What we keep, and what we never do
Four plain claims. Under each one, the exact thing the system does.
The seal
When you both sign, the words are stamped. If a single character changed afterwards, the stamp would no longer match, and anybody holding the pacti could see it.
SHA-256 over the canonical JSON of the agreement, computed at signature time and stored on the signature event.
The record
Nothing that happened gets rewritten. A correction is a new line, never an erased one, so the history reads like a story instead of a final draft.
The events table is append-only: rows are inserted, never updated and never deleted.
What we are not
Pacti is not credit and does not lend. We do not check anybody, we do not vouch for anybody, and we never say who deserves a yes. What you sign is your own judgment about someone you already know.
Your count is private, is not a score, and is shared only through a snapshot you consent to, which expires on its own.
Your data
We keep what the promise needs: who signed, what was signed, when, and what the two of you marked afterwards. We do not sell it and we do not share it with anybody who is not part of your pacti.
You can ask us to delete your account data, and we tell you plainly what stays because a signed record belongs to the other person too.