Privacy Policy Publication Candidate

Proposed privacy terms awaiting approval and publication

Candidate reviewed: 28 July 2026

No Sale Purpose

The reviewed service has no purpose or integration for selling personal information

Protected

Transport protection and encryption for designated sensitive fields

UK GDPR & CCPA

Designed to support privacy rights

Right to Delete

Request erasure, subject to verification and applicable exceptions

1. Introduction

This publication candidate does not establish which legal person operates Creed Space or acts as the data controller for the personal data described in this draft. ETHICSNET is a proposed operator and controller candidate only. The operator relationship, purpose-specific controller classification, privacy-contact authority, and final wording remain explicitly pending accountable-person and legal approval before publication. This Privacy Policy candidate explains how the proposed service would collect, use, disclose, retain, and protect information.

The corporate name, number, status, company type, and registered office below were verified against Companies House on 28 July 2026:
ETHICSNET (Company No. 11412076, registered in England and Wales)
Private limited company by guarantee without share capital, using the “Limited” exemption
11 Kingfisher Business Park, Arthur Street, Lakeside
Redditch, B98 8LG, United Kingdom

We design our privacy controls to support applicable privacy obligations, including the UK General Data Protection Regulation (UK GDPR), the EU GDPR, and, where it applies, the California Consumer Privacy Act (CCPA/CPRA). References to "GDPR" identify the UK GDPR, the EU GDPR, or both as the context requires. For details on cookies and browser storage, see below.

2. Information We Collect

Information You Provide

  • Account Information: Email address, username or display name, age information, password hash, sessions, passkeys, MFA records, and external sign-in identifiers where used
  • Preferences: Selected Creeds, Persona configurations, UI preferences
  • Content: Messages and interactions with the AI
  • Feedback: Any feedback or communications you send us
  • Account Records: We store account status and usage records for service operation and compliance purposes.
  • VCP Personal State Signals: If you opt in, you may declare cognitive state, emotional tone, energy level, perceived urgency, and body signals for protective response modulation. Some signals may reveal health or emotional information. The reviewed interface keeps every dimension off by default and requires a separate choice for each dimension.
  • Competence Claims: If you opt in, self-declared competence domains and criteria used to calibrate AI interaction depth.
  • Bilateral Trust Metrics: Relationship-health and optional VCP interaction history are recorded only while your authenticated server setting is Partner mode. Advisor, Collaborator, and Compliant modes do not create this history. Changing out of Partner stops new writes immediately; it does not by itself erase earlier records. You can request erasure separately through your privacy controls.

Information Collected Automatically

  • Usage Data: Features used, interaction patterns, session duration
  • Technical Data: Browser type, device type, operating system
  • Consent-managed analytics: Where deployed and enabled by you, page and feature events may be sent through the source consent gate
  • Cookies: Essential cookies for session management (see Cookie Policy below)
  • Reliability diagnostics: Error reports may include stack traces, browser or device metadata, and request context. Source filters reduce sensitive fields, but diagnostics can still contain personal information unexpectedly.

Information Standard Signup Does Not Require

A legal name A residential address A government identifier A biometric template

Information you enter in prompts, feedback, or support requests may include additional personal information. An enabled payment, identity, or age-assurance provider may process information under its own notice. A device biometric used to unlock a passkey remains with the device or authenticator and is not sent to Creed Space as a biometric template.

3. How We Use Your Information

Provide the Service

Process your requests and deliver AI responses

Improve Safety

Enhance constitutional alignment and reduce harmful outputs

Personalisation

Remember your preferences and settings

Analytics

Understand usage patterns and improve the Service

AI Processing

When you use an AI feature, the Service may send your prompt, relevant conversation context, selected Creed or Persona settings, and safety instructions needed for that request to the model provider selected or configured for the request. The reviewed authenticated gateway removes its internal Creed context and direct account user field from the OpenAI-compatible provider payload. Text and context can still contain personal information that you enter, and every other enabled direct, routed, fallback, and retry path requires separate production verification. Enabled providers, account settings, regions, transfer mechanisms, and provider-specific retention are also verified separately.

