From b795bfee7f3be358f85982b6d7bb485fe746a15a Mon Sep 17 00:00:00 2001 From: sase25sep26a Date: Wed, 30 Sep 2026 14:35:18 -0500 Subject: [PATCH] Add Usermin Privacy Policy draft --- .../usermin/usermin_privacy_policy.md | 183 ++++++++++++++++++ 1 file changed, 183 insertions(+) create mode 100644 artifacts/policies/usermin/usermin_privacy_policy.md diff --git a/artifacts/policies/usermin/usermin_privacy_policy.md b/artifacts/policies/usermin/usermin_privacy_policy.md new file mode 100644 index 0000000..86c3b0a --- /dev/null +++ b/artifacts/policies/usermin/usermin_privacy_policy.md @@ -0,0 +1,183 @@ +--- +artifact: usermin-privacy-policy +version: 1.0-draft +status: draft +publication_cid: null +supersedes: null +--- + +# Usermin Privacy Policy + +## 1. Scope + +This Privacy Policy applies only to the Usermin service operated as the **Portal** at: + +`portal.diagnostics.kane-il.us` + +It applies to information associated with the Participant's Portal account, UNIX home directory, virtual mailbox, and Portal facilities. + +It does not govern Hubzilla, Gitea, IPFS, Kane Fabric, or unrelated Civic Infrastructure components. + +## 2. No Tracking or Secondary Use + +The Portal does not treat Participants or their activity as a source of data. + +Information is processed only as necessary to operate, secure, maintain, diagnose, or provide functions deliberately invoked by the Participant. + +Portal information is not collected or used for: + +- advertising; +- behavioral profiling; +- targeted marketing; +- sale of personal information; +- audience monetization; +- unrelated commercial analytics; +- unrelated research. + +## 3. UNIX Account Information + +Operation of a UNIX account necessarily creates technical information. + +This may include: + +- account identifiers; +- authentication records; +- ownership and permission information; +- filenames and directory structures; +- timestamps; +- storage usage; +- process and session information; +- technical and security logs. + +This information is processed only as necessary to operate and protect the Portal. + +## 4. Home Directory + +The Participant retains the rights and responsibility associated with material in their home directory. + +The home directory may contain digital assets such as documents, keys, certificates, archives, scripts, correspondence, media, and other Participant-controlled files. + +Storage on the Portal does not transfer ownership to the Civic Infrastructure. + +The Civic Infrastructure does not acquire a general right to inspect, publish, reuse, license, commercialize, or otherwise exploit those assets merely because they are stored on the Portal. + +## 5. Virtual Mailbox + +The Participant likewise retains the rights and responsibility associated with the contents of their virtual mailbox, subject to the rights of other authors and correspondents in material they created. + +Receipt of a message does not transfer the author's rights to the Civic Infrastructure. + +Operation of the mail service necessarily requires technical processing needed to accept, route, store, display, transmit, and maintain permitted email. + +## 6. Restricted External Email + +Portal mail uses a restricted external-delivery model. + +Arbitrary inbound Internet mail is not accepted by default. + +Specific external namespaces may be deliberately added to an allowlist. + +For example, an authenticated or otherwise established municipal email namespace may be permitted so Participants can exchange messages with municipal officials. + +Only the approved namespace or path is thereby admitted. The broader Internet remains outside the permitted inbound mail boundary. + +This design reduces unsolicited email, bulk spam, external tracking mail, and other traffic that would accompany a conventional publicly addressable mailbox. + +## 7. Digital Assets and Cryptographic Material + +A Participant's digital assets may include security-sensitive material such as: + +- SSH keys; +- OpenPGP/PGP keys; +- certificates; +- private keys; +- signatures; +- password-protected archives; +- encrypted documents. + +These remain Participant-controlled assets. + +The Portal does not obtain ownership of cryptographic material because it resides in the Participant's account. + +## 8. Participant-Controlled Encryption + +Participants may use available cryptographic tools to reduce the amount of intelligible information exposed to the underlying system. + +Where supported by the configured File Manager and installed archive tools, files may be placed into password-protected or encrypted archives. + +Compatible email clients may use OpenPGP/PGP so message content is encrypted using keys controlled by the communicating parties. + +Encryption materially changes what administrative filesystem access alone reveals. + +A system administrator with root access can generally access or copy an encrypted file, but properly encrypted content is not thereby converted into readable plaintext without the required secret. + +This protection has limits. + +Plaintext may become accessible when the Participant deliberately decrypts material on the Portal, and administrative privilege may permit observation of running processes, temporary files, memory, or other system state. + +The Portal therefore supports Participant-controlled confidentiality; it does not claim that server-side encryption can make a running UNIX account absolutely opaque to its system administrator. + +## 9. Licenses and Author Rights + +Participants and Outside Contacts retain the rights they hold in their own content. + +The Civic Infrastructure may process that content as necessary to provide the requested Portal function. + +Where an author grants a particular license, broader use must conform to that license. + +Absence of such a license does not create an unrestricted right of reuse. + +## 10. No Automatic Publication + +Material stored in the Portal does not automatically become a Civic Infrastructure publication or immutable record. + +A home-directory file, email, key, certificate, or archive remains ordinary Portal content unless the Participant deliberately invokes a separate publication or evidentiary process. + +## 11. Technical Logs + +Technical logs may be generated as necessary to: + +- authenticate Participants; +- operate UNIX services; +- route permitted email; +- investigate failures; +- maintain security; +- protect the integrity of the Portal. + +They are not generated for advertising or behavioral profiling. + +No specific retention period is promised unless separately published. + +## 12. Administrative Access + +Administrators may possess technical privileges necessary to operate and recover the Portal. + +Those privileges do not grant ownership of Participant content or authorization for unrelated use. + +Administrative access is limited in purpose to operation, maintenance, security, recovery, and other legitimate infrastructure functions. + +Participant-controlled encryption can provide an additional confidentiality boundary for stored material, subject to the limitations described above. + +## 13. Additional Facilities + +The Portal may gain new functions over time. + +New functionality does not automatically authorize a new use of previously collected Participant information. + +Material changes in data handling should be reflected in the applicable published documentation before becoming part of ordinary operation. + +## 14. Changes to This Policy + +This Policy follows the Civic Infrastructure Publication Model. + +A changed Privacy Policy is issued as a replacement Published Version rather than silently modifying the existing publication. + +Earlier Published Versions may remain available as part of the publication history. + +## 15. Privacy Principle + +The Participant's home directory and virtual mailbox are the Participant's working digital space. + +The Civic Infrastructure operates that space; it does not acquire the Participant's content by doing so. + +Participant information and digital assets are processed only to provide deliberately invoked functions, protect the service, or exercise permissions granted by the appropriate author. \ No newline at end of file