Privacy policy.
What we collect, what we don't, and what we do with it. Last updated 2026-05-16. Builder-tone draft pending legal review.
1. What we collect.
- Collect Email address — only if you contact us (mailto, contact form, or pilot signup).
- Collect IP address + user-agent — in standard Cloudflare access logs, retained 30 days for security and abuse-prevention.
- Collect SHA-256 hash of any payload you submit to the Tribunal — written to the public chain at
chain.epochcoreqcs.comas part of the chain receipt, retained 6 years.
2. What we explicitly don't.
- Don't The raw text of decision payloads you submit. Only the SHA-256 hash is persisted; the payload itself is processed in-request and not stored server-side.
- Don't Use customer data to train any machine-learning model. The Tribunal's agent votes are deterministic from the payload hash; we do not learn from your payloads.
- Don't Sell or rent personal data to third parties.
- Don't Set advertising cookies. No third-party analytics on the production surface beyond Cloudflare's own request-level analytics.
3. Third parties.
The service runs on Cloudflare Workers (Cloudflare, Inc., U.S.). Chain receipts are written to the public read-only endpoint at chain.epochcoreqcs.com — once written, they are append-only by design. The watsonx Orchestrate bridge skill at watsonx-bridge.epochcoreras.workers.dev proxies tribunal-decision requests originating from Watson.x Orchestrate; payloads pass through the bridge but are not persisted there.
The current subprocessor list lives on the trust page.
4. Retention.
- 30 days Cloudflare access logs (IP, user-agent, path).
- 6 years Chain receipts on the public chain — immutable; we cannot delete them once written.
- Indef. Account / contact email — while you have an active subscription, plus 12 months for billing-record purposes.
5. Your rights (GDPR / CCPA).
If you're a resident of the EU/UK or California, you have the right to access, correct, port, or delete personal data we hold about you. Email privacy@epochcoreqcs.com with subject "Data subject request" and we will respond within 30 days.
Chain receipts are immutable. A payload SHA-256 hash on the public chain cannot be deleted on request. The hash is one-way; without the original payload, it is not personal data on its own. If you have a legitimate erasure concern about a specific receipt, contact privacy@epochcoreqcs.com and we will work through your options under the applicable framework.
A Data Processing Agreement (DPA) is available on request from privacy@epochcoreqcs.com. The substantive shape we'll execute is online: /dpa-template (builder-tone draft).
6. Children.
The service is not directed to children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided personal data to us, contact privacy@epochcoreqcs.com and we will delete it.
7. Security.
Cryptographic substrate details, key management, and incident-response procedures live on the trust page. Security disclosures: security@epochcoreqcs.com.
8. Changes.
We may revise this Privacy Policy. Material changes will be communicated to active subscribers at least 30 days before they take effect.
9. Contact.
Privacy / DPA: privacy@epochcoreqcs.com.
Security: security@epochcoreqcs.com.
Founder / general: john@epochcoreqcs.com.
Mail: EpochCore LLC, Charlotte, North Carolina, United States.
Draft. This page is a builder-tone working draft. Final policy will be reviewed by qualified counsel before first paid customer.