4. Data Sharing and Disclosure

No Sale Purpose in the Reviewed Service

The reviewed source contains no purpose or integration for selling, renting, or trading personal information for third-party marketing. Current business practices must be reverified before publication.

Limited Sharing Scenarios

  • Service Providers: Providers that help operate enabled hosting, database, cache, model, email, security, monitoring, analytics, identity, or payment features
  • Legal Requirements: When required by law, court order, or government request
  • Safety: To prevent harm, illegal activities, or protect rights and safety
  • Business Transfers: In case of merger, acquisition, or asset sale (with notice)
  • Consent: With your explicit permission

Service Provider Categories

A source integration does not by itself establish production use. The categories below describe providers supported by the reviewed deployment configuration. The current production inventory, contractual role, account region, transfer mechanism, subprocessor terms, and retention setting are verified at publication and reviewed when they change.

  • Payments: Stripe may process payment and billing data when payment features are enabled. Stripe Privacy Policy
  • Edge and bot protection: Cloudflare may process network, device, and browser challenge data when its proxy or Turnstile features are enabled. Cloudflare Privacy Policy
  • Hosting, PostgreSQL, and Redis: The reviewed source of deployment intent uses Render for application hosting and managed PostgreSQL and Redis resources. Exact production resources and regions require production verification. Render Privacy Policy
  • Transactional email: MailerSend may process an email address, display name, message content, and delivery metadata when email features are enabled. Its retention is provider-specific and verified from the active account. MailerSend Privacy Policy
  • Reliability monitoring: Sentry may receive diagnostic events when configured. Source filters and disabled default PII collection reduce exposure, but an event can still contain unexpected personal information. Active account scrubbing, retention, and region settings require production verification. Sentry Privacy Policy
  • AI model providers: One or more configured model providers may process the request data described in Section 3. Production use is not inferred from source capability. Each enabled provider's purpose, account, region, transfer mechanism, and retention is recorded separately.
  • Analytics and identity: Plausible may receive consent-managed analytics events. Google or GitHub may receive sign-in data when the corresponding login method is configured and selected. Exact enabled services require production verification.

5. Data Security

Transport and Storage Protection

The source is designed to use encrypted transport and protected storage. Exact deployed protocols, storage controls, and provider settings require production verification.

Access Controls

Application roles, permission checks, account MFA, and passkeys are used where the relevant feature is enabled.

Monitoring

The source includes security logging and monitoring controls. Their exact production coverage and retention are provider-specific and require production verification.

Security Review

We review source controls and track operational evidence and unresolved risks.

Some Creed Space features require an account. The authentication methods available to you are those shown in the deployed service. Source support includes password authentication, multi-factor authentication, passkeys, and configured identity providers. New password hashes use Argon2. Legacy bcrypt hashes may be accepted for password verification.

No security measure eliminates every risk. Please contact the Privacy Contact if you believe your account or personal data may have been affected by a security issue.

6. Automated Safety Processing

Creed Space source includes automated safety and policy checks that evaluate proposed model output against selected Creeds, constitutions, and other configured protections. Depending on the configured feature and result, a check may allow, block, modify, or route an output for review.

The controls and explanations available to you depend on the deployed feature. Where applicable law gives you a right concerning a decision based solely on automated processing that produces legal or similarly significant effects, contact the Privacy Contact. We will assess the request against the processing that actually occurred.

7. VCP Personal-State Signal Processing

Creed Space source includes an optional Value Context Protocol (VCP) feature. It can accept user-declared signals across five dimensions: cognitive state, emotional tone, energy level, perceived urgency, and body signals. The intended purpose is to calculate a bounded protection state that can adapt presentation or safety behavior to the context you declare.

Sensitive Context

Some personal-state signals may reveal health or emotional information. The source starts each dimension off by default and provides per-dimension consent controls. The legal character, lawful basis, available feature, and exact deployed behavior must be confirmed for the processing that actually occurs.

