# PRIVACY POLICY

**TenkaSystem Installer and Tenka System Software**

**Effective Date:** May 9, 2026
**Version:** 1.0
**Operator:** Tenka Software Studio ("Tenka," "we," "us," or "our")
**Contact:** privacy@tenkasystem.com | PO Box 62, Hoytville, OH 43529

---

## 1. INTRODUCTION

This Privacy Policy describes how Tenka collects, uses, discloses, and protects information in connection with the TenkaSystem Installer, the Tenka Window host application, the Tenka command-line interface, the graphical user interface, the tenkasystem.com website, and any related services (collectively, the "Services").

This Policy applies to natural persons who install or use the Services. It does not apply to data You process using the Services that is not transmitted to Tenka.

By installing or using the Services, You agree to the practices described in this Policy. If You do not agree, do not install or use the Services.

---

## 2. INFORMATION WE COLLECT

### 2.1 Information You Provide During Installation

To generate Your TSAIF Anchor and create Your account, the Services collect:

- Identity inputs: first name, last name, optional nickname, suffix, pronouns, cultural origin selection
- Account credentials: email address, password (stored only as a salted hash on our backend), preferred username, preferred workspace name
- Geographic input: city, region, or country of residence (as You provide it)

### 2.2 Information Generated by the Services

When You use the Services, the following information is generated:

- **TSAIF Anchor metadata.** A Genesis Unique IDentification value (deterministically derived from Your name inputs via SHA-256), an Ed25519 public key, and metadata fields. The corresponding Ed25519 private key is generated and stored locally on Your device and is not transmitted to Tenka.
- **Chain entries.** Hash-chained records of operations You perform, including operation type, timestamp, target file metadata (filename, hash, size), reference codes, and the cryptographic hash of the prior chain entry. Chain entries are stored locally; certain operations transmit chain entry metadata to our backend (see Section 2.3).
- **Signatures and provenance metadata.** Cryptographic signatures, public key fingerprints, and embedded provenance metadata produced when You sign files or write provenance into supported file formats.
- **Session data.** Session identifiers, command history (locally), substrate version, and Tenka Window host version.

### 2.3 Information Transmitted to Our Backend

The following Services features transmit data to Tenka's backend:

- **Account creation and email verification.** Email address, hashed password, username, workspace name, TSAIF GUID, public key, and verification codes.
- **Authentication.** Session tokens, refresh tokens, and login timestamps.
- **Peer attestation requests (`tenka request`).** Sender TSAIF GUID, recipient TSAIF GUID, request payload, and signed attestation responses.
- **Session export with email delivery.** The signed boundary manifest content, recipient email address, and delivery metadata.
- **Signed pings (`tenka ping`).** The target endpoint URL, request method, response status and headers, body excerpt (truncated to a configurable maximum), and the resulting signed chain entry.
- **Credentials card generation.** Card payload, QR code content, and the verification link the substrate endpoint resolves.

### 2.4 Information Collected Automatically

When You use the Services, we may automatically collect:

- **Log data.** IP address, browser type (for the website), operating system, device identifiers, request timestamps, and error logs.
- **Usage data.** Feature engagement, command frequencies, session length, and error rates.
- **Cookies and similar technologies (website only).** Where Tenka publishes a Cookie Policy, it will be available at tenkasystem.com/cookies.

### 2.5 Information We Do Not Collect

Unless You explicitly invoke a feature that transmits content (such as session export with email delivery, or a signed ping that targets a URL You choose), the Services do not transmit to Tenka:

- The content of files You sign, verify, or process locally;
- Your Ed25519 private key;
- The full contents of Your local chain entry directory beyond what is captured by features You explicitly invoke;
- The content of PowerShell commands executed in terminal mode.

