Cover photo

After Privacy, a People

Notes in the margins of The Politics of Privacy

A note on order: this piece is part of a set of three that go together. Each stands on its own, but they build in sequence. The order is this one, then "The Mechanism and the Demos," then "The Missing Variable."

The anthology's central move is the right one. The Politics of Privacy refuses to treat privacy as mere secrecy. It frames it as the distribution of power - "To observe is to influence" - and names the real stake: keeping human beings "authors, and not mere subjects, of their own lives." That framing could sit at the front of almost anything I care about. The diagnosis is shared: power concentrates, the algorithmic layer optimizes for prediction over autonomy, and the person is quietly demoted from author to data.

This is not a disagreement. It is a question the book opens and, I think, deliberately leaves standing: authors of their own lives - and then what do those authors compose into?

Privacy, encryption, and self-custody are defensive by design. They protect the individual from capture. They are necessary. But they answer only the first half of the problem the foreword itself poses. Defense keeps each author intact; it does not give those authors a voice on the planetary questions that no single state represents. That is protection, not yet a seat at the table.

There are, roughly, two families of answer to that gap.

The first runs through most of the anthology: defend the individual - with encryption, privacy-preserving tech, self-custody - and, where the argument turns constructive, improve the mechanisms of existing democracy (plural governance, quadratic voting, deliberative tools). The unit is the person, protected; the horizon is a better-functioning version of the institutions we already have.

The second is the one I have been building, and it starts from the opposite end: constitute a subject. Not only shield the individual, but aggregate verified individuals upward into a people - one with enough standing to speak. The divergence runs along two axes.

The first axis is the verb: protect autonomy, or constitute a people. International law grants self-determination to peoples, and it leaves "a people" deliberately undefined - a gap states kept open to protect their own sovereignty. That undefined space is buildable. A voluntary, non-territorial people, formed by the free choice of its members, adds a planetary belonging without seceding from anything or claiming any territory. Addition, not secession. In this space the closest analog is Coordi-Nations, except the ambition here extends beyond a new institutional form to functional legal personality - standing, not just coordination.

The second axis is how you keep collective decisions honest. The plural-governance tradition weights the vote: quadratic voting lets intensity be expressed while dampening the advantage of the wealthy. It is elegant, and it still weights. Our model refuses to touch the vote at all. One verified human, one vote, inviolable - reputation, contribution, and the internal unit of participation never convert into voting weight. Decision quality is loaded onto the process, not the ballot: mandatory expert review, open deliberation, a cooling-off period, and higher consensus thresholds on specialized or high-risk questions. Protection from populism without sliding into epistocracy. On the value that matters most in this space - that money cannot buy governance - refusing to weight the vote is the cleaner answer, because quadratic voting quietly reintroduces the resource weighting we remove by design.

Which brings the obvious objection from any privacy-native reader: KYC.

A verified, sybil-resistant people - one without bots or deliberate bad actors, where one human really is one vote - cannot be built on pure anonymity. Pseudonymity breaks the moment one actor spins up a thousand identities. A countable people, and one-person-one-vote at any scale, requires a proof of unique personhood. That is the unsolved hole in most of the anonymity-first stack.

We fill it, and how we fill it is the point. Biometric verification mints a soulbound passport that proves a single, unique human to the world - without revealing who that human is. It is done in-house and data-minimizing; the system retains the fact of a passed check, not biometric templates or document scans. This is not a compromise with privacy. It is what the anthology's glossary gestures at - proof of personhood that does not expose identity - running in production.

There is one more difference worth naming, and it is a difference of altitude rather than a fault. The anthology works at the level of analysis and individual tools - by design it offers diverse pathways rather than one finished model, and most of the tools it points to are existing, standalone, and someone else's. That is a real contribution. It is simply not a built, interacting whole.

The core of what I am describing is not technical at all - it is legal. The claim is that a new people can be constituted, with the legal consequences that follow, on ground that international law already contains. The software is not the argument; it is what makes the argument demonstrable instead of merely asserted. To the book's third aim - proposing concrete responses - I would answer not with a menu but with one integrated instance already in production, where the parts actually hand off to each other: a founding text, verification, a governance layer, an internal economy, a reputation system, the corpus cryptographically signed and anchored on-chain. That specific implementation can be swapped or rebuilt; the legal foundation is what it exists to prove.

The sequence matters. The right to self-determination has sat in international law for decades. What never existed, until these tools did, was a way for a people without territory to make itself verifiable enough to claim it: to prove unique personhood, to anchor a founding text beyond tampering, to run one-person-one-vote governance that capital cannot buy. The technology did not create the right; it made the right reachable. The architecture is testable, forkable, and if communities could take the whole thing and continue it without me, that is a feature. So the response I am actually after is the adversarial one: where does an architecture like this break first?

So: protect the individual, or constitute a subject. Two bets, both worth testing, and the tension between them is productive rather than hostile. The anthology makes the first case about as well as it can be made. I am trying to make the second one real - and "real" here is specific: a founding text, verification, and one-person-one-vote governance you can inspect today, not a proposal for later.