Privacy Commitments Statement
Version: 1.2 Status: Public-facing statement of record; versioned; digest-pinnable Identity: Laws Of Robots (product-side governance artifact) Authorship: Owner-ratified; wording drafted with AI assistance; the owner owns every commitment Date: 2026-07-23 Relationship: Companion to the internal erasure-posture doctrine. Cited by the privacy whitepaper. Consistent with both by construction.
§1 — Purpose and scope
This document is the binding public statement of the system's privacy commitments. It is not a privacy policy, not legal terms, and not a feature description.
"Binding" here means published, versioned, and changed only in the open. The commitments below govern the system's design and operation. Any revision is itself a visible, dated act.
§2 — The four commitments
2.1 Bystander exclusion
The machine's perception of anyone other than the owner does not enter the record. This includes visitors, children, neighbors visible through windows — anyone merely present in its environment. Interacting with the machine, speaking to it, or answering its questions does not create a route into the record. Admission, defined below, is the only route.
Information about a person other than the owner may enter the record only through an explicit act of admission. That act must be deliberate, attributed to the person performing it, and tied to a clear reason for accountability. There is no passive or automatic route by which a bystander's information becomes part of the machine's record.
2.2 The hard gate
The system will not collect personal data about any person other than the owner until the capability to erase that data completely and provably is operational.
That capability has now been built and demonstrated: in a development environment, fifty synthetic test subjects were erased by key destruction, and the destruction of their keys was verified on 2026-07-21. The gate remains closed. It opens only when erasure has been proven on the first entries of the live path that would carry a third party's data — exercised with synthetic subjects before any real person's data is ever admitted. Until then, the record contains no personal data about any third party. The gate does not merely slow collection — it forbids it.
2.3 Erasure semantics
Erasure is performed by destroying the key that makes an entry's content readable. Key destruction completes within a bounded, capped window that no one — including the owner — can shorten, extend, or override; that window is currently seven days. No standing permission to reverse a destruction during that window exists, no backup of an erasure key is ever taken, and no standing capability to take one exists. Once destruction completes, the content is permanently unrecoverable. The sealed entry remains in the record — its position in the sequence, its integrity, and the fact that a decision occurred stay intact and verifiable.
This approach makes privacy and accountability complements rather than opposites. A person's information can be destroyed on request, but the tamper-evident record of what the machine did cannot be altered or erased by anyone, including the owner.
2.4 No permanent carve-outs
The erasure guarantee applies to every surface where a person's data can reside. There are no permanent exceptions.
Where a gap exists during construction, that gap must be explicitly named and given a completion deadline internally. An unnamed or unclocked gap is treated as a violation of the commitment, not an oversight.
§3 — What these commitments do not claim
Stated plainly, in one place:
- The erasure mechanism has been demonstrated on synthetic subjects in a development environment. It has not yet been exercised on any real person's data — the record holds none.
- Erasure destroys the sealed entry's content. It does not reach information exported or disclosed from the record before the erasure occurred.
- When third-party data is admitted, the link between a person and their entries will be held by the owner alone, outside the system. Disposing of that link on erasure is the owner's own act; the system does not perform or verify it.
- Key destruction is carried out by the managed key-storage platform that holds the keys; the system relies on the platform to enforce the destruction window. That enforcement was verified in practice on 2026-07-21.
- The empty state cannot be inspected from outside.
- No third party audits or certifies these commitments today.
- The commitments bind this system's design and operation, not the law of any jurisdiction.
§4 — Change discipline
These commitments may be strengthened or added to. They may not be weakened or removed. Every version is retained and publicly comparable to the last.
§5 — Definitions
- Bystander — Any person the machine perceives who is not the owner.
- The record — The sealed, tamper-evident sequence of the machine's decisions.
- Key destruction — Erasure performed by destroying the key that makes an entry's content readable, leaving the sealed entry in place.
- Destruction window — The bounded, capped period between the start of key destruction and its completion.
- Admission — The deliberate, attributed act by which information about a person other than the owner is entered into the record.
The definitions in this Statement are authoritative. The privacy whitepaper's corresponding definitions conform to them.
Verification hooks
- Version number: 1.2 (this document)
- Ratified: 2026-07-23
- Publication date: 2026-07-23
- Stable URL: https://lawsofrobots.com/privacy-commitments/ — every version retained at a permanent path beneath it
- Digest: published beside this document at the stable URL, computed at build time over the exact bytes of this document's source file
Version history
- v1.0 — 2026-07-07 — initial text (superseded before URL assignment; never published)
- v1.1 — 2026-07-07 — §2.1 first paragraph tightened to admission-only; §3 meta-commentary sentence removed
- v1.2 — 2026-07-23 — §2.2 and §3 updated from "not yet built" to the demonstrated state of the erasure mechanism, with the gate's discharge standard stated publicly; §2.3 restated as the precise destruction sequence (bounded, capped window; standing-reversal and backup refusals added; end-state unchanged — permanently unrecoverable once destruction completes); scope limits added to §3; destruction-window definition added; stable URL assigned; authorship line corrected to disclosed provenance; identity line aligned to brand casing. First published version.
End of Privacy Commitments Statement v1.2