths, including but not limited to /infosec, /lol, /tos, /privacy, and any other static or client-side pages hosted under the same domain.
  • "Third-Party Service" — any external website, API, tool, or resource not owned or controlled by the Operator, including but not limited to Mullvad, Bitwarden, haveibeenpwned.com, VirusTotal, and Cloudflare.
  • "Educational Purpose" — personal, non-commercial study and general awareness-raising. Using any tool or technique described here to gain unauthorised access to systems, conduct surveillance, or perform any illegal act is expressly excluded from this definition and constitutes a violation of the Terms regardless of any claimed educational intent.

Nature of This Site

All pages on damned.wtf are static, client-side only educational resources. There is no server-side backend, no database, no user accounts, no login systems, no persistent data storage, and no analytics or tracking implemented or controlled by the Operator.

The sole purpose of this site is to educate visitors about browser security, privacy concepts, and related technical topics. Nothing here is intended as a commercial service.

Information Collected

zero personal data collected
  • The site consists of static pages served directly to your browser. Nothing is ever sent to, logged by, or stored on any server the Operator controls.
Your browser or network will send standard HTTP headers (IP address, user agent, referrer, etc.) to the Operator's hosting provider or CDN (e.g., Cloudflare) for basic delivery, caching, and DDoS protection. This is standard web infrastructure behaviour entirely outside the Operator's direct control — refer to your hosting/CDN provider's privacy policy for their logging and data retention practices.

The Operator does not set or read cookies, pixels, beacons, localStorage for tracking, or any form of persistent identifier.

How Information Is Used

The Operator uses no information because none is collected or retained. The purpose of the Site is purely educational — to demonstrate concepts in a transparent, zero-server context.

Cookies & Similar Technologies

No cookies or tracking technologies are set by the Operator.

Data Sharing & Third Parties

The Operator shares nothing — there is nothing to share. The Operator does not sell, rent, trade, or disclose visitor information to any third party (because no such information exists). Third-party requests described above are initiated directly by your browser and are not proxied, intercepted, or logged by the Operator.

EU / UK GDPR — Transparency & Legal Basis

For visitors in the European Economic Area (EEA) or United Kingdom subject to the EU or UK General Data Protection Regulation: the only processing that occurs is the delivery of static content to your browser. This is based on legitimate interest (Article 6(1)(f) GDPR) — specifically, providing free educational resources to visitors who have actively navigated to the site.

In compliance with GDPR Articles 12–14 transparency obligations (a 2026 EDPB enforcement priority): the Operator confirms in plain language that no personal data is collected, stored, or processed by the Operator beyond what your browser and your CDN/hosting provider handle as standard infrastructure. The Operator does not profile visitors, build audiences, or engage in any automated decision-making.

Since the Operator holds no personal data, GDPR data subject rights — access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), and objection (Art. 21) — cannot be meaningfully exercised against us. There is nothing to act on. Requests relating to CDN or hosting data should be directed to those providers (e.g., Cloudflare's privacy policy). Requests relating to third-party services (e.g., Mullvad) should go to those parties directly.

No Data Protection Officer (DPO) is required or appointed, as the Operator does not engage in large-scale or systematic monitoring of individuals, nor process special category data.

Regarding international data transfers (GDPR Art. 13/14/46): the Operator transfers no personal data — any infrastructure-level data (e.g., server logs) is governed solely by your CDN or hosting provider's own privacy policy and transfer mechanisms.

EU Digital Services Act (DSA)

As a small personal, non-commercial website operated by a single individual, damned.wtf qualifies as a micro-enterprise under EU definitions and benefits from applicable DSA exemptions including reduced reporting obligations. The Operator commits to the following baseline DSA principles:

  • The Operator does not use manipulative design patterns or dark patterns intended to deceive visitors.
  • The Site does not host user-generated content, and therefore has no content moderation obligations under Article 16.
  • Content is presented transparently.
  • This policy and the Terms of Service constitute the transparency documentation available to users.

US State Privacy Laws

As of 2026, comprehensive privacy laws are in effect across numerous US states including California (CCPA/CPRA), Virginia (CDPA), Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, New Hampshire, New Jersey, Tennessee, Nebraska, Maryland, Indiana, Kentucky, and Rhode Island, among others.

