Privacy and data control

Your information. Defined access. Visible consequences.

This page separates the Self-Sovereign Civic Profile architecture from the contact information submitted through today's website. Identity connections and Civic Mission processing are under development; this site currently accepts founding registrations, research inquiries and contact messages.

Before any mission begins, its actual access, processing, retention and withdrawal terms must be disclosed. This architecture description is not a substitute for those mission-specific terms.

Self-Sovereign Identity

The participant controls the VerusID and associated civic profile used by compatible applications. Civic Ledger is an interface to that identity rather than its owner or identity provider.

Participant Key Control

The participant controls the relevant encryption and decryption authority. Participation should never require handing Civic Ledger the master private key controlling the VerusID. Do not send private keys or recovery information through a contact or registration form.

Application Permissions

An application receives the fields and capabilities the participant authorizes for an interaction. Connecting an identity, registering interest and authorizing a research mission are distinct actions.

Mission-Specific Decryption

Civic Ledger may receive mission-scoped decryption capability only when the participant authorizes a mission requiring readable data. The mission must identify the requested information, purpose, processing and duration of access.

Portable Profile

The participant can choose to bring compatible profile information into another application. Portability depends on supported data types and participant permission, not on Civic Ledger owning the profile.

Checks and Balances Attestation

The Checks and Balances Human Verification Protocol provides community-attested proof appropriate to the interaction. Civic Ledger verifies the relevant attestation; it does not own the underlying credential. Each mission must disclose its verification requirements.

Civic Pulse Processing

Only authorized mission information may enter the agreed analysis. The sponsor receives the defined research product rather than automatic access to the underlying identifiable profile. Human-confirmed responses and participant-authorized agent executions must remain distinguishable.

De-identification and Aggregation

Each mission must describe data minimization, mixing, aggregation, de-identification and privacy thresholds appropriate to its outputs. Small or identifying groups may require suppression. These methods and their limits belong in the published methodology; aggregation alone is not a guarantee against re-identification.

Retention

Mission terms must disclose retention periods, aggregation cut-offs, deletion rules and completed-report treatment before access is authorized. This website does not publish a universal retention period for future missions.

Today's registration, inquiry and contact forms store the details submitted to the service and queue a team notification and a submitter acknowledgment. Those operational records are separate from the proposed self-sovereign profile. The current form service does not provide an automatic deletion schedule or self-service deletion mechanism.

Withdrawal

Ending future access or a standing instruction stops future authority within the applicable terms. It does not cryptographically erase information already legitimately decrypted. A mission must explain the withdrawal deadline and what can still be removed at each stage.

For questions about information already submitted through the website, contact Civic Ledger. Do not include additional sensitive records in the request.

Completed Research Outputs

Data already incorporated into a completed aggregate product may not be removable by revoking future access. Each mission must explain those consequences and the treatment of published or delivered reports before participation begins.

Blockchain Records

Any workflow that writes to a public or persistent ledger must disclose exactly what will be recorded and the limits of later correction or removal. Private profile information should not be treated as public merely because a participant uses a blockchain identity. The current website forms do not write submissions to a blockchain.

Cross-Application Sharing

A common VerusID does not grant Civic Ledger, Rate My Representatives or any other application automatic access to private fields. Participants choose the receiving application, compatible information and scope of permission.

Website preferences and external resources

The theme control stores the selected light or dark appearance in your browser. The site also requests its fonts from Google Fonts. These website functions are separate from identity ownership and mission authorization.

Read the trust architecture · Review the participant agreement framework