*[REVISION NOTE for Hunter: §2.5 is the most legally exposed disclosure in the document bundle. The "we do not transmit file content" commitment must align exactly with how the code behaves. Confirm during review that the eight CLI commands operate as described and that no future feature additions silently change this behavior without policy updates.]*

---

## 3. HOW WE USE INFORMATION

We use the information described above for the following purposes:

**3.1 Provide the Services.** Create and authenticate Your account, generate Your TSAIF Anchor, deliver email verification codes, route peer attestation requests, deliver session exports, and operate substrate-gated features.

**3.2 Secure the Services.** Detect and prevent fraud, account abuse, unauthorized access, and security incidents; investigate violations of our Terms of Service or EULA.

**3.3 Maintain and Improve the Services.** Monitor performance, diagnose errors, fix bugs, and develop new features.

**3.4 Develop and Improve AI and Substrate Models.** Process Operational Data (as defined in the EULA) to develop, train, evaluate, and refine artificial intelligence and machine learning models, governance automations, and substrate functions that are part of Tenka's products and services. See Section 4 below.

**3.5 Communicate with You.** Send transactional messages (verification codes, security alerts, service notices) and, where You have opted in, marketing communications.

**3.6 Conduct Research and Analytics.** Aggregate and de-identify data to analyze usage patterns and publish research.

**3.7 Comply with Law.** Meet legal, regulatory, and audit obligations; respond to lawful requests from government authorities; enforce our agreements; protect the rights, property, and safety of Tenka, our users, and the public.

**3.8 Legal Basis (Users in the EEA, UK, and Similar Jurisdictions).** We process personal data under the following legal bases:

- **Performance of a contract:** to provide the Services You requested;
- **Legitimate interests:** to secure, maintain, and improve the Services;
- **Consent:** where required, including for certain AI training uses and marketing;
- **Legal obligation:** to comply with applicable law.

---

## 4. AI AND MODEL TRAINING

**4.1 Purpose.** Tenka develops artificial intelligence and machine learning systems intended to operate within the Tenka substrate. To support that development, we may process Operational Data generated by Your use of the Services.

**4.2 What We Use.** For AI training and model improvement, we may use:

- Operation metadata (operation type, timestamp, target file metadata such as filename, hash, and size, but not file content);
- Chain entry structure and hashing patterns;
- Session-level usage patterns and command sequences;
- De-identified or aggregated TSAIF metadata;
- Reference codes and substrate version markers.

**4.3 What We Do Not Use.** Unless You explicitly invoke a feature that transmits content to us, we do not use the content of Your local files, the content of Your PowerShell commands, or Your private key material for AI training. We do not use account credentials, payment information (if collected by future paid tiers), or precise location data for AI training.

**4.4 De-identification.** Before using Operational Data for AI training, we apply commercially reasonable de-identification or aggregation consistent with industry-standard practices, so that the data does not identify You as a natural person. We do not attempt to re-identify de-identified data except as required by law.

*[REVISION NOTE for Hunter: §4.4 no-re-identification commitment is industry standard. Confirm Tenka's actual operational practice matches this commitment, particularly that no internal personnel have access to both de-identified data and user-identifying tables in a manner that would allow re-identification through join operations.]*

**4.5 Opt-Out.** Where required by applicable law (including the GDPR, CCPA/CPRA, and similar regimes), You may opt out of the use of Your data for AI training by contacting us at optout@tenkasystem.com. Opt-out does not affect (a) processing necessary to provide the Services, (b) processing required by law, or (c) data already incorporated into trained models, which cannot be selectively removed from a model after training.

**4.6 Model Ownership.** Trained models, weights, embeddings, fine-tuned variants, and derivative datasets are owned by Tenka. Your underlying personal data remains subject to the rights described in Section 7.

*[REVISION NOTE for Hunter: §4.6 model-ownership clause is standard for vendors but may be contentious in EU, Brazil, and Quebec where user-data rights frameworks differ. Confirm enforceability per-jurisdiction.]*

**4.7 No Sale of Personal Data for Training.** We do not sell Your personal data to third parties for the purpose of training their AI models.

