Earthlings

The Earthlings Digital Platform

Infrastructure of identity, participation, and projects for the Earthlings people

This document describes the technical implementation of the rules set out in the Earthlings Charter. Where they diverge, the Charter prevails; where the Charter diverges from the Declaration, the Declaration prevails. The platform does not establish rules: it executes them.

SECTION 01. Purpose of the platform

The Earthlings digital platform is the core in which four levels of the people come together:

  • identity - confirmed and at the same time private;
  • participation - signing the Declaration, voting, discussions, joint action;
  • projects and Cells - initiating, forming, coordinating, carrying out, and recording results;
  • the economy of participation - the unit of account, the common fund, reward for work contributed.

The platform is not a social network or just another blockchain system. It is the instrument through which the Earthlings people can exist: with infrastructure that is transparent yet protective of every person.

The main task is to make participation practical, safe, and honest: from the first signing of the Declaration to the delivery of complex international projects.

Limits of the platform. The platform takes no decisions and cannot take them. Binding decisions are taken only by the DAO Assembly. The platform is the executive level: it provides the interface, records the outcome, and puts it into effect. Neither any component of it, nor any automatic mechanism, nor any person operating it has power to alter, revoke, or block a decision of the Assembly. The Charter enters into force with the adoption of the Declaration (Charter, Article 38); until then there is no DAO Assembly, no Core Nodes, no Emergency Multisig, and no Independent Council, and the only discretionary power of the founding period with regard to the texts is the decision of the author of the Declaration to include proposals in the text (the document "The Founding Period").

SECTION 02. Architectural levels

The architecture is built on a multi-layer principle. Each layer performs its own task and interferes with the others as little as possible.

1. Presentation level. Web interfaces; mobile applications and an API for external integrations - in the longer term. Here a person sees the Declaration, the map of participants by country, the panel of Cells, votes, and their personal account. The priority is accessibility and clarity.

2. Application level. Modules of functionality: profile management, submission of initiatives, the work of Cells, voting, delegation, fund management, supporting AI tools. Business logic without the storage of low-level data.

3. Data level. Profile stores, project metadata, Cell statuses, DAO configurations, voting results, event logs. The principles of minimization, separation, and "collect nothing superfluous".

4. Identity and trust level. The in-house identity-verification system, the issuance and record-keeping of non-transferable identity tokens, the recording of the Declaration's signing. This layer is isolated and protected to the greatest possible extent.

5. Level of the economy of participation. The infrastructure of the unit of account, the common fund, the distribution of rewards, integration with projects and Cells.

6. DAO integration level. The interfaces and protocols through which decisions of the Assembly are reflected in the work of the platform: settings, access rights, economic parameters, development priorities.

The layers evolve separately: the application level can be updated without touching identity, and economic mechanisms can be changed without affecting the DAO core.

Who operates the platform

Technical operation is provided by the Core Nodes - elected technical coordinators (Charter, Article 2). They maintain the infrastructure and are responsible for cybersecurity and technical support for voting, but they take no decisions on behalf of the people, do not manage finances, have no special weight in votes, and cannot block DAO decisions. They may be recalled by a simple majority at any time.

The Emergency Multisig (Charter, Article 3) is entitled to suspend particular smart contracts when a critical vulnerability or a cyberattack is discovered. Every such action requires a public report within 48 hours and confirmation by the Assembly within 7 days, failing which it is reversed.

The Charter provides for no other structures with technical powers over the platform. Until the Declaration is adopted, these bodies do not exist (Charter, Article 38), and after it is adopted, until Core Nodes and the Emergency Multisig are elected, their functions are performed procedurally (Charter, Article 39); the points at which one has to trust those who operate the platform today are named in the document "Where We Are Now".

On AI

The platform will use existing artificial-intelligence models to analyse initiatives, support projects, and automate routine work; today it has no such tools. In the longer term, developing an in-house model adapted to the people's tasks is under consideration.

