Privacy Checklist: What to Verify Before Launching Your Site
Your site is public by default, and so is everything you haven't hidden. Run through this checklist before you hit publish.
Your website is public by default. Anyone can visit it, screenshot it, archive it and share it. For creators in adult-adjacent spaces, that isn't an inconvenience; it's a safety issue.
The good news: almost all of it is preventable, and most of it takes an afternoon. Before you hit publish, work through this list — Digital OpSec goes deeper on the four protocols that matter most.
Domain & Hosting
- WHOIS privacy enabled: Your name and address don't appear in public domain records. Most registrars offer it; make sure it's on, and that it renews with the domain.
- Adult-friendly hosting: Your host won't terminate your account for your industry. Check the acceptable-use policy before you build, not after.
- Separate billing: The card or account paying for the domain and hosting doesn't link back to your personal identity.
- Business email: Your contact address isn't your personal inbox. A dedicated alias keeps your real email out of every form, receipt and footer.
Technical Privacy
- HTTPS everywhere: A valid SSL certificate, no mixed-content warnings. Non-negotiable.
- No third-party trackers: No analytics, fonts or widgets that sell or share visitor data. If you can't say what a script does, it doesn't ship.
- No author names in the source: Your real name doesn't appear in meta tags, page source or feed data.
- Anti-scraping basics: Sensible protection against bots harvesting your content, without breaking normal visitors.
- Age gate, where needed: Appropriate for your content and your jurisdiction.
Content Review
- No identifying details: Address, real name, workplace, school, or a small city that narrows it down. Read every page as a stranger who wants to find you.
- Image metadata stripped: EXIF data removed from every photo. It carries GPS coordinates, camera models and timestamps.
- No personal social links: Your personal Instagram, Facebook or TikTok isn't linked from the site.
- Testimonials that stay vague: Client quotes don't reveal names, locations or anything that pins them, or you, to a place.
Analytics & Data
- Privacy-focused analytics: Plausible, Fathom or similar. Not Google Analytics.
- No IP logging: Your analytics don't store visitor IP addresses, and your server logs are rotated, not accumulated.
- Minimal form data: You only ask for what you actually need, and the form says so.
- A retention rule: You know how long you keep data, and when it gets deleted.
Security Basics
- Unique, strong passwords: Every account (domain, hosting, email, CMS) has its own.
- 2FA on everything: Registrar, host, email, CMS. This one stops most breaches.
- Backups you can restore: Automated, off-site, and tested at least once.
- Software kept current: CMS, plugins and dependencies updated on a schedule, not after the exploit.
Legal & Business
- Privacy policy: Plain words on what you collect and why. Required in most jurisdictions if you collect personal data, and good practice everywhere.
- Terms of service: Clear rules for using the site.
- Written agreements: If you work with other creators or vendors, it's in writing.
- Separate records: The business is documented separately from your personal finances.
The Alias Test
Before launch, do the hardest check of all:
If someone screenshots your site and posts it online, can they work out who you are?
If the answer is yes, or even "probably", go back through the list. Every piece of identifying information is a thread someone can pull.
Run this before launch, and revisit it whenever you add a page, a form or a new tool. Privacy isn't a launch-day task. It's a habit.
This is general information, not legal advice. For your specific situation, ask a lawyer who knows your jurisdiction.
Want one built for you?
Bespoke, privacy-first, built from scratch and owned by you.
Start a conversation