Last updated: 14 September 2026.
Information currently processed
The website hosting infrastructure may process ordinary technical request data required to deliver and protect pages and API endpoints, such as IP address, device and browser information, request time, response status and security metadata.
The public Proof Engine processes agreement terms, supplied evidence, output text and imported receipts locally in the browser. Raw output text is hashed locally and is not included in the generated receipt. Using the browser engine does not intentionally upload its inputs or receipts to the PactVerity Receipt API. Users can download a receipt to their own device.
The public Receipt API beta is a separate, optional path. JSON submitted to its create or verify endpoints transits PactVerity's hosting infrastructure so the server can return a result. The application does not intentionally store request bodies or receipts in a database or intentionally write those bodies to application logs. Ordinary hosting, abuse-prevention and security metadata may still exist. Do not submit secrets, private keys, recovery phrases, confidential material or unnecessary personal data to either the browser engine or the API.
The deterministic scenario simulator runs in the browser and uses model counts, nominal amounts and a seed. It moves no funds. Its default $25,000,000 result is synthetic nominal volume, not customer activity; service and escrow volume is $0.
If a user chooses an optional wallet signature, the page requests the connected public Solana address and asks the wallet to sign the receipt digest as an off-chain message. The signature, public address and signed message are included in the receipt. This proves key control only, not identity, role or evidence truth. The action does not require SOL or submit a blockchain transaction. The engine disables automatic wallet persistence.
When the owner launch console is used, it requests the connected public wallet address, reads its SOL balance through PublicNode and asks that wallet to sign mainnet transactions. Before broadcast, the signed transaction bytes and public signature are sent to PactVerity's same-origin validator, which accepts only the exact published mint ceremony; the browser then broadcasts an accepted transaction through PublicNode. Neither service receives a seed phrase or private key. Owner authorization remains inside the wallet. The mint address is deterministically derived from the published owner address, original SPL Token Program and a fixed public seed, so no separate mint-account secret is generated or stored.
The Buy PVTY page requests a read-only test quote from Jupiter through PactVerity's market-status endpoint. The route checker sends token mint addresses and a fixed test amount; it does not send a visitor's wallet address, balance or intended purchase amount. Opening Jupiter or Raydium leaves this website and is governed by the selected provider.
The Integration Challenge application stores the applicant's name, email address, project name, public project URL, selected track, proposal, evidence plan, consent version, review status and submission time. The weekly evidence-update form stores the subscriber's email address, active status, signup source, consent version and subscription time. The design-partner form stores the contact name, work email, organisation, public URL, proposed use case, available evidence signals, pilot goal, review status, consent version and submission time. These records are used only to evaluate integration or pilot proposals, contact applicants and deliver requested PactVerity project updates. Do not include secrets, private customer data, wallet credentials or confidential source material.
The privacy-minimised growth funnel stores an event identifier, event type, page path, optional UTM source, medium and campaign labels, optional referring hostname and time. It does not intentionally store full referrer URLs, IP addresses, wallet addresses, receipt contents, advertising identifiers or cross-site behavioural profiles. Counts are not deduplicated people and may include repeat actions or automated traffic.
Responsible project and contact boundary
PactVerity operates this live public MVP and publishes its official domain, canonical token identity and owner wallet. Privacy and data-rights requests can be sent to contact@pactverity.com. A formal protocol-operating entity is not yet published. Applicant and subscriber records will be retained while the challenge or subscription remains active and then deleted when no longer required, subject to legitimate security or legal recordkeeping needs.
Blockchain information
The owner wallet, mint and token-account addresses, balances, transaction signatures and transactions may be sent to Solana RPC services and recorded publicly on Solana. Public blockchain records cannot generally be removed by clearing this website's data.
Cookies and local storage
The PVTY guide compares two factual research invitations. A random A/B label is kept only in sessionStorage. We count the first visible invitation and first evidence-link click per browser session using event types, without a persistent visitor identifier. These are session events, not verified people or purchases. The experiment is disabled when Do Not Track or Global Privacy Control is enabled or session storage is unavailable; internal QA is excluded. No automated monitoring or advertising audience is created.
Campaign source, medium and campaign labels are retained in sessionStorage for internal navigation during the same browser session. They are not person identifiers and are not used to link separate browsers or sessions. Growth reporting respects the browser Do Not Track and Global Privacy Control signals. Designated internal QA sessions are excluded from the client growth reporter. Third-party swap providers have their own data practices.
No advertising cookies are intentionally used. A session-storage marker prevents the same page from being counted repeatedly during one browser session; clearing site data removes that marker. The Proof Engine and scenario simulator store no receipt or scenario in localStorage. The owner console disables automatic wallet persistence and stores a public recovery record in browser localStorage containing the canonical mint address, launch stage, attempt times and available transaction signatures so an interrupted launch can be reconciled. It can also download those public identifiers as JSON. The same canonical address is re-derived if browser data is lost; neither mechanism stores wallet secrets. Clearing site data removes only the local record, not a downloaded file or blockchain records.
Third-party services and links
The Receipt API and owner transaction validator use this site's hosting provider. The owner console interacts with the connected Wallet Standard provider, PactVerity's same-origin validator and PublicNode's Solana mainnet RPC. Links to Solana, PublicNode, x402 or future exchange services are governed by those providers' own policies. Sending an API request or opening an external link may reveal ordinary request information to the relevant provider.
Changes
This notice will be updated when processing materially changes and before any account, analytics feature, on-site transaction signing or production settlement service is introduced.