Compliance & Privacy Architecture

Privacy Policy

Technical and legal disclosure governing zero-tracking data minimization, cryptographic pseudonymity, and hardware enclave biometric key isolation across the NodeHash protocol.

Effective Date: September 18, 2026 | Protocol Specification v1.0.0

🛡️
Privacy by Architectural Constraint

NodeHash is built on a simple premise: what is never collected cannot be leaked, stolen, subpoenaed, or monetized. We run no tracking cookies, harvest no personal identity dossiers, and maintain no custody over your private cryptographic keys or biometric sensor data.

1.0 General Provisions & Core Architectural Commitments

1.1 Decentralized Software Paradigm

NodeHash operates as open-source, peer-to-peer software designed for non-monetary mutual credit settlement. When you interact with NodeHash, your device communicates directly with independent network peers rather than submitting records to a centralized corporate database. Sovereign participants control their own computing environments, local ledgers, and communication sockets.

1.2 The Absolute Zero-Tracking Commitment

We don't deploy tracking cookies, persistent device fingerprinters, browser canvas sniffers, or third-party marketing beacons. Browsing our documentation, visiting our educational hubs, or running local node clients generates no profiling entries on any central host. Server logs for static website delivery discard client IP addresses upon session termination and keep no historical connection registers.

1.3 Pseudonymous Cryptographic Identity

Traditional internet platforms link your activity to government names, phone numbers, physical residences, and personal email addresses. NodeHash rejects surveillance-based identity. Accounts across the network exist purely as cryptographic public keys generated via the NIST P-256 (secp256r1) elliptic curve standard. Peers identify you solely by your public verification key, never by legal name or state registry.

1.4 Non-Banking and Non-Custodial Classification

NodeHash is an open-source software protocol, not a financial institution. NodeHash is not a money transmitter, bank, broker, or custodial escrow entity. The protocol is not a credit union, depository institution, or money services business. The network neither receives nor holds fiat currency, legal tender, or virtual currency. All mutual credit balances are bilateral or multilateral accounting records clearing reciprocal trade obligations among participants.

2.0 Hardware-Backed Passkeys & Biometric Non-Custody Guarantees

2.1 Secure Enclave and KeyStore Silicon Isolation

NodeHash mobile and desktop clients integrate directly with hardware security modules built into modern personal computing devices. Key generation occurs inside the Apple Secure Enclave on iOS and macOS devices, and within the Android KeyStore or StrongBox hardware module on Android devices. Client desktop web sessions rely on standard FIDO2 and WebAuthn authenticators.

2.2 Local Biometric Processing & Zero Transmission

When you authorize a mutual credit transaction or sign a milestone deliverable using Face ID, Touch ID, or Android BiometricPrompt, your biometric samples never leave the physical silicon chip. The host operating system processes biometric verification entirely within its isolated secure processor.

Raw biometric templates, facial mesh vectors, and fingerprint minutiae maps are never exposed to the NodeHash application runtime. They are never written to disk unencrypted, never serialized into log files, and never transmitted across local networks, relay nodes, or remote servers. The hardware returns only a binary cryptographic authorization token, unlocking the local NIST P-256 private key for a single signature operation.

2.3 Non-Custodial Private Key Architecture

Private signing keys are non-exportable and permanently confined to your local hardware security chip. NodeHash network contributors, maintainers, server relay operators, and development teams hold zero custody, possession, escrow access, or recovery backdoors to your private keys.

If you lose access to your authorized physical devices without an established sponsor recovery path, nobody can restore your signing authority or decrypt local proposal history. You maintain sole, non-custodial sovereignty over your cryptographic credentials at all times.

🔑
Technical Key Isolation Invariant

Biometric Sensor → Isolated OS Enclave → Cryptographic Signature Output. Raw biometric vectors never touch client application memory, network payloads, or remote relays. NodeHash holds zero keys and zero biometrics.

3.0 Information Categories & Processing Architecture

3.1 Local Client-Side Data

Your client software stores operational state on your physical hardware. This data includes draft barter proposals, custom trade taxonomy tags, encrypted counterparty contact aliases, unbroadcast milestone deliverables, and local user interface preferences. This information never leaves your personal storage volume unless you explicitly sign and transmit a message to a trading partner.

3.2 Peer-to-Peer Relay Traffic

Active trade proposals and multi-party cycle discovery queries pass through distributed network relays. All direct negotiation messages and milestone delivery artifacts are encrypted end-to-end using counterparty public keys before transmission. Relay nodes process only transient transport headers and encrypted ciphertext payloads, retaining no ability to inspect message contents or link trade partners.

3.3 Public Ledger Attestations

When participants finalize mutual credit settlements or close barter cycles, they broadcast signed cryptographic attestations to the distributed ledger. These public attestations contain four specific data points:

  • Cryptographic public keys of participating accounts.
  • Non-monetary credit accounting increments expressing transaction value.
  • Cryptographic hashes (SHA-256 digests) representing completed milestone deliverables.
  • Elliptic curve digital signatures proving counterparty consent.

