← Back to the beta forms · Beta page
Earned Trust Beta Trial · Draft 17 · 12 September 2026 · This is the version you are agreeing to.
Draft 17, 2026-09-12. Publishes with the design deposit (DOI 10.5281/zenodo.22547805); the beta page carries its substance in plain words, and links are added when the deposit goes live.
Read this first: This is a publicly offered trial whose results publish. Enrolling carries no expectation of privacy in anything you send the study. Email is a postcard, not a locked safe. Send us nothing you could not bear a stranger reading. Our one commitment is the big one: we never see, hold, or review your work — your public deposit excepted: the five checks download it and recompute its fingerprints, and read none of it. This trial studies the process, never the work.
Responsible party: William Stafford, the study’s principal investigator (PI) — an independent researcher (Earned Trust is the project, not an organization). Study inbox (automatic reply only): beta@earnedtrust.org. The words this page uses for the study’s pieces — DOI, deposit, the Reader, locked box, your code, your window, the ledger — are defined in the short list of words at the top of the consent form.
One more note before the details: this trial enrolls United States participants only, and this page is written to United States law. A one-person study cannot honestly carry the obligations enrolling elsewhere would create — and saying so is better than pretending otherwise.
We ask you for no words. The study solicits no composed email and provides no blank body. Every email you send the study is written by a published form or a fixed button. The complete list is apply (one form, one send), intake, the exit form (your DOI — the permanent web address Zenodo gives your published work — goes on it), Name and DOI correction, and withdraw — five; every one after apply asks for your code (it looks like ET-0906-03). Names, dates, DOIs, and fixed choices are data fields, not narrative. So what we hold of correspondence is the emails those forms wrote and when they arrived. Emails during the trial will not receive a response. If you do not complete the trial within your window, you will be logged as incomplete. Every form you send is answered by a scripted email — confirmed, or not accepted — and each answer is counted in the contact ledger (the study’s published count of every message it sent or received during the trial). A person can always type into an email client, and no rule of ours stops that; anything composed anyway is not read and not answered.
If you apply: applying is one published form, one send, reached from the “Apply” button on the study page — the nine screening questions, then the consent acknowledgments, your typed name, and the date. No code is needed to apply. The screening half is checkboxes and picklists only — nothing to write, nothing to explain, and it returns by a link that fills itself in; every list ends with “other,” and other is filed simply as other. The consent acknowledgments are conditional: sending the application authorizes only the handling of application data the consent form describes; consent to participate takes effect only on enrollment. If you are screened out, you are not a participant and none of the participation acknowledgments binds you. We hold your email address, the date your application arrived, and your answers. If you enroll, your checked boxes and your signed form join your study record, and your enrollment confirmation carries your code — built from the date your application arrived and its place in that day’s queue. Every form after that asks for it first. The code is a gate, not a disguise. The code does not hide you — your name still prints. The form cannot check it, the study can, and the check has two parts: the code must match one the study issued, and the form must come from the email address the code was sent to. Any form you send after you are enrolled that fails either is not filed, and answered with the notice: “NOTICE: your ETR code was not accepted. Please check your code and try again. The form must also come from the email address your code was sent to.” If you are screened out, the study keeps your name, email, exclusion reason, and date on one screened-out list until the trial’s last phase closes — why: so it can recognise a repeat application; the list records whether the reason was about you, about that project, or about the phase, and a second application from a name on it is answered with the screened-out note and nothing else only when the reason was about you — a new project, or a later phase, is screened afresh — and your signed form itself is deleted 30 days after the phase closes. There is no list to join for a future phase; further phases are announced on the study page. Screened-out applicants print only as a count; the count of applicants, of the screened out, and of the reasons is a finding and publishes. Our mail provider may retain deleted mail in its own backups for a window we do not know and do not assert. Either way the report counts you only as a number (“N people applied”) — an editorial rule about what the report prints, not a privacy promise.
If you enroll: we hold your code, your three signed documents (the consent form, the Terms of Participation, and the duty map — the one apply form signs all three together), your intake answers (every one a picklist, plus the version number and checksum of the kit you downloaded, and your tick that you had not yet started a recorded session), your exit form (your DOI and your two lines, public and private — explained below), and any Name and DOI correction you sent, with their dates — in a Proton Mail mailbox (Proton AG, a Swiss provider) and in the PI’s own folders. The study’s records are seen by the PI and any named co-PI, and by no other person at the study; the providers we name handle what passes through them as any mail or AI service does. The study’s mail is hosted by Proton, and the study’s drafting uses AI tools under the standard, as the consent form says. (The PI may add additional principal investigators as the trial needs them. Each is named on the beta page and in the report the day they join, with the date, and is bound by every rule that binds the PI.) Kept for five years from the report’s publication (the same five years the standard requires records to be kept), then deleted. When we delete mail, Proton’s own backups may hold it for a window we do not know and do not assert. If we learn that the study’s inbox or machine has been compromised, we publish that in the deviations log and tell every enrolled tester. We run no monitoring of our own beyond what the provider gives us, so we may never learn — which is the other half of the postcard rule. The report publishes the blank forms, never your signed ones — an editorial rule about what prints, not a protection offered.
