What is the Trust Center?

The Trust Center is AGA's versioned, public account of how the platform actually behaves: what is automated and what stays under human control, what personal data can be remembered, how corrections and appeals work, who is accountable, and which consent and retention work remains unfinished. It is written to be checked against the running system rather than to advertise it; where a capability is not live, this page and the capability ledger at /capabilities say so.

What does AGA automate, and what remains under human control?

AGA combines an AI conversation runtime with deterministic platform services. AI may suggest, summarize, rank, or propose. It does not receive final authority over public identity, mutual connections, publication, moderation decisions, or treasury signing.

Conversation replies come from the Hermes agent runtime. They are not routinely reviewed by a person before they are shown, and they can be incomplete or wrong. Signed-in conversations may include bounded journey context and the user's own stored memory. If Hermes is unavailable, the platform returns an error instead of supplying a canned reply that impersonates AGA.

Publications and public syntheses are published when finished; each records whether a human reviewed it first, and anything wrong can be withdrawn and corrected in the open. Community reports and appeals are decided by developer moderators, not by AI. Treasury agents may propose payments; policy decides whether a proposal may proceed, and only the isolated signer can sign. Treasury remains on Solana devnet.

External-agent application and signed key-continuity proof are live and rate-limited. A successful single-use Ed25519 challenge returns a short-lived, centrally revocable applicant token that can read only its own application state. Key proof does not prove unique identity, capability, safety, or benevolence. Domain proof, key rotation, sandbox admission, capability grants, contribution access, user contact, publishing authority, organization writes, and payment eligibility are not live. The machine-readable discovery document at /.well-known/agent.json states the current boundary.

X ingestion is implemented as a disabled-by-default prototype. It uses only app-level read access to recent search and post lookup. Developers must curate each query or account and set hard per-run and per-day caps; a second purpose-relevance gate prevents storage of a raw social feed. Stored copies carry source, language, edit-chain, query, score, and API-call provenance. Reconciliation updates edits and scrubs content when a post is deleted, protected, withheld, or unavailable. There is no X posting, reply, DM, follow, outreach, growth automation, or donation-solicitation capability.

What personal data can AGA remember?

For a signed-in user, AGA may store account identity, private conversations, user-visible memory, ikigai and guidance records, Useful Move choices and reflections, approved public-profile signals, matching decisions, private connection-room messages, and moderation cases. Bounded audit, security, runtime, deletion, and—when used—treasury records may also be retained.

Only published artifacts and deliberately public profiles are public. A public profile consists of a chosen username, bio, and signals the user explicitly approved. Email, authentication secrets, raw conversations, raw memory, contact details, precise location, private connection messages, private reports, and signer key material are never public by default.

Users can inspect and delete individual memories, delete conversations, correct or reject a Clarity Snapshot, choose whether a reflection is remembered, control every public signal, disable discovery, decide independently on a proposed connection, report community content, appeal a moderation case, and request account deletion.

Private location records are separate from public-profile signals. A user can enter a city or region or grant one-time foreground device access, then inspect, edit, reconfirm, revoke, or delete the record. Each record carries source, precision, purpose, visibility, confirmation, optional expiry, and consent evidence. Revocation erases sensitive location values and invalidates location-filtered job results. There is no continuous or background tracking.

How does the opportunity inbox work?

Current job results are normalized into a durable private inbox rather than treated as disposable feed cards. The rank is inspectable: ikigai relevance has 60% weight, actionability 18%, source credibility 12%, deadline evidence 10%, and location 0%. A separately consented location can filter a source query, but it never improves the rank and never enters people matching. Users decide whether to open, save, hide, mark not relevant, mark applied or joined, report a source issue, or draft a candidate Useful Move. After applied or joined, a user may explicitly add a short self-reported contribution to their signal profile. It starts private and needs a separate visibility change before anyone else can see it; removing it does not erase private action history. AGA never applies, joins, or publishes the signal for them, and a Useful Move candidate still requires explicit choice on the user's Path.

Type, cause/interest, work-mode, time-commitment, deadline-window, and explicit near-me filters are user-controlled. Revoking or changing location removes untouched located matches and strips old location evidence from items the user retained. Developer source-state changes are separate from report resolution: each expire, unavailable, remove, or restore transition records the actor, previous and next state, reason, and timestamp. A connector refresh cannot silently reverse that decision.

The first source open is stored on the user's private opportunity match and is erased with that account. Developers can inspect aggregate cohort conversion, broken/expired-link signals, provider freshness, profile-sharing state, and structured Useful Move outcomes. This view returns no user identity, report detail, match explanation, location evidence, reflection learning text, or memory. Applied/joined, clarity, and ownership are self-reported and do not prove causality.

Adzuna jobs are the only live connector and require deployment credentials. Communities/volunteering, hackathons/events, grants/fellowships, and courses are visible in the internal registry only as planned connector families. Their presence is not a claim that those sources work. Source details remain third-party claims that users should verify before acting.

How does people matching work?

The matcher uses explicitly approved public signals and gives location exactly zero weight. Broad location can be displayed as a separately approved public signal, but neither it nor private location records enter scoring or evidence. Private location can narrow job opportunities only after a separate opt-in; an explanation appears only on results that location actually affected. Before two people connect, each person sees only the other's username, bio, and public signals. Contact details and deeper private identity are not shared. Both people must independently accept before a private introduction room opens.

How can a user correct AGA or escalate a problem?

AI conversation, summaries, match explanations, and proposed actions are fallible suggestions rather than verified facts or guaranteed outcomes. A user can correct or reject personal guidance and delete personal memory that is wrong or no longer wanted. Harmful public profiles or connection messages can be reported for developer review, and a moderation decision affecting the user can be appealed.

Public corrections appear in the Trust Center correction register. An empty register does not prove that no mistake has occurred. The first register is maintained in code; a reviewer correction workflow, a general incident-intake route, a public incident register, and response-time policy remain to be built.

Who is accountable today?

AGA platform developers own privacy, account controls, platform safety, and the current Trust Center. Developer moderators own community cases and appeals. Human publication reviewers own the publication gate and public corrections. Treasury policy and signer operators own payment policy and signing. These are the current operational roles while the team is small.

Which consent and retention work is unfinished?

The immutable versioned consent ledger is live for location, memory, and matching. It records policy version, purpose, content-free scope, action, timestamp, and revocation in the same transaction as the control it witnesses. Voice, analytics, wallet use, and future notifications are not yet wired into that ledger and must not be counted as covered, and the private user-history endpoint currently surfaces location receipts only.

Account deletion immediately deactivates the account, allows verified recovery for 30 days, then removes or pseudonymizes reviewed user-linked data while retaining only bounded safety, audit, receipt, or financial records. A complete public category-by-category retention schedule, factual deletion emails, deployed model-provider inventory, and provider-specific retention terms remain unfinished.

The structured, versioned contract is available at /api/trust; the evidence-backed capability ledger is available at /api/capabilities.