Methodology
This page is the contract. It says where every fact comes from, how it is written, what the site will never say, and how the register is kept honest after launch. Written 6 September 2026.
What this site is, and is not
It is a transparency register. For each online service it answers one question: does it check your age in the UK, how, through which vendor, and what does it say it keeps. Every row is a dated quotation with a link.
It is not a guide to avoiding checks, and it is not a ranking. It carries no VPN recommendations, comparisons, links or codes, and no instructions of any kind for evading a check. Reporting what Ofcom or the government has said about VPNs, in a news context, is the only place the word appears.
Sources, in order of authority
- Primary: the service's own help or policy page, the vendor's own policy page, Ofcom or the ICO. Only a primary source may supply a retention quotation; the validator that runs before every build rejects a retention quote from anything else.
- Secondary: press and trade reporting. Allowed for a gate status or a method, always labelled "secondary source (press)" on the page, and never presented as the company's own words. Where a secondary source quotes the company, the page says so and names the outlet.
Five service help pages (Discord, Kick, OpenAI, X and Bumble) refused automated reading during the September 2026 research. Their entries say so and carry a "still being verified" box until a human has read the page. The full list of URLs is on the sources page.
The retention rule
Every retention statement on this site is one of exactly two things:
- a quotation of the service's or vendor's published wording, with the URL it came from, the date the source itself carries where it has one, and the date we checked it; or
- the line "No published retention period found (checked 6 September 2026)." with the date we looked.
The site never paraphrases retention into a claim about what a company does or does not do with an image. If a company has not published a period, the absence is the fact, and the absence line is what appears. A build check fails the site if a retention cell is anything other than a sourced quotation or that line.
Vendor default versus deployer configuration
The same vendor's retention is often stated four different ways depending on who deployed it. Persona's own policy allows up to three years; Reddit's deployment says three days (its July 2025 launch coverage said seven); Roblox says images are deleted immediately while its own help page says Persona keeps biometric data for up to 30 days. This site does not decide which is right. Each vendor page has a table with the vendor's wording in one column and each deployment's wording in the other, both dated. Where they differ, the difference is the fact.
No scores, no adjectives
The facts panel on every page contains only published statements, dates and links. There is no privacy score, no star rating and no "safe" or "risky" label, because a score is an opinion and the facts panel is not the place for one. If a mechanical score is ever added it will be computed deterministically from the facts panel by a published rubric, with the inputs shown on the page, and it will sit in a separately labelled panel. Questions such as "is Yoti safe" are answered on the vendor page with the vendor's retention wording, its certifications, regulator actions and published incidents, and nothing else.
What this site never publishes
- Anything that describes, recommends or links to a way of defeating or evading an age check. That includes VPN products, comparisons, codes and affiliate placements. A build check scans every file in the built site for a fixed list of phrases associated with that kind of content and fails the build on a single match; the same check runs on every data record and on the agent tools' descriptions and outputs.
- The inverse list. People do search for services with no check. This site answers with the neutral status "no active age check as of [date]" on the relevant entry, never with a list titled that way.
- Names of individuals at any service or vendor. Companies, policies, certificates and regulator actions only. A regulator's statement attributed to a named public official is the one exception.
- User-generated content of any kind: no comments, reviews, ratings or forum. Corrections go by email to the editor and are published by the editor with the source. That keeps the site outside the Online Safety Act's definition of a user-to-user service.
Adult-service entries
Entries for adult services record the age-assurance facts only. The domain appears as text, the page carries no outbound link of any kind (source URLs are shown as text), there is no screenshot and no description of the content. No advertising or affiliate placement appears on those pages. A build check enforces all of this.
Freshness
- Every entry carries the date a human last read its sources.
- Older than 60 days: the date turns grey and reads "unverified since".
- Older than 120 days: the row is moved to the bottom of the index.
- The badges are computed when the site is built, so the site is rebuilt at least weekly whether or not anything changed.
Upkeep
Nightly, automated (planned): every source URL is fetched, stripped to text and compared with the last copy. Any change goes to a review queue. Nothing automated ever changes a gate status, a vendor or a retention quotation; a human reads the page and makes the edit, and the changelog records how it was detected.
Weekly, by hand (about ninety minutes): re-read Ofcom's enforcement programme page and the ICO's news page and add entries; work the review queue; rebuild.
On every Ofcom, ICO or government publication: a timeline entry the same day, a feed item and a changelog entry.
Corrections and right of reply
Every entry ends with a "Correct this entry" link. Corrections are answered within a week. A verified correction changes the entry, is logged in the changelog with its source and the label "user_tip", and appears in the feeds. Services and vendors are welcome to correct their own entries: point us at the policy page and the wording is replaced with the quotation, dated. Nothing sent through the form is published. The process is described on the corrections page.
Privacy architecture
- The site is static HTML. There are no accounts, no cookies of our own, no analytics and no third-party scripts anywhere. Pages are served with a Content Security Policy of
script-src 'self'andconnect-src 'self', so nothing on a page can send a request anywhere but this origin. - The only script that talks to the server is the correction form, which posts to this site's own endpoint and stores nothing. If that endpoint is unavailable the form opens your own mail app instead.
