<!-- PUBLIC MIRROR of docs/legal/ENLIST-PRIVACY-NOTE.md (single source of truth). Re-copy on change. -->

# Enlist Privacy Note (S85)

> Companion to `landing/ENLIST-SPEC.md`. Status: DRAFT, pending S90 legal review.
> Plain words. Lines carrying [NEEDS-LEGAL] await final legal wording and the
> final contact route before launch.

## 1. What Enlist is

Enlist is an updates list for the rollout. Giving an address and confirming it
joins that list and nothing else: no play, no keys, no seat, no artifact, no
pledge. Play Free stays the only door into the room.

## 2. Consent record — what we keep when you agree

One record per confirmed address, holding only these fields:

| Field | Meaning |
|---|---|
| Address | The address you typed and confirmed. |
| Source | The surface where you enlisted (the landing Enlist block). |
| Agreed at | Date and time your confirmation landed. |
| Wording version | Which consent wording you agreed to (the S85 line). |
| Standing | confirm-sent or confirmed (see the Enlist spec flow). |

No other field is part of the record. Consent is a deliberate mark on the
checkbox, never implied by typing or by pressing submit.

## 3. What we never take

No real names, no street addresses, no payment detail, no anything beyond the
§2 fields. The Enlist block asks for one address and one mark of consent, and
the record keeps exactly that plus the bookkeeping above.

## 4. No address in analytics

Counts of submits, confirmations, and errors may be tallied in aggregate to
keep the block honest. Those tallies never carry addresses, never carry consent
wording, and never single out a reader. Joining a confirmation to its record
happens against the §2 record alone, never through analytics.

## 5. Minimization and retention

- Keep only §2 fields; collect nothing speculative against a future use.
- A confirm-sent record that never confirms is pruned after a short span
  [NEEDS-LEGAL: final span].
- A confirmed record is kept while the updates list runs, and no longer than
  24 months past the last confirmation without fresh consent [NEEDS-LEGAL:
  final span].
- Withdrawing consent removes the record (see §6); removal is confirmed back to
  the withdrawing address where deliverable.

## 6. Leaving and removal

You may leave at any time: follow the leave path in any update we send, or
write to the contact in §7 naming the enlisted address. We remove the §2 record
and reply to confirm where deliverable. Leaving touches play nothing, since
Enlist grants nothing.

## 7. Contact for removal

Write to the privacy contact published in the site footer and on the legal page
[NEEDS-LEGAL: final route], naming the enlisted address and asking for removal.
If the route ever moves, the footer and the legal page name the current one.

## 8. Changes to this note

This note is versioned with the consent wording. Material changes are announced
through the updates list, and where the change widens use, fresh consent is
asked before the wider use begins [NEEDS-LEGAL].

## 9. Review checklist

- [ ] §2 fields are the whole record; §3 holds.
- [ ] Analytics carry no address (§4).
- [ ] Retention spans and the §7 route cleared by S90 (no [NEEDS-LEGAL] left).
- [ ] Leave path present in every update sent.
