Sovereign Privacy Charter
Encrypted biometrics, blind passwords, zero-knowledge security collaborations, and statutory European GDPR protections.
Encrypted Biometrics & Mathematical Abstraction
We use encrypted biometrics and strong password enforcement for security. We do not store raw biological features (retina scans, raw fingerprints, or genetic markers).
When Citizens participate in questionnaires or biometric telemetry (such as the Emotion Engine / ecalc or voice room frequency spectrums), data is processed using AES-256-GCM envelope encryption and transformed into non-reversible mathematical coordinate vectors.
Blind Passwords to Biometrics Separation
We enforce blind passwords to biometrics for maximum defense:
STRUCTURAL PARTITION: Authentication credentials (salted password hashes and session tokens) are stored in completely separate data structures from biometric trait vectors.
NO REVERSE CORRELATION: Even if an adversary or administrator acquires authentication database tables, they cannot decrypt, correlate, or unmask the biological persona or biometric questionnaire answers of any Citizen.
Cybersecurity Collaboration & AI Swarm Disclaimers
We actively and routinely collaborate with professional cybersecurity experts strictly using encrypted and pseudonymized data to maintain the highest security and privacy standards.
GDPR Compliance & Cryptographic Erasure (Recital 26)
Under Regulation (EU) 2016/679 (GDPR), Citizens have full rights of access (Art. 15), rectification (Art. 16), portability (Art. 20), and erasure (Art. 17).
Stripe Payment Gateway Privacy, Vendor Nomenclature & Token Fluidity
The platform integrates Stripe specifically so that administrators, node operators, and third-party vendors can monetize custom environments, cover infrastructure costs, and make money. When Citizens purchase time and static advancement through Stripe, strict privacy guarantees apply:
- Zero Payment Credential Ingestion: Credit card numbers, CVC codes, and billing postal codes are tokenized directly with Stripe over TLS 1.3 encryption (PCI-DSS Level 1 compliant). Neither SocialeTicket nor independent vendor servers ever process, inspect, or retain raw payment instruments.
- Vendor Currency Renaming vs. Underlying SCL Engine: Vendors and server hosts are permitted to rename and rebrand Sparks into their desired game currency (e.g. Gold, Credits, Mana). Regardless of the cosmetic title, the underlying technology remains immutable Stack Chain Language (SCL) and the IAM1000 Method. Vendors only receive your pseudonymous citizen handle and SCL wallet ledger confirmation; they never receive banking credentials or real-world identities.
- Infinite Token Circulation: SCL tokens circulate infinitely without arbitrary expiration or vendor silos. When Citizens purchase tokens, they are purchasing Time and Static Advancement (rather than speculative investments or bank deposits); consequently, the platform does not collect financial wealth profiles, credit scores, or invasive tax surveillance telemetry.