Privacy Policy

Invisible-Internet, LLC collects only the information needed to operate and protect this website, provide member and support services, review contributions, and meet legal obligations

When you register or use a member account, we process the username, email address, password hash, confirmation state, account profile, roles, login and logout events, password-recovery events, application and session identifiers, and security information such as timestamps and network addresses. Passwords are not stored in readable form. Administrators may see account records when needed for support, security, or legal operations.

The contact form processes the information you provide, such as your name, email address, reason for contact, subject, and message, together with limited delivery and abuse-prevention metadata. The public Contact form does not accept attachments. Do not send secrets, payment credentials, private keys, wallet seeds, or unnecessary identity documents through the contact form.

SupportCandy processes the member identity, case subject, messages, status, assigned operators, timestamps, and private operator notes needed to handle a case. Authenticated or email-piped SupportCandy tickets may contain attachments under the existing ticket attachment policy, although the public Contact form does not. Legal and abuse mail sent to [email protected], [email protected], or [email protected] may be converted into private tickets. Production mailbox retention, source-of-record copies, and forwarding remain server-level controls. Counter-notice identity and contact information is kept in private notes and is not placed in public case content. postmaster@ is handled through support or manual operations.

Article contributions

Article intake processes the member account ID, email address, proposed title, summary, manuscript, source links, topic suggestion, byline preference, conflicts or sponsorship disclosure, AI-assistance disclosure, private editor notes, agreement records, submission status, and editorial history. The public article may show only approved article content and the controlled byline Invisible-Internet or Anonymous Contributor. Public anonymity is a presentation choice, not a promise that Invisible-Internet has no private records or cannot respond to valid legal process. Every final submission records the exact contributor-terms version and SHA-256 digest.

The site uses cookies or equivalent browser storage needed for security, member login, account sessions, form progress, preferences, maintenance controls, and ordinary WordPress and WooCommerce operation. The site does not use checkout or payment cookies to complete a transaction. Third-party content, if deliberately embedded on a page, may be able to set its own cookies; pages should avoid unnecessary third-party embeds.

The web, application, database, mail, firewall, proxy, and security layers may record timestamps, requested paths, response status, network addresses, user agents, authentication events, delivery status, sender and recipient routing headers, rejection reasons, and diagnostic details. Message bodies are not ordinary log fields, although a restricted mailbox necessarily stores the messages delivered to it. Logs are used for reliability, abuse prevention, incident response, and legal compliance.

We use information to operate and secure accounts; deliver requested contact, support, and account mail; answer inquiries; manage private support and legal cases; review and publish contributions; maintain service integrity; diagnose failures; prevent spam, fraud, and abuse; enforce site policies; and comply with valid legal obligations. We do not sell personal information. We do not use private contribution identity as the public article author.

The following retention schedule is measured in UTC:

Record Launch retention
Incomplete article draft Delete 30 days after its last activity.
Never-published completed article submission Delete 90 days after final submission. If it is still pending at that deadline, first record it as Not selected.
Ever-published article private provenance Keep while the article is public and for 365 days after its most recent exit from publication. Republishing keeps it retained while public; the next exit starts a new 365-day period.
Member account and profile Keep while the account remains open, then delete or de-identify within 30 days after a verified closure request, except records still needed for security, an active case, or law.
Ordinary contact inquiry Delete or de-identify 24 months after the last substantive activity.
Ordinary support case Delete or de-identify 36 months after closure.
Restricted legal or abuse mailbox and case record Keep for seven years after the matter closes, unless a shorter period is approved after legal review.
Routine web, mail-routing, and security logs Keep for up to 90 days unless an incident, active case, backup rotation, or legal duty requires longer.
Session and password-recovery tokens Expire according to their security purpose and are removed or invalidated when no longer valid.

A documented legal hold suspends deletion without changing the original deadline. When the hold is released, the original deadline still applies and an overdue record becomes eligible on the next locked retention run. Repeated runs do not extend a deadline. Isolated rollback backups can retain a deleted record until the backup expires under its restricted rotation; backups are not used to recreate deleted operational records except for an authorized recovery or legal requirement.

Invisible-Internet uses DigitalOcean for server infrastructure and Cloudflare for DNS, edge, access-control, and web-security functions. It also uses the WordPress, Avada, WooCommerce, Gravity Forms, SupportCandy, and authenticated mail components identified in the site’s release record. Infrastructure, network, certificate, backup, and mail-delivery providers can process limited technical data needed to provide their service.

We disclose information only to authorized operators and service providers that need it for these purposes; when a person directs us to do so; to protect rights, safety, service integrity, or other users; or when required by valid legal process. A provider’s own handling is governed by its terms and privacy policy. We do not promise that using a privacy-oriented service eliminates all metadata or makes a person anonymous.

We restrict administrative and case access by role, keep legal and abuse cases private, omit attachments from the public Contact form, apply the ticket attachment policy to authenticated and email-piped cases, separate private contributor provenance from public bylines, and keep payment and provisioning automation disabled. Email piping remains disconnected in development and is connected only to the production-verified mailbox. No security system is perfect. Please avoid submitting information that is not needed for the request.

You may ask to access, correct, close, or delete account-linked information by using the Contact page or an authenticated support case. We may need to verify the request and may retain a limited record when required for security, an active dispute or legal hold, or another legal obligation. Public article changes remain subject to editorial, archival, and legal considerations.

The corporate site and contribution program are not directed to children. Do not submit a child’s personal information without appropriate authority.

Material changes will be published on this page with a new version and effective date. Questions or privacy requests may be submitted through the Contact page. Legal or abuse reports should use the addresses and processes published in the Legal center.