Privacy / Customer Sovereignty

Your evidence is not the hidden price of the product.

Truth Compiler needs evidence to perform an audit. That does not mean Massive Magnetics gets an unlimited license to exploit private customer material. This policy defines what we collect, what we can use to improve the product, what remains restricted, and the rights customers can exercise.

Core rule: public-source evidence and de-identified service telemetry may be used to improve Truth Compiler. Raw private repositories, personal financial records, credentials, account numbers, and other sensitive customer content are not used to train shared models or published as examples unless the customer gives separate affirmative permission.
Effective August 19, 2026

1. Scope

This policy applies to Truth Compiler, Repository Reality Audit, Business Financial Reality Audit, Personal Financial Reality Audit, Knowledge Capital Audit, remediation services, continuous governance, and related intake, checkout, report-delivery, and support workflows operated by Massive Magnetics.

Where applicable law gives you stronger rights than this policy, the law controls. Where it is operationally feasible, we extend the core access, correction, deletion, export, and restriction rights described below to all customers rather than limiting them only to residents of a particular state.

2. Data classification

PUBLIC SOURCE

Public evidence

Lawfully public repositories, public filings, published documentation, public websites, government records, and other material reasonably available to the public. We may analyze, retain references to, benchmark against, and use this material to improve or demonstrate the service, subject to applicable law, licenses, and source terms.

SERVICE DATA

Operational metadata

Checkout identifiers, timestamps, product tier, error codes, feature-use events, latency, report-quality scores, and similar operational records. We may use this information for security, billing, reliability, fraud prevention, support, measurement, and product improvement.

CUSTOMER PRIVATE

Private customer content

Private repositories, non-public business documents, unpublished inventions, internal records, customer-supplied files, and non-public audit evidence. We use these materials to provide, verify, support, and secure the purchased service. Raw private content is excluded from shared-model training and public case studies by default.

SENSITIVE

Sensitive financial / identity data

Financial-account information, bank or card statements, credentials, government identifiers, precise address information, private communications, and similarly sensitive records receive the strictest handling. They are not sold, used for targeted advertising, or reused as raw training material for shared products by default.

3. What we collect

Depending on the service, we may collect name, email, business name, repository or project URL, audit objective, requested deadline, payment and receipt references, customer-supplied files or records, audit evidence, support communications, and technical metadata needed to perform and secure the service.

Payments are processed by Stripe. We do not need customers to send us full payment-card numbers to perform an audit. Do not place passwords, secret keys, Social Security numbers, authentication tokens, or full financial-account credentials into free-text checkout fields.

4. Why we process data

5. Product improvement: the actual license

We do not claim an unlimited right to use everything a customer submits. The product-improvement license is deliberately narrower:

Customers may voluntarily authorize broader research or case-study use through a separate, specific permission. Refusing that permission does not reduce the purchased audit service.

6. No sale of customer evidence

We do not sell private customer audit evidence or sensitive financial information. The audit funnel is not designed to make customer data available to unrelated third parties for their own advertising. If this practice changes, this policy must be updated before the new use begins and applicable opt-out/consent rights must be honored.

7. Retention

We retain information only for as long as reasonably necessary for the purpose for which it was collected, contractual support, security, dispute resolution, legal obligations, and legitimate audit verification. Raw sensitive evidence should be removed after the delivery and reasonable quality/support window unless the customer requests ongoing monitoring or another lawful need requires retention. Audit receipts, hashes, findings, order records, and billing/tax records may be retained longer because they support verification, contracts, accounting, fraud prevention, or legal obligations.

Where possible, improvement datasets should retain de-identified derived measurements rather than unnecessary raw customer content.

8. Customer rights

Submit a request to bandobandz440@gmail.com with “Privacy Rights Request” in the subject. We may need to verify identity or authority before disclosing or deleting protected information.

9. Global Privacy Control and state rights

California law provides rights to know, delete, correct, opt out of sale/sharing, limit certain uses of sensitive personal information, and receive non-discriminatory treatment. Colorado law similarly provides access, deletion, correction, portability, opt-out rights and consent requirements for certain sensitive-data processing. The audit funnel is designed around data minimization and purpose limitation even when a particular statutory threshold does not apply.

If future audit pages use technology that constitutes sale, sharing, or targeted advertising under applicable law, recognized browser-based opt-out preference signals such as Global Privacy Control will be honored where required.

10. Security and customer responsibilities

We use reasonable administrative and technical measures appropriate to the nature of the service. No system can promise zero risk. Customers should provide the minimum evidence necessary for the audit, redact unnecessary secrets, use read-only access where possible, and never send authentication secrets through public forms.

Financial audit rule: never send online-banking passwords or full card credentials. A financial audit should use statements, exports, or other authorized records—not credentials that let an auditor transact on the account.

11. Public case studies

Public-source case studies may identify the public company, public repository, filing, or published artifact being analyzed and link directly to the underlying public evidence. Customer-private case studies require permission or are materially de-identified/redacted so the report does not expose the customer or confidential evidence.

12. Changes

Material changes to this policy will be posted with a new effective date. A new policy will not retroactively convert raw sensitive/private customer content into unrestricted training data. Any materially broader use that requires consent will be handled prospectively.