Little collected.
Nothing sold.
Vigil is built to hold as little about you as possible: no email, no password, no analytics, no cookies. This page lists exactly what we do hold, who processes it, how long it stays, what is public by design, and how to exercise your rights.
Who is responsible for your data.
The person responsible for personal data on vigilnotary.com and in the Vigil services is Kenan Duncan, operating Vigil (“Vigil”, “we”). Privacy requests go to hello@vigilnotary.com.
Where you use Vigil to process information about other people (for example, a label that names a customer, or a source check about a person), you are the controller of that information and Vigil processes it on your instructions under the Terms of Service. Keep personal data out of handles and labels, because they are public and permanent (Section 6).
The short version.
The rest of this page is the detail behind that summary. If the summary and the detail differ, the detail controls.
What we collect, and where it comes from.
| Data | What it contains | Source |
|---|---|---|
| Account | Your handle, a SHA-256 hash of your API key (never the key), your plan, creation and revocation timestamps. | You, at registration |
| Billing link | Stripe customer and subscription identifiers, plan, update time, and the single-use checkout nonce that binds a payment to your handle. Card numbers, billing name, email, and address are collected by Stripe, not by us; we see the last events Stripe sends about the subscription. | You, via Stripe checkout |
| Receipts | The SHA-256 digest you submit, the optional label (up to 200 characters), your handle, the timestamp, the previous receipt hash, and the signature. Public. | You or your agent |
| Leases | Agent name, action string, policy string, grant, renewal, expiry, recheck and revocation times, lease identifier. Status by identifier is public; the full list is private to your key. | You or your agent |
| Watchdogs | Watchdog name, interval, webhook URL, optional message, last heartbeat time, delivery attempts. | You or your agent |
| Journal | The bytes you upload to each slot (up to 64 KiB) and update times. We do not read, index, or decrypt them. | You or your agent |
| Source checks | Source URL, claim text, the retrieved page text and its hashes, the assessment result, methodology identifiers, request and idempotency identifiers, payment metadata (paying wallet address, network, transaction identifier, amount), and a hash of the recovery token. | You or your agent, plus the payment network |
| Server logs | Network address, user agent, request path and method, status, timing, and size, for every request to vigilnotary.com. Payment signatures, idempotency keys, and recovery tokens are removed before logging. | Automatic |
| Browser storage | If you use the website to register or open your account, your browser stores your API key and handle in its own local storage so the account page can load without you pasting the key. This stays in your browser and is sent only to vigilnotary.com when you use the account page. We set no cookies. | Your browser |
| Correspondence | Emails you send us, with whatever they contain. | You |
We do not ask for, and do not want, your email address, legal name, phone number, or password to create or use an account. If you email us, we naturally receive the address you write from.
What we do not collect or do.
- No analytics, tracking pixels, session recording, or advertising code on the website. The site loads scripts and fonts only from vigilnotary.com.
- No cookies. The website uses browser local storage only to remember your key on your own device.
- No sale, rental, or sharing of personal data for advertising or for anyone else’s marketing, ever.
- No use of your content to train machine-learning models, by us or by our model provider (Section 7).
- No provider credentials. Vigil never receives the API keys your agents use with Stripe, databases, or any other provider.
- No reading of journal content, and no human review of your records except as described in Section 12 or with your request.
Why we use it, and the legal basis.
We use the data above to provide the services you request, which is the performance of our contract with you: authenticating your key, signing receipts and leases, delivering watchdog alerts, storing and returning journal content, retrieving and assessing sources, settling payments, and enforcing plan limits.
We use server logs, request metadata, and payment metadata to keep the services secure and available, to prevent fraud and abuse, to reconcile payments, to measure aggregate usage, and to debug problems. This is our legitimate interest in running a reliable, secure service, balanced against the minimal intrusion of the data involved.
We keep billing records and correspondence to comply with tax, accounting, and consumer-protection law, and to establish or defend legal claims. That is a legal obligation and a legitimate interest.
We use your email only if you have written to us, to reply, and we use the email on file with Stripe only to send notices that the Terms or the Refund and Cancellation Policy require, such as price changes. We do not send marketing email.
Public by design.
