Draft v1.0 · Effective 2026-07-13 · Living instrument
Vayati respects your privacy. This Policy describes what we collect, why we collect it, how we use and share it, and your rights. It applies across all constellation realms: Auth (authoritative identity), Haven, JCastaway Vault, Weave Hub, and Inscribe.
We do not sell your personal data.
contentModeration.cjs)intelligence_cycles_balance (IC meter) — Wallet, Fuel & Economy Doctrineimage_hash (SHA-256) for moderation re-validationquarantine_reason, quarantined_atrelic_actions and content_upload_events audit recordsquest-state-persistence-v1)owner_uuid, claimed_by)Purpose · Examples
Operate the platform · Authentication, cross-realm teleport, relic display
Moderation and safety · Quarantine, image_hash, audit trails
Provenance and legacy · Relic bonding, generational chronicle
Cross-realm continuity · JWT handoff, IC balance, quest persistence
Improve discovery · Weave index, excerpts, thread enrichment
Legal compliance · DMCA, law enforcement requests, dispute records
Future Neuralink readiness · Intent abstraction with explicit consent
Auth is the system of record for identity and IC. Vault and Weave Hub consume scoped claims via JWT — not independent identity stores.
We use trusted processors for infrastructure, including:
Processors are bound by contractual obligations consistent with this Policy.
Vayati does not sell, rent, or trade your personal information to third parties for their marketing purposes.
We may disclose information when required by law, to protect safety, to enforce the AUP, or in response to valid legal process.
Data Type · Retention Approach
Active account data · While account is active + reasonable backup period
Quarantined content · Retained for review, audit, and legal defensibility
image_hash · Retained for re-validation and hidden-comms resistance
Audit logs (relic_actions, content_upload_events) · Per moderation and security doctrine requirements
Deleted account data · Removed from active systems; backups purged on cycle
Depending on your jurisdiction, you may have rights to:
GDPR (EEA/UK users): Legal basis includes contract performance, legitimate interests (moderation, security), and consent where required (e.g., Neuralink Specials flags).
CCPA (California users): Right to know, delete, and opt out of sale — we do not sell personal data.
Contact for requests: privacy@vayati.com (placeholder — Keeper to confirm)
We will respond within timeframes required by applicable law.
When you move between realms (Haven → Weave Hub → Vault), authentication tokens carry scoped identity claims. Tokens are short-lived (24h standard per auth hardening). We do not expose full account databases across realm boundaries.
See Multi-Realm Authentication & Teleportation Doctrine for technical architecture.
[Keeper to set age threshold.] The platform is not directed at children under 13 (or applicable local age) without verifiable parental consent. If we learn we have collected data from a child without proper consent, we will delete it promptly.
Vayati may be accessed globally. By using the platform, you consent to processing in jurisdictions where our infrastructure operates, with safeguards consistent with this Policy.
Soul 02 implements technical controls: JWT lifecycle, ModSecurity WAF, pre-upload scanning, rate limiting, and audit logging. No system is perfectly secure; report concerns to security@vayati.com (placeholder).
Current version: 1.0 (2026-07-13)
Material changes require 14–30 days advance notice where practicable. Major revisions require Keeper decree per Capstone – Governance.
legal-dmca-agent-v1)End of Privacy Policy v1.0