Skip to content

Add privacy policy and terms of service drafts - #37

Draft
wksantiago wants to merge 8 commits into
mainfrom
legal-docs
Draft

Add privacy policy and terms of service drafts#37
wksantiago wants to merge 8 commits into
mainfrom
legal-docs

Conversation

@wksantiago

@wksantiago wksantiago commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

Refs #36

Summary by CodeRabbit

  • Documentation
    • Added/updated a draft Privacy Policy covering data collection, processing purposes, sharing, retention, security measures, cookies/tracking, international transfers, and privacy rights.
    • Added draft Terms of Service covering service scope, client responsibilities, confidentiality, fees/payment (including optional digital-asset payment terms), IP, liability, acceptable use, termination, and arbitration/dispute resolution.
    • Updated SECURITY.md with Coordinated Disclosure and Safe Harbor guidance.
    • Added an internal publication checklist to coordinate final review and consistency across legal pages.

@wksantiago wksantiago self-assigned this Jul 27, 2026
@coderabbitai

coderabbitai Bot commented Jul 27, 2026

Copy link
Copy Markdown

Review Change Stack

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 72c4488c-559f-4b32-aae7-05a0c55d43df

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Walkthrough

Adds attorney-review drafts for PrivKey LLC’s Privacy Policy and Terms of Service, coordinated disclosure and safe-harbor guidance, and an internal publication checklist covering data practices, service obligations, payments, intellectual property, liability, termination, and dispute resolution.

Changes

Legal documents

Layer / File(s) Summary
Privacy framework and data practices
legal/privacy-policy.md
Defines policy scope, privacy commitments, collected information, processing purposes, and legal bases.
Privacy operations and rights
legal/privacy-policy.md
Documents sharing, transfers, tracking, retention, security engagement data, blockchain limitations, and privacy rights.
Privacy notices and incident handling
legal/privacy-policy.md
Adds security measures, breach notification, children’s privacy, third-party sites, policy changes, and contact details.
Service contract and engagement rules
legal/terms-of-service.md
Defines service scope, client responsibilities, testing authorization, disclaimers, and confidentiality.
Commercial, intellectual property, and liability terms
legal/terms-of-service.md
Specifies payment, digital-asset, intellectual property, warranty, disclaimer, liability, and indemnification provisions.
Compliance, termination, and dispute resolution
legal/terms-of-service.md
Adds compliance, acceptable use, termination, arbitration, general contract terms, and contact details.
Security research and publication readiness
SECURITY.md, legal/PUBLICATION-CHECKLIST.md
Adds coordinated disclosure and safe-harbor guidance and records publication blockers and cross-document consistency checks.

Estimated code review effort: 2 (Simple) | ~15 minutes

Poem

I’m a rabbit with papers stacked high,
Privacy and terms now reach for the sky.
Keys stay guarded, contracts stand tall,
Check every bracket before publishing all.
Hop, review, and make the pages shine!

🚥 Pre-merge checks | ✅ 3 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Linked Issues check ⚠️ Warning The PR adds draft markdown policies but does not publish /privacy/ and /terms/, add footer/sitemap links, or remove bracketed placeholders. Convert the drafts to styled HTML pages at /privacy/ and /terms/, resolve all placeholders, add footer and sitemap links, and set effective/last-updated dates.
Out of Scope Changes check ⚠️ Warning The SECURITY.md and publication checklist edits are not required to publish the two legal pages and appear outside the issue scope. Drop those unrelated edits unless they are intentionally part of the publication work.
✅ Passed checks (3 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main change: adding draft privacy policy and terms of service documents.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch legal-docs

