/** doctrines/Vayati Constellation - Privacy Policy.txt **/ Vayati Constellation – Privacy Policy Version: 1.0 (Draft) Effective Date: 2026-07-13 Status: LIVING INSTRUMENT — Draft v1.0 (doctrine estate) Assigned Guardian: Soul 11 – Legal Guardian Authorizing: Vayati Constellation – Legal Doctrine v0.1; Multi-Realm Authentication & Teleportation Doctrine; Future-Proof Neuralink Integration Architecture; Wallet, Fuel & Economy Doctrine; Relics – Provenance Key Doctrine; Capstone – Risk Management; sources/legal2-in.txt — legal-privacy-policy-v1 (2026-07-13). --- ## 1. Introduction Vayati respects your privacy. This Policy describes what we collect, why we collect it, how we use and share it, and your rights. It applies across all constellation realms: Auth (authoritative identity), Haven, JCastaway Vault, Weave Hub, and Inscribe. **We do not sell your personal data.** --- ## 2. Principles - **Data minimization** — collect only what operation, moderation, and provenance require - **Purpose limitation** — use data only for stated purposes - **Cross-realm continuity** — Auth is system-of-record for identity; other realms consume scoped data via JWT - **Security by design** — Soul 02 technical controls; Soul 11 contractual instruments --- ## 3. What We Collect ### 3.1 Account and Identity (Auth / Haven — authoritative) - Email, display name, OAuth provider identifiers - JWT session tokens and refresh metadata - Character UUID, soul/character profile fields - Avatar and character images (uploaded via `contentModeration.cjs`) - Stripe payment metadata (if applicable) — processed per Stripe's policies - `intelligence_cycles_balance` (IC meter) — Wallet, Fuel & Economy Doctrine ### 3.2 Relic and Provenance Data (Vault / Auth) - Relic images: full, extra, certificate, veiled-tag variants - Relic metadata, provenance keys, tier and chronicle fields - `image_hash` (SHA-256) for moderation re-validation - Quarantine status, `quarantine_reason`, `quarantined_at` - `relic_actions` and `content_upload_events` audit records ### 3.3 Quest and Gameplay (Vault) - Quest progress and state (`quest-state-persistence-v1`) - Inventory and game-object bonding - Player profile and plot ownership (`owner_uuid`, `claimed_by`) - Presence and session events where logged ### 3.4 Weave and Discovery (Weave Hub / Vault index) - Public weave index data: excerpts, thread metadata, thumbnails - Filter preferences (localStorage on client) - Guest session and conversion events - Weave thread content and linking data ### 3.5 Neuralink Phase 1 (Soul 12 coordination) - Intent abstraction claims and resolution metadata - Specials consent flags — **immutable once set to true** (Umbrella Security GAP-08) - Command-bar intent targets (Inspectspot, key usage, etc.) ### 3.6 Technical and Security - IP addresses, user agents, rate-limit counters - ModSecurity / WAF logs (aggregated) - Error and audit logs for authentication and moderation events ### 3.7 Ordinals-Related (Soul 10 — where applicable) - Inscription request metadata - Wallet addresses associated with inscription flows (not platform sale of data) --- ## 4. Why We Collect It | Purpose | Examples | |---------|----------| | Operate the platform | Authentication, cross-realm teleport, relic display | | Moderation and safety | Quarantine, `image_hash`, audit trails | | Provenance and legacy | Relic bonding, generational chronicle | | Cross-realm continuity | JWT handoff, IC balance, quest persistence | | Improve discovery | Weave index, excerpts, thread enrichment | | Legal compliance | DMCA, law enforcement requests, dispute records | | Future Neuralink readiness | Intent abstraction with explicit consent | --- ## 5. How We Share Data ### 5.1 Internal Cross-Realm Auth is the **system of record** for identity and IC. Vault and Weave Hub consume scoped claims via JWT — not independent identity stores. ### 5.2 Service Processors We use trusted processors for infrastructure, including: - **OVH / S3-compatible storage** — relic and character media - **Stripe** — payment processing (if applicable) - **OAuth providers** — authentication (Google, X/Twitter, etc.) Processors are bound by contractual obligations consistent with this Policy. ### 5.3 We Do Not Sell Personal Data Vayati does not sell, rent, or trade your personal information to third parties for their marketing purposes. ### 5.4 Legal Disclosures We may disclose information when required by law, to protect safety, to enforce the AUP, or in response to valid legal process. --- ## 6. Retention | Data Type | Retention Approach | |-----------|-------------------| | Active account data | While account is active + reasonable backup period | | Quarantined content | Retained for review, audit, and legal defensibility | | `image_hash` | Retained for re-validation and hidden-comms resistance | | Audit logs (`relic_actions`, `content_upload_events`) | Per moderation and security doctrine requirements | | Deleted account data | Removed from active systems; backups purged on cycle | --- ## 7. Your Rights Depending on your jurisdiction, you may have rights to: - **Access** — request a copy of personal data we hold - **Correction** — request correction of inaccurate data - **Deletion** — request deletion where applicable (subject to legal retention) - **Portability** — receive data in a structured format where feasible - **Objection / restriction** — object to certain processing where applicable **GDPR (EEA/UK users):** Legal basis includes contract performance, legitimate interests (moderation, security), and consent where required (e.g., Neuralink Specials flags). **CCPA (California users):** Right to know, delete, and opt out of sale — we do not sell personal data. **Contact for requests:** privacy@vayati.com (placeholder — Keeper to confirm) We will respond within timeframes required by applicable law. --- ## 8. Cross-Realm JWT Handoff When you move between realms (Haven → Weave Hub → Vault), authentication tokens carry scoped identity claims. Tokens are short-lived (24h standard per auth hardening). We do not expose full account databases across realm boundaries. See Multi-Realm Authentication & Teleportation Doctrine for technical architecture. --- ## 9. Children **[Keeper to set age threshold.]** The platform is not directed at children under 13 (or applicable local age) without verifiable parental consent. If we learn we have collected data from a child without proper consent, we will delete it promptly. --- ## 10. International Users Vayati may be accessed globally. By using the platform, you consent to processing in jurisdictions where our infrastructure operates, with safeguards consistent with this Policy. --- ## 11. Security Soul 02 implements technical controls: JWT lifecycle, ModSecurity WAF, pre-upload scanning, rate limiting, and audit logging. No system is perfectly secure; report concerns to security@vayati.com (placeholder). --- ## 12. Versioning and Notice **Current version:** 1.0 (2026-07-13) Material changes require **14–30 days advance notice** where practicable. Major revisions require Keeper decree per Capstone – Governance. --- ## 13. Related Policies - Vayati Constellation – Terms of Service - Vayati Constellation – Acceptable Use Policy - Vayati Constellation – Legal Doctrine v0.1 - Vayati Constellation – DMCA Agent and Takedown Process v1.0 --- **End of Privacy Policy v1.0** ### Friends Graph Data (Light Confirm — 2026-07-27) **Package:** `composer-doctrine-session-closeout-haven-personal-hub-friends-2026-07-27-v1` Friendships and blocks are **soul-keyed** (`auth_user.id`). Rate limits apply on friend requests. There is **no** public friend directory and **no** who-blocked-me directory. Presence signals are minimal (online/offline/unknown; optional realm when already available). Soft limits: no private notes UI in Friends v1. Authorizing: sources/friends.txt (2026-07-27); Multi-Realm Auth §13.