None of these laws apply to the Operator because: (a) the Operator collects zero personal information from anyone, and (b) virtually all state laws only impose obligations on entities that collect data from 25,000–100,000+ state residents and/or derive revenue from the sale of personal data — neither of which applies here.

The Operator does not sell, share, rent, or trade personal information, does not process sensitive personal data, and does not engage in targeted advertising. There is no personal data to request, correct, delete, or opt out of — residents of any US state have no actionable privacy rights to exercise against the Operator because nothing is held.

Acceptable Use

All content on this site is provided strictly for personal, educational, and informational purposes.

Prohibited uses include, without limitation:

  • Applying any technique described here against systems, networks, or devices without the owner's explicit consent.
  • Applying content from this site for any unlawful purpose, including but not limited to unauthorised computer access, surveillance, or circumventing security controls you are not permitted to circumvent.
  • Misrepresenting the content here as your own work or as professional security advice.
Violation of acceptable use may constitute a criminal offence under applicable laws including but not limited to the Computer Fraud and Abuse Act (CFAA, US), the Computer Misuse Act (UK), and equivalent legislation in other jurisdictions. You are solely responsible for ensuring your use complies with all applicable local laws.

Disclaimer of Warranties & Liability

This site and all content are provided "as is" and "as available" without warranties of any kind, express or implied, including but not limited to merchantability, fitness for a particular purpose, accuracy, or non-infringement.

To the maximum extent permitted by applicable law, the Operator of damned.wtf — a single private individual operating a personal, non-commercial educational site with no registered legal entity — shall not be liable for any direct, indirect, incidental, special, consequential, or exemplary damages arising from your use of or inability to use this site, including reliance on any information presented here.

The Operator's total aggregate liability for any and all claims arising from your use of the Site shall not exceed zero monetary value in any currency, cryptocurrency, token, or any other form of payment or consideration whatsoever — the Site has always been provided entirely free of charge, with no payment, subscription, fee, data exchange, or consideration of any kind required or solicited. This cap applies regardless of the theory of liability and regardless of whether the Operator was advised of the possibility of such damages.

Content on this site is for general educational purposes only and does not constitute professional security, legal, or technical advice. Do not rely on it as a substitute for professional consultation.

Intellectual Property

All original content, code, and design on damned.wtf is the property of the site operator unless otherwise noted. You may view and reference content for personal and educational use. Reproduction, redistribution, or commercial use without explicit permission is prohibited.

Third-party libraries, fonts, or services used on this site retain their respective licenses and ownership.

Children's Privacy (COPPA 2025)

This site is not directed at children under the age of 13 (under US COPPA), or under 16 where applicable under GDPR. The Operator does not knowingly collect any data from anyone of any age.

The FTC's amended COPPA Rule (effective June 23, 2025; compliance deadline April 22, 2026) expanded the definition of personal information to include mobile phone numbers, government-issued IDs, and biometric identifiers. The Operator collects none of these. No children's information is shared with third parties because no information is shared with anyone. No verifiable parental consent is sought or required — there is simply nothing to consent to.

The content on this site is technical and educational in nature, intended for users with a baseline understanding of web and browser technologies. If you are under the applicable age in your jurisdiction, please use this site only with parental or guardian supervision.

AI-Generated Content

Where any content on this site is substantially assisted by or generated with artificial intelligence tools, the Operator aims to label it as such as a voluntary transparency practice. The EU AI Act (effective August 2, 2026 for most provisions) does not apply to this site — it regulates providers and deployers of AI systems, not individuals who use AI tools to assist in writing static content. This labeling is a best-effort commitment to transparency and does not create an enforceable obligation.

The site itself does not use machine learning, make predictions about individuals, or constitute automated decision-making with any legal or significant effect.

The /infosec Guide — Privacy Clarifications

The page at damned.wtf/infosec is a static cybersecurity education guide. The following privacy-specific clarifications apply:

  • Simulated login screen: The terminal-style loading screen and login form (USER_ID / AUTH_KEY) are purely cosmetic. No credentials are entered, validated, stored, or transmitted anywhere — by the Operator or anyone else. It exists solely for aesthetic presentation.
  • Optional audio: The page includes an optional background audio track that is off by default and requires explicit user interaction to enable. No audio data is recorded, captured, or transmitted.
  • Third-party links: The guide links to external tools and services (e.g. Mullvad, Bitwarden, haveibeenpwned.com, VirusTotal) for educational purposes only. Clicking those links takes you to third-party sites governed by their own privacy policies — the Operator has no affiliation with or control over them.
  • No automatic network requests: The guide itself makes no automatic network requests. All content is served statically. The only outbound requests possible are those you explicitly trigger by clicking an external link — at that point you are navigating to a third-party site governed by its own privacy policy.

