183 lines
7.4 KiB
Markdown
183 lines
7.4 KiB
Markdown
---
|
|
artifact: usermin-privacy-policy
|
|
version: 1.0-draft
|
|
status: draft
|
|
publication_cid: null
|
|
supersedes: null
|
|
---
|
|
|
|
# Usermin Privacy Policy
|
|
|
|
## 1. Scope
|
|
|
|
This Privacy Policy applies only to the Usermin service operated as the **Portal** at:
|
|
|
|
`portal.diagnostics.kane-il.us`
|
|
|
|
It applies to information associated with the Participant's Portal account, UNIX home directory, virtual mailbox, and Portal facilities.
|
|
|
|
It does not govern Hubzilla, Gitea, IPFS, Kane Fabric, or unrelated Civic Infrastructure components.
|
|
|
|
## 2. No Tracking or Secondary Use
|
|
|
|
The Portal does not treat Participants or their activity as a source of data.
|
|
|
|
Information is processed only as necessary to operate, secure, maintain, diagnose, or provide functions deliberately invoked by the Participant.
|
|
|
|
Portal information is not collected or used for:
|
|
|
|
- advertising;
|
|
- behavioral profiling;
|
|
- targeted marketing;
|
|
- sale of personal information;
|
|
- audience monetization;
|
|
- unrelated commercial analytics;
|
|
- unrelated research.
|
|
|
|
## 3. UNIX Account Information
|
|
|
|
Operation of a UNIX account necessarily creates technical information.
|
|
|
|
This may include:
|
|
|
|
- account identifiers;
|
|
- authentication records;
|
|
- ownership and permission information;
|
|
- filenames and directory structures;
|
|
- timestamps;
|
|
- storage usage;
|
|
- process and session information;
|
|
- technical and security logs.
|
|
|
|
This information is processed only as necessary to operate and protect the Portal.
|
|
|
|
## 4. Home Directory
|
|
|
|
The Participant retains the rights and responsibility associated with material in their home directory.
|
|
|
|
The home directory may contain digital assets such as documents, keys, certificates, archives, scripts, correspondence, media, and other Participant-controlled files.
|
|
|
|
Storage on the Portal does not transfer ownership to the Civic Infrastructure.
|
|
|
|
The Civic Infrastructure does not acquire a general right to inspect, publish, reuse, license, commercialize, or otherwise exploit those assets merely because they are stored on the Portal.
|
|
|
|
## 5. Virtual Mailbox
|
|
|
|
The Participant likewise retains the rights and responsibility associated with the contents of their virtual mailbox, subject to the rights of other authors and correspondents in material they created.
|
|
|
|
Receipt of a message does not transfer the author's rights to the Civic Infrastructure.
|
|
|
|
Operation of the mail service necessarily requires technical processing needed to accept, route, store, display, transmit, and maintain permitted email.
|
|
|
|
## 6. Restricted External Email
|
|
|
|
Portal mail uses a restricted external-delivery model.
|
|
|
|
Arbitrary inbound Internet mail is not accepted by default.
|
|
|
|
Specific external namespaces may be deliberately added to an allowlist.
|
|
|
|
For example, an authenticated or otherwise established municipal email namespace may be permitted so Participants can exchange messages with municipal officials.
|
|
|
|
Only the approved namespace or path is thereby admitted. The broader Internet remains outside the permitted inbound mail boundary.
|
|
|
|
This design reduces unsolicited email, bulk spam, external tracking mail, and other traffic that would accompany a conventional publicly addressable mailbox.
|
|
|
|
## 7. Digital Assets and Cryptographic Material
|
|
|
|
A Participant's digital assets may include security-sensitive material such as:
|
|
|
|
- SSH keys;
|
|
- OpenPGP/PGP keys;
|
|
- certificates;
|
|
- private keys;
|
|
- signatures;
|
|
- password-protected archives;
|
|
- encrypted documents.
|
|
|
|
These remain Participant-controlled assets.
|
|
|
|
The Portal does not obtain ownership of cryptographic material because it resides in the Participant's account.
|
|
|
|
## 8. Participant-Controlled Encryption
|
|
|
|
Participants may use available cryptographic tools to reduce the amount of intelligible information exposed to the underlying system.
|
|
|
|
Where supported by the configured File Manager and installed archive tools, files may be placed into password-protected or encrypted archives.
|
|
|
|
Compatible email clients may use OpenPGP/PGP so message content is encrypted using keys controlled by the communicating parties.
|
|
|
|
Encryption materially changes what administrative filesystem access alone reveals.
|
|
|
|
A system administrator with root access can generally access or copy an encrypted file, but properly encrypted content is not thereby converted into readable plaintext without the required secret.
|
|
|
|
This protection has limits.
|
|
|
|
Plaintext may become accessible when the Participant deliberately decrypts material on the Portal, and administrative privilege may permit observation of running processes, temporary files, memory, or other system state.
|
|
|
|
The Portal therefore supports Participant-controlled confidentiality; it does not claim that server-side encryption can make a running UNIX account absolutely opaque to its system administrator.
|
|
|
|
## 9. Licenses and Author Rights
|
|
|
|
Participants and Outside Contacts retain the rights they hold in their own content.
|
|
|
|
The Civic Infrastructure may process that content as necessary to provide the requested Portal function.
|
|
|
|
Where an author grants a particular license, broader use must conform to that license.
|
|
|
|
Absence of such a license does not create an unrestricted right of reuse.
|
|
|
|
## 10. No Automatic Publication
|
|
|
|
Material stored in the Portal does not automatically become a Civic Infrastructure publication or immutable record.
|
|
|
|
A home-directory file, email, key, certificate, or archive remains ordinary Portal content unless the Participant deliberately invokes a separate publication or evidentiary process.
|
|
|
|
## 11. Technical Logs
|
|
|
|
Technical logs may be generated as necessary to:
|
|
|
|
- authenticate Participants;
|
|
- operate UNIX services;
|
|
- route permitted email;
|
|
- investigate failures;
|
|
- maintain security;
|
|
- protect the integrity of the Portal.
|
|
|
|
They are not generated for advertising or behavioral profiling.
|
|
|
|
No specific retention period is promised unless separately published.
|
|
|
|
## 12. Administrative Access
|
|
|
|
Administrators may possess technical privileges necessary to operate and recover the Portal.
|
|
|
|
Those privileges do not grant ownership of Participant content or authorization for unrelated use.
|
|
|
|
Administrative access is limited in purpose to operation, maintenance, security, recovery, and other legitimate infrastructure functions.
|
|
|
|
Participant-controlled encryption can provide an additional confidentiality boundary for stored material, subject to the limitations described above.
|
|
|
|
## 13. Additional Facilities
|
|
|
|
The Portal may gain new functions over time.
|
|
|
|
New functionality does not automatically authorize a new use of previously collected Participant information.
|
|
|
|
Material changes in data handling should be reflected in the applicable published documentation before becoming part of ordinary operation.
|
|
|
|
## 14. Changes to This Policy
|
|
|
|
This Policy follows the Civic Infrastructure Publication Model.
|
|
|
|
A changed Privacy Policy is issued as a replacement Published Version rather than silently modifying the existing publication.
|
|
|
|
Earlier Published Versions may remain available as part of the publication history.
|
|
|
|
## 15. Privacy Principle
|
|
|
|
The Participant's home directory and virtual mailbox are the Participant's working digital space.
|
|
|
|
The Civic Infrastructure operates that space; it does not acquire the Participant's content by doing so.
|
|
|
|
Participant information and digital assets are processed only to provide deliberately invoked functions, protect the service, or exercise permissions granted by the appropriate author. |