Version 1.0 · September 2026
Status: Draft for review
keton.ir site
Persian version
Ketonia ($KTN) — Tokenomics Litepaper
A Data-Backed DeSci Economy for Longitudinal Metabolic Health
This document supersedes the loyalty-oriented model and defines the transition path from the
Bale pilot points economy to a data-asset-backed token economy.
1. Executive Summary
Ketonia operates a functional-medicine platform for reversing metabolic disease (primarily Type 2
Diabetes) through lifestyle intervention. Its decisive, non-replicable asset is not its brand, its
community, or its token — it is a structured, longitudinal clinical database:
1,700+ complete clinical records of fully tracked patients (1,701 as of September 2026, growing daily)
spanning multi-year metabolic trajectories (HbA1c series, medication tapering histories, fasting
protocols, anthropometrics, lab panels).
Longitudinal outcome data of this kind is among the scarcest inputs in metabolic research, Health-AI
model training, and payer-side risk modeling. Cross-sectional datasets are commoditized;
multi-year per-patient trajectories with documented intervention outcomes are not.
$KTN is the access and settlement token for this data economy:
- Demand side: pharmaceutical companies, longevity researchers, Health-AI developers, insurers, and DeSci DAOs must acquire, lock, or burn $KTN to license anonymized cohorts, query the data layer, or train/validate models against it.
- Supply side: patients mint $KTN through Data-to-Earn — informed consent to share anonymized longitudinal records, and verifiable clinical milestones (documented HbA1c reduction, insulin reduction/discontinuation). Minting for raw activity is deprecated.
- Trust layer: zero-knowledge proofs and a consent registry allow clinical outcomes and data quality to be proven without revealing patient identity, supporting GDPR-grade compliance posture from day one.
- Two layers: a non-transferable Soulbound reputation layer (health credentials, governance weight, data-access tiers) and the liquid $KTN token (settlement, staking, governance).
The design is deliberately non-gamified. Rewards are tied to durable clinical value, not engagement
frequency — consistent with Ketonia’s serotoninergic (long-term well-being) philosophy and its
35–65 adult audience. The architecture is modular: verified device data (CGM, smartwatches) plugs in
later as a higher-quality oracle tier, never as the core engine.
2. Strategic Pivot: From Loyalty Points to Data Infrastructure
2.1 What is being retired
The previous model (Ketonia Points on Bale) was a closed-loop loyalty system: points for daily check-ins, glucose logging, and challenge completion, redeemable for consultation discounts. Its structural limits:
| Limitation | Consequence |
| No external demand | Points had value only because the platform subsidized discounts; no market clearing price |
| Action-to-Earn minting | Paid for frequency of behavior, which correlates weakly with data value; inflationary and farmable |
| Closed loop | No path for the world’s most interested buyers (pharma, AI labs, DAOs, payers) to participate |
| Dopamine mechanics | Daily-streak rewards conflict with Ketonia’s stated philosophy and its adult clinical audience |
2.2 What replaces it
A data-asset-backed token economy. The clinical database is treated as the reserve asset; $KTN is the instrument through which access to that reserve is priced, paid for, and governed.
Patient1,700+ longitudinal records
→
Informed consentanonymized record
→
Data reservecohorts · trajectories · outcomes
→
Institutional accessbuy / lock / burn $KTN
→
Revenue sharebuyback-burn + data dividend
- Supply is capped by biology and time. No competitor can retroactively create five-year metabolic trajectories. New entrants must recruit patients and wait years; Ketonia already holds the asset.
- Demand is non-discretionary. A Health-AI developer training a hypoglycemia-prediction model, or a DAO funding an RCT on fasting protocols, needs real outcome data. There is no synthetic substitute that passes clinical review.
- The token is the toll. All institutional access routes through $KTN acquisition, staking, or burn — creating structural, recurring demand proportional to the commercial value of the data.
