The Z00Z Protocol is code and rules, not a legal actor. Z00Z includes the
wallet role as a core architectural component. The
project’s z00z_wallets crate is one open-source reference/demo implementation,
not the only permitted implementation. In a self-custodial flow, the user
controls keys, local settings, transaction history, backups, receipts, and
disclosures and remains responsible for the user’s own conduct and for duties
that applicable law assigns to the user. The wallet is a software component,
not a legal person or a liability sink. Project-linked and independent operators
retain duties arising from the functions, interfaces, profiles, data, claims,
control, and services they actually distribute, operate, or provide. Those
operator duties cannot be reassigned to wallet software or to the user through
self-custody language. This page is the canonical source for
cross-jurisdictional compliance wording across the Z00Z corpus. Other pages
should state only the feature-specific fact and link here.
This framework does not certify universal compliance. Classification follows actual functions, control, affiliations, information, relationships, and applicable law—not a protocol, wallet, DAO, or self-custody label.
Canonical Actors And Legal Hierarchy
The following vocabulary controls throughout the legal corpus:
| Term | Canonical meaning |
|---|---|
| Z00Z Protocol | Published software, rules, and data formats; not a person, company, contracting party, controller, processor, custodian, or service operator. |
| Z00Z project or corpus | Shorthand for code and documents; not an entity or allocation of duty. |
| Publisher or steward, if any | The actual person or body publishing, maintaining, funding, or controlling identified project functions. |
| Project-linked operator | A person or body actually distributing, operating, or controlling an identified Z00Z-branded or affiliated surface. |
| Independent operator | A person or body whose ownership, control, data, branding, distribution, support, and operations factually support independence. |
| Self-custodial user | The person controlling the user’s keys and local records, responsible for duties assigned to that user’s own conduct. |
The word Z00Z alone identifies no company, operator, controller, support desk, or key holder. Regulated roles follow purposes, means, functions, authority, data, relationships, and law. Permissionless or DAO eligibility creates no agency or endorsement.
Mandatory law controls where it cannot be varied; applicable licences govern licensed code; a valid service agreement governs only its identified actor and surface; technical specifications govern protocol semantics; and legal notices govern only their stated subject. Whitepapers, roadmaps, examples, and maturity notes do not silently amend legal duties. This allocation is independent of feature maturity and cannot move duties between a user, operator, or software.
Product And Responsibility Model
| Surface | Canonical position |
|---|---|
| Z00Z base protocol | Validates confidential transitions, proofs, replay boundaries, and checkpoints without requiring a universal identity, balance-account graph, or complete named per-wallet history. That boundary does not classify a person operating another function. |
| Self-custodial user | Controls keys, devices, settings, local transaction history, backups, receipts, exports, and disclosures; meets duties applicable to the user’s own conduct. |
| Z00Z wallet role | May provide local possession, transaction preparation, bounded history, risk notices, recovery, policy tools, and scoped disclosure. z00z_wallets is the open-source reference/demo implementation; software assists but neither certifies nor becomes responsible for the user. |
| Project-linked operator | Retains duties arising from each build, interface, profile, data flow, claim, or service it actually distributes, operates, or controls. |
| Independent wallet or service operator | Retains duties arising from its actual functions and is independent only where ownership, affiliation, control, data, support, and operations support that conclusion. |
Terms such as VASP, CASP, MSB, money transmitter, custodian, issuer, or payment service require a fact- and jurisdiction-specific assessment. Neither a diagram nor reference-wallet label proves an exemption or a regulated role.
The technical rule is maintained in Wallet SDK: Reference Implementation And Interoperability. Accordingly, compatible wallets may be built, forked, modified, or extended. Compatibility follows wire formats, cryptographic domains and versions, evidence rules, and settlement validators—not the reference crate’s internals.
Privacy And Scoped Disclosure
The Protocol reduces base-layer public observability but does not guarantee anonymity, untraceability, or absence of records. Users control voluntary wallet-originated disclosure; counterparties and operated services may independently receive or infer information. Each actor must perform any collection, retention, screening, reporting, or disclosure duty applicable to its own function, using purpose-bound data where possible.
A legal demand creates no missing key, record, or authority. No Z00Z document may promise a universal disclosure backdoor, and no wallet may export secrets or unrelated history as a shortcut. Possessing local data does not make every user a controller; controller, processor, and joint-controller roles follow actual purposes and means under applicable law.
