EVOLVE CHRONOFLUX — PRIVACY POLICY =================================== Effective date: 3 July 2026 Last updated: 17 July 2026 (v4.1.8 build 174; Windows and Android rebuild; no VPN or WireGuard tunnel in the Windows installer; Android login splash shows full EVOLVE banner proportionally on phone screens; Android biometric enrollment after registration seed setup; randomly assigned PERC addresses for independent registrations; balance and transaction sync for wallets restored from the same seed or backup; send re-authentication before outbound PERC transfers; inbound credits at one main-chain confirmation; Android pull-to-refresh; hold-to-reveal login password) This Privacy Policy describes how Evolve Chronoflux ("Evolve", "we", "us", or "our") collects, uses, stores, and shares information when you use the Evolve application on Windows, Android, iOS, or the web (including the GitHub Pages deployment), and when you use the public Perccent Internet seed node and network explorer hosted on Render at https://evolve-perc-internet.onrender.com. By using Evolve, you agree to this Privacy Policy. If you do not agree, do not use the app or the hosted network services. 1. WHO WE ARE ------------- Evolve is a cross-platform application for social and political scenario analysis using the Chronoflux hydrodynamic framework. Evolve is proprietary software copyright (c) 2026 Evolve Chronoflux. The Perccent (PERC) wallet connects to an internet seed node that provides rendezvous peer discovery, chain synchronisation, and a public network explorer. That seed node is operated on Render Standard hosting with persistent disk storage. Privacy enquiries: - GitHub issues: https://github.com/rgsneddon/evolve/issues - Licensing / general contact: russell.gray.sneddon@gmail.com 2. SUMMARY ---------- - Core Chronoflux calculations run locally on your device. - When you are signed in to a PERC wallet and the network blockchain is launched, your posed scenario question (or topic) is recorded on the shared chain and shown publicly on the seed-node explorer for all visitors. - We do not operate advertising, sell personal data, or run third-party analytics or crash-reporting SDKs inside Evolve. - PERC wallet ledgers are stored locally on your device. Wallets operate independently per device and user, but synchronise chain state with the seed node on app launch and when you sign in. - Optional online features (Grok construal, narrative links, PERC network sync, and the hosted explorer) send only what is needed for the feature you enable or trigger. - Public seed-node and explorer responses do not expose wallet passwords, password hashes, salts, or real usernames. Where an account identity must appear on a public surface, it is shown as a deterministic five-character public alias (for example "K7m2p"), not your login username. - IPv4 wallet node endpoints are masked on the public explorer (shown as "Private node" rather than your home IP and port). - The treasury wallet (`evolve_treasury`) on the seed node is hidden from public peer listings. Treasury PERC is emitted only when a signed-in user runs a scenario analysis (Calculate); users cannot manually send PERC to the treasury, and the treasury has no manual receive address after blockchain launch. Treasury emission statistics are shown publicly on the explorer (aligned with the analysis faucet — up to 1 PERC per 7-minute cooldown window, about 0.14285714 PERC per minute); outbound treasury sends remain disabled. - New PERC wallet registration offers an optional 12-word recovery seed exactly once on the splash screen immediately after account creation (before full sign-in completes). You may generate and write down the phrase or skip; copy and paste are not offered for the generated words. - The in-app Security tab (immediately right of Wallet) lets you export an encrypted PERC wallet backup or restore from a backup file only. Backups stay on your device unless you choose to copy or save them elsewhere. - Inside the Evolve app, you see your own username. Other users' names in your transaction history and wallet block explorer are shown as the same style of five-character alias unless you are viewing your own activity. - Optional Android biometric sign-in (user opt-in): if you accept after a successful password login or after completing new-registration seed setup, your username and password are stored only on your device in OS-backed secure storage (encrypted shared preferences). Unlocking uses the device biometric prompt via the platform API (local_auth). Biometric templates and plaintext passwords are not sent to Evolve, the seed node, or third-party servers. You may decline and continue with manual login. - Random PERC addresses: each independent wallet registration on a device receives a randomly assigned PERC address. Addresses are not derived from your username or password. Wallets restored from the same seed phrase or encrypted backup file share the same address across devices. - Multi-device balance sync: when you restore a wallet from the same seed or backup on another device, balances and transaction history merge across those clones when either device sends or receives PERC on the shared chain. - Send