DRAFT FOR LEGAL REVIEW. NOT FINAL. NOT LEGAL ADVICE. Drafted on 2026-10-03 by an AI agent from the terminal's source code (vxc/vxweb/src/auth.rs, accounts.rs, lib.rs, render/wl.rs, render/shell.rs, render/wheel.rs) and release/phase2n-accounts/OPERATOR-ACCOUNTS.md. It describes what the code does as of the phase2n release (not yet deployed at the time of drafting). It has not been reviewed by a lawyer and must not be published as final. Square-bracket items are placeholders or notes for counsel and the operator; remove every one before publication. Re-check the facts against the code at every release.
Last updated: [DATE]
This policy explains how [ENTITY NAME] ("we", "us") handles personal information when you use the VX Convergence terminal at terminal.vxconvergence.com and related websites (the "Service"). We are the party responsible for that information. [COUNSEL: contracting entity not yet decided; the operator's parent company may be North South Industries, but that is undecided.]
Contact: [CONTACT EMAIL], [POSTAL ADDRESS], South Dakota, USA.
When you redeem an invite and create an account we store, in our account database:
| item | what it is |
|---|---|
| user name | 3 to 64 characters you choose; it may be your email address. Stored in lower case. |
| password | never stored as typed. We store only a one-way hash made with argon2id, a slow password-hashing method designed to resist guessing. We cannot see or recover your password. |
| tier | your access level (for example beta or paid) |
| enabled flag | whether the account is active or suspended |
| created | when the account was created |
| last sign-in | when you last signed in successfully |
| access end date | if your access is set to end on a date |
| welcome flag | whether you have seen the one-time welcome message |
| note | a short internal note we may write (for example who an invite was for) |
For each invite or password-reset link we store a hash of the link (never the link itself), the tier, when it was created and expires, who created it, whether and when it was used and by which account, whether it was revoked, and a short internal note. Links are single use and expire after 1 to 30 days (reset links 2 days by default).
When you sign in we create a random session token. We store only a hash of it, with your user name, when the session was created and when it expires (72 hours later). Signing out ends the session.
When you create an account, and again whenever we change the Terms, we ask you to confirm that you agree to the Terms of Service and this Privacy Policy. We record your user name, the version of the terms you accepted, the date and time, and your IP address as reported by our web server, and we write a line to the security log. We keep this record for as long as your account exists and for [RETENTION PERIOD] after it ends, because it is our evidence that you accepted the terms.
We keep a security log with one line per account event. Each line records: the time, the event type, the user name involved, the client IP address as reported by our web server, and a short detail. Events recorded are: account setup, successful sign-in, failed sign-in, sign-in blocked (account disabled or access ended), sign-in throttled, sign-out, invite created, redeemed, rejected or revoked, password-reset link issued, password reset, password changed or failed change, account disabled or enabled, tier changed, and sessions ended. No password or token is ever written to this log.
To stop password guessing, we count failed sign-in attempts per IP address. Ten failures from one address within 15 minutes block that address for the rest of the 15-minute window. These counts are held only in the server's memory, not written to disk, and are lost on restart; a throttled attempt is also recorded in the security log (3.4).
[OPERATOR TO CONFIRM BEFORE PUBLISHING: the terminal application itself does not log page requests, but the web server in front of it (nginx) and the hosting provider may keep standard access and error logs that include IP address, date and time, the page requested, response code and browser user agent. State here whether access logging is on, what it records, and how long it is kept, or switch it off.]
During the paid beta we bill by [invoice / hosted payment link]. We keep the billing contact name, email,
[company name, billing address, tax identifiers if provided], amounts, invoice numbers and payment status. Card and bank details are entered on the payment provider's own pages and are processed by that provider; they do not pass through or get stored on our servers. The provider handles them under its own privacy policy: [PROVIDER NAME AND LINK, once chosen].
If you email or otherwise contact us, we keep the message and your contact details to respond and to keep a record. [OPERATOR: name the support channel once chosen.]