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 12

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@legal/privacy-policy.md`:
- Around line 3-8: Finalize the privacy policy before publication by removing
the draft banner and resolving every bracketed placeholder throughout the
document, including dates, vendors, retention periods, contacts,
representatives, tooling, and implementation details. Ensure the resulting
document contains only attorney-approved, publication-ready content with no
unresolved placeholders.
- Around line 22-27: Validate the enforceable commitments in the privacy policy
against production tooling, vendor terms, and deletion workflows, especially the
third-party AI training restriction and minimum-collection/deletion statement.
If operational evidence confirms them, retain the current wording; otherwise,
soften or revise those statements to match verified practices before
publication.
- Around line 111-120: Revise the cookie sections 7.1–7.3 to remove or qualify
unverified claims about analytics consent, the consent banner, cookie settings,
and GPC handling, matching the currently deployed behavior. Do not publish
statements that depend on unimplemented controls; retain only confirmed cookie
practices.
- Around line 234-247: Remove the “Reviewer Checklist — Resolve Before
Publication” section and all ten checklist items from the public privacy policy
content. Preserve the surrounding policy sections, and move or retain these
publication tasks only in an internal checklist or issue tracker so they are not
rendered on /privacy/.
- Around line 124-141: Resolve all bracketed retention durations in the Section
8 “Data Retention” table, including the entries referenced near the Section 9
destruction commitments, only after confirming each period is operationally
enforceable. Align the published schedule with documented deletion ownership,
legal-hold and dispute exceptions, backup handling, secure-destruction
procedures, and certificate-of-destruction evidence; do not promise 30-day
destruction or certificates unless those controls are implemented.
- Around line 197-201: Update Section 13’s breach-notification language to apply
the direct notification commitment only when PrivKey is the controller for the
affected personal data. For business-client processor engagements, state that
notification is made to the applicable client/controller without undue delay,
with the MSA or DPA governing the engagement-specific requirements; remove the
blanket promise of notifying individuals and supervisory authorities within the
GDPR 72-hour window.
- Around line 178-184: Update sections 11.3 “Timing” and 11.5 “Appeals and
complaints” to replace the broad U.S. 45-day wording with jurisdiction-specific
deadlines or an “applicable law” qualifier. Preserve the stated 45-day response
and extension for CCPA/CDPA-like regimes, the one-month GDPR/UK GDPR response
with a two-month extension, and ensure appeal timing is not incorrectly applied
to GDPR requests.

In `@legal/terms-of-service.md`:
- Around line 259-270: Remove the “Reviewer Checklist — Resolve Before
Publication” section from the published Terms, including all eight internal
review items. Ensure the document ends after the Contact section and does not
expose drafting or publication workflow content.
- Line 74: Update the key-material handling language in section 5.1 to match the
mandatory process in the Privacy Policy: state that PrivKey will delete
accidentally submitted private keys, seed phrases, or key shares and notify the
sender to rotate them, while retaining the existing responsibility and liability
statements.
- Around line 18-20: Revise the acceptance language in the Terms section so it
does not treat mere Site access as acceptance without an affirmative flow.
Either add a click-to-accept or scroll-to-accept mechanism that records the
accepted Terms version and date, or narrow the stated acceptance scope to
Services engagements covered by signed agreements.
- Around line 3-7: Finalize legal/terms-of-service.md by replacing every
bracketed placeholder with attorney-confirmed values and removing the draft
banner after approval: lines 3-7 for status and dates, 14 for formation state,
102-104 for payment terms, 110 for refund currency, 138 for confidentiality
survival, 154 for liability limits, 160 for claim limitation, 194-196 for
termination terms, 210 for arbitration panel size, 218 for the opt-out, 226 for
non-solicitation, 234 for legal notices, and 249-254 for the mailing address and
contact emails.
- Around line 34-54: Align the key-management service descriptions with the
non-custody representations in sections 4.1 and 5.1. After confirming the actual
workflow with counsel, either constrain the “Multisig Concierge Services” and
“Private key management advisory” entries to advisory/configuration assistance
that never involves possession or control, or update the corresponding
non-custody language consistently; preserve the SOW-based scope limitation.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: a85a7e78-93cf-469e-874f-f732f62b7566

📥 Commits

Reviewing files that changed from the base of the PR and between 89cb36f and 374adf2.

📒 Files selected for processing (2)
  • legal/privacy-policy.md
  • legal/terms-of-service.md

Comment thread legal/privacy-policy.md
Comment thread legal/privacy-policy.md Outdated
Comment thread legal/privacy-policy.md Outdated
Comment thread legal/privacy-policy.md
Comment thread legal/privacy-policy.md Outdated
Comment thread legal/terms-of-service.md
Comment thread legal/terms-of-service.md
Comment thread legal/terms-of-service.md
Comment thread legal/terms-of-service.md Outdated
Comment thread legal/terms-of-service.md Outdated
@wksantiago
wksantiago requested a review from kwsantiago July 28, 2026 00:20

@kwsantiago kwsantiago left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Audit of the drafts against this repo and the live site. I skipped anything CodeRabbit already covered (placeholders, consent banner and GPC, retention schedule, response deadlines, the controller/processor split in Section 13, checklist removal before publication, click-to-accept, and key-material handling). Everything below is a mismatch with code or config in this repo, which is the class of problem an attorney review will not catch.

