<!-- Public archive edition: 2026-09-18-simsim-protocol; status: experimental. Local paths and operational identifiers omitted. -->

# Private Universes and shared simulations — architecture proposal

18 September 2026 · EXPERIMENTAL specification for the current planning direction. No personal-data service, learned model, Room Mode or shared simulation is implemented by publishing this document. Read the [current plan](/review/simsim-astro-master-plan/) and [decision evolution](/documents/universe-evolution/).

## One conceptual language, separate kinds of truth

**You are a Universe. Astro learns your Universe. SimSim explores its possible futures. Master Brain connects Universes without owning them.** These are product metaphors and responsibilities, not claims of complete knowledge or proven prediction.

| Component | Responsibility | Boundary |
|---|---|---|
| LLM | Interpret language, ask useful questions, explain candidate choices | Fluent language does not establish an event or causal effect |
| Astro | Companion and permission-aware interface for one person | Goals and model suggestions are not execution authority |
| Private Universe | Permitted events, goals, contexts, relationship perspectives and derived state | Owned by the person; fictional records and real reports remain separate |
| SimSim | Authored game transitions and a separate experimental personal transition model | Shared interfaces do not make fictional rules empirically true |
| Master Brain | Coordinate bounded requests between participating Astros | Receives only explicitly permitted inputs; no universal private-memory access |

### Proposed data flow

1. A selected report or authorized observation enters a private event store with its original source status.
2. A versioned projection derives the current state and distinguishes unknown values from observations.
3. Astro supplies allowed choices, goals and constraints to SimSim. SimSim returns conditional scenarios and assumptions.
4. The person chooses. Any external action passes a separate authority check.
5. Voluntarily supplied immediate and delayed outcomes form new real records. Predictions and errors remain linked to their original versions.
6. For a joint request, each participant's Astro evaluates scope locally and returns only permitted constraints or answers. Master Brain compares feasible intersections and returns a proposal for human acceptance.

No arrow from a simulated outcome into observed reality is allowed. A fictional success may inspire a real self-report of feeling encouraged; it cannot become evidence that the imagined event occurred.

## Events are evidence, not permanent labels

The proposed envelope records `event_id`, `universe_id`, `actor_kind`, `record_kind`, event time and recording time, source/claim status, context, allowed purposes, schema version and correction links. Actor kinds distinguish the owner, a participating person, a subjective shadow and an authored character. IDs for another person are local references until a separately authorized identity link exists.

A decision record adds source snapshot, goal/constraint versions, genuinely considered options, intended action before advice, model version, assumptions, conditional prediction and applicable horizon. Outcome records reference the decision and actual action, distinguish self-report from observation, retain missingness and interruptions, and separate immediate from delayed outcomes. An error assessment names the outcome definition and evaluation method; uncertainty may remain qualitative.

Store an interaction in context: activity, duration when known, voluntary before/after self-reports, possible confounders and attributed interpretation. Do not reduce a person to a permanent energy, morality or trust value. Requested fields are a menu, not a mandatory questionnaire. Latent dimensions such as masking load or recovery debt are hypotheses until their meaning and measurement are established with the user.

Event sourcing is a planning foundation for later personal-model work. Retained records survive model upgrades without silent reinterpretation of their original assertions. Corrections supersede claims; mutable views are rebuilt. **Append-only intellectual history does not mean undeletable intimate data.** Delete controlled sensitive payloads and revealing derivatives when required by the user's scope; retain only necessary nonrevealing integrity metadata. Recovery, backups, future training and exported copies need explicit retention and deletion limits. This is not a requirement to build a universal event platform into G1.

## Ownership has independent controls

| Axis | Proposed choices | What it does not authorize |
|---|---|---|
| Storage | My Device by default; My Cloud; Astro Cloud | Remote inference, sharing or model training |
| Access | Owner, own Astro, selected Astros or a temporary coordinator | Access by every integration or all future participants |
| Depth | Particle, Signal, Constellation, World, Universe | A blanket database export |
| Purpose and duration | Named task, deadline, outputs, allowed processing path | Reuse after expiry or for unrelated decisions |

Local storage is the default direction; device encryption, key recovery, backups and multi-device conflict handling still need design and verification. Storage on a user's cloud is not necessarily local processing. Managed encrypted storage is an intended capability, not an already-verified security property. Neither local nor hosted placement implies permission to train a model.

## Temporary Universe bridges

A proposed grant binds grant ID, participants, exact purpose, allowed input categories, query operations, output disclosures, processing location/provider, expiry, retention, revocation, resource cap and current prerequisites. Particle through Universe are navigation terms; the actual grant must remain inspectable. “Universe” should mean broad but specified reasoning scope, not access to everything known about every third party.

Prefer local evaluation with small authorized answers. A coordinator or another Astro that receives data has received a disclosure even if the other human sees nothing. Derived answers can reveal secrets, especially through repeated queries, small groups or combining outputs. Query limits, output minimization and leakage tests are required before promising confidential negotiation. Do not advertise cryptographic privacy without an implemented, evaluated protocol.