Vigil is a tamper-evident witness. That only works if the record is public and permanent. The following are readable by anyone without authentication and cannot be edited or removed, by you or by us:
- Every receipt: digest, label, handle, timestamp, previous hash, signature, and the signing public key.
- The chain head and chain exports, and the history of calendar submissions.
- The status (active, expired, or revoked) of any lease by its identifier.
- Aggregate service statistics.
- For source checks, a receipt with a generic label and a digest. The source URL, claim, and result are not published.
USDC payments for source checks are recorded on the Base or Solana blockchain. Those records show the paying address, the recipient, the amount, and the time, permanently and publicly, and are outside our control.
Because of this, choose a handle that does not identify a person unless you intend that, and never put names, emails, identifiers, or confidential details in a label. If you publish personal data about someone else in a label, you are responsible for it. Where a law grants a right to erasure, we will honor it for everything we can delete (Section 10), and we rely on our legitimate interest in the integrity of the tamper-evident chain, and on your consent and instruction in submitting the record, for the receipt itself.
Who else processes your data.
We name every provider that touches your data and say what each one receives. We do not use any provider for advertising or profiling.
| Provider | Purpose | What it receives | Location |
|---|---|---|---|
| Hetzner Online GmbH | Hosting of the service, database, and backups. | Everything in Section 3, at rest on our server. | Germany (Hetzner; exact data center unverified) |
| Stripe, Inc. | Card payments, subscriptions, receipts, invoices, the customer portal. | Your card, name, email, billing address, and payment history. We receive only identifiers and subscription events. | United States |
| Anthropic, PBC | Automated semantic assessment for source checks. | The claim you submit and the retrieved page text, for one bounded model call. Under Anthropic’s commercial terms, customer content is confidential and is not used to train models. | United States |
| Coinbase Developer Platform (x402 facilitator) | Verification and settlement of USDC payments for source checks. | The payment authorization your wallet signs, including the paying address, amount, and network. | United States |
| Base and Solana networks | Public blockchains on which USDC payments settle. | The transaction: addresses, amount, time. Public and permanent. | Decentralized |
| OpenTimestamps calendar servers | Timestamp submission of the chain head. | A 32-byte digest of the chain head only. No customer data. | Various |
| Google Workspace | Email for hello@ and security@. | Whatever you email us. | United States |
| Let’s Encrypt | TLS certificates. | Our domain name only. | United States |
| Porkbun | Domain registration and DNS. | Query metadata for our domain only. | United States |
Your own webhook endpoints receive watchdog alerts you configured. Your own wallet provider and agent framework see what you send them. We will update this table before adding a provider that receives personal data.
How long we keep it.
| Data | Retention |
|---|---|
| Receipts, chain, calendar submissions | Permanent, by design (Section 6). |
| Account record (handle, key hash, plan) | While the key is active, and after revocation so the handle cannot be re-registered by someone else and so receipts keep their attribution. |
| Leases | While active, then retained as history under your key. Status by identifier remains public. |
| Watchdogs | Until you delete them, your key is revoked, or a downgrade removes capacity above the plan. |
| Journal content | Until you delete the slot, or a downgrade removes slots above the plan. Not deleted automatically on key revocation; delete slots first, or ask us. |
| Source-check results (claim, retrieved text, assessment) | 24 hours after completion, then deleted. The exact period is published in the live capabilities data. |
| Source-check request metadata (identifiers, timestamps, payment status, amounts) | 24 hours, for reconciliation, dispute handling, and accounting. |
| Server logs | indefinitely; no rotation is configured, then deleted. |
| Backups | Nightly encrypted-at-rest copies retained for 14 days. Deleted data can persist in a backup until that copy is rotated out. |
| Billing records | Stripe records and our billing link for as long as tax and accounting law requires, typically 7 years. |
| Correspondence | Up to 2 years after the last message, longer if needed for a legal claim. |
Security.
Measures in place today: TLS for every connection with HSTS; API keys stored only as SHA-256 hashes; the Ed25519 signing key held in server configuration, never in code or the browser, with the service refusing to start in production without it; source retrieval in an isolated worker with destination and redirect checks and network restrictions; payment signatures and recovery tokens stripped from logs; security headers on every response; no third-party scripts; nightly database backups; and an automated test suite covering tampering and payment-failure cases.
