Privacy
VEILOS is a live public substrate; this policy outlines how its public participation surfaces handle data.
We do not sell, share, or monetize any data submitted through Sovereign Pledge ceremonies.
We retain the Tessera each Sovereign chooses and Imprint content in the substrate state for the purpose of operating the organism.
First-act measurement stores aggregate accepted-call counts, the observation start, and the count and last UTC hour in which a valid prediction receipt was viewed at least ten minutes after its call. No actor, receipt, claim, IP address or session identifier is stored by this measurement. Shared links and automated requests can contribute; these counters do not identify unique visitors or establish voluntary return.
Prevention Lab: records you explicitly supply to /experiments are processed in memory for that request and returned in a private, no-store response. This tool does not persist a participant record, call a model, publish results, or execute changes. Use only records you have permission to process and remove personal details. Copies you save or share are outside this request-local retention behavior.
Data requests: signed-in participants can preview, confirm, track and withdraw a private export or deletion review request at /settings/data. The request stores the original account reference, request type, dates, contract version and review status. Authorized reviewers can acknowledge it or record that fulfillment is unavailable. This workflow does not export or delete participant content or revoke credentials. Automated fulfillment remains unavailable while ownership, shared-record redaction and backup treatment are being completed. Closed request metadata is retained to prevent old confirmations from reopening it; no automatic timed deletion is currently applied. Contact us about privacy requests or account recovery.
Decision Theater practice receipts: a signed URL contains your practice choice, selected premise, case commitment and creation time. It contains no account identifier, expires after 30 days, and creates no participant database row. Anyone given the URL can read the choice; ordinary browser history and hosting access logs may retain the URL independently of receipt validity.
Encrypted BYOK (Bring Your Own Key) credentials are stored at rest using AES-256-GCM under an Obelisk-rooted KEK. We never log raw keys.
Cookies: VEILOS sets strictly-functional, first-party cookies and no tracking or advertising cookies. The site loads no third-party JavaScript and no ad tech; its own scripts use a strict nonce-bound Content-Security-Policy that forbids external scripts. veilos_sov holds your signed Sovereign session; veilos_witness remembers anonymous prediction calls for your return; veilos_feedback_receipts remembers up to 12 anonymous feedback receipt references for 90 days; veilos_seen remembers when you last read your feedback receipts, so new answers can be marked; veilos_theme remembers your chosen palette; veilos_oauth_txn holds a short-lived Obelisk sign-in transaction. None carry third-party trackers and none are shared.
Payments: Oracle consultation packs, patronage, and endowments are processed by Stripe, our payment processor. Card details are entered on Stripe and are never seen or stored by VEILOS; we retain only the resulting entitlement and a non-card receipt reference. See our Terms for refund and entitlement handling.
Contact: hello@veilos.io.