Aruta Logo

Privacy Policy & Synthetic Data Governance

Comprehensive disclosure of Dansocial Inc.'s data minimization standards, sandboxed ambient summon architecture, and statutory consumer rights across the United States and Canada.

Effective: October 1, 2026
STATUTORY DISCLOSURES

Do Not Sell or Share My Info

Exercisable under CCPA/CPRA. One-click opt-out of cross-context behavioral targeting and diagnostic training aggregation.

GPC Signal Honored Submit Opt-Out →
DATA PORTABILITY

Telemetry & Audit Logs

Obtain an encrypted machine-readable active (JSON/CSV) of ambient query tokens, resolved merchant checkouts, and device fingerprints.

Avg Delivery: 1–4 Hours Request Archive →
RIGHT TO ERASE

Cryptographic Deletion

Execute irreversible zeroization of your Dansocial identity graph, token vaults, paired social handle IDs, and merchant proxy keys.

Irreversible Operation Initiate Wipe →
SECTION 01 / FOUNDATION

Overview & Our Privacy Commitment

Dansocial Inc. ("Dansocial", "we", "us", or "our") designs and deploys Aruta, an autonomous synthetic commerce agent operating across proprietary mobile/web applications, embedded browser extensions, and conversational platforms (including Instagram Direct, TikTok Direct Messages, WhatsApp, Telegram, and Apple Messages via SMS proxy).

Traditional internet search and commerce platforms monetize surveillance capitalism: tracking your digital footprint, categorizing your psychological profile, and selling targeted auctions to advertisers. Dansocial rejects this paradigm. Our foundational doctrine is Synthetic Sovereignty: we do not trade, broker, or sell personal identifiers or contextual query histories. We engineer autonomous agents that complete real-world purchasing actions on your behalf with mathematical telemetry boundaries.

⚖️ FTC AI Transparency Notice In accordance with the Federal Trade Commission's guidelines on automated decision-making and artificial intelligence disclosures, Aruta operates as an autonomous heuristic system. Aruta explicitly informs users whenever a transaction, price calculation, or recommendation is synthesized by machine learning models.
SECTION 02 / TAXONOMY

Information We Collect

We collect information strictly when necessary to resolve autonomous shopping prompts, verify shipment parameters, and prevent fraud across global merchant gateways:

A. Direct Account & Vault Data Encrypted at rest (AES-256-GCM)
When creating an Aruta profile, we collect your name, phone number, primary delivery address, and delegated payment token. Payment card numbers (PANs) are never exposed to or stored by Dansocial; they are directly tokenized via PCI-DSS Level 1 compliant gateway partners (Stripe, Apple Pay, Adyen).
B. Ambient Social Summon Tokens Ephemerally Sandboxed
When you mention or summon @Aruta within third-party messaging apps, our intake webhook receives a payload containing your unique platform user ID, the timestamp, and strictly the isolated message containing the summon trigger. We capture no prior conversational context, no profile media files, and no metadata from unmentioned conversation participants.
C. Synthetic Diagnostic & Device Telemetry Zero-Identifiable Hash
IP address (coarsened to city/region level for tax/jurisdiction compliance), browser agent hash, client runtime latencies, and diagnostic session crash traces. Diagnostic identifiers are rotated every 72 hours to prevent perpetual user stitching.
SECTION 03 / PROCESSING

How We Process & Use Your Information

Dansocial processes ingested telemetry under legitimate interest, statutory contractual necessity, and explicit opt-in consent for the following bounded objectives:

  • Autonomous Checkout Dispatch: Resolving product URLs, querying real-time inventory indices, calculating carrier shipping rates, and passing one-time merchant execution tokens.
  • Risk Modeling & Anti-Abuse: Detecting bot manipulation, counterfeit listings, stolen credentials, and anomalous multi-destination checkouts.
  • Statutory Compliance: Remitting accurate state sales taxes (e.g., California CDTFA, Streamlined Sales Tax protocols) and cross-border Canadian GST/HST calculations.
🛡️ STRICT AI MODEL TRAINING BOUNDARY Under Dansocial's Architecture Charter, we do not train foundational frontier Large Language Models (LLMs) on your raw personal conversation transcripts, private billing details, or identifiable shopping sessions. Any telemetry utilized for internal agent routing is stripped through an irreversible differential privacy pipeline (ε = 0.5, δ = 1e-5), rendering reverse-engineering of user identity mathematically impossible.
SECTION 04 / ARCHITECTURE

Zero-Leak Social Summon Architecture

Patent Protected

The central privacy concern with third-party social agent integrations (e.g., inviting an AI assistant into a WhatsApp group, Instagram direct chat, or TikTok comment chain) is the risk of ambient eavesdropping surveillance. Dansocial resolves this through our proprietary Ephemeral Ingress Enclave:

1. Zero Ambient Buffer Aruta cannot access or read historical chat messages preceding the summon tag. When '@Aruta' is invoked, only that discrete string is transmitted.
2. Tokenized Nonces Conversation participant handles are hashed into one-time cryptographic nonces before reaching inference models, ensuring external LLMs never receive social usernames.

We never maintain persistent listening sockets. After an inquiry is answered or a transaction is confirmed, the enclave memory instance dissolves immediately.

SECTION 05 / DISCLOSURES

Sharing & Third-Party Transfers

Dansocial does not monetize consumer profiles. We transmit data strictly to authorized sub-processors required to complete user-commanded commerce executions:

Entity / Category Data Elements Transferred Purpose Retention
Authorized Merchants (e.g., Shopify, Amazon, Direct Brands) Shipping address, recipient name, encrypted checkout nonce Order fulfillment & tracking delivery Merchant Privacy Policy Governed
Payment Facilitators (Stripe, Apple Pay) Billing postal code, tokenized credit card authorization PCI-DSS authorization & fraud verification Statutory 7-Year Tax Ledger
Cloud Enclave Infrastructure (AWS Nitro / Google Cloud) Encrypted memory states, temporary query tokens Real-time LLM inference & web parsing Volatile RAM only (0 seconds persistent)
SECTION 06 / TRACKING

Cookies, Tracking & Ambient Session Tokens

Aruta web applications do not deploy cross-site tracking pixels (such as Meta Pixel or third-party ad networks). We employ strictly functional and security tokens:

Strictly Essential Tokens Encrypted authentication cookies (HTTP-Only, SameSite=Strict) ensuring zero cross-site scripting exposure for session persistence.
Diagnostic Anomaly Tokens Client-side performance metrics measuring load speeds and network errors. Can be toggled off at any moment via privacy controls.
SECTION 07 / CALIFORNIA & STATE PROTECTIONS

California Consumer Privacy Act (CCPA / CPRA) Disclosures

This section applies exclusively to residents of California, Colorado, Virginia, Connecticut, and Utah under their respective comprehensive consumer privacy statutes.

1. Notice of Collection & Right to Know You have the right to request twice within a 12-month period the categories of personal information Dansocial collected, the categories of sources, the business purpose for collection, and the specific pieces of data held.
2. Right to Opt-Out of "Sale" and "Sharing" (Cross-Context Behavioral Advertising) Dansocial does not "sell" personal information in exchange for monetary consideration. However, certain state definitions construe targeted advertising data exchanges as "sharing." You may opt-out permanently via the persistent footer link "Do Not Sell or Share My Personal Info" or by enabling the Global Privacy Control (GPC) signal on your browser.
3. Right to Limit Use of Sensitive Personal Information We do not collect sensitive personal information (such as social security numbers, racial or ethnic origin, genetic data, or precise geolocation below 1,850 feet) except as necessary to deliver physical shipments.
4. Non-Discrimination Guarantee We will never degrade transaction speeds, charge discriminatory algorithmic pricing, or deny service features if you exercise your statutory privacy rights.
SECTION 08 / CANADIAN MANDATE

Canadian Consumer Protections (PIPEDA)

In accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and provincial statutes (Alberta PIPA, BC PIPA, Quebec Law 25), Dansocial adheres to the 10 Fair Information Principles.

Canadian users have the right to contest the accuracy and completeness of their personal information and have it amended appropriately. Any cross-border transmission of Canadian resident data is bound by contractual terms ensuring protection equivalent to Canadian standards.

SECTION 09 / TRANSFERS

Cross-Border Data Transmission

Dansocial's primary data centers and confidential computing nodes reside in the United States. If you interact with Aruta from Canada, Europe, or other international regions, your information will be transmitted, processed, and safeguarded within the United States using Standard Contractual Clauses (SCCs) and cryptographic transit layers (TLS 1.3).

SECTION 10 / RETENTION

Data Retention & Cryptographic Deletion

We apply an automated lifecycle to all ingested telemetry:

  • Unclaimed Conversational Sessions: Permanently purged after 14 days of inactivity.
  • Resolved Transaction Records: Retained for 7 calendar years solely to fulfill IRS, state tax, and merchant dispute resolution mandates.
  • Zeroization Command: When an erasure request is confirmed, Dansocial deletes all key-pair associations within our KMS vault, rendering remaining database backups mathematically non-recoverable.
SECTION 11 / CHILD SAFETY

Children's Privacy (COPPA & Age Restrictions)

Aruta is an autonomous purchasing agent and is strictly restricted to individuals aged 18 and older (or the age of majority in your jurisdiction). We do not knowingly solicit, collect, or store personal information from children under 13 under the Children's Online Privacy Protection Act (COPPA), nor minors aged 13–16 without explicit affirmative consent.

If Dansocial discovers that an account has been initialized by an unauthorized minor, all associated records are purged immediately from our directories.

SECTION 12 / SECURITY

Security Measures & SOC 2 Type II Safeguards

Dansocial implements defense-in-depth protocols audited annually by independent AICPA-accredited assessors:

Confidential VM Data encrypted in memory during active synthesis using hardware roots of trust.
mTLS 1.3 Everywhere Strict mutual cryptographic handshakes across all microservice boundaries.
Redundancy & BCP Continuous zero-loss replication across isolated geographic fault domains.
SECTION 13 / GOVERNANCE

Changes to this Privacy Policy

We reserve the right to amend this document to reflect changes in regulatory directives, machine learning paradigms, or new conversational platform integrations. When material adjustments occur, we will dispatch an advisory notification through registered Aruta mobile interfaces 30 days prior to the effective date. Continued usage constitutes acceptance.

SECTION 14 / CONTACT

Contact Dansocial's Data Protection Officer

To exercise statutory rights, file formal inquiries, or escalate data privacy disputes, reach out directly to our dedicated legal & privacy team:

Dansocial Inc. • Privacy & Trust Division Attn: Data Protection Officer hello@aruta.xyz
Contact Legal Counsel