The limits on the use of AI are set out in Article 3 of the Declaration: no algorithm, code or artificial-intelligence system may be the final source of a decision affecting the rights, the dignity or the position of a person, and no technology may be used to manipulate people (including covertly) or to suppress human autonomy. Hence three strict rules that apply whichever model is used:

  • AI has the final say on nothing (Declaration, Article 3). AI output on an initiative or a project is advisory and is not a ground for refusal; a refusal by the automated system during identity verification is not final, and review by a human being is carried out under the Biometric Verification Policy.
  • Reasons are disclosed. A person whose initiative AI has flagged receives a statement of the reasons in intelligible form, not a refusal without explanation.
  • Human review is guaranteed. The initiator is entitled to demand review by a human being, and such review is carried out within a set period.

SECTION 03. Identity: verification and the non-transferable passport

Identity is built around a non-transferable digital passport (SBT) linked to a person whose uniqueness has been confirmed. A strict separation is observed:

  • biometrics and documents are processed by the in-house identity-verification system in real time;
  • from the identity-verification system the platform receives the verification result, the passport record number, the participant identifier, the pseudonym, the wallet address, the email address, and the country, but no biometric data, no images, and no document data;
  • after verification and the signing of the Declaration, a passport confirming the participant's belonging to the people is issued to their wallet address; during the founding period signing is suspended, and on completion of identity verification a temporary document of a participant in the founding is issued (the document "The Founding Period", Part 2, section 5);
  • one person, one passport; the passport is not transferred, not sold, and not taken away.

Separating the axes: identity, vote, economy

The architecture requires that identity, the vote, and the economic trace not merge into a single point of power:

  • identity is set by the passport and by identity verification;
  • the vote follows from earthling status: one person, one vote;
  • economic activity is reflected in the unit of account and gives no additional votes, whatever its volume.

Burning a passport

As a general rule a passport is burned only by the holder themselves, with their own key, from their own wallet. The platform stores no participant keys and is technically unable to prevent the burning; no one is entitled to burn a passport for a participant, but until the contract owner's rights are transferred to a multisignature, issuing and burning a passport are technically available to a single key (the document "Where We Are Now").

The Charter (Article 21) establishes two and only two exceptions, which the platform must support and must not extend:

  1. annulment of an invalid issuance - where it is established that the passport was issued in breach of the conditions of issuance; only by decision of the Assembly with a sanction majority, by secret ballot, with a right of appeal;
  2. technical reissue - at the holder's own request on loss of access to a wallet or on migration of the contract; belonging is not interrupted.

No other grounds for burning by someone other than the holder are implemented in the platform, and against the holder's will a passport is burned only upon annulment of an invalid issuance. The death of the holder is not among the grounds: the platform does not and cannot hold information about deaths, and belonging ends on death of its own accord, with no decision by anyone (Declaration, Article 4); the passport remains in the registry, and participation that no longer exists is handled by the inactivity mechanism (Charter, Article 20).

SECTION 04. Personal account and profile

The personal account is a person's principal point of contact with the ecosystem.

Main elements of the profile

  • the earthling pseudonym - a public name in the ecosystem;
  • country of residence;
  • identity verification status;
  • a mark that a passport is held, without disclosing personal data;
  • areas of interest and competence - optional.

Marks of participation

  • participation in Cells;
  • participation in projects: role, work contributed, completion status;
  • participation in votes is not marked: whether a particular person took part in a vote is not published (section 06);
  • recognition marks received.

Recognition marks affect nothing and remain purely informational (Charter, Article 8). The platform must not use reputational indicators as a condition of access to any function.

What the account does not contain

Passport data, biometrics, and sensitive legal attributes are neither displayed nor stored. They remain in the identity-verification system and are not retained after verification. The platform works with a pseudonym, an email address, a country, a wallet address, a mark that a passport is held, and data on use of the platform; the list and the purposes are in the Privacy Policy.

