aboutsummaryrefslogtreecommitdiffstats
path: root/docs/meshbay-draft-v5.md
diff options
context:
space:
mode:
Diffstat (limited to 'docs/meshbay-draft-v5.md')
-rw-r--r--docs/meshbay-draft-v5.md3
1 files changed, 2 insertions, 1 deletions
diff --git a/docs/meshbay-draft-v5.md b/docs/meshbay-draft-v5.md
index 68f6843..a8b7e4b 100644
--- a/docs/meshbay-draft-v5.md
+++ b/docs/meshbay-draft-v5.md
@@ -358,7 +358,8 @@ password hash cleared, node linking key dropped, memberships, notifications and
tokens removed, active access tokens refused at once by status check rather than left to
expire. Two things survive on purpose. The IP log is kept for its legal retention period
and stays attributable, since detaching it would keep the data and lose the only thing it
-is for. And **nothing on a node is touched**: files, the pinned identity and the keypair
+is for — the name is copied onto those rows as the account goes, since the join that used
+to supply it would answer with the tombstone. And **nothing on a node is touched**: files, the pinned identity and the keypair
bundle live on machines the hub does not command, which is the same sovereignty that makes
§5.5 work. Deleting the hub account is not an erasure request to the operators who host
you — the operator interface (§5.3) is where that happens. Deletion is refused outright