Inline comments cover: Miami vs Tampa, cookie and automatic-collection claims that the code contradicts, the empty subprocessor table (fillable from the code today), unverified Section 12 security controls, the researcher safe harbor conflict across three documents, unconfirmed email aliases, the MIT license conflict with ToS 9.1 and 15, uncapped confidentiality liability in 12.3, the service list outrunning what the site sells, and the survival list.

Three that do not anchor to a line in this diff:

1. Closes #36 will auto-close an issue that is one fifth done. #36 has five acceptance items: attorney approval with no remaining brackets, HTML pages at /privacy/ and /terms/, footer links, sitemap entries, and effective dates. This PR delivers the drafts. On merge the issue closes and the publication work goes quiet. Suggest Refs #36.

2. The contact form has no notice at collection. index.html:298 collects name, email, referral source, and free text with no privacy link anywhere near it. CCPA/CPRA requires notice at or before collection and GDPR Art. 13 likewise; a footer link alone does not cover it. Worth folding into the #36 publication work.

3. Delivery format. .md files under legal/ will not render as pages on a static host reading _headers; they serve as raw text or a download. Fine as a staging step since #36 already calls for HTML at /privacy/ and /terms/, just do not link to the .md paths. Related: privkey.io/subprocessors and privkey.io/pgp are both referenced and neither exists.

Drafting quality is high. The gaps are all in the seam between the documents and the deployed site.

Comment thread legal/privacy-policy.md Outdated
Comment thread legal/privacy-policy.md Outdated
Comment thread legal/privacy-policy.md Outdated
Comment thread legal/privacy-policy.md
Comment thread legal/privacy-policy.md Outdated
Comment thread legal/terms-of-service.md Outdated
Comment thread legal/terms-of-service.md Outdated
Comment thread legal/terms-of-service.md
Comment thread legal/terms-of-service.md Outdated
Comment thread legal/terms-of-service.md Outdated
@kwsantiago

Copy link
Copy Markdown
Contributor

6085e47 works through both review passes. Where a finding needed a business or legal decision I left the text alone and wrote the decision down instead of guessing.

Resolved

Finding Change
Miami vs Tampa (both docs) Tampa throughout; arbitration seat moved to Hillsborough County. index.html already said Tampa and is unchanged
3.2 described collection the Site does not perform Rewritten: no cookies, no analytics, no behavioral tracking. What remains is host access logs and the IP disclosure your browser makes to third-party asset providers
Cookie section (CodeRabbit privacy:120) Section 7 now states the Site sets no cookies and presents no banner because there is nothing to consent to, with a forward-looking commitment to build consent before any tag ships
Empty subprocessor table Split into two tables. The Site half is filled from the code: Formspree, Setmore, jsDelivr, Google Fonts, rss2json, with the data each receives. Hosting row still open
Response deadlines (CodeRabbit privacy:184) 11.3 is now a per-jurisdiction table: CCPA 10-business-day acknowledgment plus 45 days, other state laws 45 days, GDPR one month plus up to two, each with its own extension rule
Appeals wording 11.5 rewritten around the state statutory appeal right, offered to everyone regardless of state
Breach notification role split (CodeRabbit privacy:201) Section 13 split into 13.1 controller (we notify regulators and individuals, 72 hours under GDPR) and 13.2 processor (we notify the client, they decide)
Researcher safe harbor across three docs SECURITY.md is now the single source and gained a coordinated disclosure and safe harbor section. Privacy 13.4 and ToS 15 both point at it, and ToS 15 no longer prohibits what the safe harbor permits
MIT license vs ToS 9.1 and 15 New 9.1.1 carve-out: the MIT grant already made is untouched, 9.1 reserves what the license does not cover plus trademarks. Section 15 no longer bans commercial reuse
Key material handling (CodeRabbit terms:74) ToS 5.1 now matches Privacy Policy Section 2 word for word in substance: delete promptly, tell you to rotate, no responsibility for loss
Custody scope (CodeRabbit terms:54) Multisig and MPC bullets carry explicit advisory-only language: you perform every operation touching key material, we never hold a key or share, alone or in combination
Survival list Adds 15 and 16 and 17.4, drops the inert 20
Under 16 vs under 18 11.6 now explains the CCPA threshold and points at our own 18
hello@privkey.io Replaced with the verified information@privkey.io. privacy@ and legal@ stay bracketed with an instruction to create and monitor them or substitute
Dangling privkey.io/pgp Reference removed rather than left pointing at a 404. Whether to publish a key is checklist item 33
Reviewer checklists in public docs (CodeRabbit privacy:247, terms:270) Both stripped and merged into legal/PUBLICATION-CHECKLIST.md, marked internal, 33 items typed counsel / ops / decision
Closes #36 Now Refs #36, so merging this does not close an issue whose HTML pages, footer links, and sitemap entries are still outstanding

