FIELD NOTES
A personal record of travel, networks and small failures
TRAVEL NOTE

The Adult Site Asked for My Passport—The Safer Choice Was to Share Less

The adult site would not let me reach the cancellation page until I uploaded a photograph of my passport. My subscription renewed at midnight, I was in a hotel room in Leeds, and the account timer said I had forty-seven minutes left to stop the next charge. I assumed the prompt was a browser error, refreshed the page, and tried the mobile app instead. The app returned me to the same screen: Verify your age to continue. Upload a government-issued ID. The connection was protected by a VPN and the page showed a padlock, but neither symbol answered the question that stopped me from pressing the camera button: what would happen to the passport image after I sent it?

I was not trying to open a video.

I wanted to cancel an account I no longer used.

The website had placed its age check in front of the account settings, so even that administrative task required proof that I was an adult.

The passport was in my bag.

Uploading it would have taken less than a minute.

I still could not make myself do it.

The short answer

Only after the account was closed did I notice the smaller app’s blocked-request counter. It had stopped several advertising and tracking requests while I moved between the adult site, its billing page, and the verifier.

A protected upload could still reveal too much

Age checks had become routine across the UK. Ofcom reported tens of millions of checks across a sample of online services after stronger age-assurance duties took effect. By 2026, many of the country’s most visited pornography services had introduced checks, while others had restricted UK access altogether.

The prompt itself was no longer surprising.

The amount of information it requested was.

A passport can reveal a full legal name, birth date, photograph, nationality, document number, and signature. The website only needed to know whether I had crossed an age threshold, yet the most prominent option asked for nearly everything printed on the identity page.

My VPN could protect that image while it crossed the hotel network.

It could not make the image less revealing once it reached the verifier.

That distinction changed the question from “Is the upload encrypted?” to “Does this company need the whole document at all?”

I opened the privacy link beneath the upload box.

The adult site said that an external company performed the check. The verifier described security controls, but the first screen did not clearly say whether the passport image would be deleted immediately, retained for fraud prevention, or connected to my adult-site account.

The cancellation timer showed forty-one minutes.

Instead of accepting a vague answer because the page looked professional, I looked for another way through.

The passport was the largest button, not the only choice

UK data-protection guidance gave me a better standard.

Age-assurance services should explain what information they collect, whether another company receives it, why it is retained, and for how long. They should also avoid collecting more personal information than the age check requires.

That mattered because a service asking only “Is this person over 18?” may not need to see an entire official document.

I returned to the verification page.

Below the large Upload ID button was a smaller link:

See other verification methods.

I pressed it.

The next page offered facial age estimation, an open-banking check, and confirmation through a mobile-network provider. Those were all recognized forms of age assurance, alongside digital identity, card, and photo-ID checks.

The passport had looked mandatory because it occupied most of the screen.

It was only the default.

That gave me a way to complete the legitimate check without surrendering the most sensitive document in my bag.

First, though, I needed the verification session to stay open.

My established VPN added friction without reducing the disclosure

I restarted the process through the established VPN I normally used while traveling.

It was a mature provider with broad server coverage and years of public history. I trusted it on hotel Wi-Fi.

The app had signed itself out after an update.

I entered my email address and password, approved a security alert, and selected a nearby server. Then I reopened the adult site.

A CAPTCHA appeared.

I completed it.

The verifier opened in a new tab.

A second CAPTCHA appeared.

By the time I returned to the alternative-method screen, the adult site said the verification session had expired.

I started again.

The connection was protected, but I was still being asked to expose the same passport details. I had also added another email login, another account record, and another security approval to an already sensitive task.

The larger service gave me more servers.

It did not help me disclose less.

That was the comparison I had missed at the beginning.

For this task, the useful VPN was not the one with the longest location list. It was the one that protected the session without demanding another identity-linked account along the way.

A short public privacy discussion captured the instinct behind that decision: an unexpected ID request made the user stop rather than upload first and investigate later.

I did the same.

Then I chose a different connection and a smaller proof.


The smaller app let me proceed without another identity account

I closed the established provider and opened OnlydogVPN, which I had installed as a travel backup.