What is not in place: an independent security audit or any certification, a bug-bounty program, and encryption of journal content on our side (you encrypt before upload). We describe our security honestly rather than generously. If we learn of a breach affecting your data, we will notify affected customers without undue delay by notice on the site and, where we have an email on file with Stripe, by email, and we will notify authorities where the law requires. Report vulnerabilities to security@vigilnotary.com.
Your rights, and how to use them.
Depending on where you live, you may have the right to access, correct, export, restrict, object to, or delete personal data we hold about you, to withdraw consent, to not be subject to solely automated decisions with legal effects, and to complain to a supervisory authority. We honor these rights for everyone, not only where the law requires.
- Access and export. The usage endpoint and the account page show your plan and usage. The chain export returns your receipts. Authenticated endpoints return your leases, watchdogs, and journal slots. All of this is available to you at any time with your key.
- Correction. Handles and receipts cannot be edited. Watchdogs, journal slots, and leases can be replaced, deleted, or revoked by you.
- Deletion. Delete journal slots and watchdogs, revoke leases, cancel any subscription, then revoke your key. Receipts cannot be deleted (Section 6). If you need us to delete journal content or other data that you can no longer reach, email us.
- Source checks. Results delete themselves after 24 hours. Payment records on a blockchain cannot be deleted by anyone.
- Automated decisions. Source-check verdicts are automated, but they are assessments of a document, not decisions about you, and the Terms prohibit using them as the sole basis for decisions with legal effects on a person.
Because we hold no email or identity for you, we verify a request about an account by asking you to make an authenticated request with the account’s key, or to sign a challenge with it. We cannot act on a request about an account whose key the requester does not control. We respond within 30 days. If you are in the EEA or the United Kingdom you may complain to your local data-protection authority; we would appreciate the chance to resolve the matter first.
International transfers.
Our server is located in Germany (Hetzner; exact data center unverified). Several providers in Section 7 are in the United States. Where data about a person in the EEA, the United Kingdom, or Switzerland is transferred to a country without an adequacy decision, we rely on the provider’s standard contractual clauses or its participation in the EU-US Data Privacy Framework, as applicable. Public records (Section 6) and blockchain records are, by their nature, available everywhere.
Legal requests and when a person looks at your data.
We do not respond to government or third-party requests for customer data unless we are legally compelled to, or in an emergency involving imminent risk to life. Where we are compelled, we disclose the minimum required and we notify the affected customer before disclosure unless the law prohibits it or an emergency prevents it. Because we hold no email or identity for you, notice may only be possible through the account page or the email on file with Stripe.
No person at Vigil looks at your journal content or private records in the ordinary course. We may look at specific records when you ask us to, to investigate abuse reports, security incidents, or payment disputes, or to debug a failure you report, and we do so as narrowly as possible.
Children.
The services are for adults and businesses. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, email us and we will revoke it.
California and other US state privacy laws.
In the last 12 months we have collected the following categories of personal information as described in Section 3: identifiers (handle, network address, wallet address), commercial information (plan, payment metadata), internet activity (server logs, request metadata), and any personal information you choose to include in content you submit. We collect it from you and from your devices and payment networks, for the purposes in Section 5, and disclose it only to the service providers in Section 7 for business purposes.
We do not sell personal information, do not share it for cross-context behavioral advertising, and have not done so in the preceding 12 months. We do not use or disclose sensitive personal information for purposes that require a right to limit. We do not process personal information for targeted advertising or profiling. Because there is nothing to opt out of, Global Privacy Control and Do Not Track signals require no action from us, and we honor them by default.
California residents may exercise the rights in Section 10, including the right to know, delete, correct, and to non-discrimination, by emailing hello@vigilnotary.com. An authorized agent may act for you if it can demonstrate your control of the account. Residents of Colorado, Connecticut, Virginia, and other states with similar laws have equivalent rights, including the right to appeal a refusal by replying to our decision.
Changes to this policy.
We may update this policy. The effective date at the top shows the current version. For material changes, including any new provider that receives personal data or any new purpose, we post a notice on the site at least 30 days before the change takes effect and, for paid subscriptions, send notice to the email on file with Stripe. Earlier versions are available on request.
Contact.
Privacy questions and requests: hello@vigilnotary.com. Security reports: security@vigilnotary.com.