Deliberately not changed

  • ToS 12.3 confidentiality cap. Bracketed alternative added, decision left open. See the thread above.
  • Section 3 service list. Trimming it needs someone who knows what PrivKey sells today. Publication gate added noting that each line commits the Privacy Policy to matching data practices.
  • Section 12 security controls. Cannot be verified from a repo. Publication gate added requiring per-control attestation rather than a blanket sign-off.
  • Retention schedule and 30-day destruction window (CodeRabbit privacy:141). Bracketed durations are business decisions; checklist items 12 and 13.
  • Click-to-accept (CodeRabbit terms:20) and notice at collection. Both are site changes belonging to the publication work, checklist items 29 and 20.

Placeholders and the DRAFT banner stay until the attorney pass. Both files are still drafts and neither is linked from the Site.

@kwsantiago
kwsantiago marked this pull request as draft July 28, 2026 01:21

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🧹 Nitpick comments (1)
legal/PUBLICATION-CHECKLIST.md (1)

1-5: 🔒 Security & Privacy | 🔵 Trivial

Verify that the internal checklist is excluded from public artifacts.

The warning is documentation only. Confirm the site build and deployment configuration cannot publish legal/PUBLICATION-CHECKLIST.md or expose it as a raw public document.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@legal/PUBLICATION-CHECKLIST.md` around lines 1 - 5, Verify the site build and
deployment configuration excludes legal/PUBLICATION-CHECKLIST.md from generated
and deployed public artifacts, including direct raw-document access. Update the
relevant inclusion, copy, or routing configuration if the checklist could
currently be published, while preserving publication of privacy-policy.md and
terms-of-service.md.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@legal/PUBLICATION-CHECKLIST.md`:
- Line 16: Update the checklist entry describing rights-request monitoring to
avoid presenting 45 days as a universal deadline. Record the applicable
jurisdiction and request type, distinguishing California’s 45-day period from
the generally one-month GDPR period, while preserving the existing mailbox
monitoring guidance.
- Line 52: Update the Section 9.1.1 checklist guidance to limit MIT-license
conclusions to repository source code and associated documentation actually
covered by that license. Explicitly distinguish those materials from website
content, policies, branding, fonts, images, and third-party works, which require
separate rights analysis.

In `@legal/terms-of-service.md`:
- Line 220: Update the Survival clause in Section 17.5 to replace the incorrect
“6 (indemnity)” label with the correct description for Section 6, while
preserving the existing section list and survival language.

In `@SECURITY.md`:
- Around line 17-21: Revise the safe-harbor language around “Research conducted
in good faith” to limit authorization to explicitly named in-scope assets and an
approved written Rules of Engagement, referencing the policy’s required
authorization process. Ensure activities outside that scope, including testing
beyond passive or reporting actions, require prior written authorization, and
align the third-party claim statement with the same constrained scope.

