Legal Document

Privacy Policy

Version

1.1

Effective

8 May 2026

Issued by

Saroir Knowledge Foundation

Saroir is a platform built for a cause we believe matters: making knowledge visible, attributed, and permanent for everyone who creates it, regardless of where they are from or what institution they belong to. We are a small founding team working in the open.

A note before the formal language: Saroir's data practices are built around a principle that we keep as little as we can. Your email is the most extreme example: it is gone the moment you have an account. The rest of this page describes the data we do keep and how we treat it. If you are looking for the email-specific policy, see /email.

If you are a lawyer, a privacy researcher, a data protection authority, or simply someone who reads these documents carefully and finds something we have missed, we genuinely want to hear from you. Please write to us at [email protected]. We are not asking for trust. We are asking for help building something worth trusting.

1

Who this policy applies to

2

Who we are

3

What data we collect and why

In plain terms:

Your email never touches our main database. Only a hash of it does. Your contributions are in a completely separate database with no link back to your email.

4

Our email handling architecture

In plain terms:

An isolated service sends your email and immediately forgets it. We never see or store your raw email in our main systems.

5

Blockchain anchoring and permanence

In plain terms:

When a contribution is accepted, a fingerprint of it is written permanently to the Bitcoin blockchain. You have 24 hours to decline this before it happens automatically.

6

Verifiable Credentials and your credential wallet

In plain terms:

Your credential lives in your wallet. It works without Saroir. It survives if Saroir closes.

7

Cookies

In plain terms:

One cookie. Session-only. Deleted when you close your browser. No tracking, no analytics, no advertising.

8

Data we do not collect

9

Legal basis for processing (GDPR)

In plain terms:

For EU users: the legal reasons we process your data, and what that means for your rights.

10

Data retention

In plain terms:

Most data is yours to keep or delete. Some things, once written to the blockchain, cannot be removed by anyone.

11

Your rights

In plain terms:

You can access, correct, export, or delete most of your data. Some blockchain records cannot be removed. We will always be honest about which is which.

12

Third-party services

13

Changes to this policy

14

Contact