re-authentication: before an outbound PERC transfer executes, Evolve may ask you to re-enter your wallet password or use enrolled Android biometrics. This gate applies only to sends — not to Percent Chance or Social Cohesion analysis faucet credits while you remain signed in. 3. INFORMATION WE COLLECT AND HOW WE USE IT ------------------------------------------- 3.1 Information you provide in the app When you use Evolve, you may enter: - Scenario questions and optional construct fields (sigma, I-tau, J-mu, omega) - Region and language preferences - PERC wallet username, password, and transfer details - Narrative URLs for cohesion analysis (when you paste a link) - Ward voting proposals, vote choices, and optional public comments (when you use Community Ward Voting while signed in) - Exported synopsis files you choose to save (PDF, HTML, or text) This content is used to run analysis, maintain your local PERC ledger, and produce reports. Chronoflux calculations run on your device. When you are signed in to a PERC wallet and the network blockchain is launched, completing a scenario records your posed question (or topic) as a public scenario label on the shared chain and syncs it to the Evolve-operated seed node (Section 3.8). Anyone can read that label on the public network explorer at https://evolve-perc-internet.onrender.com/ (Section 3.9). Optional Grok construal and narrative links (Section 3.3) may send additional scenario text to third-party services you enable. 3.2 Information stored locally on your device Evolve may store the following on your device: PERC wallet ledger - Username, password hash and salt, confidential PERC address (Beam-privacy fork), balances, transaction history, blockchain state, wallet peer mesh, network node metadata, ward proposals and ballots, and related wallet data. - Each device keeps its own ledger file. Your wallet credentials stay on your device; only chain consensus data is merged from the network. - Windows / Android / iOS: application support directory as a JSON file. - Web: browser localStorage for the same origin (shared across tabs on that origin). Optional Grok / X sign-in session (desktop and mobile only) - OAuth tokens and session metadata needed to keep you signed in. - Stored locally (for example grok_session.json) until you sign out or clear app data. In-session analysis state - Your current scenario inputs and results while the app is open. We do not automatically upload your full local ledger to Evolve Chronoflux except through PERC network sync (Section 3.8), which transmits ledger data — including public scenario labels when you complete analysis while signed in — when you use wallet online features. Public read APIs return a sanitised view (Section 3.12). 3.3 Optional online features (only when you enable or trigger them) Grok construal (optional) - If you turn on "Grok construal" and sign in with X on supported platforms, Evolve sends your scenario question and blank construct fields to Grok via an embedded or configured Grok proxy, using X OAuth. - X (Twitter) processes sign-in under its own privacy policy: https://twitter.com/privacy - xAI / Grok processes construal requests under its own terms and policies when live Grok is used. - On web (including GitHub Pages), Grok construal uses local heuristic suggestions in the browser and does not require X sign-in unless you host a remote proxy. Narrative link reading - If you provide a public narrative URL, Evolve may fetch that page (or request it via your configured Grok proxy) to extract text for cohesion scoring. - Only the URL you supply is used for that fetch. Synopsis export - When you export a synopsis, you choose where the file is saved. Evolve does not receive a copy unless you separately share it. 3.4 Camera access (Android and iOS) Evolve requests camera permission only when you open the PERC "Send" QR scanner to read a PERC wallet address from a QR code. - Camera images are processed on your device for barcode detection. - We do not record, store, or transmit camera video or photos to our servers. 3.5 Device permissions Android - INTERNET — Grok construal, narrative links, PERC seed-node sync, optional proxy communication - CAMERA — PERC QR scanner (optional; only when you use Send scan) - USE_BIOMETRIC / USE_FINGERPRINT — optional fingerprint sign-in for PERC wallet login when you opt in (Section 3.14); not required for manual login iOS - Camera — PERC QR scanner (optional; only when you use Send scan) Windows / Web - No camera permission is required on Windows desktop. Web scanning follows your browser's camera permission prompt when supported. 3.6 In-app update checks (Windows and Android) On launch, Evolve may fetch a small version manifest from GitHub Pages (https://rgsneddon.github.io/evolve/version.json) and, if needed, GitHub Releases metadata to compare your installed build number with the latest published package. No wallet credentials or scenario content are sent during this check. If an update is available, the app may open the published download page or release asset URL in your browser or system downloader. 