|  | This is aninformation page. It is not anencyclopedic article, nor one ofWikipedia's policies or guidelines; rather, its purpose is to explain certain aspects of Wikipedia's norms, customs, technicalities, or practices. It may reflect differing levels ofconsensus andvetting. | 
|  | This page in a nutshell: Use caution when postingpersonally identifiable information online. If you becomestalked orharassed through such information, or simply want any identifiable information removed, email a trustedAdministrator orWikipedia:Requests for oversight for discreet and confidential handling of such incidents. | 
This page is intended as a guideline for user security concerns and practices on Wikipedia. It adapts some information from theWikimedia Foundation'sprivacy policy to address somepersonal security concerns that may arise in the course of editing Wikipedia.
Many of these concerns have to do with the availability ofpersonal information in apublic space. If you only read Wikipedia without contributing, no more personal information is collected than is typically collected in server logs by web sites in general.
If you contribute to Wikipedia, however, you arepublishing every word you post publicly. If you write something, assume that it will be retained forever. This includes articles, user pages and talk pages.
If you becomestalked orharassed on Wikipedia via any information posted about you on-site, whether by you or anyone else, it is recommended that you report this discreetly via off-site means, such as email, to a trustedadministrator or atWikipedia:Requests for oversight, which maintains a confidential email service that can be used to request removal of such instances without drawing further attention to them on-site. Edits removed with oversight can only be seen by editors with oversight access, stewards, and certain WMF staff members.
When you edit any page in the wiki,you are publishing a document. This is a public act, and you are identified publicly with that edit as its author.
The wiki will set a temporary sessioncookie whenever you visit the site. If you do not intend to ever log in, you may deny this cookie, but you cannot log in without it. It will be deleted when you close your browser session.
More cookies may be set when you log in, to avoid typing in your user name (or optionally password) on your next visit. These last for up to one year. You may clear these cookies after use if you are using a public machine and don't wish to expose your username to future users of the machine. (If so, clear the browser cache as well.)
When you publish a page, or any text, onto the wiki, you may be eitherlogged in using aWikipedia account, or simply logged out and not using an account.
If you are logged in with your Wikipedia account, you will be identified by your account'susername. Most editors choose a username that is apseudonym, or a fictitious name or nickname. Although you are welcome to use yourreal name as your username if you wish to do so, this ishighly not recommended as it puts you at significant risk for having your non-public personally identifiable information discovered and published in an effort to harass or intimidate you.
If you are not logged in with a Wikipedia account and instead choose to edit without one, you will be identified by your networkIP address. This is a series of four to eight numbers which identifies the internet address from which you are contacting the wiki. Depending on your connection, this number may be traceable to your home, place of business, or school, or only to yourInternet service provider.
It is possible that the origin of your IP address could be used in conjunction with the pattern of edits in your contribution history to identify you, even by private individuals unknown to Wikipedia. Every edit made with an IP address is logged and publicly accessible.
It may be either difficult or easy for a motivated individual to connect your network IP address with your real-life identity. Therefore, if you are concerned aboutprivacy, it ishighly recommended that you use an account with a username that is under apseudonym. If you are using yourreal name as your user name and wish to change this, the best way to do so is to stop using that account (seeWP:CLEANSTART), create a new account with a pseudonymous username, and use that account for all future edits moving forward. While you canrequest the username of your current account be changed, it will not stop other users from searching through your edit history and discovering your former username in old edits where yousigned a comment, message, or response with that former username.
Most Wikipedians edit under pseudonyms because they wish to remainanonymous. Still, some users registered under pseudonyms make no other attempt to disguise their real identities (for example, by placing their real names, photographs of themselves, or other identifiable information on their user page). True anonymity is only achieved if there is absolutely no ability for anyone to link the user's actual identity from any information that is posted under the pseudonym.[1] However, true anonymity on Wikipedia is difficult, if not impossible, to achieve due to the fact that Wikipedia's server logs still enable system administrators to determine the IP address, and perhaps even the true name, of any registered user (seeWikipedia:Privacy Policy for a list of the conditions under which such a linkage would be attempted); this is not done unless there is a compelling reason (for example, significantvandalism or a law enforcementsubpoena).
