Version 1.0.0 · effective 2026-08-01 · for the gateway operated by [operator not configured — see docs/legal/README.md]
playnet is federated: anyone can run a gateway, and the software's authors run none of them. The controller of your personal data is the operator of the gateway you use — here, [operator not configured]. The authors of the software are not a controller and hold none of your data.
Contact for anything in this notice, including any request under §5: [operator contact not configured]. Postal address, where the operator has one: [not configured].
| Data | Where it comes from | Notes |
|---|---|---|
| Your AID and its key event log — creation, key rotations, signatures, registration time | Created in your browser when you sign up | Published — see §4.1. Contains no name or contact detail. |
| Display name and email | Only if you enter them in settings — both are optional and blank by default | Name aids discovery; email enables notifications. Neither is used for account recovery. |
| The index from your AID to your name | Derived, so the gateway can look you up | This is the single record that turns a pseudonym back into a person. Its removal is the core of any erasure request (§5). |
| Notification bindings — email address, Telegram chat id, Matrix room, Reticulum/LXMF address, browser push subscription | Only channels you connect | Keyed by your AID, which joins them all together. |
| Presence — your display name against a live session | While you are signed in | Broadcast to other connected members. |
| Server logs | Operation of the service | Currently include usernames and AIDs. See §7 — this is a known defect being fixed. |
Most of what the system knows about you is held as signed credentials, stored by the hash of their contents and anchored in the issuing scope's key event log:
How you vote is recorded against your identity, in signed form. Under Article 9 GDPR that is special-category data and needs a specific condition to process at all. The condition relied on is Article 9(2)(d): processing by a not-for-profit body with a political or philosophical aim, in the course of its legitimate activities, concerning its own members, with no disclosure outside the body without your consent.
What that means in practice, and its limits:
If you do not want a political opinion recorded against your identity, do not vote. Abstaining is the only complete protection we can honestly offer.
Every key event is broadcast to witnesses — independent machines run by other people, in jurisdictions we do not choose or know — which keep copies so that no single party, including us, can rewrite your key history. Your key event log is also served at this gateway's discovery endpoints, without authentication: anyone who knows your AID can fetch it. It contains your public keys, rotation history and timestamps; it does not contain your name or email.
Credentials are shared with federated gateways so that work, skills and personhood recognised in one commune are recognised in another. Those gateways are run by other people under their own notices and their own law.
| Service | What reaches it | When |
|---|---|---|
| Web-push providers (Google, Mozilla, depending on your browser) | Your push subscription endpoint and notification content | Only if you enable browser notifications |
| Telegram | Your chat id and notification content | Only if you connect Telegram |
| Matrix homeserver | Your room id and notification content | Only if you connect Matrix |
| Email delivery | Your address and notification content | Only if you give an email address |
| Reticulum / LXMF mesh | An opaque cryptographic address | Only if you use the mesh. Preferred: it carries no identifying address. |
We do not sell your data, do not use it for advertising, and run no analytics or advertising trackers. We may disclose data where a valid legal order compels it, and will tell you unless we are prohibited from doing so.
You have the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent. Exercise any of them by writing to [operator contact not configured]. We answer within one month.
Stated so you can judge the gap rather than take a promise on trust:
If you are in the EU or EEA you may complain to your national data protection authority (directory); the authority for this operator is [not configured]. Elsewhere, to your equivalent regulator. Please raise it with us first if you are willing.
| Data | Purpose | Legal basis |
|---|---|---|
| AID, key event log, authentication | Providing the service at all | Contract — Art 6(1)(b) |
| Display name, notification bindings | Discovery and notifying you | Consent — Art 6(1)(a); both are optional and withdrawable |
| Work, claim and skill credentials | Computing the plan; recording contribution and entitlement within the commune | Contract — Art 6(1)(b), and the legitimate interest of the association in an auditable record — Art 6(1)(f) |
| Personhood and relationship credentials | Keeping out spam and vote-stuffing; resolving delegation | Legitimate interest — Art 6(1)(f) |
| Stances and ballot snapshots | Counting votes and resolving delegated voice | Art 6(1)(a) together with Art 9(2)(d) — see §3 |
| Server logs | Security and debugging | Legitimate interest — Art 6(1)(f) |
Where we rely on consent you may withdraw it at any time, and where we rely on legitimate interest you may object; in both cases write to the contact in §1.
Stated honestly: no retention period is enforced today. Credential validity windows — a personhood credential's expiry, a skill's valid-until — govern whether a credential still counts, not whether it is still stored; a lapsed credential remains readable on disk. Server logs currently contain identifiers and have no rotation policy. Both are known defects. The intended position, and the one we are implementing, is: a retention sweep for all non-key-event stores, log rotation with identifiers stripped, and member data kept only while you participate.
The planner computes allocations automatically — by convex optimization over recorded needs, capacities, limits and contributed labour — and those allocations affect what you can claim from the commons. We consider this not to be a decision "based solely on automated processing" within Article 22 GDPR, because the output is a proposal that the federation adopts, amends or rejects through its governance, in which you have a voice and a vote. Either way, you can ask a person to look at any allocation that affects you, express your point of view and contest it — through the governance process, or by writing to the contact in §1.
No system is perfectly secure. If a breach is likely to put your rights at risk we will notify the supervisory authority and, where the risk is high, you.
Witnesses and federated gateways are run by independent people in places we do not choose, and mesh transport routes wherever the mesh routes. Publishing to them is inherent to how the system resists tampering, and by participating you are asking for your key events to be witnessed in exactly this way. No standard contractual clauses or other transfer mechanism are in place for these flows. If that is unacceptable to you, this system is not suitable for you — we would rather say so than bury it.
This service is not intended for children below the age given in §8 of the terms. If you believe a child has created an identity here, write to [operator contact not configured] and we will remove the member record — subject to the limits in §5.2.
No advertising, analytics or third-party tracking cookies are used. The page keeps a small amount of data in your browser's own storage — your sign-in hint, your keys, and your interface preferences — all of which stays on your device.
Material changes are published here with a new version number and effective date, and you will be asked to acknowledge them the next time you sign in.