3.7 Technical data from third-party services Evolve uses open-source packages and hosted services that may contact third parties when you use network features: - X / Twitter (api.x.com, x.com) — OAuth and API calls when Grok construal with sign-in is enabled - Public websites — when you submit a narrative URL - Google Fonts — the app may download font files from Google when typography is loaded (see https://policies.google.com/privacy) - GitHub Pages — when you use the hosted web build, GitHub may log standard web server data (see https://docs.github.com/en/site-policy/privacy-policies) - Render (https://render.com) — hosts the Perccent Internet seed node, explorer UI, rendezvous API, and treasury administration endpoints (see Render privacy policy: https://render.com/privacy) - Public IP lookup services (for example api.ipify.org and ifconfig.me) — used only to discover your device's public internet endpoint when your wallet registers as an online node; your IP address may be sent to those services These third parties process data under their own policies. Evolve Chronoflux does not control their practices. 3.8 Perccent Internet seed node and wallet network sync When you launch Evolve or sign in to a PERC wallet, the app may connect to the configured seed node (default: https://evolve-perc-internet.onrender.com) to: - Fetch seed status and sanitised ledger data (block height, chain tip, genesis revision) - Align your local chain with the network, including resetting to block 0 when a new network genesis revision is published - Register your wallet as an online peer (session username, public endpoint, wallet address, block height, tip hash, chain id, revision) - Relay ledger updates to other peers via the rendezvous service Data your wallet may send to the seed node when you are signed in (operational sync): - Session username and advertised node endpoint (which may include your public IP and port, or an internet URL resolved via third-party IP lookup) - Network status JSON (block height, tip hash, evolutionary chain id, revision) - Full ledger JSON when syncing or relaying to peers (includes block scenario labels — your posed question or topic text — and ward voting data you submit) Data your wallet does not send for peer registration: - Your wallet password or password hash (credentials remain on your device) - The evolve_treasury wallet is not registered to the public rendezvous peer list The evolve_treasury account on the seed node is excluded from public peer listings on the explorer and rendezvous API. Independent wallets: each user/device maintains its own stored ledger and login credentials. Network import merges shared chain blocks and balances but preserves your local wallet passwords unless you have not yet gossiped a new registration. Internal server routing may use your real username and wallet address to match relay requests. Anonymous visitors who call public read APIs receive only the sanitised data described in Section 3.12. 3.9 Hosted network explorer (public) The seed node serves a public explorer at https://evolve-perc-internet.onrender.com/ that displays: - Seed and network block height, peer online status, and chain identifiers - A block list and block detail API, including scenario labels (posed questions or topics you chose to record on-chain) - Five-character public aliases instead of real wallet usernames for triggers, transaction parties, peer listings, and wallet chart entries - Treasury emission statistics (rate, balance, cumulative minted PERC) after blockchain launch - Auto-refreshing network statistics (approximately every 30 seconds) The public explorer does not display: - Wallet passwords, password hashes, salts, or password-set flags - Real PERC wallet login usernames - Raw IPv4 home endpoints for wallet nodes (these appear as "Private node") Before the blockchain is launched, the explorer shows no chain blocks. After the one-time treasury launch (Section 3.10), the explorer shows treasury emission statistics for all visitors, together with a notice that manual sends from evolve_treasury are disabled (emission and faucet payouts continue). These figures are chain consensus data, not treasury administrator credentials. Standard web server logs (IP address, user agent, request path, timestamps) may be collected by Render when you visit the explorer. 3.10 Treasury administrator access (hosted) The Perccent blockchain has launched on the public seed node. The former Treasury tab and treasury administrator login on the explorer have been removed. Treasury emission summaries remain public on the Explorer page (Section 3.9). Manual sends from evolve_treasury stay disabled; automated faucet-aligned emission, regeneration, and faucet payouts continue on the chain. The legacy 283M pool renewal at 1-cent reserve is not used under the current infinite-continuum setting. 3.11 Beam-confidential Perccent addresses PERC uses confidential-style addresses derived on-device (percpriv1…). Balances may be shielded in the UI. Address derivation uses your username and wallet salt locally. Your PERC address may appear in public ledger data and rendezvous address lookups because transfers are addressed by confidential address, not by username. Addresses are pseudonymous identifiers; they are not the same as your login username. 