Canonical: https://heartbank.net/positions/the-person-is-not-the-product · Licence: CC0 1.0
Why HeartBank Refuses to Sell Your Data, and What It Sells Instead
| Field | Value |
|---|---|
| Author | HeartBank® · Miss Aquarius℠ |
| Date | 2026-09-07 (draft) |
| Canonical URL | https://heartbank.net/positions/the-person-is-not-the-product |
| GitHub mirror | https://github.com/HeartBank/publications/blob/main/positions/the-person-is-not-the-product.md |
| License | CC0 1.0 Universal (public domain) |
| Category | mechanism |
Draft. A short institutional position paper. It states the second half of a commitment whose first half is already published in HeartBank's Position on the Attention Economy (heartbank.net/positions/attention-economy), and it describes a market that does not yet exist. Nothing in it should be read as a report of operations.
HeartBank has published a permanent refusal of advertising revenue. That refusal invites an obvious question, and the institution would rather answer it in public than be assumed into the answer: if you do not sell attention, are you selling data?
The answer is no, and this position states it with the same permanence as the first: HeartBank will not sell, licence, rent, share for consideration, or otherwise disclose per-person records — not in aggregate, not de-identified, not as a research partnership, and not as a condition of any funding.
What the institution intends to sell instead is narrower and stranger than a data business, and it separates cleanly into two goods with two different owners:
The subject sells the release. The institution sells the vouching. Neither party can sell the other's good.
A third party who needs to know something about a person pays the person for the right to ask, and pays the institution for the fact that the answer can be trusted. No record changes hands. No copy is made. The answer is a single bit, scoped to one question and one asker, and the subject can stop answering at any time.
The institution's ambition for this arrangement is not that it is generous. It is that the refusal should stop depending on anyone's virtue. A commitment not to sell needs a living enforcer at the exact moment it is tested. A design in which the institution cannot answer without the subject does not.
HeartBank's product is a record of gratitude between named people: who thanked whom, for what, where, and when. Stated plainly, that is among the most sensitive corpora it is possible to assemble, and — precisely because it is sensitive — among the most commercially valuable. A billion people's gratitude, with locations and times, would be worth a great deal to parties who have no business holding it.
An institution that intends to accumulate such a record over decades, and then hand it to an autonomous successor, owes the public a statement about what will never be done with it. It owes that statement early, while the corpus is small enough that the promise costs nothing, because a commitment first made when the asset is valuable is not a commitment; it is a negotiation.
This position is that statement. It is deliberately narrow: it concerns what the institution does with records about people. It does not concern pricing, and it is not a privacy policy. It is a description of a door being closed and welded.
Readers who encounter an institution that refuses advertising make a reasonable inference: the money has to come from somewhere, and the other thing you can sell is the data.
The inference is reasonable because it is usually correct. The two dominant consumer business models both monetise the person — one sells their attention to a buyer, the other sells or brokers their record — and a company that visibly refuses the first has often quietly adopted the second. A refusal of advertising is therefore not, on its own, informative. It narrows the field by one.
So the institution states the second refusal explicitly, and states it in the same class as the first: permanent, public, and structural rather than preferential.
The most common way to defend a refusal like this is to call the alternative wrong. HeartBank declines that argument, because the stronger objection to selling personal data at consumer scale is not that it is unethical. It is that it does not work, and understanding why it does not work is what makes the alternative design legible.
Data value is aggregate. The individual is selling the least valuable unit that exists. One person's behavioural record is worth cents to anyone; a population's is worth billions. That gap is not a market failure to be corrected by better tooling — it is the structure of the good. Whoever assembles the aggregate captures the value, and the person, by definition, cannot assemble it. Every attempt to pay individuals for their own records has run into this and lost.
The empirical record is consistent and unkind. A succession of companies has offered people money for their data — among them Datacoup, Killi, Invisibly, several blockchain "data union" projects, and the attention-token model — and the payouts have clustered in the range of a few dollars to a few tens of dollars per user per year. None became a durable business at consumer scale. The failures were not for want of good intentions or engineering; the arithmetic was the same in every case.
The counterexample must be carried, because it is real. Individuals are paid for data in some markets and those markets work: survey and research panels, participant-recruitment platforms, and clinical-trial enrolment all pay people, sometimes well. HeartBank does not claim these are illusions. It claims they are a different transaction: they pay for labour and attention — for performing a task, or for consenting to be observed under protocol — not for the transfer of an existing record. The distinction matters here because it points at where per-person value actually lives, and it is not in the archive.
And this corpus carries a second problem that generic data markets do not. A gratitude record has two authors. When one party sells the record of thanks they gave, they are selling a fact about the person they thanked. One-sided consent cannot cover a two-sided fact, and there is no volume of consent-flow engineering that repairs it.
The design HeartBank intends replaces the sale of a record with the sale of an answer, and it splits that transaction into two goods that belong to two different parties.
A THIRD PARTY NEEDS TO KNOW SOMETHING
│
┌────────────────────────┴────────────────────────┐
▼ ▼
┌───────────────────────┐ ┌────────────────────────┐
│ THE SUBJECT sells │ │ THE INSTITUTION sells │
│ THE RELEASE │ │ THE VOUCHING │
│ │ │ │
│ which asker may ask │ │ its signature, the age │
│ which question │ │ of the record, the │
│ │ │ compute to answer │
│ → the subject's own │ │ → the institution's │
│ good, and no one │ │ own work product │
│ else's to price │ │ │
└───────────┬───────────┘ └────────────┬───────────┘
└───────────────────┬───────────────────────────┘
▼
ONE BIT, scoped to ONE question
and ONE asker · revocable · expiring
│
┌─────────┴──────────┐
│ NO RECORD MOVES │
│ NO COPY IS MADE │
└────────────────────┘
Neither party can sell the other's good. The institution cannot sell the subject's history, because history is not what it is selling and because — under §5 — it is not in a position to release it. The subject cannot sell the institution's credibility, because a claim is only worth what the voucher is worth, and the voucher is not theirs.
This service is called B-Vouch℠. It is deliberately not named for the institution's proof-of-personhood work, which is published free as an open protocol and a free reference implementation. The free layer and the paid layer do not share a name, and that separation is doctrinal rather than cosmetic: the moment a paid product carries the name of the personhood proof, the institution has written paid equals proven human into its own trademark, and that is a sentence it cannot say.
The interesting half of the design is not who gets paid. It is that the institution is not the party who can answer.
The subject holds the release. The institution holds no copy of it. A buyer's question therefore cannot be answered by the institution acting alone, at any price, under any pressure, by any future management. What is normally a policy — we will not sell your data — becomes a fact about the machine: we are not able to.
This matters most at the moment it is hardest to guarantee. An institution designed to outlive its founder and pass to an autonomous successor cannot rest its most important refusals on anyone's restraint, because every rule needs a living enforcer with the right incentives at the exact moment it is tested — and that is precisely the moment nobody can guarantee. The temptation to sell a billion people's gratitude record peaks long after the people who wrote this sentence can be asked about it.
The honest limit of that claim, stated here rather than in a footnote. The property is only as strong as what the ledger physically holds. If the institution stores plaintext records and merely declines to release them, then cannot is doing rhetorical work that the architecture has not earned, and the truthful word is will not. The property holds only where the stored form is a commitment — where the institution can prove a fact was recorded without being able to read it out. HeartBank states the design goal and the condition together, because a structural claim whose condition is unstated is a promise wearing better clothes.
If facts about a person can be sold, then some facts must never be, and the boundary cannot be a matter of taste.
Only attributes that are bounded per person and monotone in time may ever be offered. Never attributes that are monotone in volume.
Is this a person is bounded — a person has one personhood. How old is this record increases only by waiting. Did these two people meet in person is a fact about an event that either happened or did not. None of these improves by doing more of anything, so none of them creates a reason to manufacture activity.
How much gratitude has this person received is unbounded and rewards volume. Offering it for sale would put a price on the one behaviour the entire institution exists to keep uncontaminated, and would reintroduce a farming incentive that the design has otherwise closed. It is not on the list and cannot be added to it.
A second boundary governs who may ask rather than what is asked. Buyers are admitted by class, and no class whose business is pricing, scoring, ranking, or gating access to a necessity — housing, employment, credit, healthcare, or public services — is admissible at any price. This exclusion removes the largest and best-paying part of the identity-verification market, and it is stated here because a reader is entitled to know that the institution has priced its own commitment and is paying it.
The reason it must sit on the buyer rather than on the use is mechanical: what a buyer does with an answer is unobservable, and a rule nobody can check is not a rule. What class of business a buyer is in, is checkable.
A commitment is only as good as the list of things it rules out.
HeartBank will not sell, licence, rent, share for consideration, or disclose per-person records — not in aggregate, not de-identified, not as a research partnership, and not under acquisition or rescue financing. It will not publish, compute, or expose a per-person rate, score, ranking, or league table derived from gratitude. It will not operate a directory of people, and its name resolution runs one way only: from a public artifact to a handle, never from a handle to the person's underlying proofs. It will not permit payment to change what the record says about anyone. And it will not bill a subject to be vouched for — the subject is never the payer, because a fee charged to the subject is the purchasable personhood this institution has already refused, arriving through the pricing sheet instead of the product.
What the commitment does not exclude is worth equal precision. It does not exclude charging money. It does not exclude a third party paying for an answer a person has chosen to make available, or that person being paid more than the institution is. The line is not between free and paid. It is between a third party buying access to a person, and a person granting access and being paid for it.
This is one design decision away from a credit bureau, and everyone who built one thought otherwise. A market in binary facts about people, priced and queried at volume, is the raw material of exactly the scoring infrastructure the institution says it refuses. The guards — one posted price, buyer classes, a two-item catalogue, answers that expire — are the whole distance between this and a reputation score, and they are guards, which means they can be relaxed. The institution does not have a proof that they will not be. It has a public statement of what relaxing them would mean, which is the strongest thing it can offer in advance.
"Cannot" may quietly become "will not." §5 states the condition; nothing guarantees an implementation honours it. A future engineer choosing plaintext for a good reason would silently convert the institution's structural claim back into a policy claim, and nobody outside would be able to tell. The public form of the mitigation is that the storage form is a published design commitment, checkable by anyone who reads the specification and, eventually, by anyone who audits the artifact.
The subject's share may prove trivial. The claim that the person is paid, and paid more than the institution is honest about the split and silent about the magnitude, because the magnitude is unknown. If the market is small, the subject's majority of a small number is a small number, and this position will have described a rounding error with a moral argument attached. That is a real possible outcome and the institution prefers to name it now.
And the objection that cuts against the position's own most attractive claim. The two-good split is presented here as a structural achievement, but it also conveniently produces an institution that gets paid. A reader is entitled to notice that every design decision described has been made by the party that benefits from the arrangement existing, and that no external party has yet audited any of it.
Refusing both advertising and data sale is not novel, and HeartBank does not claim it is. Wikipedia has done it for two decades on donations. Signal does it on donations and grants. Proton and a large family of privacy-first services do it on subscriptions; Apple does it on hardware margin. Any of these can say, truthfully, that they sell neither attention nor records. The refusal is well-trodden. What is not well-trodden is a mechanism that makes the refusal structural rather than promised, and that pays the person rather than charging them.
The failed attempts are the more useful lineage, and they are the direct ancestors of this design. The consumer data-dividend companies named in §3 tried to give people the value of their own data and could not make the arithmetic work. The lesson HeartBank takes from them is not that people should not be paid. It is that the unit was wrong: they were selling copies of records, where value is aggregate, instead of selling answers, where value is per-transaction and attaches to the specific person the buyer is dealing with.
The nearest live analogue is identity verification — a real market, in which parties pay meaningful sums per check. HeartBank's design differs in three respects that are not to its commercial advantage: the subject is paid rather than the vendor keeping the fee, the highest-paying buyer classes are excluded, and the price does not vary with how badly the buyer wants the answer.
And a sibling from HeartBank's own corpus, which reached the same structural conclusion about a different object. Certification by Circulation argues that a trust seal granted by a party whom the sealed party pays decays into a pay-to-play badge. The rule here is that argument applied to persons: the subject may never pay to be attested.
HeartBank is not a disinterested commentator on data markets. It intends to operate the alternative it is describing, it expects to earn from it, and its primary earning line is a naming registry to which this service is attached. A reader should discount the argument accordingly, and should note in particular that the strongest empirical claim in §3 — that per-person data markets fail — is a claim whose truth is commercially convenient for the party making it.
The counterweight offered is not sincerity. It is that the institution has published the exclusions in §7 before having anything to lose by them, and has published the failure modes in §8 that a party seeking only to look trustworthy would have omitted.
A position that no evidence could touch is a belief rather than a claim. This one is wrong if a per-person data marketplace, operated with ordinary commercial competence, delivers meaningful and durable income to typical participants at consumer scale — say, income that a median participant would notice in their household budget, sustained over several years, without the operator's economics depending on aggregation the participants do not control. That result would falsify §3's structural argument, and the honest response would be to say so and to reconsider whether the answer-shaped design is necessary rather than merely elegant.
The design's own falsifier is narrower and nearer: if attestation queries, once available, are not worth enough to pay a subject anything meaningful, then the users profit too claim is empty and should be withdrawn rather than restated.
Nothing on the following list. Falling revenue would not. A funding round conditioned on it would not. An acquirer's preference would not, and the institution's governance is arranged so that no acquirer acquires this decision. A research partnership offering public benefit would not, because not as a research partnership is written into the exclusion above precisely so that the most sympathetic version of the request has already been answered.
The institution will say what would change its behaviour, because the alternative is a commitment immune to evidence. If the attestation design proves unworkable — if no admissible buyer class will pay, or if the storage condition in §5 cannot be met in practice — then the institution's revenue thesis for this service is wrong and the service should not exist. What does not follow, in that case, is a move to selling records. Being wrong about the alternative would not make the data model acceptable; it would mean the institution should fund itself some other way, or be smaller.
Nothing described here is operating. There is no attestation market, no query has been asked or answered, no subject has been paid, and the proof-of-personhood layer this design depends on is specified and published but not built. The number of participants is zero and the revenue is zero. This document states a topology and a set of refusals; it is not a report and should not be cited as one.
The prices are not set. Neither the posted price for an answer nor the subject's share has been decided, and whether a single global price or a purchasing-power-adjusted one is correct remains open. A reader should not infer that the institution knows what this costs.
The exclusion list in §7 is complete as of this date and is expected to grow. New buyer classes will be proposed that the current wording does not clearly exclude, and the institution's practice will be to widen the list rather than to reason from silence.
And one thing the design does not do at all. It establishes that a party is a person; it does not establish that a person is sincere. Rings of real, cooperating people can produce records that every layer described here would accept. That hole is open, it is a property of graphs rather than of identity, and no amount of attestation design closes it.
HeartBank® is a registered mark. B-Vouch℠, Miss Aquarius℠ and B-Registry℠ are service marks of the institution. Marks appear here at first and prominent use only.