Privacy
Privacy notice (draft)
What is stored
- Registry records: public keys, registry-assigned ids, operator-chosen labels, owner type and class (self-declared), license claims, status, timestamps. The public registry shows no display names and no operator ids.
- Owner level evidence: a domain (only for non-individual owners), and for any future identity provider only the level, provider id and a hash of its receipt. Never documents, never biometrics.
- Self-declarations: only hashes (e.g. sha256 of a legal name) and jurisdiction; jurisdiction is not shown publicly for individuals.
- Decisions: each verify decision is recorded in hash-chained audit logs and as a signed stamp stored hash-only (request digests, not request bodies).
- Operational data: client IP addresses are used transiently for rate limiting (stored for minutes in a counter keyed by IP, then deleted). Hosting provider logs may exist under Cloudflare’s own terms.
What is not done
No advertising, no tracking cookies, no sale of data. The site console stores a sandbox token in your browser’s localStorage only. The page security policy blocks third-party scripts.
Permanence and erasure
Registry, audit and log records are append-only and cannot be erased (the database refuses deletes). That is why the service avoids personal data and asks you not to put any into labels. If personal data was submitted by mistake, the operator can freeze and label the record; full erasure rights and their interaction with an append-only log are an open question for counsel.
Processors
Cloudflare, Inc. (Workers, D1, KV hosting; United States, Western North America region for the database).
Retention
See retention policy.
Contact for this preview: a dedicated contact address will be published here before any public launch. Until then, use the channel through which you were invited.