LEGAL · PRIVACY POLICY
A privacy policy needs a controller. Ours has no name yet.
A privacy policy has to say who is processing your data and under what legal basis, and the entity that would hold that responsibility for ORBIS.ID is not published yet. The formal notice — what is collected, why, for how long, and your rights over it — is being drafted with counsel. What already holds regardless of who signs that notice: a person's device generates and keeps its own signing key, and an organization's signing key lives in a vault this platform calls but does not export.
What this page is missing, named plainly.
This page depends on two things the register has no row for: a named legal entity to be the data controller, and the privacy notice itself. Both are absent, not merely unwritten.
The register holds 17 live · 2 partial · 2 planned · 5 not yet.
2 of the 2 capabilities this page depends on have no row in the register yet, so this page will not print a state for them. They are named rather than dropped, because a slice that silently shortens itself is the same defect as a claim with no receipt.
- legal-entity-name
- privacy-policy
The register route serves, but it carries no row for these yet. List what it does carry:
curl -s https://id.orbis.id/api/site/register | jq -r '.entries[].slug' A policy with no controller named in it protects the controller, not you.
Straight answers.
- Does this page make a data-protection compliance claim?
- No. That claim needs a finished policy and a named controller, and this site will not make it before both exist.
- Can ORBIS.ID read the credentials in your wallet?
- No — there is no operation in the system that hands a private key to anyone, including us. The company page names exactly what that architecture does and does not let us see.
Do not trust us. Check us.