Photographs and scans are not retained; biometrics are processed only at the moment of verification. What exactly is retained to prevent repeat registration is in the Biometric Verification Policy.

SECTION 05. Cells and the project flow

The platform supports the full cycle: from the appearance of an idea to the completion of a project.

1. Project application. Any earthling may propose a project through their personal account. The application includes a description of the subject, the aim, the expected effect, the competences required, and the delivery timeframe. The initial analysis may be performed by AI - for conformity with the Declaration, with ethics, and with priorities - and this analysis is advisory: it constitutes no refusal, the reasons are disclosed, and review by a human being is guaranteed (section 02).

2. Notification of relevant participants. After the initial analysis the application is directed to those whose declared competences match it - lawyers, engineers, programmers, analysts, and others.

3. Forming the Cell. The Cell is formed from those who respond. Size is from 2 to 6 people (Charter, Article 23). If a task requires more people, several linked Cells are created rather than one unwieldy one.

4. Coordination and delivery. A task board, timelines, communication channels, stage reporting, integration with document storage and supporting tools. Decisions within a Cell are taken by consent; if a reasoned objection on the grounds of harm, unworkability, or serious risk is not removed, the question is decided by a vote of the Cell: a decision is taken if more votes are cast in favour than against; those who abstained took part in the vote but do not count towards "for" or "against". The vote is valid only if more than half of the participants of the Cell took part (the document "Cells", section 05).

5. Completion and recording. The platform records the result, distributes rewards where they are provided for, updates the status of participants, and reflects what the project has contributed on the general map of activity.

On the division into professional and project Cells. The Charter recognizes one form - a Cell of two to six people. The division into standing professional groupings by competence and temporary project teams is a technique for organizing work on the platform, not a separate structure of the people. It may be changed by decision of the Assembly and creates no organs, no powers, and no representation: no Cell has a collective vote or speaks on behalf of other participants.

SECTION 06. Voting and delegation

One earthling, one vote

Every participant who has signed the Declaration has one vote; the passport confirms that vote. The vote is not strengthened by a quantity of units of account, by standing within Cells, or by reputation. Economic weight and the right to vote are separated architecturally, not just on paper.

The right to vote cannot be restricted for a person's views, for how they voted, or as a general measure of liability (Declaration, Article 4; Charter, Articles 17 and 37). There is one measure addressed to a person under Article 22 of the Charter - a warning, and it takes nothing away: not the vote, not access to the voting itself, not the right to submit proposals, not the right to create and join Cells, not access to services, nothing at all. The other measures are addressed to a project or a Cell and do not concern the rights of a person.

The only case in which the platform executes a suspension of the vote is a decision of the Assembly under Article 22 bis of the Charter for proven undermining of the integrity of voting, for a period of no more than 6 months. The platform executes such a decision and can neither initiate it, nor apply it on any other ground, nor extend it.

Openness and secrecy

A personal vote is secret: voting must be arranged so that no one, including those who operate the platform, can learn how a particular person voted or, even with that person's consent, satisfy themselves of it. Whether a particular person took part in a vote is not published. We do not yet have a tool for secret voting - one is being chosen, and today these rules are not observed everywhere: in the open voting channel each vote and the voter's wallet address are public, and the platform stores votes cast in Cells together with the voter's account (the document "Where We Are Now"; Privacy Policy, section 02).

Transparency extends to the actions of institutions, not to the personal data of people. The platform is therefore obliged to ensure a secret ballot with a verifiable count: the outcome is verified by everyone, and the link between a vote and the voter is disclosed to no one, including those who operate the platform. The procedure is set out in the Charter, Article 6.

The platform must also ensure:

  • until voting closes - a hidden interim count and the ability to cast a vote again, with the last vote cast being counted; a personal vote on a question cancels delegation on that question;
  • openness of a delegate's votes - transferred votes cast by a delegate are visible to all; who transferred a vote to a delegate is not published.

