DISCLAIMER

MATHEMATICAL DISCLAIMER OF LIABILITY

Effective Date: May 22, 2026 • Last Revised: May 24, 2026

⚠ CRITICAL SECURITY MANDATE

BlackBox is an automated, client-side executed commercial cryptosystem utilizing X25519 Elliptic-Curve Diffie-Hellman (ECDH) and ML-KEM-768 (Kyber) Post-Quantum Key Encapsulation. The server acts exclusively as a blind transit relay operated by **the BlackBox 1:1 Project Operator**. By initializing an identity on this service, you acknowledge that all encryption keys, secrets, and credentials remain in your exclusive, offline custody.

1. Mathematical & Operational Disclaimer

THE PLATFORM, WEBPAGES, SCRIPTS, AND DATABASES ARE PROVIDED STRICTLY ON AN **"AS IS"** AND **"AS AVAILABLE"** BASIS, WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT.

The Operator does not warrant that:

  • Sockets and databases will operate uninterrupted, error-free, or fully immune from network disruptions, DNS hijacks, or latency.
  • The compilation of browser-compiled WebAssembly or client JS will run with 100% compatibility across all device hardware, sandboxes, and browser configurations.
  • Cryptographic protocols (X25519, ML-KEM-768, AES-GCM) are immune to future quantum decryption schemes.
📝 PLAIN-ENGLISH TRANSLATION: We built this app with advanced security, but we do not guarantee it will never crash or that it will be compatible with every single browser sandbox. You use the service entirely at your own risk.

2. Cryptographic & Operational Risk Disclosure

By utilizing the Service, you acknowledge and accept the following cryptographic and operational risks:

  • Self-Custody Risk: There is no server-side backup of private keys. If your terminal device is damaged, lost, or wiped, your secure sessions are mathematically lost forever.
  • Inactivity Erasure Risk: Anonymous account sessions that remain completely inactive for 7 consecutive days are permanently wiped from the database relays by a background scheduler. All conversation payloads, chat indexes, reported abuse data, and associated public identity keys are erased and are 100% unrecoverable.
  • Local Session Timeout Risk: E2EE private keys stored in the browser sandbox memory are destroyed after 5 minutes of total user inactivity (warning displays at 2 minutes and 30 seconds), terminating dynamic WebSocket sockets.
  • Local Security Risk: The E2EE security is contingent upon the security of your device operating system. If your device has local malware, hardware keyloggers, screen recording scripts, or unauthorized browser add-ons, your chats can be compromised at the terminal level.
  • Quantum Vulnerability: Standard public-key cryptography (like X25519) faces decryption risks from future quantum computers. While we implement Kyber/ML-KEM-768, this hybrid post-quantum protocol is experimental.
  • Disappearing Messages Recipient Retention Disclaimer: While E2EE disappearing messages are permanently and securely deleted from active server storage, the Operator cannot control or prevent the recipient from making physical screenshots, taking photos of their screen with secondary cameras, or copying cleartext payloads before deletion occurs.
  • One-Sided Clear Chat Preservation Disclaimer: Executing "Clear Chat" is strictly a client-initiated selective deletion for the initiator's account index. It will not delete or alter E2EE records held in custody by the conversation recipient's profile without their explicit command.
📝 PLAIN-ENGLISH TRANSLATION: E2EE only protects data in transit. If your phone or computer has spyware, hackers can read your messages. Wiping your cache deletes your keys. For security, inactive anonymous accounts are deleted after 7 days, and you are automatically logged out in your browser after 5 minutes of inactivity.

3. Limitation of Liability Clause

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL THE OPERATOR, DEVELOPERS, CREATORS, OR CONTRIBUTORS OF **blackbox1to1** BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, PUNITIVE, OR EXEMPLARY DAMAGES (INCLUDING LOSS OF PROFITS, REVENUE, OR DATA; CORRUPTION OF ENCRYPTION KEYS; LOSS OF PASSWORDS; OR COMPUTER FAILURES) ARISING OUT OF THE PLATFORM.

IN ALL CIRCUMSTANCES, THE MAXIMUM MONETARY LIABILITY OF THE OPERATOR ARISING OUT OF OR IN CONNECTION WITH THE SOFTWARE, ROUTING TRANSIT, OR WEBPAGES SHALL BE ABSOLUTELY CAPPED AT **$100.00 USD** (OR THE TOTAL AMOUNT YOU PAID TO THE OPERATOR IN THE PRECEDING 12 MONTHS, WHICHEVER IS GREATER).

📝 PLAIN-ENGLISH TRANSLATION: You are 100% responsible for your own device security and key backups. If you lose your keys, delete your cache, or get hacked, we bear zero responsibility and owe you $0. In the event of any court dispute, the absolute maximum legal ceiling we could ever be held liable for is capped at $100.

4. Law Enforcement Cooperation Policy

We will cooperate fully with valid law enforcement subpoenas, court orders, or search warrants issued by competent legal authorities.

Because our database contains only salted SHA-256 blind indexes and AES-GCM ciphertexts:

  • We are **mathematically unable** to comply with decryption directives.
  • We do **not** possess persistent IP connection logs or cleartext email lists.
  • We will deliver only the raw database blobs (salted hashes, ciphertexts, and public ratchet keys) as they exist, without any decryption capacity.
📝 PLAIN-ENGLISH TRANSLATION: If the police bring a valid legal warrant, we will cooperate. However, since your chats are fully encrypted and we do not store IP logs or cleartext emails, we can only hand over scrambled files that we mathematically cannot read.

5. Fraud & Platform Abuse Reporting

To report phishing, impersonation, or platform abuse, you can send an email with cryptographic logs or screenshots to the Operator.

The Operator will investigate and, if verified, block the offender's blind hash index from routing.

📝 PLAIN-ENGLISH TRANSLATION: If someone is abusing the platform, email us at support@blackbox1to1.com and we will block them.
OPERATIONAL COMPLIANCE DIRECTIVE
Designated Operator: the BlackBox 1:1 Project Operator
Official Correspondence Email: support@blackbox1to1.com

[ SECURE HANDSHAKE // DOCUMENTATION TERMINAL CLOSED ]
BY PROCEEDING TO USE BLACKBOX, YOU ACCEPT THESE TERMS IN FULL.