Updated 26 August 2026 · Oernoe Editorial Team
A “15 privacy tools that actually work” article is almost always a roundup of VPNs, password managers, and browsers copied from last year’s roundup. Google’s publisher rules are blunt about scraped and templated pages. This URL was one of those. The address stays so old links do not break. The document is now the operational kit for www.oernoe.com and the live hosts.
None of this is a recommendation that you install the same stack. It is a description of what we run, so a reader can check us. If a tool below is missing from the live site, this page is wrong.
ads.txt
The file at https://www.oernoe.com/ads.txt names google.com, pub-9477175344230263, DIRECT. That line is how an ads buyer can tell this site authorized Google to sell inventory. If the file 404s, or names a different pub, the rest of the advertising copy on this site is suspect. We keep it at the site root on purpose, not buried in a legal PDF.
The AdSense client, used narrowly
Eligible finished pages load adsbygoogle.js with client ca-pub-9477175344230263 and request non-personalized ads by default. Home, About, legal, login, the journal listing, and the apps do not load that script. The google-adsense-account meta tag still appears site-wide so Google can verify the publisher even on pages that have no units. Verification is not the same as an ad.
We also keep Google Ads Settings and the industry opt-outs in the footer and the cookie notice. A publisher that hides those links is asking people to trust a caption.
noindex as a publishing tool
Application shells on www (/mail, /login, /signup, /console, /dashboard, /auth, leftover /studio) send X-Robots-Tag: noindex, nofollow. Promotional journal slugs drop out of /blog and /sitemap.xml through the content-quality checks. robots.txt no longer tries to hide those shells with a trailing-slash Disallow, because that stopped Google from reading the header. The write-up is Corrections we have already made.
Separate hostnames
Search, Account, Health, Chat, AI, Docs, Drive, and Tracker are different hosts. Ads stay off the product hosts. Queries stay off the advertising file. The map is Which Oernoe hostname does what. DNS is a privacy tool here in a boring way: it keeps a chat thread from sharing a page with an ad unit.
Public inboxes
support@oernoe.com, privacy@oernoe.com, legal@oernoe.com, hello@oernoe.com. They are printed on Contact, not hidden behind a ticket portal. Privacy requests are a written process in How a privacy request is handled. Copyright has the DMCA page. We do not run unmoderated comments, so these inboxes are the entire public conversation channel.
Account at account.oernoe.com
Signup and login do not happen in a banner on this publisher site. They happen on account.oernoe.com. One account opens the live products. Basic access does not wait on a verification ritual. Password reset lives there. Those screens do not load ads. Older /login and /signup URLs on www still resolve and are noindexed.
Tracker
tracker.oernoe.com is the public status host. It is for uptime, not for journal essays. If Search is down, that is where we want a stranger to look before they assume the publisher site is the product. Tracker does not run ads.
The journal filter
Indexable journal posts need enough original text to be a document, currently at least 700 words, and they still fail if the title is hype or the body is an unfinished launch note. Test slugs are excluded. The code path is described in How we keep the journal index honest. A denylist is a tool. So is deleting a waiting-list form.
What we do not list here
We are not going to rank consumer VPNs. We are not going to paste a password-manager affiliate table. We are not going to claim that using Oernoe makes Google unable to see an ad request on an eligible www page. Those claims are how the old article failed. This kit is smaller and checkable. If you want a consumer roundup, plenty of other sites will sell you one.