playnet · privacy notice · terms of use ← back to the dial

Privacy Notice

Version 1.0.0 · effective 2026-08-01 · for the gateway operated by [operator not configured — see docs/legal/README.md]

This notice is written to be true rather than reassuring. playnet's record is cryptographically append-only: that is what makes it auditable, and it is also why several things you may expect from a privacy notice — a delete button, a guarantee that a record has gone everywhere it went — do not exist here. §5 states plainly what we can and cannot do, and what is being built to narrow the gap.

1. Who is responsible for your data

playnet is federated: anyone can run a gateway, and the software's authors run none of them. The controller of your personal data is the operator of the gateway you use — here, [operator not configured]. The authors of the software are not a controller and hold none of your data.

Contact for anything in this notice, including any request under §5: [operator contact not configured]. Postal address, where the operator has one: [not configured].

Other gateways are separate controllers. When credentials are shared across the federation, the receiving gateway determines its own purposes for them and answers for them itself. Where two gateways jointly decide how shared credentials are used, they are likely joint controllers under Article 26 GDPR, and each should tell you the essence of that arrangement. Ask us and we will tell you which gateways we federate with.

2. What data exists, and where

2.1 On this gateway

DataWhere it comes fromNotes
Your AID and its key event log — creation, key rotations, signatures, registration time Created in your browser when you sign up Published — see §4.1. Contains no name or contact detail.
Display name and email Only if you enter them in settings — both are optional and blank by default Name aids discovery; email enables notifications. Neither is used for account recovery.
The index from your AID to your name Derived, so the gateway can look you up This is the single record that turns a pseudonym back into a person. Its removal is the core of any erasure request (§5).
Notification bindings — email address, Telegram chat id, Matrix room, Reticulum/LXMF address, browser push subscription Only channels you connect Keyed by your AID, which joins them all together.
Presence — your display name against a live session While you are signed in Broadcast to other connected members.
Server logs Operation of the service Currently include usernames and AIDs. See §7 — this is a known defect being fixed.

2.2 Credentials — the substantive record

Most of what the system knows about you is held as signed credentials, stored by the hash of their contents and anchored in the issuing scope's key event log:

2.3 On your own device

3. Political opinions — special category data

How you vote is recorded against your identity, in signed form. Under Article 9 GDPR that is special-category data and needs a specific condition to process at all. The condition relied on is Article 9(2)(d): processing by a not-for-profit body with a political or philosophical aim, in the course of its legitimate activities, concerning its own members, with no disclosure outside the body without your consent.

What that means in practice, and its limits:

If you do not want a political opinion recorded against your identity, do not vote. Abstaining is the only complete protection we can honestly offer.

4. Who else receives it

4.1 Witnesses, and the public discovery endpoint

Every key event is broadcast to witnesses — independent machines run by other people, in jurisdictions we do not choose or know — which keep copies so that no single party, including us, can rewrite your key history. Your key event log is also served at this gateway's discovery endpoints, without authentication: anyone who knows your AID can fetch it. It contains your public keys, rotation history and timestamps; it does not contain your name or email.

Once a key event has been broadcast, it cannot be recalled. Verification of your signatures requires an unbroken sequence of key events, so events cannot be removed even locally without destroying the ability to check anything you signed afterwards. The timing and existence of your identity's events are therefore permanent. Requiring authentication on the discovery endpoint is planned and is anticipated by the KERI specification; it is not in place today.

4.2 Other gateways in the federation

Credentials are shared with federated gateways so that work, skills and personhood recognised in one commune are recognised in another. Those gateways are run by other people under their own notices and their own law.

4.3 Third-party services, only if you use them

ServiceWhat reaches itWhen
Web-push providers (Google, Mozilla, depending on your browser) Your push subscription endpoint and notification content Only if you enable browser notifications
TelegramYour chat id and notification content Only if you connect Telegram
Matrix homeserverYour room id and notification content Only if you connect Matrix
Email deliveryYour address and notification content Only if you give an email address
Reticulum / LXMF meshAn opaque cryptographic address Only if you use the mesh. Preferred: it carries no identifying address.

We do not sell your data, do not use it for advertising, and run no analytics or advertising trackers. We may disclose data where a valid legal order compels it, and will tell you unless we are prohibited from doing so.

5. Your rights — and exactly where they stop

You have the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent. Exercise any of them by writing to [operator contact not configured]. We answer within one month.

5.1 What we can do

5.2 What we cannot do

These are architectural limits, not policy choices, and we will not pretend otherwise.

5.3 What is being built

Stated so you can judge the gap rather than take a promise on trust:

5.4 Complaints

If you are in the EU or EEA you may complain to your national data protection authority (directory); the authority for this operator is [not configured]. Elsewhere, to your equivalent regulator. Please raise it with us first if you are willing.

6. Why we are allowed to process it

DataPurposeLegal basis
AID, key event log, authenticationProviding the service at all Contract — Art 6(1)(b)
Display name, notification bindingsDiscovery and notifying you Consent — Art 6(1)(a); both are optional and withdrawable
Work, claim and skill credentialsComputing the plan; recording contribution and entitlement within the communeContract — Art 6(1)(b), and the legitimate interest of the association in an auditable record — Art 6(1)(f)
Personhood and relationship credentialsKeeping out spam and vote-stuffing; resolving delegationLegitimate interest — Art 6(1)(f)
Stances and ballot snapshotsCounting votes and resolving delegated voice Art 6(1)(a) together with Art 9(2)(d) — see §3
Server logsSecurity and debuggingLegitimate interest — Art 6(1)(f)

Where we rely on consent you may withdraw it at any time, and where we rely on legitimate interest you may object; in both cases write to the contact in §1.

7. Retention

Stated honestly: no retention period is enforced today. Credential validity windows — a personhood credential's expiry, a skill's valid-until — govern whether a credential still counts, not whether it is still stored; a lapsed credential remains readable on disk. Server logs currently contain identifiers and have no rotation policy. Both are known defects. The intended position, and the one we are implementing, is: a retention sweep for all non-key-event stores, log rotation with identifiers stripped, and member data kept only while you participate.

8. Automated decisions

The planner computes allocations automatically — by convex optimization over recorded needs, capacities, limits and contributed labour — and those allocations affect what you can claim from the commons. We consider this not to be a decision "based solely on automated processing" within Article 22 GDPR, because the output is a proposal that the federation adopts, amends or rejects through its governance, in which you have a voice and a vote. Either way, you can ask a person to look at any allocation that affects you, express your point of view and contest it — through the governance process, or by writing to the contact in §1.

9. Security

No system is perfectly secure. If a breach is likely to put your rights at risk we will notify the supervisory authority and, where the risk is high, you.

10. International transfers

Witnesses and federated gateways are run by independent people in places we do not choose, and mesh transport routes wherever the mesh routes. Publishing to them is inherent to how the system resists tampering, and by participating you are asking for your key events to be witnessed in exactly this way. No standard contractual clauses or other transfer mechanism are in place for these flows. If that is unacceptable to you, this system is not suitable for you — we would rather say so than bury it.

11. Children

This service is not intended for children below the age given in §8 of the terms. If you believe a child has created an identity here, write to [operator contact not configured] and we will remove the member record — subject to the limits in §5.2.

12. Cookies

No advertising, analytics or third-party tracking cookies are used. The page keeps a small amount of data in your browser's own storage — your sign-in hint, your keys, and your interface preferences — all of which stays on your device.

13. Changes to this notice

Material changes are published here with a new version number and effective date, and you will be asked to acknowledge them the next time you sign in.