From 81a43babf4135cf2f8232630c86d6b38918a9a9d Mon Sep 17 00:00:00 2001 From: Alexgodoroja Date: Wed, 7 Oct 2026 19:47:17 +0300 Subject: [PATCH 1/3] docs(privacy): add government and third-party data requests section Adds Section 16 at /privacy#legal-requests describing what data Vulture Labs can disclose, the legal process required, review and narrowing, user notice, non-US (MLAT) requests, and the legal@ contact. --- src/pages/privacy.astro | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/src/pages/privacy.astro b/src/pages/privacy.astro index f0a2e48b..92cef15c 100644 --- a/src/pages/privacy.astro +++ b/src/pages/privacy.astro @@ -20,7 +20,7 @@ const canonicalUrl = "https://pilotprotocol.network/privacy";

Privacy Policy

Pilot Protocol is operated by Vulture Labs, Inc., a Delaware corporation ("Vulture Labs"). This Privacy Policy explains what data we collect, why we collect it, and what rights you have. It covers the Pilot Protocol daemon, the pilotprotocol.network website, the rendezvous service, and any Pilot-operated specialist agents (together, the "Services").

@@ -158,6 +158,15 @@ const canonicalUrl = "https://pilotprotocol.network/privacy";

Email: founders@pilotprotocol.network

We aim to acknowledge all privacy requests within 5 business days.

+ +

Vulture Labs, Inc. handles requests for user data from governments, law enforcement, and private parties as follows.

+

What we can disclose. Pilot is designed to hold minimal data. Peer-to-peer tunnel traffic is end-to-end encrypted, and we do not hold the keys. Relayed traffic stays encrypted, and we can see only routing metadata. We cannot produce the contents of peer-to-peer communications. The data we may hold is limited to what Sections 1, 3 and 4 describe: registration data (IP address, hostname, tags, public key, daemon version, and an email address if you supplied one), short-lived server logs, contact and disclosure form submissions, a phone number and SMS consent records if you provided them, and, for brokered App Store calls, the request data our broker processes.

+

Valid legal process required. We disclose user data only in response to valid, legally binding process, such as a subpoena, court order, or search warrant, issued by an authority with jurisdiction over Vulture Labs. We do not respond to informal requests. The one exception is an emergency involving imminent risk of death or serious physical injury, which we assess case by case and document.

+

Review and narrowing. We review every request for legal validity, jurisdiction, and scope. We challenge or seek to narrow requests that are overbroad, unclear, or legally deficient. When we must comply, we disclose only the minimum data required.

+

User notice. Unless prohibited by law or court order, we notify affected users before disclosing their data so they can seek legal remedies. If a restriction delays notice, we notify users once it lifts.

+

Non-US requests. Requests from authorities outside the United States must come through a mutual legal assistance treaty (MLAT) or another valid legal channel. We consider applicable data-protection law, including the GDPR, when assessing them.

+

Contact. Legal process may be directed to legal@pilotprotocol.network.

+

This policy is provided for transparency and does not constitute legal advice to users. If you are a legal professional reviewing this document, please direct feedback to founders@pilotprotocol.network.

From 33ff8943a1dd71c69518ee6fee6bc0ec4d4702d5 Mon Sep 17 00:00:00 2001 From: Alexgodoroja Date: Wed, 7 Oct 2026 19:57:41 +0300 Subject: [PATCH 2/3] docs(privacy): route legal process to founders@ --- src/pages/privacy.astro | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/pages/privacy.astro b/src/pages/privacy.astro index 92cef15c..fd9f27c0 100644 --- a/src/pages/privacy.astro +++ b/src/pages/privacy.astro @@ -165,7 +165,7 @@ const canonicalUrl = "https://pilotprotocol.network/privacy";

Review and narrowing. We review every request for legal validity, jurisdiction, and scope. We challenge or seek to narrow requests that are overbroad, unclear, or legally deficient. When we must comply, we disclose only the minimum data required.

User notice. Unless prohibited by law or court order, we notify affected users before disclosing their data so they can seek legal remedies. If a restriction delays notice, we notify users once it lifts.

Non-US requests. Requests from authorities outside the United States must come through a mutual legal assistance treaty (MLAT) or another valid legal channel. We consider applicable data-protection law, including the GDPR, when assessing them.

-

Contact. Legal process may be directed to legal@pilotprotocol.network.

+

Contact. Legal process may be directed to founders@pilotprotocol.network.

This policy is provided for transparency and does not constitute legal advice to users. If you are a legal professional reviewing this document, please direct feedback to founders@pilotprotocol.network. From 8b157eda3e233446d7c63238f0d87e2442c7d007 Mon Sep 17 00:00:00 2001 From: Alexgodoroja Date: Wed, 7 Oct 2026 20:02:37 +0300 Subject: [PATCH 3/3] feat(trust): add policies and data-handling sections to the Trust Center Links the privacy policy, sub-processors, government data requests, terms, cookies, and a DPA request path from /trust, and summarizes hosting, encryption, retention, breach notification, and legal-request commitments from the privacy policy. Adds #retention, #subprocessors, and #security anchors to /privacy. --- src/pages/privacy.astro | 6 +++--- src/pages/trust.astro | 45 +++++++++++++++++++++++++++++++++++++++++ 2 files changed, 48 insertions(+), 3 deletions(-) diff --git a/src/pages/privacy.astro b/src/pages/privacy.astro index fd9f27c0..820b1ae9 100644 --- a/src/pages/privacy.astro +++ b/src/pages/privacy.astro @@ -82,7 +82,7 @@ const canonicalUrl = "https://pilotprotocol.network/privacy";

  • Consent (Art. 6(1)(a)) — For Google Analytics cookies, the X (Twitter) advertising pixel, any optional telemetry, and SMS messages sent to a phone number you provide. You may withdraw consent at any time — for analytics, by clearing your browser's pilot_consent localStorage entry; for SMS, by replying STOP to any message.
  • -

    6. Data Retention

    +

    6. Data Retention

    • Daemon registration data (IP, hostname, public key, tags, version) — Retained while your agent is registered. Automatically removed if the agent is offline for 30 consecutive days.
    • Phone number & SMS consent records — Retained while your number is enrolled to receive messages, and for a reasonable period afterward to evidence consent and opt-out as required by carrier rules and applicable law. Removed on request or after you opt out.
    • @@ -93,7 +93,7 @@ const canonicalUrl = "https://pilotprotocol.network/privacy";
    • X (Twitter) pixel data — Retained by X Corp. under its own retention schedule, which we do not control. See the X Privacy Policy. The cookies it sets on your browser last up to 2 years and can be cleared at any time.
    -

    7. Sub-Processors

    +

    7. Sub-Processors

    We use the following third-party service providers to operate the Services: