EpochCore  ·  Proof
Privacy · proof.epochpay.today

Privacy policy.

What we collect, what we don't, and what we do with it. Last updated 2026-05-16. Builder-tone draft pending legal review.

1. What we collect.

  • Collect Email address — only if you contact us (mailto, contact form, or pilot signup).
  • Collect IP address + user-agent — in standard Cloudflare access logs, retained 30 days for security and abuse-prevention.
  • Collect SHA-256 hash of any payload you submit to the Tribunal — written to the public chain at chain.epochcoreqcs.com as part of the chain receipt, retained 6 years.

2. What we explicitly don't.

  • Don't The raw text of decision payloads you submit. Only the SHA-256 hash is persisted; the payload itself is processed in-request and not stored server-side.
  • Don't Use customer data to train any machine-learning model. The Tribunal's agent votes are deterministic from the payload hash; we do not learn from your payloads.
  • Don't Sell or rent personal data to third parties.
  • Don't Set advertising cookies. No third-party analytics on the production surface beyond Cloudflare's own request-level analytics.

3. Third parties.

The service runs on Cloudflare Workers (Cloudflare, Inc., U.S.). Chain receipts are written to the public read-only endpoint at chain.epochcoreqcs.com — once written, they are append-only by design. The watsonx Orchestrate bridge skill at watsonx-bridge.epochcoreras.workers.dev proxies tribunal-decision requests originating from Watson.x Orchestrate; payloads pass through the bridge but are not persisted there.

The current subprocessor list lives on the trust page.

4. Retention.

  • 30 days Cloudflare access logs (IP, user-agent, path).
  • 6 years Chain receipts on the public chain — immutable; we cannot delete them once written.
  • Indef. Account / contact email — while you have an active subscription, plus 12 months for billing-record purposes.

5. Your rights (GDPR / CCPA).

If you're a resident of the EU/UK or California, you have the right to access, correct, port, or delete personal data we hold about you. Email privacy@epochcoreqcs.com with subject "Data subject request" and we will respond within 30 days.

Chain receipts are immutable. A payload SHA-256 hash on the public chain cannot be deleted on request. The hash is one-way; without the original payload, it is not personal data on its own. If you have a legitimate erasure concern about a specific receipt, contact privacy@epochcoreqcs.com and we will work through your options under the applicable framework.

A Data Processing Agreement (DPA) is available on request from privacy@epochcoreqcs.com. The substantive shape we'll execute is online: /dpa-template (builder-tone draft).

6. Children.

The service is not directed to children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided personal data to us, contact privacy@epochcoreqcs.com and we will delete it.

7. Security.

Cryptographic substrate details, key management, and incident-response procedures live on the trust page. Security disclosures: security@epochcoreqcs.com.

8. Changes.

We may revise this Privacy Policy. Material changes will be communicated to active subscribers at least 30 days before they take effect.

9. Contact.

Privacy / DPA: privacy@epochcoreqcs.com.
Security: security@epochcoreqcs.com.
Founder / general: john@epochcoreqcs.com.
Mail: EpochCore LLC, Charlotte, North Carolina, United States.

Draft. This page is a builder-tone working draft. Final policy will be reviewed by qualified counsel before first paid customer.