The technical half. Written so somebody who knows what they are reading can check it.
Phone numbers — both the ones this site sells and the one you gave at registration — and the unblurred photograph originals live in a separate part of the database called `private`. None of the roles a browser can ever hold is granted access to that part at all. Your own receipts are not in there: what you bought is readable by you, and by the house, and by nobody else.
That is protection by absence rather than by rule: there is no permission to get around, because no permission was ever given.
It is collected once, at registration, so the house can match a message from you to your account. It is never shown to an advertiser, never published, and never sold. It is used once more, and it is worth knowing about: registering with a number already on another account is refused, so somebody who has yours can learn from that refusal that it is here.
An administrator can look one up, one at a time, and every single look writes a record of who looked and when.
On the site, a photograph is served only to somebody entitled to it — no page and no query hands an unentitled browser a blurred copy or a smaller version, because the database does not tell it where the file is. Two honest exceptions: blurred copies published before 7 August 2026 are still fetchable by anyone who kept the address, and the daily email carries blurred thumbnails on links that need no sign-in. Both are being closed.
Photographs are also kept out of search: every profile page carries noindex, nofollow, noarchive and nosnippet, and the answer-engine crawlers are named individually rather than left to a wildcard.
There is no checkout on this site and no card is ever stored, because there is nothing here that could charge one. Everything is settled by hand, directly with the house.
It follows that no card number of yours can leak from here, because none of them is here.
Sign-in is an email address and a password. There is no two-factor authentication yet — if you want one thing to do after reading this page, make it a password you use nowhere else.
If you lose it, the reset link goes to your own inbox, and nobody here can read your password because nobody here has it — the database keeps only a hash. What the house can do is issue your account a new password without your inbox being involved, which is how somebody locked out of an old address gets back in. There is also a sign-in link by email, so a working inbox is enough to reach an account on its own.
This one is honest and unfinished. There is no button that closes an account, and there is not one hidden anywhere else either — it is done by asking, by hand. Nothing here will tell you your data has been erased when it has not.
It is on the list, and it matters more than most of what is on that list.