Earthlings

Privacy Policy of the Earthlings People

In force from the moment of publication

Where this Policy diverges from the Charter, the Charter prevails; where the Charter diverges from the Declaration, the Declaration prevails. The processing of biometric data is described separately, in the Biometric Verification Policy, and where the two Policies diverge on that subject, the Biometric Verification Policy prevails. During the founding period - from 22 November 2026 until the Declaration is adopted - signing the Declaration and entering the people are suspended: a people defined by an adopted text does not yet exist. During this period identity verification is carried out free of charge, and on its completion a temporary document of a participant in the founding is issued, rather than a passport (the document "The Founding Period", Part 2, section 5). The temporary document is issued in the same contract as the passport (the document "Where We Are Now"). This Policy also applies to such verification; what it says about signing, the contribution, and the passport refers to the main regime after the Declaration is adopted.

Our principles

  • we collect only the data without which the people cannot exist;
  • your data are never sold; they are disclosed to third parties only in the cases expressly described below;
  • you can at any time obtain, correct, or delete your data within the permitted limits;
  • you decide under what name the community sees you, and you can leave at any time;
  • transparency matters more to us than corporate secrecy.

SECTION 01. Who is responsible for your data

Controller of personal data. At the structure-formation stage the functions of the controller are performed by the founders of the project. As institutional development proceeds, the function will be handed over to a structure, and its registration particulars will be published here.

Requests concerning data subject rights: privacy@earth-lings.org

Three principles

Minimization. Only what is genuinely necessary for the people to work is collected. If a function can be performed without data, it is performed without them.

Purpose limitation. Data collected for one purpose are not used for another. The list of purposes in section 03 is exhaustive.

Intelligibility. Every decision about collecting or using data is explained in plain language. If an explanation requires a legal education, then the explanation is a bad one.

Most platforms treat personal data as a commodity. We treat them as part of human dignity.

SECTION 02. What data are collected

Account data

What: a pseudonym of your choosing, an email address, a country of residence, confirmation that you are 18 or over.

Why: the pseudonym is the name under which other participants see you on the platform and which appears in your passport; it is not shown in the open passport check or in the registry; the email is for confirming registration and for contact; the country is for statistics on geographical spread, and for the passport page and your profile on the platform; age is a mandatory condition of participation.

Real first and last names are not retained.

Identity verification data

What is retained: the verification status, the document type and issuing country, the numeric verification scores, the reasons for rejection, and irreversible hashes computed with the server's secret key - a hash of the document number and a single combined hash of the first name, last name, and date of birth from the document; the document number, first name, last name, and date of birth themselves are not retained.

What is not retained: images of the face and of the document, biometric templates. They are processed at the moment of verification and deleted.

Why: so that one person cannot hold two valid passports.

Precisely on the status of the hashes. A hash is irreversible and is computed with the server's secret key: a name or a document number cannot be read out of it, and without the key they cannot be guessed by brute force either. But it does allow a particular person to be singled out among others - otherwise it would not do its job. These are therefore pseudonymized, not anonymous data, and the protection of personal data applies to them in full.

The details are in the Biometric Verification Policy.

Technical data

What: IP address, browser and device type, operating system.

Why: security, detection of suspicious activity, technical support.

Platform usage data

What: records of actions in the interface - which sections were opened, participation in the work of Cells, support requests; messages in chats, vote delegation, reputation and marks of participation; location down to city, region, and time zone, if you have given it.

Why: operating these platform functions, improving the platform, and technical diagnostics.

What is not included here and will not be. The content of your vote must not be available to anyone, including those who operate the platform, and whether you took part in a vote is not published. The outcome of a vote and transferred votes cast by a delegate are public - that is a property of the vote itself, not of analytics. The tool that will ensure this technically is still being chosen, and we say plainly how things stand now: in the open voting channel that has been deployed, each vote and the voter's wallet address are public, and no substantive votes have been held in it; the platform stores votes cast in Cells together with the voter's account and shows other participants in the Cell the outcome and the objections with the reasons given for them, and those who operate the platform do have technical access to the stored votes.

To improve the platform, usage data are used in aggregate form. These are aggregated data, not anonymized: while a record is linked to an account, it remains personal data.

Distributed ledger data

What: wallet addresses, passport records, transactions.

Why: running the infrastructure and your participation in decisions.

Entries in the ledger are by the nature of the technology not deletable - and that is precisely why names, document data, biometrics, and verification hashes are not written to them on issue. On issue, the ledger records the wallet address, the passport record number, the participant identifier through which the entry is linked to the data of the identity-verification system, and the time of issue; issuing and burning leave marks in the ledger. These are pseudonymous data that we link to your account.

How this relates to the right to erasure (Art. 17 GDPR). The right to erasure is exercised where data are held by us: the account and the platform logs are deleted at your request, except for the wallet address, the passport record number, the pseudonym, and the country - and for a person who belongs to the people the deletion of the account goes only together with leaving; the identity verification data named above remain, including the hashes - so that one person cannot hold two valid passports. The ledger entry itself is not deleted, because no one can delete it, ourselves included: it is not under our control, and names, document data, biometrics, and verification hashes are not written to it. We do not claim that this exhaustively resolves the question - the relationship between immutable ledgers and the right to erasure is not settled in the practice of supervisory authorities. We chose a design in which no names, document data, biometrics, or verification hashes enter the immutable part.

