Recovered Archive / Privacy

Privacy

Deceit names the machinery of deception. The machinery runs on surveillance. This page documents what the project collects, what it keeps, and what it advocates.

The project advocates for privacy law and encryption as core civil-liberties infrastructure. It also tries to practice what it advocates. The two are connected: a project that documents surveillance architecture should not build its own.

What this means in practice

  • Analytics are cookieless and first-party (Cloudflare Web Analytics). No third-party trackers, no cross-site profiling, no behavioral advertising.
  • Whispers of Deceit has no analytics at all. A site collecting anonymous pattern observations must not track the people submitting them.
  • Whispers does not ask for a name or email. The server discards those fields if a forged request includes them.
  • Before a Whispers observation is stored, an automated filter removes common direct identifiers such as email addresses, phone numbers, URLs, handles, account numbers, precise dates, street addresses, and likely personal or organization names. Automated redaction cannot identify every contextual clue, so submitters must still omit details they need kept private.
  • Whispers observations are stored in Cloudflare KV for editorial review. Pending observations expire after 90 days. Rejected observations expire after 30 days. An approved observation remains available for editing and publication until it is deleted.
  • Turnstile is used for bot protection. Cloudflare processes network information for that check. Deceit converts the request IP into secret-keyed, short-lived rate-limit records that are not stored with the observation.
  • Whispers receives a private removal code after submission. Only a hash of that code is stored. The code can delete the observation without providing a name or email.
  • The admin inbox is protected by Cloudflare Access. Only verified editors can view submissions. Access requires a valid JWT with a verified email on the editor allowlist.
  • The project does not treat submissions as automatic permission to publish. Every submission is reviewed by a human before anything is published.
  • If you need a correction or deletion request handled, use direct contact.

The stance the project advocates

  • Privacy is structural, not personal. The project writes about who owns the machinery of observation, not about reading privacy policies.
  • Surveillance is the infrastructure that makes propaganda, doxxing, and deportations work. Naming it is the first step. Refusing it is the second.
  • The project advocates for privacy law in AI that reaches training-data extraction at ingestion, not disclosure-and-consent theater after the fact.
  • The project advocates for retroactive encryption of surveillance archives that already exist. The lever is not delete. The lever is cost.
  • The project uses encrypted AI tools for drafting and research. The tools are used on terms that do not feed the surveillance dividend.

The full policy framework: Privacy Law in AI Is Infrastructure Policy. The cost-imposition argument: The Archive Is Already Built. The encrypted-inference practice: Encrypted AI: The Tool That Does Not Keep You.

Use contact when the request is administrative. Corrections, deletion requests, and operational questions should go through direct contact rather than being buried inside a story submission. See also: terms of service, disclaimer, DMCA / takedown.