---

Nitpick comments:
In `@legal/PUBLICATION-CHECKLIST.md`:
- Around line 1-5: Verify the site build and deployment configuration excludes
legal/PUBLICATION-CHECKLIST.md from generated and deployed public artifacts,
including direct raw-document access. Update the relevant inclusion, copy, or
routing configuration if the checklist could currently be published, while
preserving publication of privacy-policy.md and terms-of-service.md.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: f7768d30-f026-4170-92c3-524337a02306

📥 Commits

Reviewing files that changed from the base of the PR and between 374adf2 and 6085e47.

📒 Files selected for processing (4)
  • SECURITY.md
  • legal/PUBLICATION-CHECKLIST.md
  • legal/privacy-policy.md
  • legal/terms-of-service.md

Comment thread legal/PUBLICATION-CHECKLIST.md Outdated
Comment thread legal/PUBLICATION-CHECKLIST.md Outdated
Comment thread legal/terms-of-service.md Outdated
Comment thread SECURITY.md Outdated
@kwsantiago

Copy link
Copy Markdown
Contributor

@wksantiago handoff: state of play after the review passes.

Where this stands. Three commits on top of your drafts (6085e47, 1b68bbd, 46a70ee) reconcile them with the deployed site and address both CodeRabbit rounds plus a manual audit. All 29 review threads are resolved, each with a note saying what happened. The documents are still drafts: the DRAFT banner and the attorney brackets are intentionally untouched, and nothing is linked from the site.

The single source for what remains is legal/PUBLICATION-CHECKLIST.md (33 items, each typed counsel, ops, or decision). The reviewer checklists that were at the bottom of your two documents were merged into it so they cannot ship to the public by accident.

Decisions already made (by Kyle, 2026-07-27):

  • Principal place of business is Tampa; arbitration seat moved to Hillsborough County (item 6)
  • Digital asset payments are accepted, so ToS 8.6 stays (item 26, closed)
  • Deliberately deferred, waiting on an owner: mailbox aliases privacy@/legal@ (item 4), trimming the Section 3 service list (23), per-control attestation of the Privacy Policy Section 12 security claims (14), and the ToS 12.3 confidentiality cap choice (21, the bracketed (a)/(b) block under 12.3; take it to the insurer, not just counsel)

Decision/ops items that block the attorney pass: items 3 (street address, state of formation), 4, 12-13 (retention durations and the 30-day destruction window), 14, 21, 23. None need a lawyer to answer.

Counsel items: 1 (full pass, resolve every bracket), 17 (Art. 27 reps), 18 (DPA/SCC package), 24 (arbitration and class waiver vs consumer customers), 25 (E&O/cyber coverage vs the cap AND the uncapped exceptions), 28 (bracketed periods).

Site work, part of #36 rather than this PR: HTML pages at /privacy/ and /terms/, footer links, sitemap entries, a notice-at-collection link beside the contact form (item 20), click-to-accept (29), and optionally self-hosting the web font to kill the Google Fonts IP disclosure (11).

On merging: the PR is currently a draft, so CodeRabbit is skipping it. It is merge-safe as-is since nothing publishes; marking it ready triggers CodeRabbit's final pass. The body now says Refs #36 instead of Closes #36 so merging does not close the issue while the publication tasks above are open.

@kwsantiago

Copy link
Copy Markdown
Contributor

@wksantiago answering "what is mine and what is for the attorney," because the honest answer is that most of the brackets are ours, not the attorney's.

A lawyer cannot tell us how long we keep scan output, which CRM we use, or what our payment terms are. They review the answers we supply. Handing the drafts over with the brackets empty buys an expensive round trip and a lawyer guessing at our operations.

6fb6eed adds a Who answers the brackets section at the top of legal/PUBLICATION-CHECKLIST.md that maps every single bracket in both documents to one of three groups. Counts: 60 brackets total, and only about 8 of them are genuinely the attorney's.

Group A, ours and only we know it (~35 brackets). Vendor names in the Privacy Policy 5.1 tables, every retention duration in Section 8, the 30-day destruction window, which encrypted channel we actually use for deliverables, whether our AI tool contracts really prohibit training on our input, the eleven security controls in Section 12 (yes or no on each, strike what is not in place), the hosting provider's log fields, the privacy@/legal@ aliases, who owns rights requests, our state of formation, and which Section 3 services we actually sell. No legal judgment in any of it.