We do not use analytics or advertising services, tracking pixels, fingerprinting, or third-party fonts or scripts in the terminal. The terminal's pages are served with a content security policy that blocks third-party resources. We do not collect payment card numbers, government identifiers, or precise location. We do not record which screens or series you view against your account. [OPERATOR: keep this statement true; revisit before adding analytics, email, server-side watchlists or API keys.]
| name | type | purpose | lifetime |
|---|---|---|---|
vxsess | cookie | keeps you signed in; holds a random session token | 72 hours (Max-Age 259200 seconds), or until you sign out |
vxwl | browser local storage | your watchlist (the series you starred) | until you clear it in your browser |
vxclosed | browser local storage | which groups you collapsed on the wheel screen | until you clear it in your browser |
The terminal sets exactly one cookie, vxsess. It is a strictly necessary first-party cookie, set when you sign in (and when you redeem an invite or change your password) with these attributes: HttpOnly (scripts cannot read it), Secure (sent only over HTTPS), SameSite=Strict (not sent with requests from other sites), Path=/, Max-Age=259200. Signing out replaces it with an empty cookie that expires immediately.
Protection against cross-site request forgery (CSRF) does not use a cookie. Forms that change your account carry a hidden value derived from your session token; it is checked on submission and is not stored anywhere.
The watchlist and collapsed-group settings are kept only in your browser's local storage. The terminal does not store them on our servers, so they do not follow you to another browser or device, and clearing your browser data removes them.
[COUNSEL: confirm that no cookie banner or consent is needed for a single strictly necessary session cookie and functional local storage, in particular if EU/UK users are admitted (ePrivacy rules).]
| purpose | information used | [GDPR legal basis: COUNSEL TO CONFIRM IF GDPR APPLIES] |
|---|---|---|
| create and run your account, sign you in, apply your tier and access dates | 3.1 to 3.3, cookie | performance of our contract with you |
| keep the Service secure: stop password guessing, investigate misuse, enforce the Terms (for example no shared logins) | 3.4 to 3.6 | legitimate interests in security and fraud prevention |
| bill for paid plans and keep financial records | 3.7 | contract; legal obligation (tax and accounting records) |
| answer your messages and send service notices (for example changes to the Terms) | 3.1, 3.8 | contract; legitimate interests |
| comply with law and respond to lawful requests | any, as required | legal obligation |
We do not use your information for advertising, profiling or automated decisions that have legal or similarly significant effects on you.
We do not sell your personal information and do not share it for cross-context behavioural advertising. We share it only with:
Data publishers whose data appears in the Service do not receive any information about you.
| information | how long |
|---|---|
| account record | while your account exists. Accounts that are suspended or whose access has ended are not deleted automatically. After you ask us to close your account we delete it within [30] days, except what we must keep for legal, tax or security reasons. |
| sessions | 72 hours from sign-in, or until you sign out. Expired session records are removed from the database when new sessions are created. |
| invite and reset links | [OPERATOR/COUNSEL: currently kept indefinitely; propose deleting used, expired or revoked link records after [12] months.] |
| security log (with IP addresses) | [OPERATOR/COUNSEL: there is currently no automatic rotation; the log grows by a few hundred bytes per sign-in. Propose keeping [12] months, then deleting or anonymising IP addresses.] |
| sign-in throttle counts | up to 15 minutes, in memory only |
| web server logs | [OPERATOR TO CONFIRM; see 3.6] |
| billing records | as long as tax and accounting law requires, generally [7] years |
| backups | the server's nightly backups are kept for up to [14] days. [OPERATOR: the account database is not yet included in off-site backups; an encrypted off-site backup is planned. Update this row when settled.] |
In plain terms:
No system is perfectly secure. If we learn of a security breach affecting your personal information, we will notify you and the authorities where the law requires. [COUNSEL: South Dakota's data breach notification law and those of users' home states.]
You can:
Send requests to [CONTACT EMAIL]. We will confirm the request comes from the account holder (for example by asking you to sign in) before acting, and we will answer within [30] days.
[COUNSEL: whether GDPR or UK GDPR applies (only if users in the EU/UK are admitted or targeted), and if so add the rights to object, restrict, data portability, withdraw consent, and to complain to a supervisory authority, plus an Article 27 representative question. Whether the California Consumer Privacy Act or other US state privacy laws apply given our size (likely below thresholds at beta scale, but to confirm), and if so add the required notices. See COUNSEL-QUESTIONS.md Q6.]
We are based in the United States and the Service is hosted in the United States. If you use it from elsewhere, your information is processed in the United States, where data protection law may differ from yours. [COUNSEL: transfer mechanism if GDPR applies.]
The Service is not directed to children and is for people aged 18 or over. We do not knowingly collect information from anyone under 18. If you believe a minor has an account, contact us and we will delete it.
We may update this policy. We will post the new version with a new "Last updated" date and, for material changes, tell you in advance by [email / a notice in the terminal].
[ENTITY NAME]
[POSTAL ADDRESS], South Dakota, USA
[CONTACT EMAIL]