WHY YOU CAN TRUST THIS
Trust isn't a promise here — it's the architecture
We'd rather show you the machine than ask for your faith. Here's exactly how we protect the person who needs help, the person who gives, and the money in between.
The person is never exposed
Identity and address open only to the one person fulfilling a specific good, only with consent, only for a limited time — then they close. For anyone under 18, they never open at all.
No cash ever reaches a person
Every contribution becomes an in-kind outcome: a product, a paid bill, a ticket, a service. Payment always goes to the seller or provider.
The lanes never mix
Support for operations, the emergency fund, and in-kind goodness are held separately. Cross-flow is blocked at the database level, not just in policy.
The ledger isn't hidden
A public transparency dashboard shows money by lane. When we miss a promised timeline, that shows too.
VERIFIED, NOT INTERROGATED
How we verify a person in need
Real trust means the shelf isn't drained by fraud and the person in genuine need isn't turned away. We verify in graduated tiers — asking for as little as possible at the start, and more only as value or sensitivity rises. No one is asked to prove their poverty to strangers.
| Tier | When | What we check | What we don't do |
|---|---|---|---|
| T1 — Light | Small in-kind goods (a meal, bread) | Phone verification, one-time code, device signals | No documents, no address, no public story |
| T2 — Standard | Baskets, school sets, higher value | T1 + basic identity check (liveness + ID match, stored sealed) | ID is never shown to any giver or business |
| T3 — Bridged | Recurring help, cash-adjacent risk (bills) | T2 + referral from a social worker, school, or municipality | We don't leave chronic need to a bandage — we route to real services |
| T4 — Emergency | Disconnection notice, hospital, stranded | Document / e-invoice verification (masked) + provider confirmation | Payment goes to the provider, never the person |
Invisible cross-signal
Device fingerprint, repeated account/IBAN patterns, and address clustering feed a risk score that only flags for human review. Software never auto-rejects a person — a human always decides.
Proxy profiles
A member can suggest help for a neighbor who won't sign up — but the profile never activates without that person's own one-time consent, and the suggesting member carries responsibility for it.
NO OVERPROMISING
What's live, and what's on the way
Live now
- ✓Private request → operator queue
- ✓Manual suspension by businesses; in-store customer suspension
- ✓Map with public-safe availability (coarse, no private locations)
- ✓Separated finance lanes with database-enforced isolation
- ✓Public transparency dashboard (sample/pilot labeled honestly)
- ✓Stripe subscriptions in test → live after end-to-end proof
On the roadmap
- ○Automated Shopify / WooCommerce / POS / ERP adapters (manual listing available first)
- ○Full interactive partner map with Google Maps (coarse partner view first)
- ○“Goodness Guide” assistant (static guided UX first; AI only behind policy + redaction)
- ○Independent annual audit (planned; we won't claim an audit until one is signed)
See the numbers for yourself
Every euro's lane is public. That's not a slogan — it's a database constraint you can inspect.
Open the transparency dashboard