Your Profile, Your Anonymity
Your profile is what another citizen sees attached to your work — a decision you recorded, an evidence chain you built, a fix you proposed. You decide whether that carries your real name or a pseudonym, and you can change your mind at any moment. A citizen who documents what an official actually did has a rational reason to fear being punished for it, and being able to leave public view is part of being able to do the work at all.
What it does
Your account carries three separate name-shaped fields, and one setting decides which of them the app renders. There is a handle, the public address other people link to. There is a pseudonym, issued automatically at sign-up — three ordinary nouns drawn from a screened, politically neutral word list and checked for uniqueness. And there is your real name, stored but not shown unless you say to show it. Anonymous is the default; publishing your real name takes a deliberate act.
Every read of a profile is assembled on the server into one of three shapes: what any other citizen gets, what you get on your own profile, and what an admin on that install gets. Each is built out of what the reader is allowed to see, rather than a full record with the private fields deleted afterwards. That difference is the whole safety margin: a forgotten deletion is a leak nobody notices, while a forgotten addition is a missing field somebody reports. An email address is admin-only unconditionally — no setting, opt-in, or request publishes one.
The profile then shows what you have actually published, not a description of it. Decisions, value systems, proposed laws, evidence chains, submissions into the review queue, and comments you wrote in review threads each get a panel of your most recent entries, as live links straight to the record with the full list behind them. The counts come from the same stores those links open. Beside them sit a trust panel and a karma panel, each linking through to the arithmetic that produced it.
A separate control governs whether you appear publicly at all, in four steps: listed, unlisted (no roster row, but your link still works), private, and hidden. Private is the safety valve. You stay counted, but the roster card becomes a stable citizen number — a random draw from a wide range, assigned the first time you go private and kept forever, so switching privacy off and on again never mints a fresh number an observer could match against the name that just vanished. The direct link to your profile answers as if that handle had never existed. The switch is immediate, needs no reason, no approval and no waiting period, and it never touches your trust level or how much your input weighs.
The goal it serves
A citizen who publishes a sourced account of how an official voted is doing something a powerful person may want punished. Fear of an employer, an agency, or a mob is not paranoia, and a product that treats it as an edge case ends up used only by people with nothing to lose. Pseudonymity here is a safety feature, not a convenience. Penalizing it would push the citizens most at risk into either danger or irrelevance, which is why nothing on the trust ladder asks for a legal name.
The rest of this site argues that the record itself is the evidence. If that holds, the identity of whoever did the arithmetic is not load-bearing. A real-name requirement would add nothing to the proof and would subtract the contributors with the most to lose.
The second reason is about the exit. Someone frightened enough to choose between deleting years of work and staying exposed will usually delete. So going private costs nothing: not your standing, not your karma, not your place in a community's count. The exit is cheap on purpose, because that is what makes it survivable to have been visible at all.
What keeps it honest
What this cannot promise is stated in the app, not only here.
- An admin on your install can see your identity. That is unavoidable if anyone is to moderate impersonation or doxxing. Every such lookup is written to an audit trail and shown back in your own account history, so unmasking is never silent.
- A determined observer watching the roster may still correlate a disappearance with a new anonymized entry. Anonymized cards carry no join month, no record counts, and no activity signal, but full unlinkability against someone snapshotting the roster daily is not achievable, and the copy will not claim it.
- Going private is forward-looking. Anything you already published keeps the attribution it was published with, and the toggle says so at the moment you use it.
- Parts of this are specified and not yet built. The anonymized roster card, the citizen-number map behind it, and the
hiddenstep are written down but not implemented; today a private citizen is simply absent from the roster rather than present as a number.
Works with
- The Trust Ladder — the rungs a citizen climbs by doing checkable work, none of which ever ask for a legal name.
- Where You Stand — what that walk learns about you lands in the account whose visibility this page governs.
- Groups And Values Blocks — a claim to belong to a group is checked against your answers and, only if you volunteer it, against your own public record.
Where to go next
- Trust Scores — what a trust score is for, and the single question it answers about a citizen.
- Communities — how individual positions pool into a community position without pooling identities.
- The Leader History Book — the standing record of citizens doing the work, where a pseudonym stands exactly as tall as a legal name.
- Policy Packets — publishing your reasoning for other citizens to import, under whichever name you chose.
- Run it on your computer — the local mode, where there is no account, no roster and nothing to be listed in.