12. Privacy and Safety
12.1 Connect authority, do not collect everything
IROA stores on user devices what can remain there and shares only minimum fields temporarily for execution. More data is not treated as automatically better intelligence.
12.2 Privacy principles
- State purpose before requesting data.
- Default to private and minimum sharing.
- Prefer user vaults, local devices, or approved institutions for sensitive information.
- Delete task data after use and separate learning consent from service consent.
- Do not unfairly restrict service after learning-data refusal.
- Do not retain raw conversation, screen, or health data indefinitely.
- Separate personal data from reward records.
- Support access, correction, deletion, portability, and withdrawal.
12.3 One-time task authority
Purpose: book rehabilitation at Hospital A
Allowed site: hospital.example
Allowed actions: view times, create booking candidates
Forbidden: payment, other departments, record download
Data: name, last digits of phone, preferred date
Expiry: 15 minutes
Final submit: separate registered approval channel required
Authority is signed, scoped, and disposed after use. Verifiable credentials should disclose only needed facts. Failed remote attestation prevents assignment of sensitive work.
12.4 Risks of agentic execution
External content is never treated as user instruction. IROA separates request from content, validates tool input and output, stops on privilege expansion, independently controls upload, download, and messaging, checks consequential outcomes, and quarantines anomalous Nodes.
12.5 Rewards and personal data
Raw health, disability, conversation, voice, video, location, identity, account, and household robot observations are never written to a blockchain or public ledger. Reward integrity uses pseudonymous qualification, outcome or dispute status, minimum calculation data, policy version, and qualification revocation state.
12.6 Security operations
Operations include updates, vulnerability response, device enrollment and disposal, hardware-backed keys and rotation, anomalous login, request and reward detection, breach response and notice, independent assessment, and responsibility contracts for hospital, payment, and public integrations.