SporeStack, comparedNo account is a real idea. The disk still sits somewhere.
SporeStack removed the account entirely: you pay, you get a token, the token runs a server for as long as it is funded. As an answer to "what do they know about me" it is the strongest on this page, and it leaves one question open.
7 minute read · Their pages last read 30 juillet 2026 · Corrections welcome
The one you are looking at
SporeStack
Where
Resold capacity, several regions
Site
sporestack.com
What they are genuinely good at
No account, no email, no password — an idea most privacy hosts talk about and this one shipped.
Bitcoin and Monero as the only way to pay, which keeps the model honest.
Open tooling and an API that treats the server as disposable, which is the right shape for the threat model.
This estate
DediPrivacy
Where
eight jurisdictions, eight companies
Site
dediprivacy.com
What we publish that most do not
Every price, including bare metal, GPU by the second and colocation.
A signed warrant canary, a quarterly transparency report and the inventory of records that exist.
Mitigation on before an attack starts, and an SLA that credits itself from the incident record.
Row by row
What each of us publishes.
Not what each of us believes. Every row below is a page you can open on either site, or an answer that is not there.
Their column reflects their own public pages, read on 30 juillet 2026. marks a thing we could not find published — it is not a claim that they do not do it.
Published?
SporeStack
DediPrivacy
Sign up without identity documentsNo name, no address, no document, at any spend level.
Published
Published
Settles in cryptocurrencyAccepted as payment, not as a gift-card workaround.
Published
Published
Accepts MoneroThe only widely accepted asset that is private by default.
Published
Published
Every price publishedThe whole catalogue on a page, with no “contact us” tier.
Published
Published
Signed warrant canaryCryptographically signed, dated, and on a schedule.
Not published
Published
Transparency report with figuresNotices received, and how many were acted on.
Not published
Published
Law-enforcement guide publishedThe inventory of records that exist, before you ask.
Partly
Published
Log retention stated as a numberHours or days, not “minimal” or “as required”.
Partly
Published
A separate legal entity per jurisdictionSo a judgment in one country does not reach the servers in another.
No
Published
Uptime SLA credited automaticallyCredited from the published incident record, with no claim form.
No
Published
DDoS mitigation includedOn every product, at no extra charge, with no protected-IP upsell.
Not published
Published
Bare metal, GPU and colocationBeyond virtual machines, on the same account and policy.
No
Published
On eight of the twelve rows above, this estate publishes an answer and we could not find one published there. Tell us if a row is wrong
Two different questions, and each of us answers one
SporeStack answers "what does the supplier know about me" with nothing, and that is genuinely the best answer available. This estate answers it with an email address and a password hash, which is worse.
The other question is "who holds the disk, and what happens when somebody complains about what is on it". A reseller answers that with the underlying provider — a company with an ordinary abuse desk and an ordinary obligation to the law where it is registered. Anonymity at purchase does not travel to the rack.
Where the models genuinely differ
A token that expires is the right shape for something short-lived. It is the wrong shape for a business: no invoice, no balance to run down, no continuity if you lose the token, and nothing to appeal to if the underlying provider suspends it.
We ask for an address, because an address is how somebody is told their server is about to lapse. SporeStack does not, and for a certain threat model that is simply better. It is worth saying so on our own page.
Questions people actually ask
Could you drop the email address?
Not without dropping the ability to warn somebody before a service expires, or to let them recover an account. What we can do is publish exactly what the address is used for and what a valid order would produce, which the law-enforcement guide does.
Is a disposable server safer?
For some things, yes, and nothing here argues otherwise. For anything that has to stay up, an SLA and a named entity holding the hardware are worth more than a shorter lifetime.
Buy theirs instead if
The threat model is "nobody should be able to connect this server to me", and a disposable token is exactly right for it.
The server is short-lived by design and an SLA would be meaningless to you.
You would rather hold no relationship with a supplier at all than hold an anonymous one.
That list is here because a comparison that cannot name a reason to buy the other one is an advertisement. If any of those three is you, they are the better buy and this page has done its job.