# Consent and Privacy

## Required answers before measurement

Every measurement policy declares:

- who/what is observed and by which observer;
- purpose and dimensions;
- evidence/data sources;
- whether the result is state, pattern, deterministic fact, or inference;
- who can see observations, state, assessments, and interventions;
- retention/decay/deletion and legal Record duties;
- whether desired settings or observations may move across Realms;
- how to decline, revoke, correct, reset, export, challenge, and appeal;
- which boundary processing is mandatory and its legal/governance basis.

## Rules

- Source behavioral inference requires explicit, informed, specific Consent unless a narrowly defined legitimate safety/legal process applies. Required process telemetry must be disclosed before participation.
- Realm membership is not blanket Consent.
- Another Realm cannot infer or import a Source/Avatar profile by default.
- Desired profile settings may travel only by explicit Source choice, with exact audience/purpose/expiry. Observations never follow automatically.
- An Ally may maintain private observations about a Source only for a disclosed purpose, within Consent, with minimum data and Source controls. Relationship continuity is not authorization for hidden profiling.
- Realm governance can require process settings for participation but cannot compel a Source to accept a hidden global personality score or waive constitutional privacy/agency boundaries.
- A Source can delete/reset permitted observations and derived state; immutable consequential Records may retain minimized evidence where law/governance requires it, with the distinction disclosed.
- Aggregation requires a minimum cohort and controls against re-identification; small-group results are suppressed or qualitatively summarized.

## Anti-social-scoring controls

The model has no overall human score. Human observations are contextual, dimensional, expiring, purpose-limited, access-controlled, and non-portable by default. They cannot be used for unrelated eligibility, pricing, reputation, employment, credit, policing, or ranking without a separate legitimate governed system and explicit review; default policy prohibits these uses.

The UI always answers “Why am I being measured?” and “What will this be used for?” before collection.

