Legal · Privacy Policy
Privacy Policy
Version 2.0 · Effective July 4, 2026 · Supersedes Version 1.0 · Open Feed Network, Inc. · Wyoming C-Corp · EIN 42-2688100
Plain language summary: We designed Candor so there is almost nothing about you to protect, because we never collect it. No name, no email, no phone number, no password. Your identity is a cryptographic key that you generate and hold on your own device. Your posts and messages are stored in Iceland under European data-protection law. Our AI safety systems analyze content to keep the platform safe — not to profile you. We cannot sell what we do not have.
✦ We never collect your name, email address, phone number, or government ID.
✦ We never sell data or use it for advertising — there are no ads on Candor.
✦ We never link your identity to your real-world self; we couldn't if we wanted to.
✦ We never use safety-system analysis to profile you politically or commercially.
1. Your Identity on Candor
When you join Candor, your device generates a cryptographic keypair (ECDSA P-256) with a recovery seed phrase (BIP-39). Your public key — your candor_pub_... identifier — is your entire identity on the platform. The private key and seed phrase never leave your device and are never transmitted to us.
- We do not have accounts, emails, passwords, or password resets. If you lose your seed phrase, we cannot recover your identity — no one can, including us.
- Your chosen display name and handle are public by design and are not required to correspond to your real identity.
2. What We Store, and Where
- Your content (Iceland): Posts, replies, messages, follows, and feed data are stored on infrastructure in Iceland, within the European Economic Area, and are not replicated to United States systems.
- Safety and transparency data (United States): Content safety scores, moderation decisions, and legally mandated compliance records are processed and stored on US infrastructure.
- Network metadata (transient): Like all internet services, our servers and DDoS-protection layer (Cloudflare) transiently process connection metadata such as IP addresses to deliver the service and defend against attacks. We do not link this metadata to your platform identity or use it to build profiles.
3. AI Safety Systems
Safety is processed at the infrastructure level. By using Candor you acknowledge that:
- Posts and messages are analyzed by AI safety systems (including Truth Shield credibility scoring, Beacon crisis detection, and threat detection) before or at publication. Transparency scores may be displayed alongside content.
- Livestream audio is transcribed and analyzed in real time for terrorist and violent extremist content.
- Uploaded files are scanned against known child sexual abuse material (CSAM) using Microsoft PhotoDNA and for malware before publication.
- Content analysis is performed via third-party AI providers (Anthropic; Deepgram for transcription) under agreements that prohibit use of your content for model training. Content sent for analysis is identified only by cryptographic ID, never by personal information — because we hold none.
4. The Legally Mandated Exceptions
Three narrow categories of data leave the platform, all required by law or essential to operate:
- Child safety: We are required by 18 U.S.C. § 2258A to report apparent CSAM to the National Center for Missing & Exploited Children (NCMEC) and to preserve related evidence on US infrastructure. This is not discretionary.
- Terrorist content: Confirmed terrorist and violent extremist content may be reported and hash-shared consistent with industry counter-terrorism frameworks.
- Legal process: We respond to valid legal process. Because we hold no personal information about you, the data available to produce is limited to content and cryptographic identifiers.
5. Commercial API Customers
This section applies only to businesses purchasing Candor safety products (Truth Shield, Beacon, ThreatShield, Sentinel, Guardian Shield, Verify, and related APIs) — not to platform users.
- Payment is processed by Stripe. The contact email you provide at checkout is held by Stripe under its own privacy policy; it does not enter Candor's user systems.
- One operational contact email is stored with your commercial account, used solely for service alerts (safety circuit-breaker notifications, quota warnings, compliance flags). It is never linked to any consumer identity.
6. Confidential Tips (Truth Shield Advanced)
Source submissions through the Tips service are encrypted (AES-256-GCM) and stored exclusively on Iceland infrastructure. Submissions carry no submitter-identifying information, and quarantined material is automatically destroyed on schedule. There is no source-identifying data in our possession to disclose, in any jurisdiction.
7. Deletion
- Your choice: You may delete your posts and your identity's content at any time from within the platform.
- Victim-initiated: Content reported by an affected person and confirmed as violating is removed.
- Safety-mandated: Content flagged by safety systems as prohibited is removed, and where the law requires, preserved as evidence on US infrastructure for the mandated period.
8. Infrastructure Processors
The platform operates on: 1984 Hosting (Iceland — user content), Fly.io (US — safety and compliance processing), Cloudflare (network protection), Netlify (public website), Stripe (commercial payments), Anthropic and Deepgram (AI analysis), Microsoft PhotoDNA (CSAM detection), and LiveKit (live streaming). Each processes data solely to provide its function.
9. Children's Privacy
Candor is not directed to children under 13, and users under 18 are not permitted on the main platform. Our separate youth platform operates on fully isolated infrastructure with its own protections and policies.
10. Changes and Contact
Material changes to this policy will be announced on the platform before taking effect.
privacy@candortheopenfeednetwork.com
Open Feed Network, Inc. · Wyoming C-Corp · EIN 42-2688100