Care of data
We protect people with clear rules and careful design. Here is what we do today — and what we are building toward.
What we do today
- Invite and trust gate — this is not an open public list.
- The map stays at city level for strangers — not street-level pins.
- Full address and how-to-find notes only after a host confirms you.
- Phone and email are not shown on the public map.
- You can delete your account. After a short wait, personal profile data is erased.
- Private DMs are encrypted at rest on our server (AES). DM emails only notify you — they never include the message body.
- Shop platform fee %, billing details, and monthly fee invoices are private — only the shopkeeper and admins see them. They are not shown on the public shop or seller pages.
- A host standing for you is per-host, not a platform-wide pass. You may see that host’s gatherings by their visibility rules — not every closed or sensitive gathering on the map. Their vouched network does not land on My Map; on Events you can choose Show network, then follow a host to add them. Ordinary hosts see connected peers, not everyone. Admin review stays a separate, named power.
- Host networks and vouches (names and a why — never scores) are visible inside a grant or a host-to-host connection when you choose Show network on Events — not as a public directory. You can hide a pin on My Map without unfollowing.
- Each host holds their own newsletter list. You opt in in the app (off by default) or a host may import addresses onto that list only. Every newsletter includes unsubscribe for that list; map access and follow can stay. Mail includes title, body, images, and links — this is not notify-only. Private DMs still use notify-only email.
- Optional: a host can create accounts and host-verify people they import, then send a map invite. That grant is for that host only. Help promote on a sensitive gathering is offered to hosts they follow; those peers choose whether to share it into their circle. Street address still waits until confirmation.
- Healers choose Open or Closed for each practice listing. Open is visible to all members at city level — not a street address, and not the public internet. Closed stays off that directory until you join a host’s circle. Hosts and admins can still see closed listings to call nearby healers.
- Ready for a next step lives on My Map, not Manage account. You choose a city, timezone, and what you are looking for. Hosts and healers you follow can see you at city level — not a street, and not a public directory.
- Applying for a gathering asks for your first and last name, after you confirm an email or phone with a login link. That name is stored on your account and shared with the host of that gathering. It is not a public directory. A host website can frame the map so visitors see that host’s open gatherings.
What we do not claim today
- This is not end-to-end encryption. Our server holds the key and can decrypt private DMs.
- Event and group chat emails may still include the message text. Host newsletters include the letter (title, body, images, links) — they are not notify-only. Profiles and other non-DM data are not encrypted at rest.
- Shop: buyers pay each seller directly. Temple of Trust tracks orders and bills shopkeepers a monthly fee % on net merchandise after refunds. We do not take the sale money through our bank. Payment instructions and billing details live on our server — not public, not encrypted at rest like private DMs.
What is NOSTR?
NOSTR is an open way to share messages using keys you can hold yourself, through relays — instead of only one company’s database. It can help keep sensitive data from living only in clear text on one server.
Today we create an identity label (called an npub) for each account, ready for that future. We do not yet send your chats or events through NOSTR encryption.
What we want next
- True end-to-end encryption for private DMs first (keys you hold — not the server).
- Then event chat: notify-only email, then stronger encryption.
- Then NOSTR: a private relay and encrypted events for sensitive ceremony data.