Verification & Privacy
How we prove "one human โ a farm of sockpuppets" without harvesting your life
Our Approach
Privacy-first human verification without biometric surveillance
Privacy-First Design
This page states plainly what data we collect now, what we refuse to collect, and how we'll prove "one human โ a farm of sockpuppets" without harvesting your life.
1. Principles
Our core commitments to user privacy
Minimize
Collect the least data required to operate the MVP
Legible
Explain choices in normal language; no dark patterns
Verifiable
Where possible, make the checks auditable or locally verifiable
Revocable
You can leave; we delete what we can and anonymize what we must retain
2. MVP Verification (No Biometrics Yet)
Layered friction instead of privacy-invasive biometrics
Why no biometrics now?
They're a privacy minefield, require specialized storage/consent, and create breach risk. For MVP we use layered friction instead:
Invite Codes
One-time codes tied to an introducer account
Phone Verification
Optional, region-limited: one number โ one account; VOIP blocked. Stored as salted hash, not plain number
Device Fingerprint
Coarse, ephemeral, salted; used for rate limiting only; not shared
Behavioral Limits
Caps on claims/day and concurrent stakes for new accounts
Future Direction
Future: As we scale, we'll consider privacy-preserving proofs (see Roadmap) before touching biometrics.
3. Data We Collect (MVP)
Minimal data collection for platform operation
Account
- Username
- Email (optional for notifications)
- Hashed phone (if used)
- Invite referrer
Activity
- Claims, votes, stakes, timestamps
- Rationales (public)
- IP (rotated logs, 14 days) for abuse mitigation
Telemetry (Minimal)
- Anonymized events for performance
- Page load, API errors
- No cross-site tracking, no ad pixels
We do NOT collect
Legal names
Government IDs
Face/voice prints
Exact location
Contact list
Background data
4. Storage & Retention
How we secure and manage your data
Primary DB
Encrypted at rest. Access scoped by role.
Backups
Encrypted; 30-day rolling window.
Log Retention
14 days for IPs/user agents; longer for aggregated counters (no IPs).
User Deletion
Hard-delete account profile + email; claims/votes remain as public records with your handle replaced by an anonymized tag (because the integrity of past resolutions matters).
5. Public Transparency
Verifiable processes and public accountability
Receipts
Each resolved claim emits a machine-verifiable receipt (seed, witness set, votes, settlement)
Daily Anchors (Optional MVP)
A Merkle root of the day's receipts anchored on a public chain; anyone can audit consistency
6. Roadmap: Stronger "One Human" Without Biometrics
Future privacy-preserving verification methods
Web-of-Trust Staking
Introducers post a small stake; fraud slashes introducer and introduced
Periodic Proof-of-Personhood Sessions
Privacy-preserving: commit-reveal rendezvous with liveness checks where only a zero-knowledge proof is published, not raw images
ZK Phone Assertions
Carrier-signed statements that a number exists and is unique per account, without revealing the number (research stage)
Biometrics Commitment
Any move toward biometrics will require:
- Explicit consent
- Local-device-only templates
- No central storage of raw images
- Third-party audits
7. Your Controls
Full control over your data and privacy
Download Your Data
JSON export of all your account data
Delete Account
See retention policy above for details
Toggle Notifications
Control email notifications
Opt-out Analytics
Functional cookies only
8. Policy & Compliance (MVP)
Legal framework and platform rules
Privacy Policy
Plain-English + full legalese version; link in footer
Terms
Code of conduct, staking rules, dispute process, jurisdiction
Age
18+ only at MVP
Security
Report vulnerabilities to security@agora.fail; rewards for valid reports
9. Blunt Risks You Should Know
Honest assessment of platform limitations
Brigading Risk
You can still get brigaded; rate limits blunt, they don't erase mobs
Centralization
Coordinators are trust anchors in MVP; not fully decentralized yet
Account Security
If your account is compromised, your stakes can be lostโuse 2FA
10. Contact
Get in touch with questions or concerns
Privacy Questions
privacy@agora.fail
Security Reports
security@agora.fail
Community Forum
#transparency forum (upcoming)
Related Documentation
Learn more about our platform
MVP Documentation
Technical specification for our minimum viable product
Token & Governance
Economic model and governance structure
Privacy Policy
Complete privacy policy and data handling practices