Mycoscopy.uk
What Mycoscopy is
Everything in this section is about www.mycoscopy.uk.
A privacy-focussed mycology and microscopy shop
Every strain is available as a spore print, and most as a 12ml spore syringe too.
One small program we wrote ourselves
The whole shop is a single program written in Go. No WordPress, no plugins, no themes, no database. Apart from Go itself, it uses one extra package, made by the Go team, and only to switch on the lockdown described below.
OpenBSD
The server runs OpenBSD, an operating system built with security as its first priority.
Locked down while it runs: pledge and unveil
The shop uses two OpenBSD security features. With pledge, the shop promises OpenBSD, as it starts, the only kinds of things it will ever do, such as answering web requests and saving files. If it ever tries anything else, like running another program, OpenBSD stops it on the spot. With unveil, the shop tells OpenBSD the only folders it needs, its orders and messages folders, and everything else on the server becomes invisible to it. So even if someone found a flaw in the shop, they couldn't use it to run their own programs, or to read or change anything else on the server.
No admin dashboard
There's no admin area, login page or control panel on the website for anyone to attack. We manage orders from our own laptops, which collect them over an SSH encrypted connection.
Nothing runs in your browser
No JavaScript, no cookies, no trackers, no analytics, no third-party scripts. Our security settings tell your browser to refuse scripts outright, so even if someone sneaked code into a page, it wouldn't run.
Nothing worth stealing
There are no accounts or passwords, and we never handle card details. You pay by bank transfer or cash.
Every order and message is encrypted the moment it's saved, using public-key cryptography. The shop only holds the public key, which can lock files but can't unlock them. The private key that unlocks them is never on the server: it's kept only on our own laptops, which collect the orders. So even if someone broke into the server before orders and messages were purged, they would only find files they can't read.
Orders don't stay on the server
Each order is saved as a file, which we move regularly multiple times a day to our own local systems before deleting from the server. The one thing kept there is any conversation you choose to have with us on the site: encrypted, readable only with your private code, and deleted after 12 weeks.
Your details are deleted after 12 weeks
12 weeks after your order, we delete everything that ties it to you: your name, delivery address, email address, phone number, order notes and support code. You can get in touch to ask for your details to be deleted before then.
What we keep is what was bought, how many, the price, the date, how it was paid and the country it went to. That's all HMRC, the UK tax office, needs: a record of every sale, not of who made the purchase.
No tracking at all
Most websites watch their visitors. A study of millions of websites found that 75% of pages contain at least one tracker from another company. Google Analytics is on 53% of pages and Facebook's tracking pixel on 15%. This website has none: no Google Analytics, no tracking pixels, no cookies, and nothing loaded from any other company's servers. We keep no record of which pages you look at.
Source: HTTP Archive Web Almanac 2025, Privacy chapter.
Encrypted connections only
Every page is served over HTTPS, using only modern encryption.
No accounts. No emails. No cookies. No JavaScript. No tracking. No BS.
Visit Mycoscopy
Go to www.mycoscopy.uk or read the Mycoscopy About page.
The addresses we own
We own all four of these addresses. Each one takes you to the same shop:
You can also visit us over Tor at nk5iqjpcj7flbilyyba7ldz3akddigel6gokgdcmyesr2r7tjndyv3yd.onion.
Any other address calling itself Mycoscopy is not ours.
