ADOFAI SEE THROUGH PUBLISHER SAFETY AND PRIVACY DECLARATION Release: 0.14.2 Issued: 2026-08-13 Official site: https://adofai.exterverz.com 1. STATUS OF THIS DECLARATION This is a signed, version-specific statement by the ADOFAI See Through Project. It records the intended behavior of the official 0.14.2 release and the checks performed before publication. It is not an antivirus certificate, insurance policy, or promise that any software can be proven 100 percent risk-free. To the best of the project's knowledge after source review, package inspection, and platform installation tests, the official files matching the published SHA-256 hashes contain no malware or intentionally harmful behavior. 2. PUBLISHER COMMITMENTS The official release is intended only to install and run the ADOFAI See Through multiplayer mod. It does not intentionally include or perform any of the following: - credential theft, keylogging, clipboard capture, or browser-data collection; - camera, microphone, contacts, documents, or photo-library access; - cryptocurrency mining, advertising, tracking, or analytics telemetry; - installation of drivers, services, scheduled tasks, login items, or other operating-system persistence; - arbitrary command execution received from another player; - downloading and executing third-party programs; - bundled applications, browser extensions, or unrelated software; - sale or upload of personal files or saved-game files. 3. EXACT INSTALLER BEHAVIOR Both installers first confirm that A Dance of Fire and Ice is closed, that the selected folder is a Steam ADOFAI installation, that Unity Mod Manager exists, and that every packaged payload file matches its embedded SHA-256 manifest. The macOS installer: - checks common Steam library locations or asks the user to choose the game; - verifies the installer app signature and its payload hashes; - moves an existing RealtimeHub mod into "ADOFAI Seethrough Backups"; - copies only the declared mod payload into Mods/RealtimeHub; - restores the prior mod if copying fails; - does not request administrator access or change Gatekeeper quarantine data. The Windows installer: - reads Steam's documented registry/library locations or asks the user to choose the game folder; - verifies all payload hashes before copying; - moves an existing RealtimeHub mod into "ADOFAI Seethrough Backups"; - copies only the declared mod payload into Mods/RealtimeHub; - enables RealtimeHub in Unity Mod Manager's Params.xml and changes the Unity Mod Manager hotkey from None to F10 only when no hotkey is configured; - requests administrator access only if Windows denies access to a protected Steam installation folder; - restores the prior mod if copying fails. 4. RUNTIME NETWORK AND PRIVACY BEHAVIOR Online rooms use Steamworks lobbies and Steam peer-to-peer networking, including Steam relay services when Steam selects a relay. While a player is in a room, room members receive the information required to display multiplayer play: - Steam identity and the player name chosen in the mod; - current ADOFAI location or built-in level identifier; - ball position, rotation, direction, colors, trails, particles, and skin state; - room options, match state, scores, deaths, tag state, and host actions. The mod has no project-operated analytics service or player database. A saved display name is stored locally in ADOFAI's PlayerPrefs only when "remember name" is selected. Unity Mod Manager may contact the official site to check for mod updates. Local multiplayer testing binds only to the local computer. Public release binaries contain no screenshot-capture or autoplay-test code; the developer-only automated test harness is excluded when releases are compiled. Room passwords are convenience access codes, not account-security passwords. A hash is placed in Steam lobby metadata so the normal client can check entry. Do not reuse an email, Steam, banking, device, or other personal password. 5. RELEASE CHECKS COMPLETED - Manual review of installer filesystem, registry, process, and network actions. - Manual review of runtime filesystem, command-execution, and network surfaces. - Oversized or malformed multiplayer packets are rejected without file or command execution, non-room Steam senders are ignored, and only a room host can publish authoritative tag state. - Windows installer executed silently under Wine against a clean Steam-style test installation; backup, payload verification, Unity Mod Manager activation, Win64 dependency, and loader checks passed. - macOS installer executed against a clean test installation; signature, payload verification, backup, installation, and rollback layout checks passed. - Release ZIPs were checked for unexpected executables, source files, debug symbols, obfuscation maps, and private signing keys. - Download ZIPs and update ZIPs are covered by published SHA-256 hashes and an Ed25519 signature. 6. INDEPENDENT VERIFICATION AND LIMITATIONS Only files whose SHA-256 values match the signed SHA256SUMS.txt at the official site are official 0.14.2 files. The release-signing public-key fingerprint is: 5e8d9615713f8d50207f36e88afce072734d8ce6f7ebf6ea9b7fea3e0ff6de14 The Windows installer has project strong-name integrity metadata, but it is not signed with a Microsoft-trusted Authenticode publisher certificate. The macOS installer has package-integrity signing, but it is not Apple-notarized with a paid Developer ID. Windows SmartScreen or macOS Gatekeeper may therefore show an unknown-developer warning. Such a warning is not proof of malware, but users should still verify the published hash and may scan the ZIP with their own up-to-date security software before opening it. The distributed runtime is obfuscated to protect implementation details. That reduces source theft but also prevents independent reviewers from rebuilding the binary from public source. Cryptographic signatures prove which project release was downloaded; they do not prove that software is harmless. No honest software publisher can guarantee zero risk on every computer or against every future security discovery. 7. AUTHENTICITY Official releases and verification files are distributed only through: https://adofai.exterverz.com This declaration is signed with the project's Ed25519 release key. Verify it with SAFETY-AND-PRIVACY.txt.sig and ADOFAI-Seethrough-release-public.pem from the official site. SHA256SUMS.txt is signed by the same key. Copyright (c) 2026 ADOFAI See Through Project. All rights reserved.