← DoubleDigitX

PRIVACY · RESOLVED PRACTICE.1

Your first resolved forecast does not require an identity.

Guest practice receipts

The browser first sends a salted commitment digest—not the probability—to obtain a short-lived server-authoritative commitment. One idempotency key maps to one accepted timestamp and dataset snapshot; conflicting reuse is rejected. Durable authority rows contain only keyed digests, version identifiers, timestamps, expiry, status, and purge metadata. They never contain the probability, nonce, reasoning, receipt, email, provider subject, or raw IP address.

Only after commitment does the browser send the probability and private nonce to open the digest. Completed receipts use a bounded, authenticated, versioned encryption envelope and stay in this browser profile. They are never placed in a URL. The service rejects them after 30 days; clearing browser storage or choosing Delete private history removes the local copy. Approved prior keys can read during a rotation grace window, while unknown, removed, malformed, tampered, expired, or revoked key versions fail closed.

Essential sign-in data

After sign-in, the hosting platform may provide a stable site-specific user identifier, email address, and optional display name. The application accepts them only when the verified hosted-identity authority is active. The governed account spine can retain a private provider-link record so the same login returns to the same DoubleDigitX account. It never merges accounts because two email strings match. Email and provider identity are never placed in Compass share URLs, public receipts, market metadata, public profiles, or advertising audiences.

Private account profile

The account center can store a bounded display name, bio, role preference, decision horizon, topic interests, and timezone. Visibility is fixed to Private in this release. It does not publish a profile, reserve or expose a searchable handle, infer expertise, grant Pro access, or grant editorial authority. Avatar and media upload are unavailable.

Optional Forecasting Passport

After—not before—a complete three-round Replay, an eligible signed-in member may explicitly save the resolved receipt chain to a private provider-neutral DoubleDigitX account. A short-lived HttpOnly, SameSite=Lax intent binds the browser's exact receipt-set digest across authentication. Receipt tokens, probabilities, account identifiers, and nonces never enter the sign-in URL. Interrupted sign-in and failed sync leave the encrypted browser copy intact.

The account-owned record contains the immutable resolved receipt content, original probability, commitment and resolution times, proper score, eligible reference score, authority and methodology versions, receipt hash, explicit storage consent, and optional private-board choice. It does not store the guest bearer token, replay token, nonce, reasoning, raw IP, provider subject, email, wallet, position, order, or P&L in the Passport tables. Same-account retry returns the first claim; another account cannot claim the same receipt. Passport history is available in owner-only export and can be physically deleted independently or through governed account deletion.

No-charge Pro pilot application

When the separately gated pilot intake is open, an enforced private DoubleDigitX account may store one application containing a bounded role, recurring research workflow, most valuable memory concept, exact CA$29 willingness-to-pay choice, optional research-contact choice, offer version, privacy version, and timestamps. The record is keyed to the private DoubleDigitX account; it does not store a separate email, provider subject, IP address, user-agent string, payment state, entitlement, or trading data. It expires after 90 days unless withdrawn or deleted sooner. Submitting it creates no charge, Pro access, invitation promise, public profile, or revenue claim.

Sessions and providers

The hosting platform uses an essential authentication session to keep protected routes signed in. DoubleDigitX does not store authentication tokens in browser local storage. Sign out is available through the hosting platform. Google, X, and passkey buttons are not active until their hosting, consent, recovery, and deletion contracts are separately verified.

Blind challenge links

A challenge link contains the public venue market identifier and a blind-first instruction. It does not contain the sender’s account, email, forecast, receipt, message, position, referral identifier, measurement cookie, or campaign token. DoubleDigitX never claims a unique open, registration, or conversion unless the optional first-party measurement path records the applicable ordered transition.

Optional first-100 product measurement

When the separately governed Founding 100 mode is ready, you may explicitly allow one first-party journey used only to evaluate the preregistered resolved-loop gates. It records an allowlisted event name, success or technical-failure state, governed question ID, schema and policy versions, timestamps, and a bounded source code. It does not accept your probability, the reference probability, outcome, receipt, token, nonce, reasoning, email, provider subject, full URL, query string, raw IP, user-agent string, wallet, position, order, or P&L.

Consent creates one random opaque HttpOnly, SameSite=Lax cookie. Only a keyed HMAC of that token is stored in D1; the raw token is never placed in HTML, URLs, exports, receipts, or share links. Declining does not block the flight. Withdrawing anonymously physically deletes the journey and its events before the cookie is cleared.

Anonymous journey rows expire after 90 days and are physically purged by the governed daily retention operation, with opportunistic cleanup on cohort writes. Measurement remains off unless the exact policy, retention owner, retention mode, secrets, and D1 binding are ready. Staff, bots, test fixtures, duplicates, and unverifiable journeys can only be excluded using fixed reason codes and recorded evidence; product failures remain in denominators.

Previously submitted preview records

Records submitted before this pause may contain email, workflow text, role, team size, legacy product context, pricing-preference band, research-call choice, consent, cohort, privacy version, timestamps, expiry target, and submission count. The application is not designed to attach IP addresses or user-agent strings to those records.

Purpose and retention truth

Existing submissions are intended only for product-demand research and preview invitations. Each row carries a 180-day expiry target, but the independent scheduled purge needed to guarantee a maximum deletion lag is not operational. Intake therefore remains paused; DoubleDigitX does not claim that every row is deleted exactly at day 180.

Infrastructure processing

The hosting and network providers may transiently process ordinary connection data, including network addresses, to deliver requests and enforce infrastructure protections. The application does not persist a raw network address. Shared application rate limits use a short-retention, rotating HMAC-derived network subject and bounded endpoint-specific windows. The application installs no advertising pixel, third-party analytics SDK, fingerprint, or advertising cookie.

Export and deletion

The private account center provides an owner-only export of allowlisted account, Passport, pilot-application, sanitized measurement, and research records and a deletion-request path. Passport, pilot, and optional measurement consent have withdrawal or deletion controls. Export includes account-owned forecast content and scores, while excluding guest bearer tokens, replay tokens, authentication cookies, raw provider subjects, measurement token hashes, and measurement idempotency/request identifiers. A valid account-deletion request withdraws Passport consent, removes pilot and measurement content, and locks product and staff authority; it is not described as complete until the independent purge proves no account-linked Passport rows remain. A keyed, non-reversible subject hash may then be retained for 180 days solely to prevent silent account recreation; the raw provider subject is not retained in that suppression record. A deletion request does not silently cancel an external payment obligation; verified billing cancellation and retention-purge controls remain separate release gates.

Before intake reopens

A real published privacy contact, production access/deletion procedure, scheduled purge with a defined maximum lag, restore rehearsal, final retention tests, enforced account mode, exact pilot offer/privacy versions, and any required jurisdiction-specific disclosures must be approved. The no-charge pilot intake fails closed until every gate is present. Visitors should never place API keys, wallet addresses, account numbers, positions, orders, or other sensitive information in a research form.