docs/privacy.mdpinned to impactium@637886d

Privacy

Impactium is built on radical transparency — "you cannot hide -$IMP." But transparency about impact is not the same as exposure of personal data, and Impactium draws that line deliberately. This page describes how privacy works, and is honest about what is built today versus what is committed for the future.

The line: existence and NET are public; detail is gated

The transparency guarantee is precise. What is always public:

  • that an Entity, claim, or capsule exists, and
  • an Entity's NET impact position — including a negative one. Nobody can hide that they hold impact, or that they carry a negative net.

What is access-gated by the viewer's relationship to the subject (the COA context layers — self → team → org → public): the granular specifics — descriptions, evidence, amounts, and personal context. A parent in the lineage can see a child's detail; peers see aggregates; the public sees existence and NET.

So the honest one-liner: you cannot hide that you made an impact, or your standing — only the private specifics behind it are gated.

Impact domains change the rules

The public/private line is not uniform across all impact. Impact is recorded across six impact domains — Environmental, Social, Economic, Personal, Freedom, and Epistemic — and each domain carries its own disclosure rule. Environmental impact is required to be public — the harm or benefit to the shared world cannot be hidden — while Personal and the others are gated by your relationship to the subject. A single record is multi-domain: minting captures all the impact an action created, decomposed across every domain it touched, and each domain's slice follows that domain's rule. This is how Impactium keeps the right things transparent (the shared world) while protecting the personal — and the per-domain policy is governed and versioned, so it evolves deliberately rather than by decree.

(This is distinct from scope — inward vs. outward — which is about whether an impact affects the self or society. A domain is the category of impact; scope is its direction.)

Your data stays yours: off-chain personal data, on-chain proof

This is the core of the model, and it resolves the hardest tension — a permanent chain (never pruned, never reset) versus the right to control and delete personal data.

The permanent record holds proof of impact, never the personal data itself. On chain: entity ids, content hashes, impact figures, and attestations. Off chain (in your wallet or a permissioned store): the raw descriptions, evidence bodies, and personal context — which you can delete or access-control without ever touching the permanent record.

Permanence applies to the impact record, not to your personal data.

This isn't bolted on: impact claims already anchor their evidence as a cryptographic hash, not by storing the evidence on chain. The model generalizes a pattern the system was already built around.

No personal data on chain — by policy

Because the chain is permanent and transparent to its operators, the only safe assumption is that every on-chain field is a permanent, public publication — so personal data does not go there at all. As a matter of policy, the chain never carries emails, phone numbers, handles, IP or device fingerprints, biometrics, or human-readable referral strings. On-chain identifiers are opaque — entity ids derived from public keys, and content hashes — never values that resolve to a person on their own. Anti-abuse and anti-sybil heuristics, which by nature touch signals like network or device data, stay off chain under retention limits and never settle into the permanent record.

This is data minimization taken literally, and it is the posture current data-protection guidance points to for immutable ledgers: keep personal data off the chain, and make on-chain identifiers pseudonymous by construction. The permanent record holds impact and proof; nothing on it should make honoring a person's control over their own personal data impossible.

Openness is your choice — and it's rewarded

You decide how much to disclose when you mint. Impactium does not force maximal transparency of your specifics; it incentivizes it: the more open the impact you mint, the more 0BONUS it earns. Openness that helps others verify, learn from, and build on your work is worth more — so transparency is a rewarded choice, not a mandate. Privacy is a dial you hold, with an honest economic signal attached to it.

Identity verification, without surrendering your identity

When the network opens to the public, identity verification becomes mandatory (see the Roadmap). It is designed so that verifying who you are does not mean publishing who you are: a verification authority holds your identity documents off chain, and the chain carries only an attestation — that you are verified, at what level, by whom, and when. The documents never touch the permanent record.

Keys are yours alone

Your keys are your on-chain identity, and they never leave your device unencrypted. The wallet derives them from your recovery phrase and encrypts them at rest, so a wrong password fails rather than leaks. You can hold and act as many identities — personal, organizational, agent — from one secured keyring.

Honest status: today vs. committed

Impactium is pre-genesis, and this page describes a model partway built. Being straight about it:

  • Today, on a closed, vetted network: visibility is enforced server-side by the public ledger (Karma) per consumer, sensitive data is kept off chain, and keys are encrypted client-side. The chain's on-chain data is transparent to its (known, vetted) node operators — it is not yet cryptographic privacy.
  • Committed before genesis: a fully secure end-to-end experience and on-chain encryption with selective disclosure are a requirement before the genesis compaction on the live network — not an open-ended someday. Zero-knowledge proofs are a candidate for privacy-preserving evidence.

We would rather tell you exactly where the line is today than imply a guarantee we haven't shipped. The direction is fixed; the cryptographic backing arrives before the record becomes permanent at Genesis.