- This directory publishes information about companies, not individuals. It does not process personal data of people who verify their age.
Full wording is on the privacy page.
Agent tools (WebMCP)
The index, service, vendor and timeline pages register four read-only tools under the draft WebMCP specification, so that an assistant browsing on your behalf can read the same facts: get_service, list_services, get_vendor and get_timeline. Every tool carries readOnlyHint: true; none takes any personal data, none submits, saves or emails, none links to an adult service, and every answer ends with "Quoted from published sources on the dates shown; not legal advice." The same wording check that runs on the pages runs on the tools.
Status as of 6 September 2026: the API is in a Chrome origin trial (versions 149 to 156) and Microsoft Edge has its own trial; the ChatGPT desktop browser can call these tools; Gemini in Chrome and Claude cannot yet. The tools do nothing for search visibility and are not crawled. Developers can inspect them in any browser console via window.__agentTools. The whole dataset is also published as JSON at /api/v1/services.json, /api/v1/vendors.json and /api/v1/timeline.json, and summarised in llms.txt.
If you use an AI assistant to read this site, your assistant's provider may retain what you ask it. This site never receives it.
Known conflicts and open points
Shown on the relevant pages as "still being verified" rather than hidden. Until resolved, the facts panel records only what a published source says.
- Apple devices: Apple support page with the primary wording.
- Bluesky: KWS retention line for the Bluesky deployment.
- ChatGPT: UK rollout status; Read the help page in a browser for the primary quote.
- Discord: Discord UK help article returned 403; confirm ID-route retention wording; October 2025 support-vendor breach (~70k IDs via 5CA/Zendesk) is a separate incident, not the age-check vendor.
- Kick: Read the help page in a browser; confirm date and retention wording.
- OnlyFans: Fan-side method and retention from OnlyFans' own page.
- Pornhub, YouPorn, RedTube: Per-method retention statement.
- Reddit: Reddit help page returned 403; confirm current retention wording on Reddit's own page; Record both the 3-day and 7-day figures with dates.
- Roblox: Reconcile "immediately" (Roblox) with "within 30 days" (Persona per Roblox help).
- Snapchat: Any change after the 30 April 2026 report to Ofcom.
- Steam: Find Valve's own support page for the primary quote.
- Telegram: Primary Telegram statement.
- TikTok: Investigation opening date confirmed only via secondary reporting.
- Tinder and Hinge: Locate Match/Hinge UK terms page for the primary retention quote.
- Twitch: Whether an ID alternative exists for users the scan cannot estimate.
- X and Grok: All method and retention facts are from press; X help page returned 403; Whether manual verification is still Premium-only.
- Xbox: Exact mandatory date.
- k-ID (vendor): Facial estimation is delegated to Privately; Privately accuracy figures not captured.
- Persona (vendor): Persona privacy policy page returned 403; the 3-year ceiling is from secondary reporting; ACCS status unverified; Discord dropped Persona 24 Feb 2026 after the exposure report.
- Yoti (vendor): ACCS registry status not confirmed (not on the Age Assurance category page fetched 6 Sep 2026); Yoti age-verification privacy policy page returned 403; quote is from the white paper; AEPD appeal outcome; AEPD decision date is given as 10 March 2026 in research/03 and 25 March 2026 in research/02; the AEPD resolution itself was not fetched.
- Apple (vendor): Quote is via press; Apple support page not fetched.
- Epic Kids Web Services (vendor): Not on ACCS registry.
- Veratad (vendor): Retention policy not located; Discord ID-document route reported via press.
- VerifyMy (vendor): FAE retention policy not fetched.
- OneID (vendor): No named UK consumer-service customer found.
Decisions taken in the build where the research left a gap
- A method row with no published retention statement shows the absence line dated with the row's own verification date, even where press has reported a figure; the press figure appears in the row's notes, labelled as reported.
- A vendor whose product page carries no retention statement at all (Veratad) shows the absence line in place of a quotation.
- Where the two research reports disagree on a date or a status (the AEPD decision against Yoti: 10 or 25 March 2026; the fapello.com investigation: open or fined; the Ofcom letters of 12 or 13 March 2026 and whether X received one), the entry records both readings and the point is listed above.
- A vendor's reported customer that has no entry in the index yet (Instagram, for Yoti) is shown as plain text with its source, not as a link.
- One research source for the Yoti fine is a VPN vendor's blog. The site never links to VPN vendor hosts, so that entry cites a secondary encyclopaedia page instead and says so.
- No affiliate links of any kind at launch; the mechanism exists (a label and a "sponsored" attribute, never on adult or gambling entries) but nothing uses it.
How the site is funded
At launch, nothing on the site is paid for. If that changes, the advertising and affiliate disclosure will change first: any affiliate link will be labelled "Ad" beside the link, will never be for a VPN product, and will never appear on an adult or gambling entry. Display advertising, if added, will run only on service and guide pages, never on the correction form, and never for VPN creatives that mention age checks.