Who this is for: people who control their own architecture — a website, an email service, a store, a newsletter you run yourself. If your entire presence lives on a platform whose business model depends on tracking and attention — social video, ad-supported content platforms — this pledge has nothing practical to offer you. That's a different, harder problem, and pretending otherwise would be dishonest.

The Manifesto

We believe in, and advocate for, an internet where:

  1. Site visitors are unique individuals who have a right to privacy, and whose behaviour, data and history are not marketable assets.
  2. Privacy is a first-class citizen — the same as you would treat accessibility. Go out of your way not to collect personal information you don't need.
  3. If you must collect data to enable some function, be clear about what you're collecting, why you need it, how it's stored, and how someone can change their mind and have everything you know about them purged.
  4. Configure your web server to record only privacy-neutral information by default — no IP addresses, no user-agent, no referrer. Where diagnosing a real problem genuinely requires more, that elevated logging should be an exceptional state: deliberately switched on, gated behind a privileged action, and set to expire and disable itself automatically if you forget to turn it off. Never let "temporary for troubleshooting" become the default by omission. Error logs leak personal data more easily than access logs — treat them with the same suspicion.
  5. Cookies are often unnecessary bundles of data. Ask: are they needed? Is there another way to achieve the same goal without storing user data — an anonymous session token in the URL, for instance?
  6. Never collect user information just because you can. Default to discarding data, not collecting it — treat anything sitting in a log as something to actively decline, not passively keep.
  7. Transparent pixel images and time-on-page counters are tracking mechanisms. Using them is against these principles — if you're using one, you don't need the data it's collecting.

Why Bother

None of these principles alone solves the internet's data problem. Together, they're a genuinely compelling defence against problems you haven't had yet — and they're not only the right thing to do, they're the pragmatic thing to do.

  1. Reduced breach severity. You cannot leak data you never collected. In a breach, personal information that was never stored is the exposure that never happens.
  2. Reduced regulatory exposure. Data protection regulators scale their interest, and their penalties, to the volume and sensitivity of what you hold. Hold little, and there is little to investigate.
  3. Visitor trust. A specific, credible privacy commitment is more persuasive than a vague one, and may earn you more trust and engagement, not less.
  4. Lower operational overhead. No data means no consent-banner theatre, no cookie-compliance tooling, and no breach-notification bureaucracy to build and maintain.
  5. No Lawyers. As much as we love lawyers, if you need one to draft your privacy policy, that's fair indicator you aren't compatible with the Priva-c pledge.
  6. Metrics still work As much as it's cool to observe who comes to the site, whey they like, how long they linger over something - do you really need that information, enough to spy on your site visitor for?

The Pledge

If your site follows the manifesto above, you're welcome to say so — in your own words, or by adapting the text below for your own privacy policy or footer.

This site follows the Privacy First pledge (priva-c.org):
no tracking, no unnecessary data collection, and privacy
treated as a first-class concern, not an afterthought.

Where we must collect data to provide a specific function,
we tell you what, why, how it's stored, and how to have it
removed.

This is a self-declared pledge, not an audited certification.

Drop the middle paragraph if your site collects nothing at all.

The Badge

You're welcome to display the badge on your own site, linked back here. Save it locally rather than hotlinking — this site makes no promise about its own uptime.

Privacy First — Pledged

<a href="https://priva-c.org">
  <img src="/badge.svg" width="132" height="40"
       alt="Privacy First — Pledged">
</a>

Self-declared, not audited

Displaying this badge means a site owner has read this pledge and states, in good faith, that their site follows it. No one from priva-c.org reviews, audits, or verifies this claim — there is no membership, no registration, no fees, and no enforcement body. Trust the badge the way you'd trust someone's word, because that's exactly what it is.

First Sites to Take the Pledge