Mission
Cunicula is a privacy-first directory and editorial project built for people who do not want every payment, message, login, or device tied to a permanent identity graph. We focus on tools that reduce surveillance, minimize data collection, and preserve optionality.
The short version is what Cunicula is and is not: privacy claims are worthless without records, and a record is not a certification, audit, or recommendation.
We do not describe surveillance tech as privacy tech. We are especially skeptical of products that depend on invasive analytics, mandatory identity checks, behavioral tracking, or opaque ownership. Jurisdiction, including Five Eyes membership, is recorded as context. It does not by itself establish that a service is safer or less safe.
Editorial standards
The Cunicula editorial team uses a documented vetting framework before it characterizes a service or writes a guide around it. Our baseline questions are simple: who owns it, what data does it collect, what jurisdiction governs it, how does it make money, has it been audited, is it open source where it matters, and does its real-world behavior match its marketing?
Our methodology is laid out in How to Vet Any Privacy Tool Before You Trust It. That article explains the checklist we use when reviewing VPNs, wallets, carriers, messengers, hosting providers, and other services in the directory.
We may publish under a pseudonymous editorial voice, but the standards are consistent: documented claims, adversarial review of privacy marketing, and preference for tools that minimize trust rather than merely asking for it.
What we list
Listings cover tools and services relevant to privacy. A listing records what the service does, what it asks from users, who operates it, and which concerns are documented. A listing is not an endorsement. The coverage map states the depth and limits by category and tracker.
How the fields work
Every service page separates observed identity requirements, operator facts, evidence confidence, and recorded risk. Evidence confidence measures source coverage and review age. Risk records material concerns. The exact inputs are published on the methodology page.
Formula 3.1 retains the numeric privacy field only for API compatibility during its documented deprecation window. Reader surfaces use the observed fields instead.
Image rights and licensing
Cunicula-created diagrams and article figures are copyrighted by Cunicula. They are not published under an open license. The source links shown with a figure document its factual basis; they do not transfer rights to the Cunicula artwork.
To request permission to reproduce an image, email tips@cunicula.com with the image URL, intended use, publication, and requested term.
Why this matters
Most privacy failures do not come from one dramatic hack. They come from small defaults that normalize logging, account binding, wallet tracing, device fingerprinting, and mandatory KYC until users have no room left to maneuver. Our job is to map the documented paths and explain the tradeoffs honestly. The reader makes the choice against their own threat model.