<!-- Public archive edition: 2026-09-18-sovereign-universe; status: research / proposal. Local paths and operational identifiers omitted. -->

# E03 — A sovereign Universe, with replaceable intelligence

**18 September 2026 · Research and planning revision.** This follows [E01](/documents/universe-evolution/) and [E02](/documents/protocol-evolution/). The [outgoing Protocol edition](/editions/2026-09-18-simsim-protocol/) and [30-round baseline](/review/master-plan-round30-baseline/) are preserved. E03 has not received those 30 reviews. No new memory backend, cryptographic system, model integration or autonomous agent is implemented by this revision.

## The recommendation

Make SimSim the portable, user-controlled record of a person's chosen context, decisions and permissions. Astro is its companion interface. Models supply replaceable intelligence. Memory engines supply replaceable storage and retrieval. The proposed SimSim Protocol discovers a possible shared experience from limited, authorized projections.

**The relationship belongs to the human. Intelligence is infrastructure.** “The relationship belongs to SimSim” is useful only if SimSim means the person's transferable Universe, never a company's ownership of that relationship.

This is a stronger direction than relying on exclusive access to a clever chatbot. It is also harder: recovery, correction, key custody and understandable permissions must work when the company is unavailable. Those obligations deserve a small technical proof before a sovereign-data promise.

## What is actually new?

| Decision | Earlier position and reason | E03 change and reason | Status / smallest test |
|---|---|---|---|
| E03-01 · Provider exit | R10/11 and E01 protected exports and model choice to preserve continuity | Add a company-failure and new-device recovery test; an export tied to the same login is insufficient | Current requirement; synthetic offline recovery proposed |
| E03-02 · Bring Your Own Memory | E01 suggested device/cloud storage and an event model | Separate the canonical contract from interchangeable stores, interchange formats and derived indexes; audit reuse before inventing a memory server | Architecture proposal; two-format round-trip first |
| E03-03 · Context broker | R24/27 already required scoped projections and real-action authority | Make provider-neutral context selection and proposed-memory writes an explicit boundary | Reinforcement; synthetic payload and poisoning fixtures |
| E03-04 · Ownership language | Earlier plans valued persistent history and attachment | Reject leaving-as-abandoning-history as a business mechanism; retention must come from usefulness and trust | Current product correction; test complete exit without paid rescue |
| E03-05 · Protocol | E01 bridges and E02 already introduced mutual intersections and Rooms | Clarify that no raw diary exchange still permits inference leakage; separate transport, semantics, privacy and governance | Research; probe repeated queries before sensitive matching |
| E03-06 · Model advantage | Original Council/provider abstraction avoided one-vendor dependence | Better external models should improve SimSim; compare them on permitted tasks instead of building a frontier model | Reinforcement; no training project authorized |
| E03-07 · “Canonical me” | One current-state record simplified coordination | Canonical means accepted records and authority, not one objectively correct personality dossier; storage may be federated | Design proposal; contradictory reports remain attributed |
| E03-08 · Memory reuse | R20 preserved a useful portability component as a release candidate | Shortlist interchangeable formats and engines by role, with explicit reject conditions | Research result; no package adoption |
| E03-09 · Economics | Chapters, support, bounded compute and sponsorship were already permitted | Add sovereign sync and context/discovery services as separate offer hypotheses; basic exit is not premium | Experimental; no prices, free allowances or commercial launch |
| E03-10 · Effort sequence | First Light plus a manual Astro probe; E02 added a pairwise pilot | Observe the existing pilot and run a separately bounded synthetic portability probe before another platform build | Recommendation; founder's substantial resource allocation remains open |

## What remains unchanged

The game still has intrinsic artistic, solitary and contemplative value. First Light keeps its exact three mornings, baseline-accessible recurrence investigation, distinct practices, two saves and scripted companion. W0–W6 are its work packages; G1–G6 remain the separately gated authored-game sequence. The provisional six-player/four-same-player understanding-plus-voluntary-route gate remains unrun. R04 emotional payoff, R13 paid-assistance dissent and the NOW/NEXT resource disagreement remain live.

Astro retains user-defined goals, hard constraints, versioned assumptions, active information gathering and the decision/outcome loop. Symbolic lenses, mirror/alternative/autonomous fiction and ancestor representations retain distinct evidence status. Simulation does not create counterfactual ground truth. A personal record is not a license to model other people without boundaries.

## Try to break the thesis

**A better assistant can copy this architecture.** No credible claim here proves frontier providers cannot offer portability, outcome logs or matching. SimSim must earn use through continuity, comprehensible controls and worthwhile experiences. A standard may be successful while the company captures little revenue.

**Longitudinal history is an asset to its person, not an exclusive corporate moat.** Interoperability intentionally makes it movable. Defensibility, if any, comes from reliable operation, community trust, integrations and useful participation. More members can also create spam, competition for attention and harassment; a network effect is a hypothesis, not a headcount.

**The cold start must work without a life dossier.** E02's small card is the better test of the social thesis. If a simple host introduction is equally useful with less burden, elaborate personal agents may add little. If people already know each other through a QR invitation, that alone cannot prove discovery of a stranger they otherwise would not meet.

**“Almost irrational not to exchange SimSim” is the wrong acceptance criterion.** Exchange should be useful and easy to refuse. No embarrassment, withheld access, opaque rejection score or social penalty should make disclosure feel compulsory. A one-time interaction must not silently create persistent discovery permission.

**Memory infrastructure is only partly interchangeable.** A graph, an agent's editable notebook and a portable bundle have different semantics. The abstraction must expose unsupported capabilities and loss, not promise every backend can honor every deletion, query or transaction.

**Sovereignty costs attention.** People can lose keys, misunderstand a scope and dislike maintenance. A recoverable managed option is legitimate if custody and operator access are explicit. A beautiful encryption diagram is no substitute for a normal person's successful recovery.

## What could make this substantially better?

1. **An exit kit before a grand protocol.** A readable, versioned, independently usable record plus recovery instructions makes ownership tangible. Test on synthetic data while disconnected from SimSim and the original model provider.
2. **A context receipt before an invisible “brain.”** Show what a provider received, why, for how long it may be used, and whether its response changed memory. Make sensitive exceptions noticeable without prompting for every unchanged, authorized operation.
3. **A shared possibility rather than a people score.** Present one feasible experience, a short explanation both approved for disclosure, and honest unknowns. Learn from each person's private outcome without exposing their rejection or emotional account.
4. **Local filtering before broader disclosure.** Check non-negotiables inside the owner's boundary. Export only permitted candidate activities or availability buckets. Do not tell another party which hidden constraint failed.
5. **A decision record that survives the narrator.** Preserve prospective assumptions, choice and observed result while allowing models, summaries and interfaces to change. Correcting a source invalidates affected advice; deletion remains possible.

These are product proposals, not implemented privacy guarantees. See the [architecture and constitution](/documents/sovereign-universe-architecture/) and [memory reuse audit](/documents/memory-reuse-audit/).

## Economics without owning the person

| Offer hypothesis | Aligned value | Incentive to resist / evidence needed |
|---|---|---|
| Local/basic use and export | Useful operation and exit | Do not promise a free service before defining costs; never charge to undo artificial lock-in |
| Encrypted hosted sync / recovery support | Availability, tested restoration, convenient operation | Disclose key custody and backup limits; measure support burden and successful recovery |
| Optional models / simulation compute | Named analysis within an enforceable allowance | More runs must not become a way to sell confidence; compare cheaper methods |
| Room/community service | Helpful voluntary introductions and organizer tools | Organizer payment grants no private profile, rejection or attendance surveillance |
| Integrations / developer APIs | Reliable scoped access and conformance | Avoid per-person data resale or a proprietary identity choke point |
| Optional transaction service | Executing a separately authorized useful transaction | Disclose commissions; no covert influence over personal advice |
| Authored chapters / curated work | A complete experience people value | Retain the existing game demand and full-production-cost gates |

Include storage, inference, failed requests, abuse handling, security maintenance, recovery/deletion support and exit obligations in costs. Free/exportable source software can coexist with paid convenience. Sponsors may fund a worthwhile service without proving consumer willingness to pay. No existing price illustration is adopted.

## The next bounded sequence

**NOW:** publish this research and preserve history; observe the already-built two-person pilot only with separately arranged voluntary participants. The manual Astro decision comparison remains available. No new background capture or memory server.

**NEXT:** a synthetic portability spike comparing a simple local record with MacPaw/PAM interchange. Define a small time cap before starting. Produce pass/fail evidence for correction, deletion, conflict and provider failure; do not build all adapters. If useful, separately test context comprehension with a human using nonsensitive examples.

**LATER:** one supported local vault and one optional sync path after recovery and deletion evidence; one approved external-model connector; then a small Room provider integration if introductions earn their burden. A generalized protocol needs independently implemented interoperation, not two endpoints controlled by one application.

**RESEARCH:** private matching, malicious-query resistance, multiple personas, credentials, semantic interoperability, minors, advanced recovery, outcome prediction and service economics. Dating, hiring, investment discovery and private image-preference modeling require their own rights, fairness and safety review. They are not extensions to turn on by relabeling this adult activity pilot.

The founder's next concrete resource decision is which bounded proof deserves the next work block: First Light's experiential proof, observing SimSim Us, or the synthetic portability spike. They answer different questions. This revision recommends reuse research and small evidence, not three simultaneous infrastructure builds.