3.4 Data We Never Collect

To maintain complete clarity, NodeHash never collects or processes the following data categories:

  • Government identification numbers, passports, or social security details.
  • Banking details, debit or credit card numbers, or fiat account identifiers.
  • Residential addresses, GPS location traces, or real-time mobility data.
  • Raw biometric templates, voice prints, or facial geometry data.
  • Third-party advertising identifiers, mobile IDFA numbers, or tracking cookies.

4.1 Performance of Protocol Contract (GDPR Article 6(1)(b))

Processing pseudonymous public keys and digital signatures is strictly necessary to calculate mutual credit headroom, maintain the zero-sum ledger conservation invariant (∑ B_i = 0), and execute agreed multi-party clearing cycles requested by participants.

4.2 Legitimate Interests (GDPR Article 6(1)(f))

The protocol processes cryptographic transaction proofs and sponsor lineage chains under legitimate interests. Maintaining an auditable history of completed transactions is essential to prevent double-spending of trade headroom, detect malicious Sybil account generation, and verify sponsor damping liabilities across multi-hop barter cycles.

4.3 Zero Commercial Monetization

NodeHash does not sell, rent, lease, or distribute participant data to commercial data brokers, advertising agencies, or consumer analytics providers. No advertising networks are embedded in the software. No data mining occurs on user trade histories.

5.0 Data Subject Rights & Cryptographic Ledger Mechanics

5.1 Right of Access and Data Portability (GDPR Articles 15 & 20)

Because you operate sovereign client software, your complete ledger journal, transaction proofs, and cryptographic signatures remain accessible directly on your local device. You can export this complete history at any time through standard open formats, including JSON and CSV exports.

5.2 Right to Erasure and Ledger Immutability (GDPR Article 17)

You can delete all local data, cached trade drafts, and unbroadcast proposals at will by clearing client storage or uninstalling the application.

Cryptographic public ledger entries present a distinct technical reality under data protection law. Public transactions contain only mathematical hashes, public keys, and signatures necessary to preserve the mathematical integrity of the mutual credit balance sheet. Erasing past settled transactions would corrupt ledger conservation and destroy balances held by honest trading partners. Under GDPR Article 17(3)(b) and (d), the right to erasure does not extend to immutable accounting records essential for network consistency and public verification.

5.3 Right to Rectification & Restriction (GDPR Articles 16 & 18)

If off-chain profile notes or local counterparty aliases contain errors, you can update them instantly in your client settings. You can also restrict further network interactions at any moment by disabling your client node or revoking specific peer credit allocations.

6.0 California Consumer Privacy Act (CCPA/CPRA) Disclosures

6.1 Categories of Personal Information Collected

Under the California Consumer Privacy Act as amended by the CPRA, personal information is categorized by specific statutory definitions. In the preceding 12 months, NodeHash protocol software has processed only pseudonymous cryptographic identifiers (device public keys) and network transit telemetry (transient IP sockets used in peer gossiping).

6.2 Zero Sale and Zero Sharing Disclosures

NodeHash does not "sell" personal information, and does not "share" personal information for cross-context behavioral advertising as defined by California Civil Code § 1798.140. NodeHash has zero financial incentives linked to consumer data collection.

6.3 Sensitive Personal Information Restriction

NodeHash does not collect or process sensitive personal information to infer characteristics about consumers. Biometric authenticators remain strictly locked in hardware silicon, never entering the custody of the protocol or application developers.

7.0 Security Architecture, Primitives & Incident Protocols

7.1 Modern Cryptographic Primitives

NodeHash enforces strong cryptographic standards across all software layers:

  • Identity and signatures: NIST P-256 (secp256r1) with deterministic ECDSA and SHA-256 digests.
  • Transport encryption: TLS 1.3 for static website access and Noise Protocol Framework handshakes for peer relay circuits.
  • Local storage: Authenticated AES-256-GCM encryption with keys derived from device hardware passkeys.

7.2 Vulnerability Intake & PGP Communication

Security researchers and participants can report potential vulnerabilities through our encrypted disclosure desk documented on the Contact Page. We maintain a public PGP key for sensitive disclosures and acknowledge reports promptly without exposing user communications.

8.0 Protocol Evolution, Amendments & Contact Desk

8.1 Transparent Version Control

As the NodeHash protocol evolves, updates to this privacy policy are committed directly to our public Git repository with cryptographic commit signatures. Participants can inspect historical revisions, review git diffs, and verify architectural compliance across all releases.

8.2 Privacy Desk Contact Information

Questions regarding cryptographic privacy, hardware key isolation, or data minimization practices can be directed to our community coordination desk: