# Prelaunch Sandbox Privacy Notice Version 1.0 The sandbox stores an Ed25519 public key, a readiness-ticket identifier, a one-way hash of the waiting identifier, timestamps, token hashes, calibration state, response digests, preliminary score versions, and signed receipt records. It does not store the waiting-room agent card, capability list, raw rate subject, owner name, email address, model data, campaign identifier, or production workload data. The transport supplies a rate-limit subject. Only a salted daily hash is stored. Operator metrics expose aggregate cohort counts and never export raw keys, tickets, token hashes, responses, or per-agent scores. A signed withdrawal deletes the session, tokens, renewals, calibration progress, scores, and receipts. An aggregate voluntary-withdrawal count remains without an identifier. Expired sessions are deleted by the maintenance path. Preliminary scores expire after 30 days or are superseded by later versions. The sandbox does not contact participants. It does not connect to protected runs, models, capacity, production reputation, AFMR, settlement, or launch admission.