2.3 Continuity with Ketonia philosophy
The pivot changes the economic engine, not the values. The 4P framework (Preservation, Cultivation, Connection, Inquiry) maps cleanly onto the data economy: Preservation becomes longitudinal data continuity; Inquiry becomes research access and validation; Connection becomes the consent-based data cooperative. Rewards remain sized to avoid crowding out intrinsic motivation — patients are compensated as data producers and research participants, a dignified framing, not a gamified one.
3. System Architecture Overview
Three layers, strictly separated:
| Layer | Instrument | Transferability | Function |
| Economic | $KTN (ERC-20) | Liquid | Settlement for data licenses, staking for query rights, burn sinks, governance voting |
| Reputation | Ketonia Soulbound Tokens (KSBT, ERC-5192) | Non-transferable | Clinical credentials, milestone attestations, data-quality score, governance weight multiplier, access tiers |
| Data & Trust | Consent Registry + ZK Attestation Layer + Data Vault | Not tokenized | The clinical reserve itself: W3C Verifiable Credentials, zk-SNARK proofs of eligibility/outcomes, differential-private query engine |
Data & Trust LayerClinical Data Vault (off-chain, encrypted) · Consent Registry (on-chain, revocable) · ZK Attestation Layer (milestone · eligibility · quality)
Reputation LayerKSBT Soulbound — credentials · tiers · governance weight
Economic Layer$KTN token — licenses · staking · burns · votes
Key separation principle: raw clinical data never touches the blockchain. Only hashes,
commitments, proofs, and consent state are on-chain. The Data Vault is a permissioned, encrypted store;
all external access passes through a query/attestation engine that enforces k-anonymity, differential
privacy budgets, and consent scope. This mirrors the standard DeSci pattern (cf. VitaDAO’s IP-NFT
abstraction) while respecting the far stricter sensitivity class of health data.
4. Demand Side: Institutional Access Economics
This is the core of the redesign. Demand mechanisms are non-negotiable: there is no institutional access path that does not require holding, locking, or burning $KTN.
4.1 The Data Access Marketplace
Four product tiers, all priced and settled in $KTN:
T1 — Cohort Licenses
Time-boxed license to a defined anonymized cohort (e.g. “T2D, HbA1c ≥ 8 at baseline, ≥ 24 months tracked, insulin taper documented”).
Buyers: pharma, CROs, longevity institutes.
Settlement: fee in $KTN; 60% burned, 40% to Data Dividend Pool.
T2 — Query Rights (Staked)
Right to submit aggregate/statistical queries via the differentially private query engine.
Buyers: Health-AI devs, academia, DAOs.
Settlement: stake $KTN; query fees from stake yield; 90-day unstake cooldown.
T3 — Model Validation
Benchmark a trained model against held-out Ketonia outcome data (predictive-validity certification).
Buyers: Health-AI companies, digital-health vendors.
Settlement: fee 100% burned; passing models may carry a “Validated on Ketonia Data” attestation.
T4 — Priority Research Access
Queue priority for prospective collection: custom surveys, targeted panels, consented follow-up studies.
Buyers: DeSci DAOs (VitaDAO-style), sponsored RCTs.
Settlement: lock $KTN ≥ 12 months; locked tokens non-circulating.
- Cohort definitions are parameterized by an on-chain Data Product Registry; each registered product has a scope, consent-coverage check, and a $KTN price band set by governance.
- T2 staking creates a persistent demand floor: query rights scale with stake size, so serious buyers keep capital locked rather than transacting once.
- T4 locking converts research urgency into time-locked demand — the mechanism institutional DeSci allocators already understand from VitaDAO/AthenaDAO-style grant staking.
4.2 API & Data Oracle Access
For Health-AI developers, the Data Vault exposes a metered API: aggregate endpoints (cohort statistics, outcome distributions) and, under stricter tiers, feature-level access for model training. API subscriptions are denominated in $KTN, purchased on a rolling basis. A future path — Ketonia as a verified metabolic-data oracle for other protocols (insurtech DAOs, underwriting models) — uses the same staked-access contract, with oracle fees settled in $KTN.
4.3 Token Sinks (structural, not discretionary)
| Sink | Mechanism | Character |
| License burn | 60% of every T1 cohort license fee | Permanent supply reduction |
| Validation burn | 100% of T3 model-validation fees | Permanent |
| Query-fee burn | 20% of T2 query fees; remainder to Data Dividend Pool | Permanent |
| Buyback & burn | 30% of all platform fiat revenue buys back and burns $KTN quarterly | Permanent, revenue-linked |
| Institutional locks | T4 priority-access locks (12–36 months) | Circulating supply reduction |
| Governance deposit | Data-commercialization proposals require a refundable-but-slashed-on-bad-faith $KTN deposit | Friction sink |
The burn share of B2B revenue is a governance parameter with a hard floor of 40% (of the token-denominated B2B revenue pool) — it cannot be voted below this, ensuring deflationary pressure is structural rather than political.
4.4 Utility summary (beyond any internal discount)
- Data licensing settlement — the only accepted payment for cohort access.
- Staking for query rights — stake size meters API/query throughput.
- Locking for priority research access — time-locked capital buys queue position for prospective studies.
- Governance — staked $KTN (weighted by Soulbound reputation) votes on price bands, consent-scope templates, burn/lock ratios, new data-product registrations, and Data Treasury grants.
- Collateral for research grants — DAOs can post $KTN as milestone-based escrow for funded studies on Ketonia cohorts.
Internal patient-facing discounts (the old points use case) are explicitly removed from the token’s utility set. Patients receive value via the Data Dividend Pool and milestone minting (§4.5, §5), not via subsidized consultations — keeping the demand side institutional and the supply side clinical.
4.5 Data Dividend Pool (patient revenue share)
40% of T1 license fees and 20% of T2 query fees flow to a Data Dividend Pool, distributed pro-rata to patients whose consented data was actually used in the licensed cohort/query, weighted by their Data Quality Score (§6.3). This is not a mint — it is revenue sharing. It creates a direct, legible link for patients between consenting to data use and receiving income — the honest framing of a data cooperative and a significant consent-rate driver.
5. Supply Side: Data-to-Earn Minting
5.1 Primary minting paths
Minting is reserved for events that create or certify data value:
M1 — Consent Grant
Patient signs informed, revocable consent to include their anonymized longitudinal record in the Data Reserve.
Verify: Consent Registry transaction + ZK proof of record completeness.
Reward*: one-time 500–2,000 $KTN, scaled by record depth.
M2 — Clinical Milestone
Documented, expert-verified outcome: HbA1c reduction ≥ 1.0 sustained 6 months; insulin dose −50%; full discontinuation; durable remission (HbA1c < 6.5 off meds ≥ 12 months).
Verify: clinical oracle signs a ZK attestation; labs stay off-chain.
Reward*: 1,000–10,000 $KTN by class; once per patient per severity level.
M3 — Longitudinal Continuity
Sustained high-quality contribution without a milestone (e.g. 12 consecutive months of structured logs meeting quality thresholds).
Verify: automated quality filters + periodic expert audit sample.
Reward*: 50–150 $KTN per qualified quarter; hard annual cap; diminishing marginal reward.
* All figures are initial parameters subject to governance calibration and the emission schedule (§8.2). Rewards are modified by the patient’s Soulbound tier multiplier (×1.0 – ×2.0).
M2 is the flagship: a verified diabetes-reversal event is exactly the outcome datum that pharma outcome studies, payers, and DeSci DAOs pay for. The milestone mint is Ketonia purchasing its own most valuable inventory with newly issued token, funded by the community treasury emission (§8).
5.2 What is explicitly NOT minted
- Daily check-ins, streaks, log frequency, likes, invites, or any engagement metric.
