Protect the believer.
Collect less. Expose less.
JCS is a Christ-centered, non-custodial XRP Ledger project. This policy governs the current JCS ecosystem—including Sign the Ledger, Prayer Map, Private Capsule, Network Observatory, Account Readiness, local browser features and support channels—and places special emphasis on people whose Christian expression may create personal, family, employment, governmental or physical risk.
High-risk Christian safety essentials
If public Christian expression could expose you or another person to surveillance, retaliation, violence, arrest, discrimination or coercion, safety is more important than creating a blockchain record.
Policy contents
This version separates human-safety rules, public-ledger realities and legal-process procedures so each can be understood independently.
1. Scope and project identity
This Policy applies to JCS-controlled pages and features that link to it.
Covered surfaces include the JCS Home portal, Sign the Ledger, Prayer Map, Network Observatory, Account Readiness, About & Vision, local prayer/fellowship tools, Private Capsule features when delivered by JCS-controlled code, privacy/terms/security pages, AI and identity manifests, and direct support communications received by JCS.
Independent systems such as XRP Ledger nodes, Xaman, GitHub, explorers, market providers, media hosts, social networks and email providers have their own privacy and legal obligations. JCS cannot promise what an independent provider collects, retains or discloses.
2. Privacy principles
The project uses privacy risk management rather than assuming that every technically obtainable data point should be collected.
Data minimization
Collect, create and retain only information reasonably necessary for the requested function, security, evidence, legal duty or project operation.
Purpose limitation
Do not quietly reuse prayer, testimony, contact or support material for unrelated profiling, advertising, spiritual ranking or general-purpose AI training.
Least disclosure
When disclosure is legally required, disclose the minimum responsive information within JCS possession or control rather than broad account histories by default.
No exact-location inference
JCS does not treat IP address, wallet address, XRPL server, relay endpoint, device, transaction route or prayer-focus label as proof of a person’s physical location.
No wallet-secret collection
JCS does not need and should never request a seed phrase, private key, recovery words, Xaman passcode or device passcode.
No hidden access path
Privacy features should not contain a secret decryption key or surveillance backdoor accessible to JCS merely because legal process might someday arrive.
3. Information involved
Availability does not mean JCS centrally stores every category.
Public XRPL evidence
Wallet addresses, hashes, ledger indexes, transaction types, trust lines, token balances, offers, AMM records, NFTs, URI fields and transaction memos may be public network data.
Deliberately submitted content
A prayer, testimony, reply, Amen, support response, Scripture reference, display name, handle or other content may be processed when you choose to publish it.
Local-only state
Drafts, display preferences, media settings, pending workflow data, downloaded evidence and Private Capsule material can remain on the user’s device unless deliberately transmitted.
Direct communications
Email or support messages may include the sender address, content, attachments and response history. Do not send secrets or unnecessary sensitive records.
Infrastructure data
Hosting, security, network and browser providers may process IP addresses, user agents, timestamps, requested paths, errors and abuse signals independently of JCS application code.
Data intentionally absent
JCS does not centrally maintain a master list of users’ exact physical locations, wallet seeds, Private Capsule keys, or private messages merely because the platform can display public XRPL evidence.
4. Religious and sensitive information
Prayer, testimony and participation in Christian ministry can reveal or strongly suggest religious belief.
Do not publish another person’s medical condition, immigration status, criminal allegation, family crisis, financial distress, precise location, persecution history, or identity simply because the information is included in a prayer request. Obtain informed permission and minimize details.
4A. Purposes of processing
JCS limits processing to functions a user requests, public-ledger verification, safety, security, support, legal compliance and project administration.
- Provide Scripture, project information, prayer/testimony tools and other requested JCS functions.
- Authorize a public account through Xaman only on pages where the user deliberately invokes wallet functionality.
- Prepare user-requested XRPL transactions for independent wallet review on transaction-capable pages.
- Reconstruct public JCS records from validated XRPL history and measure threshold-safe public aggregates.
- Maintain local drafts, preferences and pending workflow state on the user device where practical.
- Answer support, privacy, security and legal communications.
- Prevent fraud, impersonation, abuse, malicious code, spam and unauthorized access.
- Comply with valid legal obligations and protect the rights and safety of users, JCS and others.