The Charter requires the following to be published: the question, the answer options, the deadlines, the number of those entitled to vote, the number of those who voted, the outcome, the proof of the count, and the way to recount the outcome independently (Article 6). There is no proof of the count today, either for the Assembly or for Cells: it will appear together with a tool for secret voting (the document "Where We Are Now").

Delegation

The platform supports transferring a vote in a particular area to another participant. The Charter's requirements (Article 7) must be implemented technically and checked on every operation:

  • by area only - delegating a vote across all questions at once is technically impossible;
  • no self-delegation - checked on every operation;
  • no chains - a delegated vote received cannot be passed on further;
  • a ceiling - 5 per cent of participants, but no fewer than 10 delegators;
  • one active delegation per area - a second is impossible without revoking the first;
  • revocation in one step - at any time, without giving reasons and without the consent of the person the vote was given to;
  • questions with no delegation - amending the Charter and the basic treasury rules, funding above a set threshold, forming the Emergency Multisig, restricting powers, suspending the right to vote, annulling the issuance of a passport, and amending the unamendable principles: on these, votes are cast only in person.

Any earthling may be a delegate: the only selection is the choice made by the delegator (Charter, Article 7).

The feed of proposals

All proposals are displayed in chronological order of submission. The author's reputation does not affect a proposal's place in the feed. Filtering by reputation will be available only as a viewing mode that each participant switches on for themselves; there is none in the platform today.

Automatic prioritization of proposals would shape the agenda without anyone being formally responsible for it, and is therefore not implemented in the platform.

What the platform does within the DAO

  • an interface for voting and discussion;
  • public recording of decisions taken and of their execution status;
  • technical implementation of decisions: changing settings, updating the rules for distributing funds, launching programmes;
  • logging of key actions for subsequent audit.

The low-level infrastructure may be anything; the principles do not depend on it.

SECTION 07. The unit of account in the platform

The platform will be the main interface for the practical use of the unit of account; today the unit has not been issued: the economy of participation is kept in the platform's internal accounting (the document "Earthlings Coin", section 8), and the scenarios below describe what the unit is intended for. The separation between economy and power is observed strictly.

Internal uses

  • reward for work contributed to projects and Cells;
  • management of internal funds;
  • payment for access to particular services and tools;
  • support for initiatives: micro-grants, experiments, pilot programmes.

What the unit of account does not do

  • it gives no additional votes and no political weight;
  • it does not determine access to basic participation: signing the Declaration, voting, discussions;
  • it does not affect a proposal's place in the feed or the priority of its consideration;
  • it cannot be used as an instrument of pressure or of excluding people from processes;
  • it does not replace national currencies and is not imposed as a means of everyday payment.

The unit of account reflects the work people contribute and makes it possible to launch projects, but it does not divide people into the important and the unimportant. The platform ensures that economic logic does not destroy equality of participation.

SECTION 08. Data and privacy

The platform is built with the principles of the GDPR and comparable standards in mind. The starting principle: preserving human dignity and the right to a private life matters more than the convenience of analytics.

Main principles

  • minimization - only what is genuinely necessary is collected;
  • separation - identity, participation, economy, and analytics are spread across layers and stores;
  • transparency - a participant understands what data about them exists and how it is used;
  • control - a participant may request correction or deletion of the data processed by the platform.

What happens to data in the distributed ledger

Honesty is needed here, not a promise that cannot be kept.

Data held in the platform's databases are corrected at a participant's request and deleted at their request - except those named in the Privacy Policy; for a person who belongs to the people, the account is deleted only upon exit. Entries in a distributed ledger are by their nature not deletable - and that is precisely why names, document data, biometrics, and verification hashes are not written to it on issue. On issue, the ledger records the wallet address, the passport record number, the participant identifier through which the entry is linked to the data of the identity-verification system, and the time of issue; on issue, the pseudonym field is filled with the single word "Earthling", and the verification hash field with a random value unrelated to the verification data; issuing and burning leave marks in the ledger. These are pseudonymous data that we link to your account.

