Privacy Policy
Effective date: July 7, 2026
Elix (domain elix.cool, "the Service") is a decentralized discussion community built on self-sovereign identity. Our design principle: data stays on your device wherever possible; what leaves your device is minimized, signed by you, verifiable, and portable. This policy explains what data is processed where, for how long, and what rights you have.
What we do not do
- No analytics, tracking, or advertising SDKs, and no third-party tracking code.
- No per-user telemetry; operational metrics are aggregate-only and cannot be tied to an individual.
- We do not collect or store your location.
- IP addresses are not written to any persistent record.
- We do not sell, rent, or share personal data with third parties for marketing.
Where data lives
Your device
- Identity private keys (Ed25519): generated and stored on your device (software custody, labeled with a custody_class), and excluded from cloud backup (noBackupFilesDir on Android, file protection on iOS). Private keys never leave your device.
- Your local database, drafts, and the Verifiable Credentials (VCs) in your wallet.
Relay
The relay stores only what you choose to make public:
- Your public DID and handle.
- Your signed public posts and operations — an append-only, tamper-evident signed log.
- Moderation records.
- Device push tokens (used only as content-free sync hints).
The relay stores no email, legal name, phone number, national ID, or location; IP addresses are not persisted.
Issuer (identity verification)
- During verification, your email and one-time passcode (OTP) are held in memory for a matter of minutes, then discarded.
- To prevent duplicate sign-ups (Sybil resistance), only a keyed, irreversible hashed commitment is kept; it cannot be reversed into your email or identity data.
- Passport NFC chip data and Taiwan MobileMoica (mobile citizen certificate) data are processed transiently during verification and never stored.
- Issued Verifiable Credentials live only in the wallet on your device; credential revocation is supported.
AppView
The AppView is a read-only projection of content that is already public on the relay, used for browsing and search. It holds no additional personal data.
When data leaves your device
Only when you choose: publishing public content, going through identity verification, or enabling push notifications. Private keys and unpublished private data do not leave the device.
Retention
| Data | Where | Retention |
|---|---|---|
| Identity private keys (Ed25519) | Your device only | Until you clear the local identity or uninstall |
| Public DID, handle | Relay | Life of the account (public record) |
| Signed public posts / operations | Relay | Removed from serving on deletion; the underlying append-only signed log is retained (see "Your rights") |
| Moderation records | Relay | Retained for governance and appeals |
| Device push tokens | Relay | Until device sign-out or token expiry |
| Email and OTP (during verification) | Issuer (memory only) | Minutes; discarded when verification completes |
| Duplicate-prevention hashed commitment | Issuer | Retained (irreversible; cannot reveal personal data) |
| Passport NFC / MobileMoica data | Issuer (transient) | Processed during verification only; never stored |
| Verifiable Credentials (VCs) | Your device wallet | Held by you; revocable |
| IP addresses | — | Not persisted |
| AppView projection | AppView | Mirrors public relay content; deletions propagate |
Your rights
- Access and portability: your public content is in a signed, portable format; you can access it at any time or take it to another compatible service.
- Deletion:
- You can clear your local identity in-app (Settings → Sign out this device), which stops this device from using the identity.
- Content you delete is removed from the AppView and other reading surfaces; deletions propagate downstream.
- Honest note: public posts on the relay are part of an append-only signed log. Deletion removes the content from every serving surface, but the underlying signed log entries are retained to preserve the integrity and verifiability of the record.
- For full account and data deletion requests, email privacy@reviz.tw; we will respond within a reasonable period. See also Account & data deletion.
- Credential revocation: issued Verifiable Credentials can be revoked.
Applicable law
We process personal data under Taiwan's Personal Data Protection Act; data subjects may exercise the rights in Article 3 (inquiry, review, copies, supplementation, correction, cessation of processing/use, and deletion). For users in the EU/EEA, the GDPR applies (legal bases: performance of contract, and your explicit consent — e.g. for identity verification). For California users, the CCPA/CPRA applies — we do not sell or share personal information. To exercise any of these rights, contact privacy@reviz.tw.
Children
The Service is not directed at children under 13. If we learn that we processed personal data of a child under 13 without the consent of a legal guardian, we will delete it promptly.
Changes to this policy
When we change this policy, we update the effective date on this page; material changes will be announced prominently in the Service. Continued use of the Service means you have read the updated policy.
Contact
Privacy questions and requests: privacy@reviz.tw