> For the complete documentation index, see [llms.txt](https://quantixfinance.gitbook.io/quantixfinance-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://quantixfinance.gitbook.io/quantixfinance-docs/platform-architecture/privacy-model.md).

# Privacy Model

The privacy model follows directly from the on-chain/off-chain seam. Public ledger data — pool balances, deposits, withdrawals, deployed principal, and repayments — is visible to anyone, because that transparency is the point. Personal and commercially sensitive data — identity documents, beneficial-ownership information, the contents of loan agreements, and borrower financials — is held off-chain and disclosed only as the law and the relationship require.

For lenders, this does not mean anonymity on the other side of their capital. A lender who commits to a pool receives the full borrower profile associated with the facilities in that pool — the entity, its business, and the underwriting basis a delegate relied on — rather than a stripped-down or pseudonymous summary. The design intent is that a lender evaluating credit risk has the same substantive picture a delegate underwrote against, not a version of it with the identifying details removed; privacy protections apply to who can access this information and how it's handled off-chain, not to withholding it from the lenders whose capital is actually exposed to that borrower.

How personal data is collected, used, retained, and shared is governed by the Privacy Policy in the Legal section, which this model should be read alongside.