For “SimSim us tonight,” both Astros may supply permitted feasible time windows and activities. If their intersection is empty, return no common plan rather than relaxing a private constraint. The reason for exclusion can stay private; even the exclusion may be sensitive. Human agreement remains separate from computation. A suggestion never establishes romantic or sexual consent.

Expiry/revocation stops further controllable queries and output delivery; it cannot erase what another party already learned. Recheck grants on delayed output, new participants, provider changes and changed requests. Preserve R27's uncertain-operation and stale-approval rules. No social penalty for declining to connect.

## Shadow agents, rooms and hubs

A shadow is explicitly one person's uncertain perspective on someone else. It is not an authenticated identity, hidden-motive detector or that person's consent. Joining later creates a distinct participant; linking requires authority and never silently merges private histories. Use generic placeholders when identity adds no decision value.

A room instance can represent people, permitted relationship context, environment, activity, time and each contribution's permissions. Influence may be bidirectional. Resonance cascades are simulated hypotheses, not measurements of everyone present. An ambient display must not expose individual private states. Hubs extend this proposal to friendship, dating, collaboration and companies; useful introductions require permission and disclose no private rationale by default. No cofounder or hiring verdict should be reduced to a global compatibility number.

Room Mode proposes three states: **Sleeping** means no room capture or inference; **Observing** requires current, informed permission from affected participants and visible capture status; **Invited** allows a bounded contribution. “Astro, private” stops controllable shared-room capture/processing and revokes ongoing room use within supported limits. A visible manual stop must work without relying on voice recognition. New arrivals, bystanders and revoked permission require a safe pause or non-recording alternative. Audio should be ephemeral by design, but temporary audio and derived events still require permission and retention controls. No listening is enabled by this plan.

## Frequency as a reflective language

Frequency may visualize multidimensional state; coherence means perceived alignment, amplitude intensity, resonance contextual compatibility, residue a persistent reported effect, and entanglement accumulated influence as metaphor. Baseline, authenticity, masking cost and recovery debt remain revisable concepts. None measures literal human Hz, virtue, contamination or spiritual rank.

Interaction depth might affect persistence or intensity, but no universal ordering, positive sign or fixed multiplier is established. Touch and intimacy are not inherently beneficial or harmful. Recovery comparisons can consider sleep, nature, movement, solitude, ritual and trusted conversation, separating immediate relief from delayed effects. A report of using alcohol or cannabis is observational input, not a recommendation or evidence of safety. The product should not optimize risky coping to maximize a short-term mood score.

Optional spiritual lenses remain reflective. Comparing explanatory models requires prospectively defined outcomes, temporal holdouts and transparent failures, not selecting the framework that explains yesterday most persuasively. Symbols can be meaningful even without predictive benefit.

## Learning path and empirical gates

The research target is a conditional transition model, conceptually P(next state | state, action, people, environment, context). Observational associations do not identify what an unchosen action would have caused. Self-selection, missing reports, changing goals and feedback from the advice itself can bias apparent performance. Keep abstention and simpler models available.

| Stage | Possible method | Evidence needed before more investment |
|---|---|---|
| V0 | LLM, explicit rules, minimal event graph and transparent preferences | Added decision value versus simple coaching at acceptable burden |
| V1 | Statistical or Bayesian personal coefficients | Sufficient permitted repeated observations; temporal evaluation against a simple baseline |
| V2 | Learned outcome predictor | Held-out predictive performance, uncertainty review and benefit beyond V1 |
| V3 | Sequence/world-transition model | Longer-horizon error, drift and model-misspecification evaluation |
| V4 | Multi-agent transition model | Joint value plus consent, leakage and shadow/participant separation tests |
| V5 | Master SimSim foundation-model research | Justified data rights, scale, cost and reproducible advantage over existing models |

V0–V5 are research maturity stages, not W0–W6 work packages or G1–G6 game gates. Every stage can be deferred, rejected or remain a durable endpoint. A thousand correlated branches do not supply a thousand human outcomes.

The longitudinal state–context–choice–prediction–outcome–delayed outcome–error record may become strategically useful. It belongs to people, not automatically to the studio. Personal adaptation, shared simulation and population training need distinct permissions. De-identification is not guaranteed anonymity; no pooled training is active. Before training, address provenance, selection bias, memorization, retention, withdrawal and the limits of removing influence from already trained models.

## Unrun checks before implementation expands

- Correct a report, change a goal and delete a sensitive source: rebuild dependent state without rewriting the old decision rationale or resurrecting deleted text.
- Ask a bridge repeated or combined questions, revoke access mid-request, change a participant and delay output: no new unauthorized disclosure; no invented guarantee about prior disclosure.
- Introduce a real participant corresponding to a shadow: keep identities, claims and authorities distinct.
- Rehearse Room Mode with a bystander, a failed voice stop and an offline manual stop before collecting real room data.
- Compare a single manual decision aid with simple coaching; record attention burden, pressure and missing outcomes. Only then consider a bounded joint-planning study.

These are proposed tests. Publishing this specification runs none of them and supplies no personal-monitoring, training, billing or agent-execution authority.
