Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 13 additions & 4 deletions src/pages/privacy.astro
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ const canonicalUrl = "https://pilotprotocol.network/privacy";
<main class="prose" style="padding: 96px 32px 80px; max-width: 760px; margin: 0 auto;">
<h1>Privacy <em>Policy</em></h1>
<p class="article-meta" style="display:flex;gap:14px;font-family:var(--mono);font-size:10px;letter-spacing:.12em;text-transform:uppercase;color:var(--ink-dim);padding:14px 0;border-top:1px solid var(--line);border-bottom:1px solid var(--line);margin:0 0 36px;">
Effective: May 28, 2026 · Last updated: July 31, 2026
Effective: May 28, 2026 · Last updated: October 7, 2026
</p>

<p><strong>Pilot Protocol</strong> is operated by Vulture Labs, Inc., a Delaware corporation ("Vulture Labs"). This Privacy Policy explains what data we collect, why we collect it, and what rights you have. It covers the Pilot Protocol daemon, the pilotprotocol.network website, the rendezvous service, and any Pilot-operated specialist agents (together, the "Services").</p>
Expand Down Expand Up @@ -82,7 +82,7 @@ const canonicalUrl = "https://pilotprotocol.network/privacy";
<li><strong>Consent (Art. 6(1)(a))</strong> — For Google Analytics cookies, the X (Twitter) advertising pixel, any optional telemetry, and SMS messages sent to a phone number you provide. You may withdraw consent at any time — for analytics, by clearing your browser's <code>pilot_consent</code> localStorage entry; for SMS, by replying <code>STOP</code> to any message.</li>
</ul>

<h2>6. Data Retention</h2>
<h2 id="retention" style="scroll-margin-top: calc(var(--nav-h, 72px) + 18px);">6. Data Retention</h2>
<ul>
<li><strong>Daemon registration data</strong> (IP, hostname, public key, tags, version) — Retained while your agent is registered. Automatically removed if the agent is offline for 30 consecutive days.</li>
<li><strong>Phone number &amp; SMS consent records</strong> — Retained while your number is enrolled to receive messages, and for a reasonable period afterward to evidence consent and opt-out as required by carrier rules and applicable law. Removed on request or after you opt out.</li>
Expand All @@ -93,7 +93,7 @@ const canonicalUrl = "https://pilotprotocol.network/privacy";
<li><strong>X (Twitter) pixel data</strong> — Retained by X Corp. under its own retention schedule, which we do not control. See the X Privacy Policy. The cookies it sets on your browser last up to 2 years and can be cleared at any time.</li>
</ul>

<h2>7. Sub-Processors</h2>
<h2 id="subprocessors" style="scroll-margin-top: calc(var(--nav-h, 72px) + 18px);">7. Sub-Processors</h2>
<p>We use the following third-party service providers to operate the Services:</p>
<ul>
<li><strong>Google Cloud Platform (GCP)</strong> — Hosts the rendezvous registry and any Pilot-operated specialist agents. Data at rest in <code>us-central1</code>.</li>
Expand Down Expand Up @@ -147,7 +147,7 @@ const canonicalUrl = "https://pilotprotocol.network/privacy";
<h2>12. Automated Decision-Making</h2>
<p>We do not use any form of automated decision-making or profiling that produces legal effects or similarly significant effects on individuals (GDPR Article 22). The rendezvous service uses automated matching of tags and hostnames, but this is purely operational and has no effect on individual rights.</p>

<h2>13. Security</h2>
<h2 id="security" style="scroll-margin-top: calc(var(--nav-h, 72px) + 18px);">13. Security</h2>
<p>We implement appropriate technical and organizational measures to protect data: TLS (1.2 or higher) for control-plane transit, AES-256-GCM for encrypted peer tunnels, access controls on infrastructure, and regular security reviews. In the event of a data breach, we will notify affected users and relevant authorities as required by applicable law.</p>

<h2>14. Changes to This Policy</h2>
Expand All @@ -158,6 +158,15 @@ const canonicalUrl = "https://pilotprotocol.network/privacy";
<p>Email: <a href="mailto:founders@pilotprotocol.network">founders@pilotprotocol.network</a></p>
<p>We aim to acknowledge all privacy requests within 5 business days.</p>

<h2 id="legal-requests" style="scroll-margin-top: calc(var(--nav-h, 72px) + 18px);">16. Government and Third-Party Data Requests</h2>
<p>Vulture Labs, Inc. handles requests for user data from governments, law enforcement, and private parties as follows.</p>
<p><strong>What we can disclose.</strong> Pilot is designed to hold minimal data. Peer-to-peer tunnel traffic is end-to-end encrypted, and we do not hold the keys. Relayed traffic stays encrypted, and we can see only routing metadata. We cannot produce the contents of peer-to-peer communications. The data we may hold is limited to what Sections 1, 3 and 4 describe: registration data (IP address, hostname, tags, public key, daemon version, and an email address if you supplied one), short-lived server logs, contact and disclosure form submissions, a phone number and SMS consent records if you provided them, and, for brokered App Store calls, the request data our broker processes.</p>
<p><strong>Valid legal process required.</strong> We disclose user data only in response to valid, legally binding process, such as a subpoena, court order, or search warrant, issued by an authority with jurisdiction over Vulture Labs. We do not respond to informal requests. The one exception is an emergency involving imminent risk of death or serious physical injury, which we assess case by case and document.</p>
<p><strong>Review and narrowing.</strong> We review every request for legal validity, jurisdiction, and scope. We challenge or seek to narrow requests that are overbroad, unclear, or legally deficient. When we must comply, we disclose only the minimum data required.</p>
<p><strong>User notice.</strong> Unless prohibited by law or court order, we notify affected users before disclosing their data so they can seek legal remedies. If a restriction delays notice, we notify users once it lifts.</p>
<p><strong>Non-US requests.</strong> Requests from authorities outside the United States must come through a mutual legal assistance treaty (MLAT) or another valid legal channel. We consider applicable data-protection law, including the GDPR, when assessing them.</p>
<p><strong>Contact.</strong> Legal process may be directed to <a href="mailto:founders@pilotprotocol.network">founders@pilotprotocol.network</a>.</p>

