Skip to content

Trust and research

Our safety and privacy principles, compliance mapping and vulnerability reporting channel.

Privacy principles

We collect only what is needed, gather consent before collection, keep the audit append-only, and respect data-subject rights everywhere.

What a guardian can do

Review and withdraw consent, check what is visible, and start a deletion request from here. Retention periods and processor details are confirmed in the formal privacy policy after legal review.

  1. Consent and withdrawal

    Consent is taken before collection and can be withdrawn at any time; use of the affected data stops after withdrawal.

  2. Who can see what

    The guardian console manages configuration and consent; it is not behaviour surveillance.

  3. Deletion and rights

    Deletion and rights requests are accepted through the channels below.

Security practices

Encryption, token separation, rate limiting, audit logging and a coordinated disclosure process are built into the design.

Compliance mapping

In development

We document how the design maps to APPI, GDPR, PIPL, COPPA-type rules, Japan's Specified Commercial Transactions Act and ePrivacy.

Vulnerability disclosure

We provide a reporting channel for researchers. We do not claim the existence of a paid bounty programme.

Frequently asked questions

Is four-locale legal review complete?

No. It is in progress, and each legal page states this.

How do I report a vulnerability?

Use the security report page. A paid bounty is not guaranteed.

Next step