From 92e479d40401b8e186d5a88e0c78cde92b2e7a63 Mon Sep 17 00:00:00 2001 From: sase25sep26a Date: Wed, 30 Sep 2026 14:49:19 -0500 Subject: [PATCH] Add Usermin Terms of Service draft --- .../usermin/usermin_terms_of_service.md | 151 ++++++++++++++++++ 1 file changed, 151 insertions(+) create mode 100644 artifacts/policies/usermin/usermin_terms_of_service.md diff --git a/artifacts/policies/usermin/usermin_terms_of_service.md b/artifacts/policies/usermin/usermin_terms_of_service.md new file mode 100644 index 0000000..856cacf --- /dev/null +++ b/artifacts/policies/usermin/usermin_terms_of_service.md @@ -0,0 +1,151 @@ +--- +artifact: usermin-terms-of-service +version: 1.0-draft +status: draft +publication_cid: null +supersedes: null +--- + +# Usermin Terms of Service + +## 1. Scope + +These Terms apply only to the Usermin service operated as the **Portal** at: + +`portal.diagnostics.kane-il.us` + +The Portal provides a private UNIX account environment and related Participant services. + +These Terms do not govern Hubzilla, Gitea, IPFS, Kane Fabric, or the Civic Infrastructure as a whole. + +## 2. Private Service + +The Portal is not a public shell provider, public cloud-storage service, or conventional public email provider. + +Access is provided to Civic Infrastructure Participants for their own use within the facilities made available to their account. + +## 3. Participant Account + +Each Participant receives access to a UNIX account and related Usermin facilities. + +The Participant is responsible for activity intentionally performed through that account and for protecting the credentials used to access it. + +Participants may use the functions made available to their accounts, but may not intentionally: + +- access another Participant's private files or mailbox without authorization; +- bypass assigned UNIX permissions; +- obtain administrative privileges without authorization; +- interfere with other accounts or system operation; +- circumvent technical restrictions deliberately imposed on the service. + +## 4. Home Directory and Virtual Mailbox + +The Participant is responsible for the contents of their own home directory and virtual mailbox. + +These may contain documents, correspondence, archives, SSH keys, OpenPGP/PGP keys, certificates, signatures, scripts, configuration files, evidentiary material, and other digital assets. + +Detailed rules governing ownership, privacy, licensing, administrative access, and cryptographic protection are described in the Portal Privacy Policy. + +## 5. Storage Limits + +Portal storage is limited by quota. + +Current storage limits are: + +- **240 MB soft limit** +- **250 MB hard limit** + +Participants are responsible for managing their own storage within these limits. + +The Portal is working storage and should not be treated as the sole archival copy of important material. + +## 6. Email + +Participants may send email to any Internet email address permitted by the mail system. + +The `sase*` address is not intended to function as an unrestricted public inbound Internet mailbox. + +When sending mail to an external recipient who may need to reply, the Participant is responsible for using an appropriate `Reply-To` address if a reply to the `sase*` address would not be accepted. + +Participants may forward email from the Portal to their own external email accounts for backup, continuity, convenience, or other personal purposes. + +## 7. Approved External Email Namespaces + +External inbound mail is restricted by default. + +Specific external email namespaces may be added to the permitted mail paths when their use supports Civic Infrastructure participation. + +For example, an established municipal email namespace may be permitted so Participants can exchange email directly with municipal officials. + +Permission for one external namespace does not open the Portal to unrestricted inbound Internet mail. + +## 8. Digital Assets and Cryptographic Tools + +The Portal is intended to support Participant-controlled digital assets and cryptographic practices. + +Depending on the facilities available to the account, Participants may use tools for: + +- SSH keys; +- OpenPGP/PGP keys; +- certificates; +- digital signatures; +- checksums; +- password-protected archives; +- encrypted files; +- encrypted email. + +Use of these tools remains the Participant's responsibility. + +The Portal Privacy Policy describes the privacy and administrative-access limits associated with such protection. + +## 9. Kane County CA + +After completing the SASE process, a Participant may choose to install the Kane County Civic Infrastructure CA certificate into a compatible browser or operating-system trust store. + +Installation is optional. + +Installing the certificate establishes local trust in certificates issued under that Civic Infrastructure trust hierarchy. + +Participants should install the CA only from an authenticated Civic Infrastructure source and should verify the published certificate fingerprint before trusting it. + +The Portal does not require installation of the Kane County CA merely to possess a Participant account unless a particular future function explicitly requires it. + +## 10. Additional Portal Facilities + +The Portal may gain additional functions over time. + +The existence of a Participant account does not imply that every possible UNIX or Usermin function is enabled. + +New facilities may be introduced gradually and may be subject to their own operational rules or published documentation. + +## 11. No Automatic Publication + +Material stored in the Participant's home directory or mailbox is not automatically published, placed on IPFS, entered into an evidentiary process, or made part of a public Civic Infrastructure record. + +Those actions require a separate deliberate process. + +## 12. Availability + +The Portal may occasionally be unavailable because of maintenance, software changes, network conditions, security requirements, or technical failure. + +Email delivery, forwarding, external delivery, and access to remote systems cannot be guaranteed. + +Participants should maintain appropriate independent copies of material whose loss would be significant. + +## 13. Participant Standing + +Portal access is associated with Civic Infrastructure Participant standing. + +Periodic SASE revalidation confirms current standing. + +Revalidation does not ordinarily require replacement of the Participant's existing `sase*` account. + +Account identity and current Participant standing remain separate. + +## 14. These Terms + +These Terms follow the Civic Infrastructure Publication Model. + +A Published Version is replaced rather than silently rewritten. + +Earlier Published Versions may remain available as part of the publication history. \ No newline at end of file