Legal bases for processing

Performance of a contract (Art. 6(1)(b) GDPR) - registration, maintaining the account, issuing and servicing the passport, participation in decisions, processing transactions, access to the infrastructure.

Explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR) - solely for the processing of biometric data during identity verification. For newsletters, the basis is consent (Art. 6(1)(a) GDPR).

There are not and cannot be two bases at once here. Biometric data belong to the special categories of personal data under Article 9 of the GDPR, and neither performance of a contract nor legitimate interests make their processing lawful by themselves. The only basis is your explicit consent, and you are entitled to withdraw it at any time. The consequences of withdrawal are described in the Biometric Verification Policy.

Legitimate interests (Art. 6(1)(f) GDPR) - preventing multiple registrations and abuse, platform security, technical support, maintaining the registry of participants in its non-sensitive fields (pseudonym, country, verification status). You are entitled to object to processing on this basis (section 07).

Legal obligation (Art. 6(1)(c) GDPR) - meeting obligations imposed on us by the law of the European Union or of a Member State.

SECTION 03. How data are used

The list is exhaustive: no processing for other purposes takes place.

  • operating your account and providing access to platform functions;
  • confirming a participant's uniqueness;
  • contacting you on matters concerning the operation of the platform;
  • technical support;
  • improving the platform, the site, and the identity verification page on the basis of aggregated data on usage and visits;
  • security and protection against abuse;
  • operating the decision-making mechanisms and, during the founding period, receiving proposals to the documents of the corpus and publishing them together with the replies (the document "The Founding Period");
  • notices about changes in how the platform works.

Never: third-party advertising and marketing; sale or disclosure to data brokers; profiling for commercial purposes; tracking beyond the platform; any purposes not listed above.

SECTION 04. Cookies and browser storage

Three different resources have to be distinguished here, because they are set up differently.

The public site uses no cookies: not for authentication, not for personalization, and not for analytics. The only thing stored in the browser is the interface language you chose, in the device's local storage. This is a technical setting, not an identifier: it is not linked to your identity.

The platform, where you log in to an account, uses technically necessary session cookies - you cannot log in without them. They are not used for analytics, for advertising, or for tracking beyond the platform, and they are deleted when you log out of your account. The identity verification page (id.earth-lings.org) sets a technically necessary form cookie, elp_form_session - it is valid for 24 hours, and the form cannot be completed without it - and an earthlings_lang cookie holding the chosen language for one year; in the browser's local storage the page keeps the chosen language and a record of the accepted agreements together with the wallet address.

There are no analytics or advertising cookies on any of the three resources, and no third-party trackers are installed. Visits to all three are counted by the people's own statistics counter (stats.earth-lings.org), also without cookies: it receives the page address, the IP address, the browser and device type, the screen size, and actions on the page, including changing the language, and serves aggregate statistics on visits.

SECTION 05. Disclosure of data to third parties

By default data remain within the people's infrastructure. The exceptions are limited to three cases.

Technical providers. Identity verification is performed by the people's own system. To run the infrastructure, participants' data are received by: the hosting provider on whose servers the infrastructure runs; the Zoho email service - emails and support requests; Web3Auth - logging in with email, Google, or Apple and creating a wallet; Cloudflare Turnstile - protecting the form against automated requests (browser signals and the IP address); the script delivery networks jsDelivr, cdnjs, and esm.sh - the IP address when a page loads; Polygon network nodes, WalletConnect, and Snapshot - the wallet address, the IP address, and actions signed with the wallet; the NOWPayments payment service - the email address and wallet address when the contribution is made under the main regime; GitHub - the open registry of founding-period proposals, in which the proposal itself and the answer to it are published (the document "The Founding Period").

Lawful requirements. Data are disclosed only under a court decision in force or an equivalent lawful requirement, whose legitimacy is checked in every case. A participant is notified of requirements that have been complied with, unless the decision itself prohibits it; a summary is published in the transparency report.

Public data on decisions. Some data are public by the nature of self-government: proposals, including proposals of the founding period together with the replies to them (the document "The Founding Period"), voting results, movements of common funds. Of a letter containing a proposal, its text is published; the sender's name and contact details are not published without their consent, and if they ask to be named, only the name they give is published. The content of a personal vote and whether a particular person took part in a vote do not fall into this category; transferred votes cast by a delegate are public.

SECTION 06. Data protection

Technical measures

  • encryption in transit;
  • images of the face and of the document, and biometric templates, are not stored after verification;
  • hashes are computed with the server's secret key; the key is stored outside the database;
  • protection against attacks on the infrastructure;
  • backups;
  • independent security audits as the infrastructure develops.

