Privacy Policy

Draft v1.0 · Effective 2026-07-13 · Living instrument

Version: 1.0 (Draft)

Effective Date: 2026-07-13

Status: LIVING INSTRUMENT — Draft v1.0 (doctrine estate)

Assigned Guardian: Soul 11 – Legal Guardian

Authorizing: Vayati Constellation – Legal Doctrine v0.1; Multi-Realm Authentication & Teleportation Doctrine; Future-Proof Neuralink Integration Architecture; Wallet, Fuel & Economy Doctrine; Relics – Provenance Key Doctrine; Capstone – Risk Management; sources/legal2-in.txt — legal-privacy-policy-v1 (2026-07-13).

1. Introduction

Vayati respects your privacy. This Policy describes what we collect, why we collect it, how we use and share it, and your rights. It applies across all constellation realms: Auth (authoritative identity), Haven, JCastaway Vault, Weave Hub, and Inscribe.

We do not sell your personal data.

2. Principles

3. What We Collect

3.1 Account and Identity (Auth / Haven — authoritative)

3.2 Relic and Provenance Data (Vault / Auth)

3.3 Quest and Gameplay (Vault)

3.4 Weave and Discovery (Weave Hub / Vault index)

3.5 Neuralink Phase 1 (Soul 12 coordination)

3.6 Technical and Security

3.7 Ordinals-Related (Soul 10 — where applicable)

4. Why We Collect It

Purpose · Examples

Operate the platform · Authentication, cross-realm teleport, relic display

Moderation and safety · Quarantine, image_hash, audit trails

Provenance and legacy · Relic bonding, generational chronicle

Cross-realm continuity · JWT handoff, IC balance, quest persistence

Improve discovery · Weave index, excerpts, thread enrichment

Legal compliance · DMCA, law enforcement requests, dispute records

Future Neuralink readiness · Intent abstraction with explicit consent

5. How We Share Data

5.1 Internal Cross-Realm

Auth is the system of record for identity and IC. Vault and Weave Hub consume scoped claims via JWT — not independent identity stores.

5.2 Service Processors

We use trusted processors for infrastructure, including:

Processors are bound by contractual obligations consistent with this Policy.

5.3 We Do Not Sell Personal Data

Vayati does not sell, rent, or trade your personal information to third parties for their marketing purposes.

5.4 Legal Disclosures

We may disclose information when required by law, to protect safety, to enforce the AUP, or in response to valid legal process.

6. Retention

Data Type · Retention Approach

Active account data · While account is active + reasonable backup period

Quarantined content · Retained for review, audit, and legal defensibility

image_hash · Retained for re-validation and hidden-comms resistance

Audit logs (relic_actions, content_upload_events) · Per moderation and security doctrine requirements

Deleted account data · Removed from active systems; backups purged on cycle

7. Your Rights

Depending on your jurisdiction, you may have rights to:

GDPR (EEA/UK users): Legal basis includes contract performance, legitimate interests (moderation, security), and consent where required (e.g., Neuralink Specials flags).

CCPA (California users): Right to know, delete, and opt out of sale — we do not sell personal data.

Contact for requests: privacy@vayati.com (placeholder — Keeper to confirm)

We will respond within timeframes required by applicable law.

8. Cross-Realm JWT Handoff

When you move between realms (Haven → Weave Hub → Vault), authentication tokens carry scoped identity claims. Tokens are short-lived (24h standard per auth hardening). We do not expose full account databases across realm boundaries.

See Multi-Realm Authentication & Teleportation Doctrine for technical architecture.

9. Children

[Keeper to set age threshold.] The platform is not directed at children under 13 (or applicable local age) without verifiable parental consent. If we learn we have collected data from a child without proper consent, we will delete it promptly.

10. International Users

Vayati may be accessed globally. By using the platform, you consent to processing in jurisdictions where our infrastructure operates, with safeguards consistent with this Policy.

11. Security

Soul 02 implements technical controls: JWT lifecycle, ModSecurity WAF, pre-upload scanning, rate limiting, and audit logging. No system is perfectly secure; report concerns to security@vayati.com (placeholder).

12. Versioning and Notice

Current version: 1.0 (2026-07-13)

Material changes require 14–30 days advance notice where practicable. Major revisions require Keeper decree per Capstone – Governance.

13. Related Policies

End of Privacy Policy v1.0