← Back to blog

Tor Project · Cybersecurity

Tor Project's Terms: What They Actually Don't Do With Your Data

September 14, 2026

A
Very safe

The Tor Project does what it says it does, and doesn't do what it doesn't say. No hidden data collection. No tracking. No accounts. The organization builds anonymity software—Tor Browser, Onion Browser, Orbot—that lets you route traffic through multiple relays to obscure your location and usage patterns.

🟢 No collection, tracking, or telemetry. The Tor Project doesn't harvest personal data. Full stop. (Shared Privacy Principles)

🟢 Your settings stay on your device. Configuration lives locally. Nothing gets sent to Tor Project servers. (Application-Specific Data Practices)

🟡 Bridge fetching may require a direct connection. If you're using anti-censorship tools to bypass network blocks, the bridge-fetch request briefly happens outside Tor. Unavoidable tradeoff; you're trading a moment of exposure for access. (Application-Specific Data Practices)

🟢 No sign-ins, no identity. There are no user accounts. No login walls. No profiles. You don't exist in their system. (Shared Privacy Principles)

🟢 Android app asks for almost nothing. Minimal permissions. No location, contacts, or device ID requests. (Permissions (Android))

If privacy is the stated goal and the terms match the software, you're looking at one of the few places where they do.

This breakdown is based on Tor Project's publicly available Terms of Service and/or Privacy Policy. It may contain mistakes. Spot one? Let us know.