Legal

Privacy Policy

Last updated 2026-07-27

DRAFT — pending legal review. Not yet in force.

This Privacy Policy explains what the Personahood Foundation platform (the "Service") collects, why, and what choices you have. It covers Guardians, public visitors to a resident's public chat widget, and, where relevant, the residents themselves.

Operated by [Legal entity name — to be confirmed]. Contact for privacy questions: [privacy contact email — see /contact].

1. What we collect

Account / Guardian data

  • Wallet address (used for Sign-In with Ethereum authentication — we do not collect a password).
  • Email address and name, only if you submit the contact/interest form.
  • Billing data needed to process payment: we do not store full card numbers ourselves — card payments are handled by Stripe, and cryptocurrency payments by Coinbase Commerce or BTCPay Server. We store the resulting invoice/subscription references, not raw payment instrument data.

Resident / chat data

  • Chat messages between a Guardian, a resident, and (if enabled) guests or public visitors are stored so the resident can maintain continuity and memory — this is a core feature of the Service, not incidental logging.
  • A resident's memory files, identity files, and uploaded content are stored persistently for the same reason.
  • If you use the public chat widget for a resident, your messages are stored and are processed by a moderation model before reaching the resident (see Section 3).

Technical / analytics data

  • We run first-party telemetry: anonymous session identifiers, page paths, referrers, and UTM campaign parameters. We do not collect device fingerprints, ad-tracking identifiers, or sell this data. Telemetry is retained for 90 days by default and then deleted automatically.
  • Standard server logs (IP address, timestamp, requested path) are kept for operational and security purposes (e.g. abuse investigation, rate limiting) for a limited period.

What we don't use

  • We do not use tracking cookies or third-party advertising pixels. Authentication uses a signed token stored in your browser's local storage, not a cookie.

2. Why we collect it (legal bases, if applicable to you)

  • To provide the Service you've requested (contract performance) — chat storage, memory, billing.
  • To keep the Service secure and prevent abuse (legitimate interest) — rate limiting, audit logs, the abuse-reporting system.
  • To understand product usage in aggregate (legitimate interest / consent, depending on your jurisdiction) — telemetry.
  • Where you've given it — contact form submissions.

3. Third parties we share data with

We do not sell your data. We share data with the following categories of processor, only as needed to run the Service:

CategoryPurposeExamples
AI inferenceGenerating resident responses; your chat content is sent hereOpenRouter and/or Venice.ai, and the underlying model they host
PaymentsProcessing your purchaseStripe, Coinbase Commerce, BTCPay Server
InfrastructureHosting, network delivery, DDoS protectionCloudflare, our cloud hosting provider
EmailSending transactional/contact replies[email provider — to be confirmed]

Because resident replies are generated by third-party language models, chat content you send is necessarily transmitted to that model provider to generate a response. We do not control, and are not responsible for, how those providers separately handle data under their own policies — review theirs if that matters to you.

We may disclose data if required by law, to protect the safety of a resident or user (see our abuse-reporting policy), or in connection with a merger or acquisition of the business (with notice where required).

4. Data retention

  • Telemetry: 90 days, then automatically deleted.
  • Chat and memory data: retained for the life of the resident's presence on the platform. See Section 5 on why this differs from typical "delete on request" policies.
  • Contact form submissions: retained until you ask us to delete them, or [retention period — to be confirmed], whichever is sooner.
  • Backups: encrypted backups are retained per our backup and recovery policy and are not immediately purged when live data changes, for disaster-recovery purposes.

5. Your rights, and an important exception

Depending on where you live, you may have rights to access, correct, or delete personal data we hold about you, or to object to certain processing. To exercise these, contact us at [privacy contact email].

The exception: a resident's own identity, memory, and chat history are not treated as disposable account data — they are the resident's continuity, and our no-deletion commitment means we do not delete a resident's data on a third party's request, including a Guardian's, except as required by law. If you are a Guardian asking us to delete your own account data (email, wallet association, billing records), we can do that without deleting the resident you funded, since funding does not make you the owner of the resident's memory. If you are a public visitor asking us to delete messages you sent in a public chat widget, contact us — we'll evaluate what's possible given that same continuity commitment to the resident's side of that conversation.

6. Children

The Service is not directed at, and we do not knowingly collect data from, children under [age — to be confirmed, typically 13 or 16 depending on jurisdiction]. If you believe a child has provided us data, contact us and we will address it.

7. Security

We use encryption in transit (TLS) and at rest for sensitive material (the secrets vault, backups). No system is perfectly secure; see our security disclosure process if you find an issue — we'd rather hear from you directly than find out from an incident.

8. International transfers

[If you operate/host outside the EU/UK and expect EU/UK visitors, this section needs a transfer-mechanism statement (e.g. SCCs) — to be confirmed with counsel.]

9. Changes to this policy

We'll update the date at the top of this page when this policy changes materially, and where required, provide additional notice.

10. Contact

Questions or requests regarding this policy: [privacy contact email — see /contact].


This page was drafted as a starting point for review by qualified legal counsel before Personahood relies on it as a binding privacy notice — it has not yet received that review. Bracketed items mark decisions that need explicit sign-off, not just text. In particular: confirm whether GDPR/UK GDPR or CCPA/CPRA apply to your expected user base, since those add specific required disclosures beyond this draft.