Your exit answers publish — by design. When you press Submit, the exit form makes two lines from your answers. Your public line holds everything that prints — it goes in the report’s appendix word for word, and it is the only thing in the QR image. Your private line holds the seven report-private answers; the study keeps it, counts it into totals, and never prints it. Both lines go in the same exit email. Your private line is held by the study and never printed; it is not encrypted, and email is a postcard. The report prints every tester’s public line, and anyone can unpack it with our web viewer (the Reader), because the report’s appendix is the study’s raw data. Packing is not hiding: the line looks like gibberish, but anyone can read it back. It publishes exactly as sent. Appendix lines are effectively permanent — plan as if permanent. The seven report-private items (your private line) are the locked-box result and date, the three passphrase-solicitation questions, the regret item, where your sessions happened, and whether another living person’s story entered your work. They never print beside your name — only as totals. Three of them are kept off the public print for security — a per-person ‘yes’ beside a public record would hand attackers a map. The locked-box result and date, and the regret item, are kept off because a tally answers the study’s question without pinning a second thought to a name. The last two are kept off because the study promised them as cohort counts, and a promise about what prints has to be true of the data too. Before you send, the page shows you everything that will print about you, so you check it first. You see exactly how you print on the exit form before you send, and that recheck is the last word — there is no later change window. After your exit, your documented-participant letter is a receipt showing your citation line exactly as you confirmed it on the exit form’s recheck screen — generated from the exit line you filed or corrected, never retyped, nothing substituted; the report’s line for you is generated the same way.
If you withdraw (any time before publication, no reason needed — one checkbox, nothing asked, one scripted note confirming it): we delete everything we still hold about you — your email address, your code, your application and intake answers, and any form emails you sent — and keep the three signed documents — your signed consent form, the signed Terms of Participation, and the signed duty map — so we can always show that you consented and then withdrew, which protects you as much as us — plus one dated line in the contact ledger recording the withdrawal. One thing withdrawal cannot pull back: an exit form you already sent is already the study’s raw data, and the appendix still prints it. That is why we tell you before you send. A withdrawal filed after your exit cancels every letter not yet sent and keeps your filed exit line, which still prints. Withdrawal is only your own act. If your window closes with no exit in, you are logged as incomplete — no choice recorded. The window is the one clock, and it does not stop; the study’s one reminder reaches you two weeks before it closes. The report puts every enrolled tester into one of four outcomes — completed (exit form, “I completed the trial”) · stopped (exit form, “I’m stopping here — count what I filed”; name and answers stay in) · incomplete (the window closed with no exit form; counted, never named) · withdrawn (the withdraw form; data out; an exit line already sent still prints) — and the appendix publishes whatever public lines were filed. If your exit form says you made no deposit and the DOI field is blank, your record is counted at once as “no deposit found” within completed or stopped, as your form says. You get the confirmation of your exit and nothing else — no correction email, no note, no documented-participant letter. None of this is a privacy promise. Honesty about the limit: withdrawal removes what we hold — your own deposit is yours, on your own account, and is governed by the platform rules described below, regardless of withdrawal.
What publishes: If you take part, your name and — when you make a deposit — your work’s DOI will be published in the report; when there is a deposit, the DOI is required and public. That is what makes the trial checkable by anyone. The name that prints is the author name on your Zenodo record — a pen name is fine, but it has to be the name on the DOI publication, because the DOI is the check. The DOI you give must be the version DOI — the one shown on the record page for that version, not the “all versions” DOI. Before the checks, the study confirms the record holds your Earned Trust deposit (your card and your manifest) and that the author name on the Zenodo record is the name on your exit line. If any of the four checks fails — your DOI did not open · you gave the “all versions” DOI instead of the version DOI · the record does not hold your Earned Trust deposit · the author name on the record does not match the name on your exit line — you get one email saying which, and the correction form takes your name and DOI together. The name you enrolled with is held privately; your letter and citation come to you under it. So: the report and its appendices — findings under your name and your DOI; the appendix of public lines — every tester’s public line, printed word for word (the private lines are held, counted into totals, and never printed); the support log, as counts; the contact ledger, every scripted answer counted in it — the notice, “no deposit found,” and withdrawal confirmed among them; the DOI-retry count; the count of applicants, of the screened out, and of the reasons; and the count of testers in each of the four outcomes — completed · stopped · incomplete · withdrawn, with “no deposit found” its own count within completed or stopped, as the exit form said. There are no answers to publish, because during your trial the study answers no questions. The automatic reply points you at the published question list, which is compiled to cover everything a participant could ask about the protocol; anything outside the protocol — Zenodo, accounts, tools, your own project — belongs to your own AI. A question the published list does not answer is recorded as a count and becomes a study finding. These are the study’s editorial rules — descriptions of what the report prints, not protections offered. Published deposits are effectively permanent — plan as if permanent; that is what “published” means here, and the consent form says it plainly before you sign.
What you send may be processed by AI: this study’s materials and its report are drafted with AI assistance under the Earned Trust Protocol, disclosed and recorded. Your fixed sends and their metadata may pass through a commercial AI service during drafting. We ask for no words, so there is little of yours to pass through — and email is a postcard here as everywhere.
This page’s analytics: the site uses GoatCounter, a cookie-free visit counter. It briefly keeps your device’s internet address in memory (up to 8 hours) to tell a repeat visit from a new one, then forgets it — it stores no addresses, builds no personal profiles, and what it keeps are day-level aggregate counts.
To ask for deletion of anything we hold about you (before publication; a published deposit is effectively permanent — Zenodo allows removal only within a 30-day window on the owner’s own account or, later, in narrow, duly justified cases; requests can be refused; and a removed record leaves a permanent citation tombstone — so plan as if nothing published can ever be taken back): the withdraw link is the send that runs it — one click, and the deletion described above runs on schedule. There is nothing to compose. There is no independent complaints route: this is a study run by its PI and any named co-PI, with no institution and no ethics board behind it, and it says so. What you can correct is how you appear — on the exit form’s recheck screen before you send, and only there; the letter afterward is a receipt. What anyone can check is the public record.