Security

With no backend, database, or stored user data, there are no user records that could be breached from the Operator's side. The site is served over HTTPS. Security of your own device, network, and browser is your responsibility.

Governing Law & Jurisdiction

This policy is governed by and construed in accordance with applicable law. As this is a personal, non-commercial educational site with no established legal entity, no single jurisdiction is designated; however, you agree that your use of this site complies with the laws of your own jurisdiction. Nothing in this policy limits rights you may have under applicable mandatory consumer protection or data protection laws in your country of residence.

Changes to This Policy

The Operator may revise this policy at any time. The "Last updated" date at the top of this page reflects the most recent revision. Non-material changes (e.g. wording clarifications) take effect immediately upon posting — continued use constitutes acceptance. If a material change is ever made to data collection practices (currently: none collected), that change will be made clearly visible on this page. Checking this page periodically is your responsibility.

No Anonymity & No Security Guarantee

This site does not provide anonymity. It does not protect your privacy. It is not a security tool. Nothing here will make you harder to track, safer online, or less identifiable to any third party.

  • The infosec guide at /infosec provides general awareness only — reading it does not protect you.
  • This site is not a VPN, proxy, ad blocker, tracker blocker, or any form of privacy-enhancing technology.
  • The operator makes no representation that any technique or recommendation described here will be effective against any specific threat or tracking method.

You are solely responsible for your own security and privacy posture.

Law Enforcement & Legal Process

The Operator holds no user data of any kind — no logs, no session records, no identifiers, no IP addresses, no usage history. There is nothing to produce in response to any legal demand, subpoena, or court order directed at the Operator regarding user behaviour, because no such data exists.

In the event of any law enforcement request or legal process:

  • Requests for user data should be directed to the relevant hosting or CDN provider (e.g. Cloudflare) — they may hold infrastructure-level records (standard server logs) governed solely by their own policies.
  • Requests relating to third-party services (e.g. Mullvad) should be directed to those parties directly.
  • The operator cannot be compelled to produce what does not exist.
  • Any misuse of this site by a user is solely that user's responsibility — the operator is the publisher of educational material and bears no criminal or civil liability for how users independently apply that material.
Important

By accessing this site, users acknowledged and agreed to the full Terms of Service — including the Release of Claims, Assumption of Risk, and Law Enforcement clauses — upon first access. Those terms remain binding.

Indemnification & Survival

By using this site, you agreed to indemnify, defend, and hold harmless the Operator of damned.wtf — a single private individual — from any claims, damages, losses, or expenses arising from your use of the site, your violation of the Terms of Service, or your misuse of any content or tool found here. This obligation is set out in full in the Terms of Service §11 and is incorporated into this policy by reference.

The following protections survive indefinitely after you stop using this site and cannot be waived by the passage of time or cessation of use:

  • All disclaimers of warranty and limitation of liability (ToS §5, ToS §6, and Privacy §10).
  • The Release of Claims & Covenant Not to Sue (ToS §16).
  • The Law Enforcement & Legal Process clause (ToS §17 and Privacy §19).
  • The Assumption of Risk clause (ToS §18).
  • The No Agency / No Professional Relationship clause (ToS §21).
  • The No Anonymity & No Security Guarantee clause (ToS §23 and Privacy §18).
  • The Indemnification obligation (ToS §11).
  • Privacy Policy §02 (Information Collected), §05 (Data Sharing & Third Parties), §19 (Law Enforcement & Legal Process), and this §20 (Indemnification & Survival).
This material is provided strictly for educational purposes only.
Some information may be outdated or contain mistakes — the Operator is not responsible for inaccuracies.
The Operator does not encourage or condone illegal activity of any kind and is not responsible for how you use this information.

Always abide by the laws of your jurisdiction. If you believe you are a victim of cybercrime or encounter a situation beyond your control, seek help from the appropriate authorities immediately.
By visiting or using any page on damned.wtf, you acknowledge that this site provides educational content only, that no personal data is collected or stored by the Operator, and that you accept responsibility for ensuring your use complies with all applicable laws.