Retention And Challenge-Data Boundary
The target challenge window is 1,555,200 finalized blocks from
da_publication_ready, nominally 90 days at a five-second cadence. It is a
block-height rule, not an exact calendar period, chargeback, limitation period,
or reversal right. Expiry makes only expressly temporary challenge material
deletion-eligible and only after every profile condition. It does not erase
current settlement, replay or spent-state records, roots, anchors, finality,
wallet-local history, or independent copies. Physical pruning maturity is a
separate release fact.
The reference wallet’s JSONL history is outside .wlt, accepts at most 10 MiB,
and is not an unlimited legal archive. Each user or operator must preserve
records required for that actor’s own conduct or function.
User-Configured Jurisdiction Policy Profiles
A wallet may expose country, regional, business, or user-defined profiles above base consensus for warnings, limits, retention, exports, or scoped disclosure. A profile is a tool, not legal advice, certification, or a guarantee. The user remains responsible for choosing and maintaining settings and records required from that user. The actor supplying or maintaining a profile retains duties arising from its claims, updates, security, and operated controls. A profile cannot override mandatory law or transfer either actor’s duties.
The reference crate has policy, bounded history, receipt, and backup building blocks but is not represented as shipping persisted jurisdiction profiles or a maintained legal-rule catalogue. Product copy must distinguish a technical template from current legal review.
Offline, Self-Hosted, And Travel Rule Flows
Offline settlement is not a compliance exemption. The user accepts disclosed local non-finality and conflict risk; an operator retains duties arising from the warnings, limits, reconciliation, records, and claims it supplies. A self-hosted transfer may remain regulated when a regulated provider participates. Any required information exchange should remain purpose-bound and outside public settlement unless the Protocol requires it.
Sanctions And Prohibited Use
Privacy and transport features do not authorize sanctions evasion, financial crime, obstruction, fraud, theft, trafficking, or market abuse. Users comply with rules applicable to their conduct; operators implement controls applicable to their actual functions. Wallet prompts do not certify either actor.
External Assets And Services
Protocol compatibility proves only technical predicates. It does not establish external legality, reserves, solvency, redemption, custody, sanctions status, or classification. Those facts follow the actual issuer, custodian, bridge, venue, affiliations, and operating arrangement. Public copy must not claim approval, safety, guarantee, or official status without an identified actor, disclosed relationship, and corresponding operating model.
Token And Market Communications
Economic discussion describes design and risk, not demand, value, yield, listing, liquidity, support, or regulatory promises. Communications must distinguish design, maturity, independent activity, and an operated service and remain factually supportable.
Evidence And Change Control
Each actor keeps records and reassesses controls where required for its own conduct or actual functions. A customer-facing custody, exchange, payment, issuance, redemption, bridge, treasury, market, or recovery service requires separate actor- and jurisdiction-specific documentation and review.
Primary Regulatory Sources
- FATF VA/VASP guidance supports activity-based analysis; recommendations require jurisdictional implementation.
- EU Regulation 2023/1113 covers CASP-involved transfer-information duties and excludes person-to-person transfers without a CASP.
- MiCA defines crypto-asset services; recital 83 addresses non-custodial wallet software, while Title V regulates actual service providers.
- FinCEN CVC guidance distinguishes wallet models by control and intermediary activity.
- GDPR Articles 4, 13, and 24 support functional controller analysis, required notice information, and accountability where applicable.
Read Next
- Public Claim Boundaries for approved and prohibited wording.
- Legal Architecture for technical capability, data possession, and operating-role evidence.
- Website Use And Risk Notice for the website notice boundary and project-operated surface restrictions.
- Website Data-Boundary Notice for the source-backed site surface and the deployment facts still requiring an identified operator.
Evidence and Further Reading
- Legal Architecture sections 3, 7, 9, 14, and 17–18 support the actual-function test, integral wallet role, reference/custom implementation boundary, jurisdiction profiles, operator-specific controls, and public-claim discipline.
- Main Whitepaper sections 5 and 10 support wallet-local possession, delayed reconciliation, the protocol/product/service responsibility map, and compatibility with custom wallet implementations.
- Privacy Threat Model And Metrics sections 3, 6, and 9 support threat-model-scoped privacy claims, metadata limits, and rejection of absolute anonymity language.