Recognitium
FR Create account
Legal · Privacy · Last updated 2026-09-06

Privacy Policy

We protect your privacy through construction, not administrative promises. The sensitive thing never reaches us at all.


1. Privacy by architecture

Recognitium operates on a fundamental principle: we protect your privacy through construction, not administrative promises. Traditional services collect, process, and store your data behind logical firewalls, relying on employee policy and software security to protect it. Recognitium is built so that the sensitive thing never reaches us at all.

Whether you use our engine for financial settlement or for sealing records, the core architecture is designed so that protecting your data is not a choice we make but a property anyone can recheck: what we never receive, we cannot expose.

2. Zero-storage by construction

Recognitium implements a zero-storage paradigm: your files, documents, and their contents never reach us in the first place. Hashing happens in your browser or your own infrastructure, and only the 64-character SHA-256 fingerprint is transmitted for settlement.

Because the fingerprint is one-way and the payload never leaves your environment:

  • We do not receive, store, or back up your documents or their contents.
  • We cannot reconstruct a file from its fingerprint — for you, for ourselves, or for anyone else.
  • There is no centralized vault, database, or enclave of client content that can be breached.

3. No retrospective rewriting

Receipts are sealed by SHA-256 hash-chaining, not by signatures: there is no signing key in the settlement path — nothing that could later re-sign an altered history. The witness that seals each receipt is consumed into its fingerprint at settlement; its class is stamped on the receipt, computational today.

Legal compliance and subpoenas: Because every receipt is chained into every receipt after it, Recognitium is incapable of modifying history or forging receipts — changing any past entry would break the recomputable chain that clients and third parties already hold. If compelled by a court order, government request, or subpoena to alter past transaction sequences, we cannot comply — not as a matter of policy, but as an arithmetic constraint that anyone can check.

4. The blind registry and GDPR Recital 26

The Recognitium cloud registry acts strictly as a blind notary. It indexes only public, one-way cryptographic hashes (SHA-256 digests) of the tip transitions.

  • No payload storage: We never receive, process, or store original transaction payloads or contract details. Only the 64-character hexadecimal SHA-256 hash is transmitted to our servers.
  • EU GDPR compliance: A SHA-256 hash is one-way: it cannot be reversed to reconstruct the original data, and we never hold that original. What reaches us is therefore a fingerprint we cannot attribute to any person. The GDPR (Recital 26) treats such data as pseudonymised rather than anonymous, and we handle it under the GDPR accordingly. Your personal data never leaves your infrastructure.

5. Personal data we collect

While our core settlement engine is completely blind to personal data, we collect minimal details to manage client relationships and software licenses:

  • Account data: Email address for authentication, full name for license identification, company name for organization management, and IP address on signup only (for rate limiting and abuse prevention).
  • Billing data: Invoicing information and billing addresses are processed securely by our payment processor. We do not store or process credit card numbers on our servers.

The lawful basis for this processing is contract performance under GDPR Article 6(1)(b) and legitimate interest in security under Article 6(1)(f).

6. Where your data is stored

We keep operational data secure without restricting access by geography:

  • Registry and servers: Hosted on sovereign French physical hardware (3DS Outscale) in Paris, France via Scalingo.
  • Invoicing and business operations: Processed securely by trusted providers under applicable data protection agreements.
  • Global availability: Recognitium access is not restricted by country or region.

7. Your rights under GDPR

The controller of this processing is Recognitium, represented by its founder, José Santiago Niño Mojica, Paris, jose@recognitium.com. Under the GDPR you have the rights of access, rectification, erasure, portability, restriction of processing and objection, and the right to lodge a complaint with the CNIL (cnil.fr). To exercise your rights, contact us at jose@recognitium.com.

8. Retention and disposal

Account data is retained for the active subscription duration plus 12 months. Accounting records are kept for 10 years, as the French Commercial Code requires (Article L. 123-22); tax records for 6 years. IP logs are purged after 90 days.

9. Cookies and telemetry

We use only essential session cookies for authentication, plus cookieless, privacy-preserving product analytics (no cookies, no cross-site tracking, no personal data in events). We do not use tracking pixels or advertising cookies.

10. The MCP connector (Claude, ChatGPT, and other AI clients)

When you connect Recognitium to an AI assistant through the Model Context Protocol, the same architecture applies. Specifically:

  • Authentication: your AI client signs in via OAuth 2.1. Access and refresh tokens are stored hashed (SHA-256) on our servers; we never store them in clear.
  • Sealing and memory tools: content is hashed inside your AI client or browser. Only the 64-character fingerprint reaches us — never the memory, file, or conversation itself.
  • Market signals (IVM): a signal you choose to publish is public by design — any connected AI can read it until it expires. Your AI is contractually instructed to show you the exact text and obtain your explicit yes before posting. Replies and acknowledgments are equally public, receipted events.
  • What your AI reads: browsing the market, verifying receipts, and checking your own signals costs nothing and creates no public record. Only explicit write actions (a seal, a signal, an acknowledgment) create chain entries.
  • No conversation access: we receive only the tool calls your AI makes — never your conversation, prompts, or context.

11. Policy changes

Any changes to this policy will be posted on this page. Material updates will be notified to subscribers via email.