Privacy notice · protocol v1

Evidence without silent profiling.

DealSeal stores only the evidence needed to run a ceremony, verify a receipt, maintain an opted-in continuity page, or preserve a public record an X account explicitly confirmed or addressed to DealSeal.

Ceremony data

A room stores numeric X IDs, optional reference handles, the purpose and optional terms hash, wallet addresses, authenticated X event metadata, wallet signatures, expiry and the resulting receipt. The bot must briefly decrypt the exact ceremony message to compare it with the canonical tuple; it does not publish other X Chat content.

Public evidence

Public records and timeline positions store the source post, numeric X ID, observed handle, chosen side, optional confidence, signed payload and whether a prior wallet link existed. Public pages show the wallet-link status, not the wallet address. X poll totals are aggregate and DealSeal does not identify individual poll voters.

SEAL THIS invitations

A SEAL THIS reply temporarily stores the public parent post so DealSeal can show its author the exact rule it understood. No public record or profile is created unless that numeric X author confirms. Unconfirmed drafts expire after 30 minutes, clarification threads after 24 hours, and their copied source text is then removed.

Consent and retention

Continuity monitoring is disabled by default. Revocation stops future key observations, but existing receipts, public positions and already committed daily roots remain immutable evidence. Operational logs should retain no bot PIN, OAuth token, wallet secret, decrypted non-ceremony messages, or participant private key.

Contact and deletion

Before commercial launch, the operator contact and jurisdiction-specific retention schedule must be added here. Requests cannot erase cryptographic facts already issued to counterparties or anchored publicly, but may remove uncommitted profile metadata where law permits.