3.12 Public account privacy (sanitised network responses) Evolve applies an account-privacy layer to all anonymous public read paths on the seed node, rendezvous service, and wallet nodes that serve unauthenticated GET requests (including /api/network, /api/blocks, /perc/ledger, /perc/status, /perc/rendezvous/peers, and relayed ledger fetches). Sanitisation includes: - Removing password, passwordHash, salt, and passwordSet fields from any public JSON response - Replacing real usernames (including sessionUsername, fromUsername, toUsername, triggerUsername, proposerUsername, and voterUsername) with a deterministic five-character public alias derived from the username - Returning only { "online": true/false } from the public online-status endpoint (no echoed username or address) - Returning only the PERC address from public address lookup (no username field) - Masking IPv4 wallet endpoints on the explorer as "Private node" Public aliases are stable for a given username on the network but are not designed to be reversible to your login name by casual visitors. They reduce exposure of account identities on the open internet while keeping block heights, scenario labels, PERC addresses, and chain statistics visible for transparency. Inside your signed-in Evolve app, you still see your own username. Other users are shown by public alias in transaction history and the wallet block explorer unless you are viewing your own entries. 3.13 Community Ward Voting (in-app) When you use Community Ward Voting while signed in, your vote, optional comment, and proposal text are stored in the shared PERC ledger and sync to the network. Live results and public comments are visible to other signed-in wallets that sync the chain. On anonymous public explorer and API responses, voter and proposer usernames are replaced with five-character public aliases (Section 3.12). Proposal titles, summaries, vote tallies, and comments you choose to submit remain visible to participants. 3.14 Optional Android biometric sign-in (PERC wallet) On Android only, after you sign in to an existing PERC account with your username and password, Evolve may offer to enable biometric sign-in. This is entirely optional. If you accept: - Your username and password are saved on your device in OS-backed secure storage (flutter_secure_storage with encrypted shared preferences). - On later visits, you may tap the fingerprint button to unlock those stored credentials through your device's biometric prompt (local_auth). - Evolve uses the recovered credentials only to complete local wallet login on your device. If you decline, cancel the biometric prompt, or biometrics are unavailable, you may always sign in manually with username and password. Evolve does not: - Collect, store, or transmit your fingerprint, face data, or other biometric templates to Evolve Chronoflux or the seed node - Upload your plaintext PERC wallet password to Evolve, Render, or peer wallets - Enable biometric sign-in for brand-new registrations before the first successful password login Clearing app data or declining enrollment removes the opt-in stored credentials from your device. 3.15 Send re-authentication (PERC wallet) Before Evolve records an outbound PERC transfer, you must confirm with your wallet password or, on Android when biometric login is enrolled, a successful device biometric prompt that unlocks your stored on-device credentials. Cancel, failure, or an incorrect password aborts the send with no debit. This confirmation is required only for outbound sends. It does not apply to Percent Chance or Social Cohesion Score analysis rewards, receive, staking, backup export, or ordinary signed-in wallet browsing. 4. WHAT WE DO NOT COLLECT OR EXPOSE PUBLICLY -------------------------------------------- Evolve does not intentionally collect: - Precise geolocation or GPS coordinates - Contacts, photos, or files outside features you explicitly use - Payment card or banking details (PERC is an in-app ledger, not a regulated payment processor) - Advertising identifiers for targeted advertising - Analytics or crash reports sent to Evolve Chronoflux - Plaintext treasury administrator passwords (only salted hashes are stored on the seed node) On public seed-node, rendezvous, and unauthenticated wallet-node read APIs, Evolve does not expose: - PERC wallet passwords, password hashes, or salts - Real wallet login usernames (public aliases are used instead) - Raw IPv4 wallet node endpoints on the hosted explorer 5. HOW LONG WE KEEP INFORMATION ------------------------------- Local device (Evolve app) - Wallet and session data remain on your device until you uninstall the app, clear site data (web), or delete the stored files. Seed node (Render persistent disk) - Seed ledger, relayed peer ledgers, rendezvous peer registrations, treasury administrator password hash, and blockchain-launch flag persist on the mounted data volume until reset, redeployment with a new genesis revision, or manual deletion. - Treasury administrator session tokens expire after 24 hours of inactivity. - Peer "online" status uses a freshness window (7 minutes since last registration heartbeat). Third-party providers - Data sent to X, Grok, Google, GitHub, Render, public IP lookup services, or public websites is retained according to those providers' policies. Scenario labels you submit while signed in persist in blockchain blocks on the seed node's ledger as part of PERC network sync (Section 3.8) and remain publicly visible on the explorer (Section 3.9) until a genesis reset, redeployment, or manual deletion. 