**4.8 Paid-Tier and Token-Based Exemption.** Users with active paid-tier accounts, token-gated access, or cross-system memberships may be exempted from the AI training data uses described in this Section to the extent set forth in their specific tier agreement or membership terms. Exemption applies prospectively from the start of the paid relationship; data processed prior to exemption activation is subject to the retention rules in Section 6.

---

## 5. HOW WE SHARE INFORMATION

We share information only as described below.

**5.1 Service Providers.** We share information with vendors who help us operate the Services, including:

- **Supabase** (database hosting)
- **Railway** (backend application hosting)
- **Vercel** (frontend website hosting)
- **SendGrid** (email delivery for verification codes and substrate-gated messaging)

These vendors process information only on our behalf and under contractual confidentiality and security obligations. A current list of sub-processors is maintained at tenkasystem.com/subprocessors.

**5.2 Peer Attestation (`tenka request`).** When You initiate a peer attestation request, we transmit Your sender TSAIF GUID, public key fingerprint, and request payload to the recipient You designate. When You accept an incoming request, Your signed attestation is returned to the requester.

**5.3 Recipients of Your Shared Artifacts.** When You export a session, share a credentials card, or publish a signed file, the recipient receives the information You chose to include. Tenka has no control over how recipients use that information.

**5.4 Verification Requests.** When a third party verifies a signature, provenance marker, or credentials card against our backend, that verification request and its result are processed by our backend; we may log verification attempts for security and audit purposes.

**5.5 Legal Compliance and Safety.** We may disclose information to comply with law, respond to lawful requests from public authorities, enforce our agreements, prevent fraud or abuse, protect the rights, property, or safety of Tenka, our users, or the public, or in connection with an investigation of suspected illegal activity.

**5.6 Business Transfers.** If Tenka is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction. We will notify You of any such transfer through the Services or by other means.

**5.7 With Your Consent.** We may share information for other purposes with Your explicit consent.

**5.8 No Sale.** We do not sell personal data within the meaning of applicable privacy laws (including the CCPA/CPRA).

---

## 6. DATA RETENTION

We retain personal data for as long as needed to provide the Services and for the following additional periods:

- **Account data:** for the life of the account and for up to ninety (90) days after account deletion for backup and recovery purposes.
- **Chain entry metadata (on our backend):** for as long as needed to operate substrate-gated features and to provide verification responses, and for an additional retention period of seven (7) years for audit and regulatory purposes.
- **Log data:** ninety (90) days for general operational logs, up to thirteen (13) months for security-related logs, subject to longer retention for security investigations.
- **Email verification codes:** until used or expired.
- **De-identified or aggregated data:** indefinitely.
- **Trained models and derived datasets:** indefinitely, in accordance with Section 4.6.

Where law requires longer retention (for example, tax, regulatory, or litigation hold), we retain data accordingly.

---

## 7. YOUR RIGHTS

Depending on Your jurisdiction, You may have the following rights:

- **Access:** request a copy of the personal data we hold about You;
- **Correction:** request correction of inaccurate or incomplete data;
- **Deletion:** request deletion of Your personal data, subject to exceptions (legal obligations, ongoing disputes, security, fraud prevention);
- **Portability:** request a copy of Your data in a structured, commonly used, machine-readable format;
- **Restriction or objection:** restrict or object to certain processing, including processing for AI training as described in Section 4.5;
- **Withdraw consent:** where processing is based on consent, withdraw consent at any time without affecting prior lawful processing;
- **Non-discrimination (CCPA/CPRA):** exercise these rights without discriminatory treatment;
- **Lodge a complaint:** with Your local data protection authority.

**To exercise these rights, contact us at privacy@tenkasystem.com.** We may need to verify Your identity before responding. We will respond within the timeframe required by applicable law.

**Authorized agents.** You may designate an authorized agent to make a request on Your behalf with appropriate documentation.

---

## 8. INTERNATIONAL TRANSFERS

Tenka is based in the United States. If You access the Services from outside the United States, Your information will be transferred to, processed in, and stored in the United States and other countries where we or our service providers operate.