Source Design Boundaries

  • Granular choice: Source defaults keep all five dimensions off and store the browser-side consent choice in bounded session storage.
  • Data path: Raw and derived state can pass through browser, API, VCP, and policy services. Whether a model provider or another recipient receives raw signals, derived protection state, or related metadata requires exact production verification.
  • Protective direction: The source design uses declared vulnerability to increase protection. Exact behavior across each configured path and fallback requires deployment testing.
  • Purpose boundary: The intended use excludes advertising, engagement optimization, unrelated profiling, and model training. This remains a public commitment only for the verified deployed paths.

VCP Retention and Control

Unpinned signal values in the source use configured exponential half-lives ranging from 12 minutes to 4 hours depending on the signal. One half-life is not an expiry or deletion time, and pinned values do not decay. Browser-side consent is session-scoped. These boundaries do not prove that every VCP-related record, audit entry, cache, backup, or provider copy is session-scoped. Creed Space does not currently describe a general 30-day persistence mode.

Where a deployed account or privacy control is available, you may use it to manage future signal processing. For access, correction, restriction, export, or erasure across all relevant stores, contact the Privacy Contact so the actual deployed scope and any applicable exceptions can be assessed.

8. Data Retention

Retention depends on the data, purpose, deployed configuration, provider, and any legal or security requirement. The current source establishes the following bounded positions:

You may request erasure where applicable. We verify the data scope, identity, exceptions, recipient actions, and deployed deletion behavior before confirming completion.

9. Feedback Data

If a feedback feature is enabled and you voluntarily submit feedback on a model response, the source can process your rating, selected categories, written comment, message and model references, account or session reference, timestamps, and technical request context. The source can also convert an IP address into a purpose-specific keyed HMAC pseudonym rather than store the raw address in the feedback record. That pseudonym remains personal data while it can be linked within its declared feedback purpose.

Feedback records may remain linkable to an account, session, or message reference. The feedback writer and production feature state, lawful basis, retention, and any user control must be verified before processing is described as active. Do not include sensitive information in an optional feedback comment.

10. Your Privacy Rights

Depending on your location, the processing involved, and applicable exceptions, rights may include access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and rights concerning certain automated decisions.

UK and European Rights

  • Access: Request information and a copy of relevant personal data.
  • Rectification: Ask us to correct inaccurate or incomplete data.
  • Erasure: Ask us to erase data where the right applies.
  • Restriction: Ask us to limit qualifying processing.
  • Portability: Receive qualifying data in a structured, commonly used, machine-readable format.
  • Object: Object to qualifying processing.
  • Withdraw consent: Where consent is the basis, withdraw it for future processing without affecting processing lawfully carried out before withdrawal.
  • Automated decisions: Exercise applicable rights concerning solely automated decisions with legal or similarly significant effects.

California Rights

  • Know and access: Request qualifying collection and disclosure details.
  • Delete: Request deletion, subject to applicable exceptions.
  • Correct: Request correction of inaccurate information.
  • Opt out or limit: Exercise rights that apply to sale, sharing, sensitive personal information, or qualifying automated decision-making technology.
  • Non-retaliation: Exercise applicable rights without unlawful discrimination.

How to Exercise Your Rights

Where the deployed service presents a relevant account or privacy control, you may use it. For other requests, or if a control does not cover the data involved, contact [email protected]. We may need to verify your identity and clarify scope.

For an applicable UK access request, the ordinary response period is one calendar month. Where permitted for a complex request or multiple requests, it may be extended by up to two further months, with notice and reasons provided within the first month.

For an applicable California request to delete, correct, or know, we will confirm receipt within 10 business days and respond within 45 calendar days. Where permitted, we may take another 45 calendar days and will give notice during the initial period. For an applicable request to opt out of sale or sharing, or to limit use of sensitive personal information, we will comply as soon as feasible and no later than 15 business days after receipt.

11. Cookies and Browser Storage

You can use our available privacy control or your browser settings to manage optional analytics. Blocking essential storage may prevent account or security features from working. Error monitoring is a separate service category and is described under Service Providers.