Because a user's interest areas, writing style, and argumentative positions may establish an identifiable pattern, true pseudonymity may not be realistically achievable.[2]
It is possible to mask a user's actual IP address by using anopen or anonymizing proxy, a server that disguises the user'sIP address with the IP address of that server. However, doing this can be inconvenient as they are often blocked due to frequent misuse by vandals (see alsoWikipedia:Open proxies).
If you use a company mail server from home or telecommute and use a DSL or cable Internet connection, it is likely to be very easy for your employer to identify your IP address and find all of your IP-based Wikimedia project contributions. Using a user name is a better way of preserving your privacy in this situation. However, remember to log out or disconnect yourself after each session using a pseudonym on a shared computer, to avoid allowing others to use your identity.
Wikipedia does not require you to providepersonal information on userpages or elsewhere in the course of editing the encyclopedia. While there is nopolicy forbidding this, remember that information revealed amongst friends and fellow editors on Wikipedia is kept in a permanent record that is accessible by anyone in the world with a networked computer. However,oversighters are granted the ability to remove such content from the database.
It is recommended that you use utmost caution and discretion when revealing information that could be used to personally identify you.
While editors are expected to observe Wikipedia's behavioral policies, particularlyAssume good faith, with regards to editorial conflicts, no user is expected to put editorial policies above their own personal welfare and security. When confronted withcyberstalking or otherharassment, the best course of action would be to report any concrete instances of this confidentially and discreetly via email to a trustedAdministrator. It is not advisable to report this activity elsewhere on Wikipedia, such as atWP:AN/I, as this may draw more public attention to whatever potentially compromising information may have been used in thepersonal attack.
Many aspects of the Wikimedia projects' community interactions depend on the reputation and respect that is built up through a history of valued contributions. User passwords are the only guarantee of the integrity of a user's edit history. All users are encouraged to select strong, unique passwords and to never share them. No-one should knowingly expose the password of another user to public, either directly or indirectly.
Here are some tips that editors should consider to reduce the likelihood that their accounts may be compromised:
Users might consider using a unique email address for their Wikipedia account. In the event of a breach of login credentials such as an account email and password, having a unique email address that is otherwise unconnected to you will make it harder for you to be identified.Securing your email account, using some of the password suggestions above, is especially important for keeping your Wikipedia account more secure.
Template:User committed identity gives editors a way to later prove that they are the person who was in control of their account on the day the template was placed. This is done by putting a public commitment to a secret string on the user page so that, in the unlikely event that their account is compromised, they can convince someone else that they are the real person behind the username, even if the password has been changed by the hijacker.
The Wikimedia Foundation makes no guarantee against unauthorized access to any information you provide. This information may be available to anyone with access to the servers. A partial list of those people can be found in the developers list.
The Foundation might also be forced to hand over identifying information by governments.
Editing Wikipedia is not without risk. Please consider your own risk profile before making edits, especially aboutliving people,organizations andcontentious topics like politics.
Journalists usually carrydefamation insurance, though it seems unlikely that a Wikipedia editor could attain insurance against defamation.
Only administrative actions appear to qualify forpotential assistance with legal fees by the Wikimedia Foundation.
Data on users, such as the times at which they edited and the number of edits they have made are publicly available via "user contributions" lists, and in aggregated forms published by other users.
Once created, user accounts cannot be removed. However, it is possible for a username to be changed (seeWikipedia:Changing username andWikipedia:Changing username/Usurpations). The Wikimedia Foundation does not guarantee that a name will be changed on request.
Removing text from Wikimedia projects does not permanently delete it. In normal articles, anyone can look at a previous version and see what was there. If an article is "deleted", any user with "administrator" access on the wiki, meaning almost anyone trusted not to abuse the deletion capability, can see what was deleted. Information can be permanently deleted by those people with access to the servers, but there is no guarantee this will happen every time it is requested.
If personally identifiable or libelous information has been published about you anywhere on Wikipedia, you can request its removal throughWikipedia:Requests for oversight. This information will only be viewable by people with direct access to the Wikipedia databases, arbitrators, ombudsmen and oversighters.
Policies
Articles
Essays and how-to guides