Legal · Privacy

Privacy Policy

How information is handled across the public website, application process, approved workspace, and governance systems.

This page is app-owned editable content describing current platform practices. It is not an independent certification and does not promise specific regulatory compliance outcomes.

01

Overview

This Privacy Policy explains how KRYOS-XS Hypercube handles information through the public website, application process, approved workspace, vector-store tools, OSINT request workflows, digital twin tools, evidence governance systems, reporting tools, audit logs, and public-proof features.

The platform is designed for sensitive work. Privacy, redaction, access control, and data minimization are core operating principles.

02

Information we may collect

We may collect:

  • Organization information
  • Applicant information
  • Contact information
  • User profile information
  • Workspace activity
  • Uploaded files
  • Prompts and requests
  • Vector-store configurations
  • Digital twin settings
  • Generated outputs
  • Audit log events
  • Release gate decisions
  • Access permissions
  • Security and technical logs
  • Device and browser information
  • Application review information
03

Sensitive information

Users may upload or generate sensitive material, including:

  • Conflict-zone documentation
  • Legal materials
  • Witness summaries
  • Child-related information
  • Survivor-related information
  • Medical or humanitarian information
  • Research files
  • Field reports
  • Source materials
  • Public-source captures
  • Donor reports
  • Program documents

Users are responsible for ensuring that they have the right to upload and process such information.

04

How information is used

Information may be used to:

  • Review applications
  • Create organization workspaces
  • Authenticate users
  • Operate private vector stores
  • Operate shared knowledge blocks
  • Parse and classify documents
  • Generate evidence objects
  • Score claims
  • Detect contradictions
  • Build digital twins
  • Run scenario workflows
  • Generate legal, humanitarian, donor, and public-proof outputs
  • Apply redaction and release controls
  • Maintain audit logs
  • Investigate misuse
  • Improve safety, reliability, and accessibility
  • Protect users, sources, witnesses, survivors, children, and affected communities
05

Vector stores and embeddings

Uploaded or approved materials may be processed into embeddings or vector representations so the platform can retrieve, compare, classify, and analyze content.

Private vector stores are restricted to authorized users and organizations unless the user or applicable grant terms authorize shared use.

Community Knowledge Blocks may be made available to other approved users under the Community Knowledge Block Policy.

06

Community Knowledge Blocks

Some user-created or platform-created vector stores may become Community Knowledge Blocks. These are intended to help approved activists, NGOs, researchers, legal teams, and humanitarian actors avoid duplicated work and benefit from shared public-interest knowledge.

Sensitive, privileged, child-related, survivor-related, witness-sensitive, private-source, or legally restricted information should not be included in a Community Knowledge Block unless properly redacted, authorized, and approved for that use.

07

Sharing

Information may be shared with:

  • Authorized users in your organization
  • Approved collaborators you authorize
  • Platform administrators
  • Security, hosting, infrastructure, and technical service providers
  • Reviewers involved in access or compliance review
  • Other approved users if material is part of a Community Knowledge Block
  • Legal or regulatory authorities when required by law or necessary to protect safety, rights, or platform integrity

We do not sell user data.

08

Public-proof outputs

Public-proof outputs are intended for external release only after review. These may include redacted summaries, proof panels, public reports, citations, FAQs, or public knowledge assets.

Users must not publish sensitive information unless release is authorized and appropriate.

09

Data retention

Information may be retained as needed to operate the platform, maintain evidence lineage, preserve audit logs, support legal or compliance obligations, enforce Terms, maintain security, and support grant-related reporting.

Some audit records may be retained even after content is removed, where necessary for integrity, safety, compliance, or dispute review.

10

Security

The platform is designed with security and access control in mind. Security measures may include authentication, role-based access, workspace isolation, audit logging, privacy classification, redaction controls, and release gates.

No system can guarantee absolute security. Users must avoid uploading materials that they are not authorized to process or that would create unacceptable risk if exposed.

11

User responsibilities

Users must:

  • Use appropriate privacy classifications
  • Avoid uploading unauthorized sensitive data
  • Protect account credentials
  • Review outputs before sharing
  • Follow release status restrictions
  • Redact sensitive material before publication
  • Respect child, survivor, witness, source, and community safety
  • Report suspected misuse or unauthorized access
12

Children and survivor data

The platform may process child-related or survivor-related material only where lawful, necessary, authorized, and consistent with applicable protection duties.

Such material should be classified as sensitive and must not be made public unless redaction, consent, legal review, and safety requirements are satisfied.

13

International use

The platform may be used by organizations across different jurisdictions. Users are responsible for complying with laws and obligations that apply to their organization, data, location, and mission.

14

Access, correction, and deletion

Authorized users may request access, correction, restriction, or deletion of certain information where applicable. Some records may be retained when necessary for audit, legal, security, compliance, or platform integrity reasons.

15

Changes to this Privacy Policy

This Privacy Policy may be updated from time to time. Continued use after changes means you accept the updated policy.

16

Contact

Privacy questions, access questions, security concerns, or data handling concerns may be submitted through the platform contact channel.