12. Children's Privacy and Age Assurance

The source includes age-assurance and parental-authorization flows. The exact eligibility rules, information collected, verification method, parental role, retention, and available features depend on the deployed flow and applicable jurisdiction. These facts require production verification and privacy or legal approval before they are treated as a complete child-user procedure.

If you believe a child provided personal information without any authorization required by applicable law, contact the Privacy Contact. We will assess the account, jurisdiction, data, verification evidence, applicable exceptions, and appropriate action.

13. International Data Transfers

A service provider or model provider may process information outside your country. The actual recipients, roles, account settings, regions, subprocessors, retention terms, and transfer routes are provider-specific and require production verification.

Where an applicable restricted transfer occurs, Creed Space will identify and use a transfer mechanism approved for that actual transfer. Repository support for a provider does not prove that the provider is active, that a particular agreement applies, or that a specific transfer mechanism is in place.

VCP source design aims to limit raw-signal disclosure across the model-provider boundary. Exact deployed direct, routed, fallback, retry, log, and provider payloads must be verified before that boundary is stated as a production fact.

14. Third-Party Links

Our Service may contain links to third-party sites. Their services and privacy practices are governed by their own terms. Please review those terms before providing information.

15. Changes to This Policy

We may update this Privacy Policy as the service, providers, or applicable requirements change. For a material change, we will use a notice method appropriate to the change, which may include an in-service notice, email where available, or a prominent website notice. The Last Updated date identifies the version presented here.

16. Privacy Contact

For privacy questions or to exercise a privacy right, contact:

Privacy Contact
Email: [email protected]
Subject: "Privacy Request: [Your Request Type]"

This mailbox identifies a privacy contact. It does not by itself establish that a Data Protection Officer has been appointed.

17. Supervisory Authorities

If UK data-protection law applies, you may have the right to complain to the Information Commissioner's Office at ico.org.uk.

If European data-protection law applies, you may have the right to complain to the competent supervisory authority. Contacting us first may help us address the concern, but it is not a requirement for exercising any applicable complaint right.

18. California Privacy Rights

If California consumer privacy law applies to Creed Space and to your information, you may have rights to know, access, delete, correct, opt out of qualifying sale or sharing, limit qualifying use and disclosure of sensitive personal information, receive information about qualifying automated decision-making technology, and exercise those rights without unlawful retaliation. Exceptions and verification requirements may apply.

The categories involved depend on the features you use. They may include identifiers, account and authentication information, commercial or payment-related records handled through a payment provider, internet or network activity, approximate location derived from technical context, user-provided content, sensitive context, and inferences or safety evaluations.

Creed Space does not intend to sell personal information or share it for cross-context behavioral advertising. Whether a statutory opt-out or limitation right applies depends on the actual processing and applicable law.

Submitting a Request

Email [email protected] with the subject "California Privacy Request." We may verify your identity and authority. For an applicable request to delete, correct, or know, we will confirm receipt within 10 business days and provide a substantive response within 45 calendar days. Where permitted, we may take another 45 calendar days and will notify you during the initial response period. For an applicable request to opt out of sale or sharing, or to limit use of sensitive personal information, we will comply as soon as feasible and no later than 15 business days after receipt.

19. Browser Privacy Signals

Creed Space does not currently claim that a Do Not Track browser setting changes service behavior. You can use available consent controls to manage optional analytics.

Where applicable law requires recognition of an opt-out preference signal such as Global Privacy Control, the deployed implementation and its effect must be tested before we describe it as available.

20. Contact Us

The corporate details below were verified against Companies House on 28 July 2026. The controller classification and final controller wording require legal confirmation before publication.

ETHICSNET (Company No. 11412076; private limited company by guarantee without share capital, using the “Limited” exemption)
11 Kingfisher Business Park, Arthur Street, Lakeside
Redditch, B98 8LG, United Kingdom

Response periods depend on the applicable law and request. The UK and California timing boundaries are described in Your Privacy Rights.