Group B, ours to pick and counsel sanity-checks (~17 brackets). The commercial numbers: net 30 payment terms, 1.5% late interest, the 15-day suspension trigger, 5-year confidentiality survival, the 12-month liability cap basis, the $100 free-use cap, the 1-year claim limit, cure and notice periods, the 12-month non-solicit. We choose because it is our business; counsel confirms it is enforceable and market-standard.

Group C, genuinely theirs (~8). Whether we need EU and UK Article 27 representatives. The SCC and DPA package. Whether the arbitration clause and class action waiver survive against individual training customers, and whether we need the 30-day opt-out. Whether the caps, disclaimers, and indemnities hold up under Florida law. Plus the final pass over our Group A and B answers.

So: yes, the list in my earlier comment is ours to answer, not the attorney's. Work Group A and B first, then send the documents over. The ToS 12.3 confidentiality cap is the one item that is really a three-way conversation, and the third party is the insurer rather than the lawyer.

Also in 6fb6eed: the address is filled in. 8710 N Renfrew Pl, Tampa, FL 33604 now appears in both contact blocks and in the ToS 19.7 notices clause, replacing three placeholders. Checklist item 3 is down to the state-of-formation lookup, which is one Sunbiz search and also gives us the registered agent for the same trip.

@wksantiago

wksantiago commented Jul 30, 2026

Copy link
Copy Markdown
Contributor Author

@kwsantiago latest push (f975ecc) resolves the remaining factual brackets. Summary of this pass:

Completed

  • Vendors (PP §5.1): Proton for Business (email), Proton Meet (video), Proton Mail/Drive (secure transfer); Xero (accounting); GitHub Pages (hosting); no dedicated CRM; bank transfer + digital assets only, no card processor; sanctions-screening row struck (we don't screen today).
  • Security controls (PP §12): attested per control — kept TLS 1.2+/at-rest, MFA, least-privilege, YubiKeys, file-level encryption (Cryptomator), segregated envs, vendor review; struck monitored logging, background checks, annual training; softened IR + endpoint wording to match reality.
  • AI claim (PP §2): confirmed against Claude paid/API (no training on inputs); verify-bracket removed.
  • Custody (ToS §3/§4.1): rewritten to state we never hold production or controlling keys and only handle key material in testing/PoC — multisig signing keys stay with you and your approved third parties.
  • Service list (ToS §3): struck compliance/AML and training; narrowed CCSS to advisory/guidance only. PP training-account rows reconciled out.
  • Privacy Lead: William K. Santiago.
  • Retention numbers, commercial terms, and §12.5 deletion (void under Fla. Stat. §95.03) from the earlier pass stand.

Pending your review / decision if any and send to counsel

  • §12.3 confidentiality cap — deferred by you until counsel + insurer review (uncapped vs 3× super-cap).
  • §18.7 consumer arbitration opt-out — training struck, but self-custody-for-individuals keeps a consumer angle.
  • Counsel items: Art. 27 EU/UK reps, DPA/SCC package, money-transmitter ratification of the custody redraft, E&O/cyber coverage, Florida enforceability, MIT carve-out intent.
  • Ops build: create/monitor privacy@ + legal@, Sunbiz confirmation, subprocessor page, RoE template, click-to-accept, HTML conversion at /privacy/ and /terms/.

Full tracking in legal/PUBLICATION-CHECKLIST.md (26 open items + the deferred §12.3). DRAFT banner stays until counsel signs off.

@wksantiago

Copy link
Copy Markdown
Contributor Author

@kwsantiago pushed 2076e3e — Sunbiz confirmation + registration pointer.

Verified against the filed 2026 annual report (doc L18000284183):

  • Active, Florida LLC (formed 12/11/2018); 2026 annual report filed 01/11/2026 — current, no dissolution risk. ToS §1 "Florida limited liability company" confirmed.
  • Officers: William K. Santiago (CEO), Kyle W. Santiago (CTO).

Heads-up (no doc change needed): the 2026 report lists the principal place of business, mailing address, and registered agent as the RA's suite — 7901 4th St N Ste 300, St. Petersburg, FL 33702 (Registered Agents Inc) — not our Tampa address. You confirmed Tampa (8710 N Renfrew Pl) is the real operating address, so all docs + JSON-LD stay Tampa and arbitration stays Hillsborough County. Action for next filing: correct the PPB/mailing back to Tampa on the 2027 annual report (due by May 1, 2027) so the public record matches — if Registered Agents Inc files it for you, tell them to use the Tampa address, not theirs.