5. Public evidence versus private dignity
Each JCS feature should state whether information remains local, becomes public, or reaches an independent provider.
| Surface | Normal privacy posture | Public? | Key warning |
|---|---|---|---|
| Scripture / About / policy pages | Read-only content | No wallet publication | Hosting/network providers may still see routine request data. |
| Sign the Ledger prayer/testimony | Explicit Xaman-authorized NFT + registry publication | Yes | Wallet and public transaction evidence are durable. |
| Prayer Map | Validated public registry history plus thresholded aggregates | Aggregate | Prayer-focus labels are not participant locations. |
| Private Capsule | Browser-local encryption; separate transport/key files | No, unless user chooses receipt | Optional NFT fingerprint receipt links a wallet to a receipt event. |
| Network Observatory | Read-only validated XRPL telemetry | Source data public | Wallet-specific view is optional and JCS-scoped. |
| Account Readiness | Read-only Xaman authorization or public-address inspection | XRPL data public | Authorization proves session account control, not legal identity. |
| Support / ordinary email | Direct communication to providers and JCS | Not intended public | Ordinary email is not end-to-end confidential or automatically privileged. |
6. Prayer Map privacy
The map is designed to visualize prayer concern without becoming a participant-location database.
- Broad-region publication requires at least 5 distinct signing accounts.
- Country-level publication requires at least 10 distinct signing accounts.
- High-risk/extreme-pressure countries use at least 20 distinct signing accounts.
- The Verify → Prayer Map handoff is content-free and tells the map only to reread validated XRPL history.
- IP address, node/relay, wallet address, browser/device and transaction route are not accepted as physical-location evidence.
- A prayer-focus choice describes what the prayer concerns; it does not prove residence, citizenship, travel or physical presence.
7. Private Capsule
Private Capsule is an experimental local-first encrypted-message mechanism, not a claim of perfect anonymity or a completed secure-messaging service.
Local encryption
The current design uses browser Web Crypto with AES-256-GCM, a random key and IV, and an encrypted-envelope SHA-256 fingerprint.
Separate artifacts
The encrypted transport and recovery key are designed to be separate. Anyone who obtains both can decrypt the message.
Optional neutral receipt
A user may choose a public NFT fingerprint receipt. The public receipt should not contain plaintext, recovery key, exact location or route data.
8. XRP Ledger permanence and public visibility
XRPL is a decentralized public network. JCS cannot turn a validated public transaction into a private record.
- Removing content from a JCS interface does not delete the underlying XRPL record.
- Wallet addresses are persistent public identifiers that may be correlated with other public activity.
- Transaction memos and NFT URI/metadata can reveal content intentionally or accidentally.
- Independent nodes, explorers, researchers, governments, analytics providers and archives may copy or index public records without asking JCS.
- Legal process directed to JCS is not necessary to obtain information already public on XRPL.
9. Local browser storage and cookies
JCS favors local processing where it meaningfully reduces central collection.
Pages may use browser local storage for theme, audio volume, local prayer drafts, incomplete publication state, map refresh signals, evidence files or similar functional state. Clearing local storage can remove unfinished work but cannot remove public XRPL transactions.
JCS does not presently use local settings to build an advertising profile or sell behavioral data. Independent third parties opened by the user may apply their own cookies and storage.
10. Independent services
Interoperability does not imply common control.
Xaman
May process wallet authorization, signing requests, session state and transaction status under its own policies.
XRPL infrastructure
Public servers, validators, explorers and market interfaces receive ledger queries or expose already-public records.
Hosting / repository
GitHub, DNS, certificate, content-delivery and security providers may process routine request and security information.
Media providers
YouTube, Internet Archive, LibriVox or similar services may receive network/browser data when media is deliberately loaded.
Social / email
Social platforms and email providers process deliberate shares and communications under their own terms.
Market references
External market/reference providers can receive network requests when those views or price references are deliberately loaded.
11. Sale, advertising, sharing and AI use
JCS does not intend to monetize religious-expression data through targeted advertising.
- JCS does not intend to sell personal information or rent a testimony/prayer mailing list.
- JCS does not intentionally provide private prayer/support material to advertisers for cross-context behavioral advertising.
- JCS does not intentionally use direct private communications, local drafts or Private Capsule plaintext to train a general-purpose AI model.
- Public XRPL records and publicly viewable website content can be copied by independent third parties outside JCS control.
- If JCS materially changes its advertising, sale/sharing or AI-processing practices, this Policy and relevant controls should be updated before that change is relied upon.
12. Legal process and compelled disclosure
JCS will not treat an informal request, accusation, badge, email signature or claimed public-interest purpose as automatic authority to disclose private information.
- Authenticate the requestConfirm the requesting authority, identity, contact information, jurisdiction, case/reference number, service method and legal instrument.
- Identify the legal basisDetermine whether the demand is a warrant, court order, subpoena, preservation request, emergency request, consent-based disclosure or another instrument, and whether it is legally applicable to JCS and the requested data.
- Map the data actually heldSeparate public XRPL data, JCS-controlled direct records, local-only data JCS does not possess, and third-party data held by another provider.
- Narrow the scopeWhere legally permitted, seek clarification, narrowing, modification or appropriate challenge of vague, overbroad, unduly burdensome, jurisdictionally defective, privileged or protected demands.
- Preserve objections and rightsDo not treat cooperation as a waiver of objections, statutory rights, religious-freedom rights, privilege claims, confidentiality protections or protections belonging to affected users.
- Disclose the minimum responsive dataProduce only what JCS is legally required to produce and actually possesses or controls. Do not create new surveillance records or hidden-location inferences merely to expand production.
- Protect transmissionUse a reasonably secure method, verify the recipient and avoid placing sensitive productions into ordinary public channels.
- Record the responseDocument the demand, authority, scope, dates, objections, disclosures and retention basis, subject to legal restrictions.
13. Preservation requests, litigation holds and deletion conflicts
A valid preservation obligation can temporarily override ordinary deletion or rotation practices for identified records.
- Preservation applies only to information in JCS possession, custody or control and to the scope lawfully required.
- A preservation request does not itself authorize JCS to begin collecting new categories of user activity that JCS did not previously maintain.
- When applicable law requires preservation pending later process, JCS may retain the identified records for the required period even if a deletion request is received.
- Public XRPL data does not need JCS preservation to remain on XRPL, though JCS may preserve a copy if legally required.
- At the end of a valid hold, information should return to the ordinary retention policy unless another lawful basis remains.
14. User notice and transparency
Notice can help a person obtain counsel or exercise legal rights, but some laws and court orders can prohibit or delay notice.
Where legally permitted, safe and operationally feasible, JCS intends to notify an affected user before disclosure or as soon as permitted afterward. JCS may withhold or delay notice when prohibited by law, court order, binding nondisclosure requirement, emergency circumstances, risk of harm, or a legitimate need to protect an investigation.
Where legally permitted and operationally feasible, JCS may publish aggregate transparency information such as numbers and categories of legal demands. Aggregate reporting will not intentionally identify an affected believer or expose sensitive case details.
15. Emergency disclosure requests
Emergency disclosure is reserved for a credible emergency involving immediate danger of death or serious physical injury where applicable law authorizes disclosure.
- Authenticate the requesting agency and callback information independently where feasible.
- Require the emergency, person at risk, requested data and connection between the data and emergency to be described with specificity.
- Disclose no more than reasonably necessary to address the documented emergency.
- Record the request and disclosure basis.
- An emergency exception is not a general shortcut around ordinary legal process.
16. Civil subpoenas, government demands and foreign requests
Different forms of legal process carry different authority and protections.
Civil discovery
JCS may require proper service and evaluate relevance, scope, burden, privilege, confidentiality and available objections. Informal demands from private parties do not receive government-request status.
Government demands
JCS will evaluate the instrument and applicable law. Electronic-communications statutes can impose different rules depending on provider classification, data type and legal process.
Foreign demands
JCS may require an appropriate U.S. legal mechanism, treaty/executive-agreement process or other recognized lawful basis rather than treating an unsupported foreign demand as automatically binding.
17. Retention and deletion
Keeping less information for less time reduces the amount that can be lost, misused or compelled.
JCS intends to retain direct communications, support/security records and operational records only as reasonably necessary for their purpose, dispute prevention, security, legal compliance, evidence integrity or project administration. Local browser data remains until the user/browser clears it or the page removes it. Independent providers control their own retention.
Eligible off-ledger information directly controlled by JCS may be deleted where technically and legally possible. Public XRPL records, independent archives and third-party copies cannot be deleted by JCS.
18. Privacy choices and rights
Rights depend on location, applicable law, JCS legal status and the category of information.
Access
Ask whether JCS directly maintains information about you and request a copy where applicable.
Correction
Request correction of inaccurate information directly controlled by JCS where applicable.
Deletion
Request deletion of eligible off-ledger records, subject to security, legal-hold and other lawful exceptions.
Restriction / objection
Request restriction or object to certain processing where applicable law provides that right.
Portability
Request portable information JCS directly maintains when legally required and technically feasible.
Withdraw consent
Withdraw consent for future optional processing. This cannot reverse an already validated XRPL transaction.
19. Children and minors
General Christian content can be read without publishing personal information.
JCS is not designed to knowingly collect personal information from children under 13 through wallet/NFT/social functions. Children should not connect a wallet, mint, publish testimony, disclose age/school/location/congregation or transmit identifying information without parental/guardian involvement and any consent required by applicable law.
Parents should understand that JCS cannot erase a validated XRPL transaction. Safety-critical information about a minor should not be placed on-chain.
20. Security and incident response
No website, browser, wallet, network, email system or encryption implementation is guaranteed secure.
- Use the canonical domain and independently verify the complete JCS issuer.
- Keep wallet secrets inside Xaman or another trusted wallet; JCS should never receive them.
- Review every signing request independently.
- Keep operating system, browser, wallet and security software updated.
- Minimize religious, legal, medical and location details in public records.
- Report suspected impersonation, malicious requests and security defects through the published security channel.
Security incidents may require containment, logging, preservation, investigation, user notice and regulatory or law-enforcement notification where applicable.
21. International access and persecuted believers
JCS can be reached from jurisdictions with very different religious-freedom, privacy, blockchain and content laws.
Reading without connecting a wallet may be safer than publishing an on-ledger Christian record. A VPN, private browser, alias, hidden-wallet display or shortened address does not guarantee anonymity. Public XRPL activity can be correlated across time and services.
Information sent to independent providers can be processed in the United States or other countries. Cross-border legal protections and government-access rules differ.
22. Ministry confidentiality, clergy privilege and legal privilege
A religious purpose does not automatically make every communication legally privileged.
- A public XRPL prayer/testimony/NFT is public and should never be treated as confidential pastoral communication.
- Ordinary email, social-media messages and website support are not automatically protected by clergy-penitent privilege.
- Whether clergy-penitent or similar privilege applies depends on the jurisdiction, communicator, recipient, role, purpose, confidentiality and governing law.
- Attorney-client privilege exists only when the legal requirements for that privilege are actually met; communicating with JCS is not the same as communicating with your attorney.
- JCS is not a medical provider and does not treat messages as protected medical records merely because a prayer mentions health.
23. Ministry and legal-status statement
The religious mission and this Privacy Policy do not independently establish organizational or tax status.
JCS describes its activities as a Christ-centered religious ministry dedicated to religious, educational and outreach purposes. This policy does not by itself create, prove or guarantee status as a church, nonprofit corporation, public charity, tax-exempt organization, integrated auxiliary or organization recognized under Internal Revenue Code Section 501(c)(3). Those questions depend on governing documents, actual operations, applicable law and any required governmental process.
No donation or payment should be treated as tax deductible unless JCS separately provides lawful written confirmation applicable to that transaction.
24. Source authority and research references
These references influenced the privacy architecture. They do not mean every listed law or framework applies to JCS in every jurisdiction.
25. Changes to this Policy
Privacy changes should track changes in JCS architecture rather than lag behind them.
JCS may revise this Policy when project surfaces, private communication, moderation, identity, hosting, law, security controls or legal-process procedures change. The effective date and release number should be updated for material revisions. A later policy cannot make a historical XRPL transaction private.
26. Privacy, legal and security contact
Use the minimum information necessary in an initial message.
Machine-readable contract: jcs-privacy-legal-process-v1
“Moreover it is required in stewards, that a man be found faithful.”
— 1 Corinthians 4:2, King James Version