7.4 KiB
artifact, version, status, publication_cid, supersedes
| artifact | version | status | publication_cid | supersedes |
|---|---|---|---|---|
| usermin-privacy-policy | 1.0-draft | draft | null | null |
Usermin Privacy Policy
1. Scope
This Privacy Policy applies only to the Usermin service operated as the Portal at:
portal.diagnostics.kane-il.us
It applies to information associated with the Participant's Portal account, UNIX home directory, virtual mailbox, and Portal facilities.
It does not govern Hubzilla, Gitea, IPFS, Kane Fabric, or unrelated Civic Infrastructure components.
2. No Tracking or Secondary Use
The Portal does not treat Participants or their activity as a source of data.
Information is processed only as necessary to operate, secure, maintain, diagnose, or provide functions deliberately invoked by the Participant.
Portal information is not collected or used for:
- advertising;
- behavioral profiling;
- targeted marketing;
- sale of personal information;
- audience monetization;
- unrelated commercial analytics;
- unrelated research.
3. UNIX Account Information
Operation of a UNIX account necessarily creates technical information.
This may include:
- account identifiers;
- authentication records;
- ownership and permission information;
- filenames and directory structures;
- timestamps;
- storage usage;
- process and session information;
- technical and security logs.
This information is processed only as necessary to operate and protect the Portal.
4. Home Directory
The Participant retains the rights and responsibility associated with material in their home directory.
The home directory may contain digital assets such as documents, keys, certificates, archives, scripts, correspondence, media, and other Participant-controlled files.
Storage on the Portal does not transfer ownership to the Civic Infrastructure.
The Civic Infrastructure does not acquire a general right to inspect, publish, reuse, license, commercialize, or otherwise exploit those assets merely because they are stored on the Portal.
5. Virtual Mailbox
The Participant likewise retains the rights and responsibility associated with the contents of their virtual mailbox, subject to the rights of other authors and correspondents in material they created.
Receipt of a message does not transfer the author's rights to the Civic Infrastructure.
Operation of the mail service necessarily requires technical processing needed to accept, route, store, display, transmit, and maintain permitted email.
6. Restricted External Email
Portal mail uses a restricted external-delivery model.
Arbitrary inbound Internet mail is not accepted by default.
Specific external namespaces may be deliberately added to an allowlist.
For example, an authenticated or otherwise established municipal email namespace may be permitted so Participants can exchange messages with municipal officials.
Only the approved namespace or path is thereby admitted. The broader Internet remains outside the permitted inbound mail boundary.
This design reduces unsolicited email, bulk spam, external tracking mail, and other traffic that would accompany a conventional publicly addressable mailbox.
7. Digital Assets and Cryptographic Material
A Participant's digital assets may include security-sensitive material such as:
- SSH keys;
- OpenPGP/PGP keys;
- certificates;
- private keys;
- signatures;
- password-protected archives;
- encrypted documents.
These remain Participant-controlled assets.
The Portal does not obtain ownership of cryptographic material because it resides in the Participant's account.
8. Participant-Controlled Encryption
Participants may use available cryptographic tools to reduce the amount of intelligible information exposed to the underlying system.
Where supported by the configured File Manager and installed archive tools, files may be placed into password-protected or encrypted archives.
Compatible email clients may use OpenPGP/PGP so message content is encrypted using keys controlled by the communicating parties.
Encryption materially changes what administrative filesystem access alone reveals.
A system administrator with root access can generally access or copy an encrypted file, but properly encrypted content is not thereby converted into readable plaintext without the required secret.
This protection has limits.
Plaintext may become accessible when the Participant deliberately decrypts material on the Portal, and administrative privilege may permit observation of running processes, temporary files, memory, or other system state.
The Portal therefore supports Participant-controlled confidentiality; it does not claim that server-side encryption can make a running UNIX account absolutely opaque to its system administrator.
9. Licenses and Author Rights
Participants and Outside Contacts retain the rights they hold in their own content.
The Civic Infrastructure may process that content as necessary to provide the requested Portal function.
Where an author grants a particular license, broader use must conform to that license.
Absence of such a license does not create an unrestricted right of reuse.
10. No Automatic Publication
Material stored in the Portal does not automatically become a Civic Infrastructure publication or immutable record.
A home-directory file, email, key, certificate, or archive remains ordinary Portal content unless the Participant deliberately invokes a separate publication or evidentiary process.
11. Technical Logs
Technical logs may be generated as necessary to:
- authenticate Participants;
- operate UNIX services;
- route permitted email;
- investigate failures;
- maintain security;
- protect the integrity of the Portal.
They are not generated for advertising or behavioral profiling.
No specific retention period is promised unless separately published.
12. Administrative Access
Administrators may possess technical privileges necessary to operate and recover the Portal.
Those privileges do not grant ownership of Participant content or authorization for unrelated use.
Administrative access is limited in purpose to operation, maintenance, security, recovery, and other legitimate infrastructure functions.
Participant-controlled encryption can provide an additional confidentiality boundary for stored material, subject to the limitations described above.
13. Additional Facilities
The Portal may gain new functions over time.
New functionality does not automatically authorize a new use of previously collected Participant information.
Material changes in data handling should be reflected in the applicable published documentation before becoming part of ordinary operation.
14. Changes to This Policy
This Policy follows the Civic Infrastructure Publication Model.
A changed Privacy Policy is issued as a replacement Published Version rather than silently modifying the existing publication.
Earlier Published Versions may remain available as part of the publication history.
15. Privacy Principle
The Participant's home directory and virtual mailbox are the Participant's working digital space.
The Civic Infrastructure operates that space; it does not acquire the Participant's content by doing so.
Participant information and digital assets are processed only to provide deliberately invoked functions, protect the service, or exercise permissions granted by the appropriate author.