Spiral Sentinel Labs Privacy ledger

public policy record

Privacy ledger // record 01

Collect less. Explain the rest.

No creepy tracking.

Spiral Sentinel Labs builds public web surfaces and private collaboration tools and owner services that stay useful without third-party analytics, behavioural ads, or visitor profiling.

This policy explains what the public sites do, what private collaboration and owner services may need, what the hosting layer may process, and what remains local in your browser.

  • 01No behavioural advertising
  • 02No third-party analytics
  • 03Local state stays local unless shared

Effective August 4, 2026

Posture privacy by restraint

Contact privacy@spiralsentinel.com

Policy scope // 02

One record across public and private surfaces.

This policy applies to Spiral Sentinel Labs public web surfaces and private collaboration services, including spiralsentinel.com, s1m4x.com, 2y4n.com, pad.2y4n.com, pad-sandbox.2y4n.com, music.2y4n.com, Games Bay, PVNS pages, static notes, Matrix identity-domain pages, and other Spiral Sentinel Labs modules.

Data boundaries // 03

Different surfaces require different disclosures.

Public browsing, encrypted collaboration, owner-only media, browser-local state, and server operations are separated here instead of being treated as one data flow.

Public surfaces // P01

No public account collection. No behavioural ads.

The public sites do not ask visitors to create accounts, do not run third-party analytics, do not use advertising networks, and do not sell or share visitor data with advertisers. Static public pages are intended to be readable without login, tracking pixels, or cross-site profiling.

Private collaboration // P02

Invite-only workspaces may use accounts.

Private collaboration services under 2y4n.com, such as a self-hosted CryptPad instance, may require invited accounts so approved collaborators can access shared documents. Public registration is not intended. These services do not use third-party analytics, behavioural ads, third-party authentication, or advertising networks.

Encrypted documents // P03

Content is encrypted before storage.

CryptPad-style collaboration is designed so document content is encrypted in the browser before it is stored on the server. Under normal operation, the server stores encrypted document data and cannot read document contents through ordinary administrative access.

Operational metadata may still exist, such as account identifiers, document sizes, timestamps, request paths, IP addresses, user agents, session state, and server logs. End-to-end encryption protects content, but users still trust the server to deliver the correct client code.

Document content
encrypted before storage
Operational metadata
may still exist
Client delivery
server trust still matters
04

Owner-only media

One private account. No public library.

The self-hosted Navidrome service at music.2y4n.com provides private music streaming for its sole owner. Authenticated offline downloads are available only to that owner and default to the original media files. Public registration, public sharing, external metadata agents, scrobbling, usage insights, third-party analytics, and advertising integrations are disabled.

Music files, the library index, the account record, playlists, favourites, and other service state may be stored on the server. This data is protected by access controls and HTTPS in transit, but it is not end-to-end encrypted from the server operator. The sole user is also the operator.

The music route keeps a short security record without query strings, referrers, or user agents: source IP address, timestamp, request method, normalized path, response status, and response size. These web logs are subject to the server's 14-file daily rotation policy. Protected application logs retain seven daily rotations of errors and narrowly scoped failed API authentication warnings; those warnings may include a source IP address and attempted username. Routine track, search, and playback logging is disabled.

Encrypted infrastructure backups include the service configuration and database. The VPS music copy is a reconstructible serving mirror and is excluded from the regular infrastructure backup; the validated local library remains authoritative.

05

Hosting logs

Basic infrastructure logs may exist.

Like most websites, the hosting infrastructure may process basic web-server logs such as IP address, user agent, request path, timestamp, and status code. These logs are used for security, abuse prevention, debugging, maintenance, and availability. They are not used to build advertising profiles or behavioural analytics.

06

Third parties

Infrastructure, not ad-tech.

Spiral Sentinel Labs uses third-party infrastructure providers for services such as domain registration, DNS, TLS certificates, hosting, and email. These providers may process technical data needed to operate the service. These sites and services do not intentionally send visitor data to analytics networks, ad platforms, social tracking pixels, or cross-site profiling tools.

Local storage // P07

Some modules remember things locally.

Browser-native modules such as Games Bay may use localStorage to remember local stats, mode choices, or best scores. PVNS tools may store answers in the URL hash or browser-local state so summaries can be copied or restored. This information stays in your browser unless you choose to share it.

Mandala Shift stores match, sound, and ledger preferences locally and may use IndexedDB for custom piece images. Those images are validated, cropped, resized, and re-encoded in the browser to remove source metadata; they are not uploaded. TriAxis Orbit stores its current match, player settings, and board-view preferences locally. Neither game includes network gameplay.

Private collaboration tools may use browser storage, IndexedDB, session storage, or service-required cookies for login state, cryptographic state, editor operation, preferences, and document access. Clearing browser data may log you out, remove local preferences, or require recovery steps for encrypted collaboration data.

  • Games Baystats + choices
  • PVNShash + local state
  • Mandala Shiftpreferences + images
  • TriAxis Orbitmatch + board view
  • Collaborationsession + crypto state

S1M4X boundary // P08

The beacon is not the being.

The S1M4X public page is a static public beacon and founding record. It does not provide public chat, accounts, cloud-hosted autonomy, or a public control surface. The local core remains hardware-bound and off-route.

Your choices // 04

You stay in control.

You can clear localStorage, site data, cache, and browser history at any time through your browser settings. You may also use privacy tools, content blockers, private browsing modes, and DNS or network protections. Some local features may reset if you clear local browser data.

Private collaboration users may export their own documents, clear browser storage, request account removal, or ask for access changes. Deletion from active service storage may not immediately remove encrypted copies from short-term backups or maintenance snapshots.

Clearing local data may also clear preferences, sessions, and cryptographic state needed by private collaboration tools.

Contact // 05

Privacy questions.

For privacy questions, contact privacy@spiralsentinel.com. For vulnerability reports about public web surfaces or private collaboration services, use the route published in security.txt.