The smaller app did not require an email-and-password registration before I could connect.

I selected the preset for a sensitive verification task on public Wi-Fi.

The adult site reopened.

So did the list of verification methods.

This time I chose the mobile-network check.

The verifier asked for my phone number and permission to confirm whether the mobile account was subject to an under-18 content restriction. It did not ask for my name, passport photograph, nationality, signature, or document number.

I approved the request on my phone.

The page changed to:

Age requirement met

The adult site received the result and opened the account dashboard.

The passport remained in my bag.

That was the result I had been looking for.

The site learned the one fact it needed.

It did not receive the collection of identity details printed inside my passport.

The smaller app had protected the verification without adding another conventional account to the chain. More importantly, its connection stayed open long enough for the mobile provider, verifier, and adult site to complete the same process.

The cancellation finally went through

I opened Billing.

The next renewal date appeared at the top of the page.

Thirty-one minutes remained.

I pressed Cancel subscription.

The site offered a discount.

I declined it.

It asked whether I wanted to pause the account instead.

I declined that too.

The final page displayed:

Your subscription will not renew.

A confirmation email arrived before I closed the tab.

The immediate problem was solved.

No additional charge would be taken.

No passport image had been uploaded simply to reach a cancellation button.

Only after the account was closed did I notice the smaller app’s blocked-request counter. It had stopped several advertising and tracking requests while I moved between the adult site, its billing page, and the verifier.

That did not interfere with the age check. The mobile-network confirmation still reached the site, and the cancellation still completed.

It removed background requests that had nothing to do with proving my age or closing the account.

For a session already involving an adult profile, a phone number, and payment settings, that was a useful second layer of restraint.

“ID deleted” should never be a vague promise

Photo ID may sometimes be the available verification method.

When it is, the important questions are practical:

Who receives the image?

Is the full document stored, or is it processed only long enough to return an age result?

How long is it retained?

Is the result linked to the adult-site account?

Can the data be reused for advertising or profiling?

Can the user request deletion?

Age assurance always involves some personal-data processing, but that does not make every method equally intrusive. UK regulators expect the collection to be necessary, proportionate, and transparent.

That is why a padlock icon is not enough.

Encryption protects the journey.

Data minimization limits what is waiting at the destination.

I could not observe every internal data flow used by the adult site, the mobile provider, the verification company, or either VPN application. I could compare what each option required from me.

The established provider protected the hotel connection but added another identity-linked login and did nothing to reduce the passport disclosure.

The smaller app connected without another conventional account, kept the lower-data verification path working, and reduced unrelated tracking requests around the session.

Sharing less mattered more than uploading faster

The smaller service has fewer server locations and a shorter public history than the established provider.

That matters when someone needs a particular exit city or prioritizes years of outside scrutiny.

It did not decide whether uploading my passport was safe.

The real choice was between two kinds of proof.

One method exposed the full identity document.

The other returned the only fact the adult website needed: that the age requirement had been met.

The VPN could not rewrite the verifier’s privacy policy, but it could avoid adding another identity account and keep the lower-data option alive until the cancellation was complete.

The safest passport upload that evening was the one I discovered I did not have to make.

Questions this experience may leave you with

What was actually causing the problem?

Only after the account was closed did I notice the smaller app’s blocked-request counter. It had stopped several advertising and tracking requests while I moved between the adult site, its billing page, and the verifier.

Why did the obvious fixes fail?

The adult site said that an external company performed the check. The verifier described security controls, but the first screen did not clearly say whether the passport image would be deleted immediately, retained for fraud prevention, or connected to my adult-site account.

What should you check first?

That did not interfere with the age check. The mobile-network confirmation still reached the site, and the cancellation still completed.

What finally changed the result?

I could not observe every internal data flow used by the adult site, the mobile provider, the verification company, or either VPN application. I could compare what each option required from me.

What is worth remembering?

The smaller app had protected the verification without adding another conventional account to the chain. More importantly, its connection stayed open long enough for the mobile provider, verifier, and adult site to complete the same process.