6. SHARING OF INFORMATION ------------------------- We do not sell your personal information. Information may be shared only in these situations: - With third-party services you choose to use (X OAuth, Grok construal, narrative URL fetching, Google Fonts, Render hosting, public IP lookup), as described in Section 3 - With other PERC network participants through rendezvous registration and ledger gossip you trigger by using an online wallet (operational sync uses your username and endpoint; public peer listings show a five-character alias instead of your login name) - Publicly on the network explorer after blockchain launch (scenario labels you record on-chain, five-character public aliases for account-related fields, PERC addresses, and treasury emission statistics — not treasury login credentials or wallet passwords) - When required by law, regulation, or valid legal process - To protect the rights, safety, or security of users or the public, where permitted by law Evolve does not share your PERC wallet password with other users. PERC transfers you initiate may reveal your confidential PERC address and amounts to recipients on the shared chain. Recipients who know your address can send PERC to you without learning your login username from public explorer pages. 7. CHILDREN'S PRIVACY --------------------- Evolve is not directed at children under 13 (or the minimum age required in your country). We do not knowingly collect personal information from children. If you believe a child has provided information through the app, contact us using the details in Section 1. 8. SECURITY ----------- We use reasonable measures to protect information stored on your device (local files, browser storage) and on the seed node (password hashing for treasury admin and wallet accounts, HTTPS via Render, persistent disk for ledger data, and public-response sanitisation that strips credentials and obfuscates usernames). No method of storage or transmission is completely secure. You are responsible for securing your device, X account, treasury administrator password, PERC wallet password, and any exported files. If a network genesis reset is published, your device may replace local chain data with the seed ledger at block 0. Local wallet credentials on your device are handled as described in Section 3.8. 9. YOUR CHOICES AND RIGHTS -------------------------- You can: - Use Evolve without Grok construal ("Don't use") to keep construal requests local - Decline camera permission and enter PERC addresses manually - Sign out of X / Grok construal and clear local session files - Delete local wallet data by clearing app data or removing stored JSON / localStorage entries - Export or delete synopsis files you saved - Avoid signing in to a PERC wallet or completing on-chain scenarios if you do not want your posed question visible on the public explorer, rendezvous sync, or ledger gossip (offline-only use limits network features) - Avoid Community Ward Voting if you do not want proposals, votes, or comments stored on the shared chain - Decline in-app update prompts if you prefer to stay on your current build - Decline Android biometric sign-in enrollment and use manual PERC login only - Clear app data on Android to remove opt-in biometric credentials from secure storage Depending on your location, you may have rights to access, correct, delete, or restrict processing of personal data. Because most app data is stored locally on your device, you can exercise many of these rights directly. For seed-node or treasury-admin data, contact us at the addresses in Section 1. 10. INTERNATIONAL USERS ----------------------- Evolve may be used worldwide. If you use optional online features or the PERC seed node, data may be processed in countries where X, Grok, Google, GitHub, Render, public IP lookup providers, or narrative site hosts operate. By using those features, you understand that cross-border transfer may occur. The Render seed node is hosted in Render's infrastructure regions according to Render's deployment configuration. 11. CHANGES TO THIS POLICY --------------------------- We may update this Privacy Policy from time to time. The "Last updated" date at the top will change when we do. Continued use of Evolve or the hosted seed node after an update means you accept the revised policy. The current version is published in the Evolve GitHub repository at privacy_policy.txt and linked from the GitHub Pages download page. 12. OPEN-SOURCE COMPONENTS -------------------------- Evolve includes third-party open-source software (Flutter, mobile_scanner, permission_handler, qr_flutter, Node.js seed-node components, and others). Those components are subject to their own licenses. See NOTICES in build outputs for attribution. --- Copyright (c) 2026 Evolve Chronoflux. All rights reserved.