Organizational measures

  • only those who need it for a particular task have access to data; at present not every access is logged;
  • incident handling protocols;
  • transparent reporting to the people.

Decentralization as a security measure

For now decentralization protects only the registry: the database of the identity verification system, together with the key used to compute the hashes, and the platform database are on a single server, and its compromise would expose the data held there. The registry of passports lives on a distributed network, not on our servers, and remains verifiable regardless of whether the platform is running.

In the event of an incident. If a security breach affecting your data occurs, we will notify you within 72 hours of discovery and report the measures taken.

SECTION 07. Your rights

Access. To obtain a copy of your data and information about how they are processed.

Rectification. To correct inaccurate or incomplete data.

Erasure. To delete data outside the distributed ledger, except those named in section 02 (the box on the right to erasure); for a person who belongs to the people, the account is deleted only upon exit. Entries in the ledger are by the nature of the technology not deletable; on exit the passport is burned, and a pseudonymous mark remains in the ledger recording that belonging existed during a particular period. This is a fact of the past, not a continuing belonging.

Restriction of processing (Art. 18 GDPR). To require processing to be suspended while the accuracy of data or the merits of an objection are checked.

Objection (Art. 21 GDPR). To object to processing based on legitimate interests. We stop processing unless we demonstrate compelling legitimate grounds that override your interests.

Portability. To receive your data in a machine-readable format and transfer them to another controller.

Withdrawal of consent (Art. 7(3) GDPR). To withdraw consent to the processing of biometric data or to newsletters at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal was received; the consequences are described in the Biometric Verification Policy.

Freedom from purely automated decisions (Art. 22 GDPR). You are entitled not to be subject to a decision based solely on automated processing and producing significant consequences for you.

What this means in practice. An automated refusal during identity verification is not final: you are entitled to state your position and to demand review by a human being, and after two unsuccessful automated attempts review by a human being is carried out without a separate request.

If supporting tools are used to analyse proposals on the platform, they take no decisions: their outputs are advisory, the reasons are disclosed, and consideration by a human being is guaranteed.

Complaint. To lodge a complaint with the data protection supervisory authority of your country.

Exit. To end participation at any time: you burn the passport with your own key. Burning the passport does not by itself delete data: account data are deleted at your request.

How to exercise these. Most functions are available in your personal account. For the rest: privacy@earth-lings.org. We reply within 48 hours and complete our handling of a request within 30 days.

The inalienability of belonging

Having become an earthling, a person remains one by their own choice. No decision of a majority, including a qualified one, can deprive them of belonging to the people. Exit is possible only by the voluntary decision of the participant themselves.

SECTION 08. Retention periods

An active account. Data are held for the duration of participation in the people.

After exit. Burning the passport does not by itself delete data: account data are deleted at your request, except those named in section 02 (the box on the right to erasure). Irreversible hashes are retained in pseudonymized form solely so that one person cannot hold two valid passports; they do not limit the right to return.

Technical logs. IP addresses and timestamps - up to 12 months, for security and incident investigation.

Distributed ledger entries. Retained permanently by the nature of the technology. When a passport is burned the entry is marked as burned and gives access to nothing; names, document data, biometrics, and verification hashes are not written to it on issue.

SECTION 09. International transfers

The people is transnational, and data may be processed in different jurisdictions.

  • the project's infrastructure is located in the European Union, in Finland; if the location changes, it will be stated here;
  • the email service processes addresses and letters on its own terms and may do so outside the European Economic Area; no separate contractual clauses have been signed with it;
  • data are transmitted over encrypted connections;
  • you may request information about where your data are held.

Infrastructure is chosen on the basis of technical capability and the level of human rights protection, not political affiliation.

SECTION 10. Age restriction

Participation is possible on reaching the age of 18. This follows from the nature of the commitments: signing the Declaration, taking part in decisions, disposing of units of account.

The age of 18 is an unconditional requirement, and the consent of parents or guardians does not substitute for it.

If it becomes known that a person under the age of 18 has registered, the account is immediately suspended, the person is informed of the grounds and of the period for objections, the objections are answered, and the decision may be appealed under the procedure laid down by the Charter (Declaration, Article 4); there is no body of appeal before the Declaration is adopted. The data outside the ledger are deleted if this is confirmed after the objections have been considered. The passport is burned in that case: either by the holder themselves or, if that does not happen, under the procedure for annulment of an invalid issuance, since age is a condition of issuance (Charter, Article 21); before the Declaration is adopted, the temporary document of a participant in the founding is burned under the procedure set out in the document "The Founding Period" (Part 2, section 5). Entry is possible on reaching the age of 18 on general terms.

Educational initiatives for young people are run through separate programmes that do not require registration in the people.

SECTION 11. Amendments to this Policy

The Policy is updated as technology and legislation develop. Amendments are published with the date of entry into force.

For material changes:

  • notice by email no fewer than 30 days in advance;
  • notice on the platform at the next login;
  • publication of the list of changes;
  • the possibility of objecting if the changes are unacceptable to you.

For questions about this Policy: privacy@earth-lings.org