Trust and research
Our safety and privacy principles, compliance mapping and vulnerability reporting channel.
Privacy principles
We collect only what is needed, gather consent before collection, keep the audit append-only, and respect data-subject rights everywhere.
What a guardian can do
Review and withdraw consent, check what is visible, and start a deletion request from here. Retention periods and processor details are confirmed in the formal privacy policy after legal review.
- Consent and withdrawal
Consent is taken before collection and can be withdrawn at any time; use of the affected data stops after withdrawal.
- Who can see what
The guardian console manages configuration and consent; it is not behaviour surveillance.
- Deletion and rights
Deletion and rights requests are accepted through the channels below.
Security practices
Encryption, token separation, rate limiting, audit logging and a coordinated disclosure process are built into the design.
Compliance mapping
In developmentWe document how the design maps to APPI, GDPR, PIPL, COPPA-type rules, Japan's Specified Commercial Transactions Act and ePrivacy.
Vulnerability disclosure
We provide a reporting channel for researchers. We do not claim the existence of a paid bounty programme.
Frequently asked questions
Is four-locale legal review complete?
No. It is in progress, and each legal page states this.
How do I report a vulnerability?
Use the security report page. A paid bounty is not guaranteed.