Skip to content

Privacy statement

This page describes what the website does, and what the CBER design promises and does not promise. No CBER instance is running today: there are no participants, no wallets and no ledger. What follows about the system is the standard the rule set imposes on an instance that does one day run.

This website

This site is a static wiki. There is no backend, no login, no account, no cookie and no analytics. Since 20 August 2026 the fonts are served locally as well: not a single request goes to a third party, Google included. That was not the case before, and it was wrong on a site that preaches transparency; an adversarial privacy review flagged it and it was fixed the same day.

The simulator at /sim/ runs entirely in your browser. Nothing is sent, nothing is stored and nothing is logged; what you set and what comes out is seen by no one else.

The web server keeps ordinary technical log lines (IP address, timestamp, requested path), needed to serve and secure the site. They are not used to track or profile visitors.

Questions or requests: info@robingenis.com.

What the design promises

The rule set (CBER-1) and the identity anchor (FEP-5fcf) impose these limits on an instance:

  • The ledger publishes system levels, not lives. Individual balances, transactions, calls, queue positions and delivery records are never published, in any form and not even pseudonymously. Of your own entries you receive a private proof that they were counted correctly in the sum.
  • Consumption and delivery data are risk data. A consumption pattern reveals whether someone is home, when they sleep, which appliances they run, and sometimes what they believe or what ails them. Profiling or segmenting on consumption patterns is therefore a breach of the rule set, not a policy choice.
  • There is no separate back door, and that is the whole trick. In phase 0 your cooperative simply knows you through its membership register. That is exactly why it must not build a second facility laying out keys in advance to link pseudonyms to names: that would create a link that does not yet exist. Only once you federate, and an instance does not know its members, does a threshold procedure appear, with several independent trustees inside the EU, and only after a lawful order from a competent authority (in the Netherlands including a public prosecutor's demand).
  • The looking is counted, but you are not in the shop window. Public are the counts: how many demands arrived, from what kind of authority, on what legal basis, on fixed dates and also when the number is zero. Who was opened is not in there: you hear that privately, and if an investigation orders that notice deferred, it arrives automatically once the deferral lapses.
  • Conservation is attested, not publicly recomputable. That no coin appears from nowhere is demonstrated in phase 0 by an independent auditor and co-signing witnesses. You as a member cannot recompute it yourself, because the series that would allow it are exactly the series that identify people at this scale. That stands here because it is true, not because it sounds good.
  • A residual trust remains. Where keys are split across several parties, the protection holds as long as fewer than the threshold number of them collude. If they do collude, enforcement is procedural (the trace in a co-signed log) and not mathematical. That residual is stated here rather than written away.
  • A DPIA is an admission requirement. An instance may not start without a completed data protection impact assessment.

What the design does not promise

Honesty applies here too, so the limits are stated outright.

  • Your own instance knows you. In phase 0 an instance is a closed cooperative with a membership register. Pseudonymity holds towards the ledger and towards other instances, not towards the organisation you are a member of.
  • Full anonymity is deliberately not offered. Anonymous money rules out the levy and fraud detection. That is a choice with a price, and the price is stated here.
  • Below roughly 10,000 participants, pseudonymity is weak. In a village of 200 households a public total can already reveal something about a single person. The rule set therefore prescribes thresholds and suppression, but anyone seeking certainty at small scale should know it is not there.
  • Coercion inside the home is a real risk. Anyone who must fear that a housemate, ex-partner or relative will use their data to find or control them is not served by ordinary privacy rules. See below.

If you are in danger

If publication of your location, your move or your status puts you in danger, the default behaviour of this system is not enough. That is not an edge case but a design requirement: adversarial review established that the most dangerous adversary is often in the same house.

The rule set therefore prescribes a safety route. What it must do is written out precisely:

  • You move your payout immediately: no announcement, no waiting period, no objection right for whoever held the old binding, no fresh neighbourhood attestations.
  • Outwardly nothing visibly changes: the public view and every authorised lookup keep showing the previous destination and status, so that standing still does not become a signal.
  • Every attempt to open your status is recorded and disclosed to you, never to whoever attempted it.
  • Your keys are covered too: if your device fell into the wrong hands, rebinding works immediately, without the incumbent holder being notified or able to object.
  • You get a floor even without an energy contract of your own, within 24 hours and without attestations, because whoever flees usually does not have one.
  • A single attestation from an institution bound by professional secrecy replaces the entire neighbourhood round.

Be honestly warned about the state of this. This is a normative requirement on whoever builds the system, and that provision is not built yet; no accredited institution has been contracted that can set the flag. While that is so, an instance must not recruit participants among people living at a confidential address, and that is fixed as an admission condition. If you are in danger now: this system runs nowhere, so there is nothing to sign up to; seek help through your local domestic-violence support service or the police.

Status

This is a draft accompanying a design in development, not a legal notice from an existing service provider. The full privacy analysis, including the objections still open, lives in the public council report and in the project's working documents.

The bank governs the human, and the human governs the bank.