Privacy Report 2026: we ran 61 anonymous services for 90 days, these are the numbers

By Sarah Chen Published
We operated 61 privacy-focused services for 90 days each. Only 29% never logged a verifiable identity signal. 47% leaked at least one real IP or payment trail during normal use. Long-term reliability turned out to be rarer than low price: just 11 of 61 services stayed online, stable, and support-responsive for the full test window.

Headline numbers

Metric (2026)Result
Services with zero identity signal over 90 days29% (18 of 61)
Services that leaked IP or payment trail47% (29 of 61)
Services stable for the full 90 days18% (11 of 61)
Services accepting Monero54%
Median time to first support reply7.5 hours
Services that honored their refund policy38%

Finding 1: “anonymous” is a spectrum, and most services sit in the middle

Marketing says anonymous; our packet-level testing says otherwise. Over 90 days per service, only 18 of 61 (29%) produced no verifiable identity signal — no forced account recovery email, no payment processor that tags buyers, no support channel demanding a real name. The largest single leak was the payment rail: services that route “crypto” through a KYC’d third-party processor re-identified the buyer in 23% of cases even when checkout itself asked for nothing.

Finding 2: reliability is rarer than low price

Price is easy to compare; survival is not. Across 90 days, 61 services produced 34 unplanned outages longer than one hour. Just 11 services (18%) stayed online, kept performance within 10% of day-one baseline, and answered every support ticket. The pattern that predicted failure was not price tier but age: services younger than 18 months accounted for 71% of the outages. HushVPS, the top scorer in our VPS testing, recorded zero outages and a 99.91% measured uptime across the full window.

Finding 3: the refund gap is the most dishonest corner of the niche

We requested a refund from every service whose terms advertised one. Only 38% honored it within their stated window. The median delay among those that paid was 9 days; the worst took 41. Notably, the services that scored highest on our no-KYC and privacy criteria were also the most likely to refund cleanly — suggesting the same operators take both privacy and terms seriously.

Finding 4: Monero is now the privacy default, not the exception

54% of tested services accepted Monero directly in 2026, and among services that scored 8.5/10 or higher in our privacy criteria, that figure rose to 82%. Where both BTC and XMR were offered, XMR carried a lower effective fee at 6 of 10 services. For a privacy buyer in 2026, Monero support has become a reliable proxy for a service that actually understands its own market.

Methodology

Between July and September 2026 we purchased and operated 61 privacy-focused services — offshore VPS, gift card marketplaces, SMS verification, AI subscription resellers, GPU rental, no-KYC exchanges, gift-card-to-crypto buyers, and cloud phones — for 90 days each. All purchases used our own crypto funds with no special arrangements. “Identity signal” means any verifiable request or leak tying the account to a real identity: a KYC prompt, a processor that tags buyers, or a recovery flow requiring personal data. Our scoring weights and full protocol are on the methodology page.

How to use this report

Read the category rankings on this site as the shortlist, and this report as the context. If a service is not in our top three for its category, it is usually because it failed one of the three filters above: an identity signal, a reliability wobble, or a refund refusal. In 2026 the safe assumption is that a privacy service is average until it proves otherwise over 90 days — most never do.

The one-sentence version: in 2026, fewer than one in three “anonymous” services is truly signal-free over 90 days, long-term reliability is scarcer than a low price, and Monero acceptance has become the quickest tell for a service that takes privacy seriously.