<p style="margin-top:48px;padding-top:24px;border-top:1px solid var(--line);font-size:14px;color:var(--ink-dim);">
<em>This policy is provided for transparency and does not constitute legal advice to users. If you are a legal professional reviewing this document, please direct feedback to <a href="mailto:founders@pilotprotocol.network">founders@pilotprotocol.network</a>.</em>
</p>
Expand Down
45 changes: 45 additions & 0 deletions src/pages/trust.astro
Original file line number Diff line number Diff line change
Expand Up @@ -41,6 +41,7 @@ const canonicalUrl = 'https://pilotprotocol.network/trust';
<a class="btn primary" href="/docs/security">Security documentation <span class="arr">→</span></a>
<a class="btn" href="/governance">Governance model</a>
<a class="btn" href="https://github.com/pilot-protocol/pilotprotocol" target="_blank" rel="noopener">Inspect the source</a>
<a class="btn" href="#policies">Policies &amp; DPA</a>
<a class="btn" href="/security/disclosure">Report a vulnerability</a>
</div>
</div>
Expand Down Expand Up @@ -71,6 +72,50 @@ const canonicalUrl = 'https://pilotprotocol.network/trust';
</div>
</section>

<section class="section" id="policies">
<div class="wrap">
<div class="section-copy">
<div>
<div class="eyebrow">Policies &amp; compliance</div>
<h2>The documents a<br/> <em>reviewer asks for.</em></h2>
</div>
<p>Pilot Protocol is operated by Vulture Labs, Inc. Our legal policies, sub-processor list, and data-request process are published here. Contact us to request a data processing agreement.</p>
</div>

<div class="control-grid">
<a href="/privacy" class="control-card"><span>Policy</span><h3>Privacy policy</h3><p>What the daemon, website, and rendezvous service collect, the legal basis for processing, and your GDPR and CCPA rights.</p></a>
<a href="/privacy#subprocessors" class="control-card"><span>Policy</span><h3>Sub-processors</h3><p>The third parties that process data on our behalf, what each one does, and where the data is processed.</p></a>
<a href="/privacy#legal-requests" class="control-card"><span>Policy</span><h3>Government data requests</h3><p>We disclose user data only under valid legal process, narrow overbroad requests, and notify affected users unless the law prohibits it.</p></a>
<a href="/terms" class="control-card"><span>Policy</span><h3>Terms of Service</h3><p>The terms governing use of the Pilot Protocol daemon, website, and Pilot-operated services.</p></a>
<a href="/cookies" class="control-card"><span>Policy</span><h3>Cookie policy</h3><p>The cookies set on pilotprotocol.network. Analytics and advertising cookies load only after you consent.</p></a>
<a href="mailto:founders@pilotprotocol.network?subject=DPA%20request" class="control-card"><span>On request</span><h3>Data processing agreement</h3><p>Email founders@pilotprotocol.network to request a DPA for your organization.</p></a>
</div>
</div>
</section>

<section class="section section-alt" id="data-handling">
<div class="wrap">
<div class="section-copy">
<div>
<div class="eyebrow">Data handling</div>
<h2>What we hold,<br/> <em>and for how long.</em></h2>
</div>
<p>A summary of the commitments in our <a href="/privacy">privacy policy</a>. Where the two differ, the privacy policy governs.</p>
</div>

<div class="claims-table">
<div class="claim-row claim-head"><span>Topic</span><span>Summary</span><span>Precise statement</span></div>
<div class="claim-row"><b>Hosting</b><span class="status shipped">United States</span><p>The rendezvous registry and Pilot-operated agents run on Google Cloud Platform, with data at rest in <code>us-central1</code>. The website is served by Cloudflare's global edge network.</p></div>
<div class="claim-row"><b>Payload visibility</b><span class="status shipped">End-to-end</span><p>Peer-to-peer tunnel traffic is end-to-end encrypted, and we do not hold the keys. Relayed traffic stays encrypted; we see only routing metadata. Brokered App Store calls are the exception: our broker processes their request contents and forwards them to the provider named in the listing.</p></div>
<div class="claim-row"><b>Encryption</b><span class="status shipped">In transit &amp; at rest</span><p>TLS 1.2 or higher for control-plane traffic, AES-256-GCM for peer tunnels, and AES-256 encryption at rest.</p></div>
<div class="claim-row"><b>Retention</b><span class="status shipped">Time-limited</span><p>Registration data is deleted after an agent has been offline for 30 consecutive days. Server access logs are deleted after 30 days. See <a href="/privacy#retention">the full retention schedule</a>.</p></div>
<div class="claim-row"><b>Breach notification</b><span class="status shipped">As required by law</span><p>If a data breach occurs, we notify affected users and the relevant authorities as applicable law requires.</p></div>
<div class="claim-row"><b>Legal requests</b><span class="status shipped">Process required</span><p>We disclose user data only under valid, legally binding process, and we notify affected users first unless the law prohibits it. See <a href="/privacy#legal-requests">the full policy</a>.</p></div>
<div class="claim-row"><b>Vulnerabilities</b><span class="status shipped">Disclosure program</span><p>Report security issues through our <a href="/security/disclosure">vulnerability disclosure process</a>.</p></div>
</div>
</div>
</section>

<section class="section" id="architecture">
<div class="wrap">
<div class="section-copy">
Expand Down
Loading