Freehold — you own the data, apps are custodians

Your data lives in a passkey-sealed vault on this device. Apps request scoped, revocable access — they never hold a key, never send SQL, and every disclosure is logged in a vault you own. See docs/data-custody-protocol.md.
Vault: no vault
boot…

Your profile (owner view — you see everything; apps see only what you grant)

name— email— date of birth— shipping—

App · Notes (tier 1 — custodian)

no access

    App · Tasks & Checkout (tiers 1·2·3)

    no access
      To “complete an order”, the app asks for the minimum:

      Disclosure ledger (owned + sealed — who asked what, and why)

      Apps hold 0 keys and 0 vault data at rest.
      whenapptiercapabilitydisclosed / withheld
      no disclosures yet