For transfers from the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards including Standard Contractual Clauses or other transfer mechanisms permitted under applicable law. Specific transfer mechanisms used with each sub-processor are described at tenkasystem.com/subprocessors.

**Testing-Period EU and UK Access.** During the testing period (through July 1, 2026), Tenka accepts users in the European Economic Area, United Kingdom, and Switzerland only on an invitation-only operator-peer basis. Commercial general availability in those jurisdictions begins on or after August 1, 2026, at which point Tenka will appoint an EU representative pursuant to GDPR Article 27.

---

## 9. SECURITY

We implement administrative, technical, and physical safeguards designed to protect personal data, including:

- Encryption in transit (TLS) and at rest where applicable;
- Salted password hashing;
- Access controls and least-privilege principles;
- Substrate-grade cryptographic primitives (Ed25519 signing, SHA-256 hashing);
- Hash-chained audit trails for governance operations;
- Monitoring, logging, and incident response procedures.

No method of transmission or storage is completely secure. You are responsible for safeguarding Your local TSAIF Anchor, including Your private key, and Your account credentials. If You suspect Your account or anchor has been compromised, contact us immediately at security@tenkasystem.com.

---

## 10. CHILDREN

The Services are not directed to children under the age of 16 (or the applicable minimum age in Your jurisdiction). We do not knowingly collect personal data from children. The Services are governance infrastructure for verified credentialed operations and are not designed or marketed for use by minors. If You believe a child has provided us personal data, contact us at privacy@tenkasystem.com and we will delete the data in accordance with applicable law.

---

## 11. THIRD-PARTY LINKS AND SERVICES

The Services may link to or interoperate with third-party services. We are not responsible for the privacy practices of third parties. Review their policies before sharing information with them.

---

## 12. AUTOMATED DECISION-MAKING

We do not use Your personal data for automated decisions that produce legal or similarly significant effects on You without human involvement, except where permitted by law. The substrate's automated chain attestation and signature verification are governance recording functions, not decisions about You.

---

## 13. CALIFORNIA-SPECIFIC DISCLOSURES (CCPA / CPRA)

California residents have the rights described in Section 7. The categories of personal information collected in the preceding 12 months are described in Section 2; the purposes are described in Section 3; recipients are described in Section 5. We do not sell or "share" (as defined in CPRA) personal information for cross-context behavioral advertising.

*[REVISION NOTE for Hunter: Confirm Tenka's status against the CCPA thresholds (gross revenue >$25M, processes >100K consumers' personal information, or 50%+ revenue from selling/sharing personal information). At pre-launch and testing-period scale, Tenka is below all three thresholds and the disclosures are precautionary. The "we do not sell or share" statement is the protective clause and should remain regardless of threshold status.]*

To submit a request, contact us at privacy@tenkasystem.com.

---

## 14. CHANGES TO THIS POLICY

We may update this Policy from time to time. Material changes will be notified through the Services, by email, or by other reasonable means before they take effect. The "Effective Date" at the top of this Policy indicates when it was last revised.

---

## 15. CONTACT US

If You have questions, requests, or complaints about this Policy or our privacy practices:

**Tenka Software Studio**
PO Box 62
Hoytville, OH 43529
United States

privacy@tenkasystem.com (privacy questions and data rights)
security@tenkasystem.com (security incidents)
support@tenkasystem.com (general support)
optout@tenkasystem.com (AI training opt-out requests)

**Data Protection Officer.** Tenka has not appointed a Data Protection Officer at this time. Tenka's processing does not currently meet the GDPR Article 37 thresholds requiring DPO designation. This will be revisited at commercial EU launch.

**EU/UK Representative.** Tenka has not appointed an EU representative at this time per the testing-period framing in Section 8. Commercial EU launch (on or after August 1, 2026) will include EU representative appointment pursuant to GDPR Article 27.

---

*End of Privacy Policy.*
