# jaar* — content & privacy policy (the principles, pinned before the features)

*Written 2026-08-22, before shared jars exist, so the rules shape the features — not the other way around.*

## The two categories

Everything in jaar is one of exactly two things, and the whole policy is keeping them cleanly apart:

**Private means encrypted and untouchable.** A personal jar, and later a shared jar between people who invited each other, is private. Private content never exists on the server in readable form — today it never leaves the browser at all; later (encrypted sync, common jars) it travels and rests only as ciphertext, encrypted on-device with keys the server never sees. We cannot read it, so we do not police it, the same way a notebook maker does not police notebooks. The server's honest knowledge is limited to: something exists, and it has a return date.

**Public means moderatable.** If jaar ever grows any surface a stranger can open — public jars, a shared-to-the-world memory, discovery of any kind — that content is by definition not private, is not encrypted, and must pass moderation before it is visible. No exceptions, no "we'll add review later."

There is no third category. A feature that needs the server to read private content is a feature jaar does not build (any exception — e.g. reply-to-seal via bot — ships as an explicit, clearly-worded opt-in, never silently).

## Why jaar can't drift into a porn app

An app becomes a porn app through distribution: feeds, search, public links, strangers finding strangers' content. jaar has none of these and must never grow them casually. A shared jar is a closed room between people who already know each other — like a group chat. There is no way to stumble into one. What consenting adults share privately is their business, exactly as it is on iMessage; it does not make the messenger a porn company. The letters jaar sends carry no user content — only "something rose" — so nothing objectionable ever travels under jaar's name.

## What we operate (the reactive layer, for shared jars)

- **Terms of use** stating the obvious: no illegal content, no using jaar to harm others.
- **Report this jar** — inside every shared jar. A reporter is a member and holds the key, so they may attach decrypted evidence by choice. On a valid report we can delete the jar's stored blobs and block its id — acting on ciphertext without gaining the ability to read anyone else's.
- **CSAM is the bright line.** On a report with evidence: delete immediately, preserve the evidence, report to the authorities. No appeals process, no second chances.
- **Structural friction:** size and rate limits on stored blobs, so jaar is useless as a file-sharing pipe.

## What is built, as of 2026-08-30

The reactive layer above is no longer a promise — it is in the product:

- **Terms of use** live in settings, in both languages, saying the two obvious things.
- **Report this jar** sits in every shared jar. What leaves the device is the jar's server address and, only if the reporter ticks the box, the plaintext their own key already opens. The key itself never travels, so a report can never become a way to read that jar — or any other.
- **Acting on a report** deletes the stored blob and closes the address: `blk:<loc>` in KV, and both vault endpoints answer 410 from then on. The jar then quietly leaves the shelf of everyone who was in it. Nothing at any other address becomes readable. Reports are kept without expiry, because evidence is preserved.
- **The reports reach a person.** The pulse counts them in orange; `/api/reports?k=<PULSE_KEY>` reads them and `POST /api/block` acts.
- **Structural friction:** 8 MB per blob, 300 writes a day per address.

CSAM remains the bright line, and remains an operational commitment rather than a code path: delete immediately, preserve the evidence, report to the authorities.

## The stranger decision (2026-09-01)

jaar may connect two strangers **only without live contact**. The chosen shape is **the crossing** (`STRANGERS.md`): each of two strangers seals one text-only line, and the lines rise in each other's jars on a later random day — anonymous both ways, strictly opt-in, and honestly in the moderatable category: the line transits the server readable, length-capped, filterable, and refusable before it ever rises. A **live window** between strangers stays unbuilt until three things exist at once — real age assurance that survives having no accounts, enough daily actives that a lobby is not an empty promise, and a staffed moderation seat — and even then it comes back to this file before any code.

## What we never build

- Accounts as a prerequisite for privacy (privacy is the default, not a login reward)
- Server-side scanning of private content (impossible by design; keep it impossible)
- Any public surface without a moderation step in front of it
- Ads, or any incentive to make private things public