Added to the docs so we don't need yearly edits: a Sunbiz pointer in ToS §1 and a Florida Division of Corporations: sunbiz.org (Document No. L18000284183) line in both contact blocks. Registration/agent details now stay verifiable from the public record; the Tampa contact/notice address is retained (required by GDPR Art. 13 and for notices). Docs only change on an actual relocation.

Tracking in legal/PUBLICATION-CHECKLIST.md (items 3 and 6 now resolved).

@wksantiago
wksantiago requested a review from kwsantiago July 30, 2026 20:49
@kwsantiago

Copy link
Copy Markdown
Contributor

@wksantiago reviewed both commits line by line. Good calls in there, particularly deleting §12.5 (Fla. Stat. §95.03 does void a sub-one-year contractual limitations period, and the agreement is Florida-governed and Florida-seated, so it was dead weight), attesting §12 per control and actually striking monitored logging, background checks, and annual training rather than keeping them, and rewording FDE to file-level encryption because Cryptomator is file-level.

Four things the pass introduced or left behind. Three are fixed in b6990c8; one needs your call.

Fixed

Key material contradiction. PP 8 gained a row for Client credentials and key material issued to us, and PP 9 repeated it, while PP 2 says "we never want your private keys, seed phrases, key shares... we do not collect them" and ToS 5.1 says "do not transmit... by any means." Access credentials for a pentest are normal; "key material" is what collided. Since ToS 3 now says testing and PoC key material does get handled, I reconciled toward what you wrote: PP 8 and 9 now read "access credentials, and non-production test key material issued to us under a SOW," and PP 2 and ToS 5.1 each carry a matching one-sentence carve-out for SOW-provided non-production test material that never controls production assets. The never-hold-production-keys promise is intact.

Sanctions screening described in four places after the vendor row was struck. You struck the 5.1 row as "we don't screen today," but PP 3.1 still listed screening results as collected, 3.3 listed them as received from third parties, 4 gave them a legal basis, and 8 kept a 5-year retention row. Same shape as the cookie problem: the policy described a practice we do not have. All four are now explicitly conditional and point at ToS 14's "may conduct" reservation, so the reserved right survives without claiming we exercise it.

Log wording. PP 3.2 said the logs are "used for security, abuse detection, and troubleshooting" immediately before the new sentence saying GitHub does not expose them to us. Reworded so the provider is the one holding and using them.

Needs your decision

PP 8 assessment-report retention, 12 months, now conflicts with the liability window. The same pass that cut reports from 3 years to 12 months also deleted §12.5. Deleting §12.5 was right, but it restores Florida's 5-year written-contract SOL, so exposure got longer in the same commit that made evidence retention shorter. PP 9 "Findings retention" still says we keep the report "to defend against claims." At 12 months the report is destroyed with roughly 4 years of claim window left, and we would be defending a claim about an assessment whose report we deleted.

There is also a row overlap: a delivered report is arguably "engagement records and correspondence" at term + 7 years, so two rows plausibly cover the same PDF with a 6-year gap between them.

Three ways out, all yours to pick:

  • (a) Raise report retention to match the exposure, 5 years or term + 7 to align with engagement records
  • (b) Keep 12 months, delete the defend-against-claims rationale from PP 9, and accept destroying our own evidence
  • (c) Split it explicitly: short retention for raw findings data, long retention for the delivered report

Tracked at the top of the Still Open section in legal/PUBLICATION-CHECKLIST.md.

Separately

Confirming GitHub Pages as the host surfaced that _headers in this repo does nothing — it is a Netlify and Cloudflare Pages convention that GitHub Pages ignores. curl -sI https://privkey.io returns server: GitHub.com and not one of the declared headers. Clickjacking protection is missing in both places it was expected, since X-Frame-Options is not served and frame-ancestors is ignored by spec when CSP comes from a <meta> tag. Filed as #40 with options; recommend fronting Pages with Cloudflare. Noted as item 10a in the checklist because a hosting change means updating PP 5.1 and 3.2.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants