Religious safety · data minimization · legal process

Protect the believer.
Collect less. Expose less.

JCS is a Christ-centered, non-custodial XRP Ledger project. This policy governs the current JCS ecosystem—including Sign the Ledger, Prayer Map, Private Capsule, Network Observatory, Account Readiness, local browser features and support channels—and places special emphasis on people whose Christian expression may create personal, family, employment, governmental or physical risk.

No wallet SDK loaded on this pageNo secret collectionPublic XRPL ≠ confidentialReligious data treated as high sensitivity

High-risk Christian safety essentials

If public Christian expression could expose you or another person to surveillance, retaliation, violence, arrest, discrimination or coercion, safety is more important than creating a blockchain record.

Read before publishing
1 · Read silentlyYou do not need a wallet or token balance to read the mission, Scripture, policy or safety information.
2 · Remove identifiersDo not publish exact location, congregation, employer, school, travel path, safe house, contact chain or vulnerable third-party identity.
3 · Prefer local/privateUse local-only tools when possible. A public NFT or transaction permanently creates wallet-linked evidence.
4 · Separate transport and keyIf using Private Capsule, keep the encrypted transport and recovery key separate and use channels you independently trust.
5 · Assume endpoint riskBrowser encryption cannot protect a compromised device, malware, hostile extension, screen capture, physical seizure or coercion.
Do not put escape routes or real-time movement details on XRPL, Prayer Map, NFT metadata, ordinary email, public social media or JCS support. JCS does not publish extraction routes and does not treat prayer-focus regions as participant locations.

Policy contents

This version separates human-safety rules, public-ledger realities and legal-process procedures so each can be understood independently.

1. Scope and project identity

This Policy applies to JCS-controlled pages and features that link to it.

JCS-controlled surfaces

Covered surfaces include the JCS Home portal, Sign the Ledger, Prayer Map, Network Observatory, Account Readiness, About & Vision, local prayer/fellowship tools, Private Capsule features when delivered by JCS-controlled code, privacy/terms/security pages, AI and identity manifests, and direct support communications received by JCS.

Independent systems such as XRP Ledger nodes, Xaman, GitHub, explorers, market providers, media hosts, social networks and email providers have their own privacy and legal obligations. JCS cannot promise what an independent provider collects, retains or discloses.

2. Privacy principles

The project uses privacy risk management rather than assuming that every technically obtainable data point should be collected.

Collect less by design

Data minimization

Collect, create and retain only information reasonably necessary for the requested function, security, evidence, legal duty or project operation.

Purpose limitation

Do not quietly reuse prayer, testimony, contact or support material for unrelated profiling, advertising, spiritual ranking or general-purpose AI training.

Least disclosure

When disclosure is legally required, disclose the minimum responsive information within JCS possession or control rather than broad account histories by default.

No exact-location inference

JCS does not treat IP address, wallet address, XRPL server, relay endpoint, device, transaction route or prayer-focus label as proof of a person’s physical location.

No wallet-secret collection

JCS does not need and should never request a seed phrase, private key, recovery words, Xaman passcode or device passcode.

No hidden access path

Privacy features should not contain a secret decryption key or surveillance backdoor accessible to JCS merely because legal process might someday arrive.

3. Information involved

Availability does not mean JCS centrally stores every category.

Public XRPL evidence

Wallet addresses, hashes, ledger indexes, transaction types, trust lines, token balances, offers, AMM records, NFTs, URI fields and transaction memos may be public network data.

Deliberately submitted content

A prayer, testimony, reply, Amen, support response, Scripture reference, display name, handle or other content may be processed when you choose to publish it.

Local-only state

Drafts, display preferences, media settings, pending workflow data, downloaded evidence and Private Capsule material can remain on the user’s device unless deliberately transmitted.

Direct communications

Email or support messages may include the sender address, content, attachments and response history. Do not send secrets or unnecessary sensitive records.

Infrastructure data

Hosting, security, network and browser providers may process IP addresses, user agents, timestamps, requested paths, errors and abuse signals independently of JCS application code.

Data intentionally absent

JCS does not centrally maintain a master list of users’ exact physical locations, wallet seeds, Private Capsule keys, or private messages merely because the platform can display public XRPL evidence.

4. Religious and sensitive information

Prayer, testimony and participation in Christian ministry can reveal or strongly suggest religious belief.

Heightened sensitivity
Religious belief can be legally sensitive information. Some privacy regimes expressly classify religious or philosophical beliefs as sensitive or special-category data. JCS therefore treats religious-expression data as high-sensitivity by project policy even where a particular statute may not apply.

Do not publish another person’s medical condition, immigration status, criminal allegation, family crisis, financial distress, precise location, persecution history, or identity simply because the information is included in a prayer request. Obtain informed permission and minimize details.

4A. Purposes of processing

JCS limits processing to functions a user requests, public-ledger verification, safety, security, support, legal compliance and project administration.

Purpose limitation
Not an authorized purpose: converting prayer, testimony, religious participation or crisis information into a secret advertising profile, spiritual ranking, paid-priority system or unrelated general-purpose AI training dataset.

5. Public evidence versus private dignity

Each JCS feature should state whether information remains local, becomes public, or reaches an independent provider.

Architecture boundary
SurfaceNormal privacy posturePublic?Key warning
Scripture / About / policy pagesRead-only contentNo wallet publicationHosting/network providers may still see routine request data.
Sign the Ledger prayer/testimonyExplicit Xaman-authorized NFT + registry publicationYesWallet and public transaction evidence are durable.
Prayer MapValidated public registry history plus thresholded aggregatesAggregatePrayer-focus labels are not participant locations.
Private CapsuleBrowser-local encryption; separate transport/key filesNo, unless user chooses receiptOptional NFT fingerprint receipt links a wallet to a receipt event.
Network ObservatoryRead-only validated XRPL telemetrySource data publicWallet-specific view is optional and JCS-scoped.
Account ReadinessRead-only Xaman authorization or public-address inspectionXRPL data publicAuthorization proves session account control, not legal identity.
Support / ordinary emailDirect communication to providers and JCSNot intended publicOrdinary email is not end-to-end confidential or automatically privileged.

6. Prayer Map privacy

The map is designed to visualize prayer concern without becoming a participant-location database.

Thresholded aggregates

7. Private Capsule

Private Capsule is an experimental local-first encrypted-message mechanism, not a claim of perfect anonymity or a completed secure-messaging service.

Experimental

Local encryption

The current design uses browser Web Crypto with AES-256-GCM, a random key and IV, and an encrypted-envelope SHA-256 fingerprint.

Separate artifacts

The encrypted transport and recovery key are designed to be separate. Anyone who obtains both can decrypt the message.

Optional neutral receipt

A user may choose a public NFT fingerprint receipt. The public receipt should not contain plaintext, recovery key, exact location or route data.

Do not use the public receipt when wallet linkage itself creates danger. JCS cannot promise anonymity against blockchain analytics, endpoint compromise, physical seizure, coercion or a recipient who rediscloses the decrypted message.

8. XRP Ledger permanence and public visibility

XRPL is a decentralized public network. JCS cannot turn a validated public transaction into a private record.

Before signing: review network, transaction type, destination, amount, fee, issuer, currency, NFT fields, memos and any six-digit challenge in Xaman. Decline anything that does not match your intent.

9. Local browser storage and cookies

JCS favors local processing where it meaningfully reduces central collection.

Pages may use browser local storage for theme, audio volume, local prayer drafts, incomplete publication state, map refresh signals, evidence files or similar functional state. Clearing local storage can remove unfinished work but cannot remove public XRPL transactions.

JCS does not presently use local settings to build an advertising profile or sell behavioral data. Independent third parties opened by the user may apply their own cookies and storage.

10. Independent services

Interoperability does not imply common control.

Xaman

May process wallet authorization, signing requests, session state and transaction status under its own policies.

XRPL infrastructure

Public servers, validators, explorers and market interfaces receive ledger queries or expose already-public records.

Hosting / repository

GitHub, DNS, certificate, content-delivery and security providers may process routine request and security information.

Media providers

YouTube, Internet Archive, LibriVox or similar services may receive network/browser data when media is deliberately loaded.

Social / email

Social platforms and email providers process deliberate shares and communications under their own terms.

Market references

External market/reference providers can receive network requests when those views or price references are deliberately loaded.

11. Sale, advertising, sharing and AI use

JCS does not intend to monetize religious-expression data through targeted advertising.

17. Retention and deletion

Keeping less information for less time reduces the amount that can be lost, misused or compelled.

JCS intends to retain direct communications, support/security records and operational records only as reasonably necessary for their purpose, dispute prevention, security, legal compliance, evidence integrity or project administration. Local browser data remains until the user/browser clears it or the page removes it. Independent providers control their own retention.

Eligible off-ledger information directly controlled by JCS may be deleted where technically and legally possible. Public XRPL records, independent archives and third-party copies cannot be deleted by JCS.

18. Privacy choices and rights

Rights depend on location, applicable law, JCS legal status and the category of information.

Access

Ask whether JCS directly maintains information about you and request a copy where applicable.

Correction

Request correction of inaccurate information directly controlled by JCS where applicable.

Deletion

Request deletion of eligible off-ledger records, subject to security, legal-hold and other lawful exceptions.

Restriction / objection

Request restriction or object to certain processing where applicable law provides that right.

Portability

Request portable information JCS directly maintains when legally required and technically feasible.

Withdraw consent

Withdraw consent for future optional processing. This cannot reverse an already validated XRPL transaction.

Do not send a government identity document, wallet seed, private key or unnecessary sensitive information in an initial privacy request. JCS may request proportionate verification before releasing or changing a record.

19. Children and minors

General Christian content can be read without publishing personal information.

JCS is not designed to knowingly collect personal information from children under 13 through wallet/NFT/social functions. Children should not connect a wallet, mint, publish testimony, disclose age/school/location/congregation or transmit identifying information without parental/guardian involvement and any consent required by applicable law.

Parents should understand that JCS cannot erase a validated XRPL transaction. Safety-critical information about a minor should not be placed on-chain.

20. Security and incident response

No website, browser, wallet, network, email system or encryption implementation is guaranteed secure.

Defense in depth

Security incidents may require containment, logging, preservation, investigation, user notice and regulatory or law-enforcement notification where applicable.

21. International access and persecuted believers

JCS can be reached from jurisdictions with very different religious-freedom, privacy, blockchain and content laws.

Safety before publicity

Reading without connecting a wallet may be safer than publishing an on-ledger Christian record. A VPN, private browser, alias, hidden-wallet display or shortened address does not guarantee anonymity. Public XRPL activity can be correlated across time and services.

Information sent to independent providers can be processed in the United States or other countries. Cross-border legal protections and government-access rules differ.

If you face targeted surveillance, do not rely on JCS alone for operational security. Use specialized digital-security assistance, local legal advice where safe, and threat-model the device, network, recipient and physical environment.

22. Ministry confidentiality, clergy privilege and legal privilege

A religious purpose does not automatically make every communication legally privileged.

For legally sensitive matters, consult qualified counsel and use the communication channel counsel directs. Do not place privileged strategy, witness identity, evidence locations or confidential case details on XRPL.

24. Source authority and research references

These references influenced the privacy architecture. They do not mean every listed law or framework applies to JCS in every jurisdiction.

Reference, not legal opinion

25. Changes to this Policy

Privacy changes should track changes in JCS architecture rather than lag behind them.

JCS may revise this Policy when project surfaces, private communication, moderation, identity, hosting, law, security controls or legal-process procedures change. The effective date and release number should be updated for material revisions. A later policy cannot make a historical XRPL transaction private.

26. Privacy, legal and security contact

Use the minimum information necessary in an initial message.

Machine-readable contract: jcs-privacy-legal-process-v1

Never include a wallet seed, recovery phrase, private key, passcode, exact safe-house location, escape route, government identity document or unnecessary sensitive third-party information in an initial privacy or legal-process inquiry.

“Moreover it is required in stewards, that a man be found faithful.”
— 1 Corinthians 4:2, King James Version