Nucleus Sovereign Systems
Effective 30 September 2026

Privacy Policy

Core Node is built so that there is very little for a privacy policy to disclose. This document says what the app does with information, what leaves your machine, and what we can see.

What we collect

Nothing, from the app. Nucleus Sovereign Systems operates no account system for Core Node and receives no telemetry, analytics, crash reports, or usage data from it. There is no sign-up, no email address, no password, and no profile. We do not know who runs Core Node, and the app gives us no mechanism by which we could find out.

The early-access waitlist

The waitlist on this website is the one place we hold anything about you, and only because you typed it in. If you join, we store the email address you give us, and the optional name and description of your Macs, together with the time you joined. We use them for one purpose: to send you an invitation to Core Node. We do not sell or share them, add you to any marketing list, or combine them with anything else, and the waitlist uses no cookies, analytics, or third-party services.

Your network address is used only momentarily to limit abuse of the form and is not stored. An invitation link carries its access code after a #, which browsers never send to a server, so the code does not appear in any log; we keep only a one-way fingerprint of it, and record when an invitation is first and last opened. Installing Core Node from an invitation does not link the app to your email address.

To be removed from the waitlist, or to see what we hold, write to privacy@nucleussovereign.com from the address you signed up with. We delete it promptly, and we delete the whole list once early access ends.

Your identity

At first run, Core Node generates an Ed25519 keypair on your device and derives your identifier from your own public key. This happens locally and requires no network connection.

  • Your private key never leaves your device. It is stored in the macOS Keychain and is not transmitted, backed up to us, or recoverable by us.
  • Your public identifier is shared with peers you transact with, because they need it to verify your signatures. That is its purpose.
  • We cannot issue, suspend, restore, or revoke your identity. It is not ours.

What is stored on your machine

  • Your keys, in the macOS Keychain.
  • Work receipts for jobs your node has run or requested.
  • Cached model and asset files, addressed by content hash.
  • Application settings and logs.

Vault contents are encrypted at rest with keys only you hold. We cannot decrypt them, and neither can anyone operating infrastructure on our behalf.

What leaves your machine

Core Node is a peer-to-peer application, so some data necessarily travels — but only to counterparties you have chosen, and only when you act.

  • Jobs you send out. When you request work from another node, the job payload and the assets it requires travel to that node. They are encrypted in transit.
  • Jobs you accept. When your node runs work for someone else, their payload arrives on your machine.
  • Signed receipts. Deliveries and acceptances are exchanged between the two parties to a job.
  • Local network discovery. Core Node advertises itself on your local network so your own devices can find it. This is confined to your subnet and can be turned off.

How your work is protected on another machine

Sealed to one machine. Every request is encrypted on your device to the key of the single node that will run it. The relay that carries it, the network, and Nucleus Sovereign Systems see only ciphertext.

Held in memory, never kept. On that node the work runs inside Core Node — signed with our developer identity, notarized by Apple, and running under Apple’s hardened runtime, which prevents other apps and debuggers from reading its memory. Your prompt and its answer are not written to disk and are not logged.

Proof of what ran. The node returns a signed receipt naming the exact build of Core Node that did the work, checked against our published list of releases, with digests salted so that a published receipt reveals nothing about the content.

Your choice of where. Work that must stay inside your own walls can be kept to the Macs you own, bound to your identity.

Permissions the app requests

  • Local network. For peer discovery on your subnet.
  • Microphone and speech recognition. Only for optional audio transcription you start yourself. Transcription runs on your Mac; audio is not sent anywhere and neither permission is used at launch.

Payments

Core Node is free, contains no in-app purchases, and no payment details are requested when you install or run it. A node accrues earnings before you choose how to be paid. If and when you configure a payout method, that arrangement is between you and the payment provider you select; we do not hold funds.

Children

Core Node is not directed to children and collects no information from anyone, including children.

Changes

If this policy changes, the effective date above changes with it, and the substance of any change will be stated plainly rather than absorbed into a longer document.

Contact

Questions about this policy: privacy@nucleussovereign.com