On exit the passport is burned, and a pseudonymous mark remains in the ledger recording that belonging existed during a particular period. This is a fact of the past, not a continuing belonging. This model predominates in European practice on church registers: the entry is preserved; the status is marked. Whether this model is sufficient is now being decided by the Court of Justice of the European Union (Case C-12/25).

Freedom of association does not require the erasure of history: renouncing citizenship does not destroy state archives.

Identity verification and data protection

  • biometrics and documents are processed by the in-house system at the moment of verification; images and scans are not retained;
  • the platform receives from the identity-verification system not biometrics or document data but the verification result and the data for the account (section 03);
  • under a court decision in force or an equivalent lawful requirement, data are disclosed under the procedure set out in the Privacy Policy (section 05); they include no biometric data, which are not retained;
  • entries in the registry follow the principle of pseudonymity and of minimizing personal links.

The platform is not built as a system of blanket record-keeping. It aims to become an example of careful handling of data in an age when almost everything is technically possible.

SECTION 09. Technical architecture and scalability

Particular technologies - blockchains, databases, languages, frameworks - may change. What matters is the architectural logic:

  • modularity - the core, the identity subsystem, the DAO component, the economic layer, and the interfaces develop independently;
  • scalability - the architecture is designed for growth in the number of earthlings by orders of magnitude without loss of availability or security;
  • resilience - fault-tolerant configurations, backup stores, independent nodes;
  • recovery - backups, a recovery plan for critical failures, protocols for action when keys are compromised;
  • auditability - the possibility of external technical and legal audit of key components.

The platform is not tied forever to a single technology stack. Through any migration the principles are preserved: non-transferable identity, an equal inalienable vote, verifiability of processes, and protection of every person.

The ability to exist without an operator. The registry of passports is kept on a distributed network, not on the platform's servers. This is why registry entries are preserved through a change of operator, through a migration of infrastructure, and through a re-founding recognized by the Roadmap as a legitimate continuation; the points at which the registry today depends on those who operate it are named in the document "Where We Are Now".

SECTION 10. Stages of implementation

Both the design of the target architecture and the way to reach it are essential.

Stage 1. The core - built and deployed. The personal account, the map of participants by country, Cell statuses, the voting mechanism, integration with the in-house identity-verification system. The minimum of functions sufficient to begin.

Stage 2. Cells and projects - built and deployed. The cycle of work with Cells: applications, formation, delivery, recording of results.

Stage 3. Filling it with practice - still ahead. Regular substantive votes, a secret ballot with a verifiable count, delegation by area, signing the Declaration, supporting AI tools for analysing initiatives, working funds, a wider range of uses for the unit of account. Filling begins when entry opens and proceeds as the number of participants grows.

Stage 4. External engagement - still ahead. Engagement with international organizations, universities, and research centres. Provision of aggregated data for the analysis of global processes. Participation of the people in discussing questions that go beyond a single country.

On the boundary of the fourth stage. This concerns the right to be heard, not decision-making power. The platform does not become and cannot become a place where decisions binding on anyone other than Earthlings themselves are taken. The powers of states are not affected (Declaration, Article 6).

The division into what is built and what is still ahead is given honestly. The passport registry contract, identity verification, Cells, and the accounting of the internal economy are deployed and working; the public voting channel is deployed, but no substantive votes have yet been held in it, there is no tool for secret voting yet, and the founding vote will be held openly, and the Treasury smart contracts have not been deployed (the document "Where We Are Now"). The evidentiary and practical value of the infrastructure arises as participation accumulates, not at the moment of deployment.

Note: the external legal interface

For engagement with traditional legal, administrative, and financial infrastructure, registered legal instruments are used in one or more jurisdictions. Such instruments are replaceable operational means of external engagement and do not define the people.

After the Declaration is adopted, the persons acting through these instruments carry out a revocable mandate of the DAO Assembly and hold no office; before it is adopted there is no people, and no one acts on its behalf. The detailed legal model is in the document Legal Basis.