- Content production or promotion. Knowledge contributions migrate to Soulbound reputation and Data Treasury grants, not token issuance — this removes the farming surface entirely.
- Device-data volume (steps, sleep scores). Device integration (§12) upgrades data quality scores and oracle tier, not raw mints, until governance approves device-verified milestone equivalence.
5.3 Emission control on the mint side
- Per-category weekly emission caps (M1/M2/M3 capped independently) — prevents supply shock from consent drives or onboarding campaigns.
- Diminishing marginal rewards within categories.
- M3 sunset clause: the continuity path decays 20% per year from TGE+3 unless governance renews it with evidence. It exists to bootstrap early supply, not to run forever.
- Individual lifetime caps on M3; no caps on M2 (genuine clinical milestones are self-limiting and maximally valuable).
5.4 Anti-sybil and clinical integrity
Health data has a natural sybil defense that open networks lack — you cannot fake a five-year HbA1c trajectory past clinical review:
- Clinical identity anchoring: mint eligibility requires a Ketonia medical record verified by licensed staff. Wallet↔patient binding is one-to-one, mediated by the clinic, privacy-preserving (only a commitment on-chain).
- Soulbound tiering: governance weight and mint multipliers attach to non-transferable KSBTs; bought accounts inherit nothing.
- Expert-oracle + slashing: clinical attestations are signed by credentialed experts; a falsified attestation slashes the expert’s stake and reputation and voids derived mints.
- Statistical anomaly detection: cohort-level outlier screening on incoming records before acceptance into the Data Reserve.
- Proof-of-personhood fallback: for future open cohorts, permissioned KYC or government-ID ZK attestation is a prerequisite — no anonymous minting path exists at any tier.
6. Privacy & Trust Infrastructure
6.1 Threat model
The asset is medical data of identifiable patients in a jurisdiction-sensitive context. A single de-anonymization event is an existential risk to both patients and the platform. Privacy is therefore load-bearing architecture, not a feature.
6.2 Stack
| Component | Technology | Purpose |
| Consent Registry | On-chain registry of scoped, revocable consent records (W3C VC + EIP-712) | Per-purpose, per-buyer-class, time-boxed consent. Revocation propagates to the Vault and voids future use; already-sold aggregates are contractually irreversible (disclosed in consent text) |
| ZK Attestation Layer | zk-SNARK circuits over Merkle-committed records | Proves “HbA1c fell ≥ 1.0 over 6 months”, “patient belongs to cohort X”, “record passes quality thresholds” without revealing the record, values, or patient |
| Data Vault | Off-chain encrypted store, enclave-isolated query engine | Holds raw records. External parties never receive row-level data at T1/T2; only DP aggregates or licensed extract under audit |
| Differential Privacy Engine | Privacy budget (ε) accounting per buyer, per query | Outputs cannot be reverse-engineered to individuals; k-anonymity floors on every cohort product (k ≥ 50) |
| Soulbound Credentials | ERC-5192 | Milestone attestations issued as private credentials; the fact of the credential is provable via ZK without exposing clinical detail |
6.3 Data Quality Score (DQS)
Every consented record carries an off-chain DQS (completeness, longitudinal span, verification depth, device-oracle backing once available). DQS determines mint scaling (§5.1), Data Dividend weight (§4.5), and cohort inclusion priority. DQS is reputation, held in the Soulbound layer — never tradeable.
6.4 Compliance posture
- Architecture is designed for GDPR-compatible operation: lawful basis = explicit consent (Art. 9(2)(a)), purpose limitation via consent scopes, erasure via vault-level deletion with on-chain revocation witness, data-minimization via ZK/DP outputs.
- Consent text and registry semantics satisfy HIPAA de-identification standards (Safe Harbor + expert determination) for US-facing products.
- A standing Data Ethics Council (medical/ethics members, distinct from token governance) holds veto power over any data product registration — commercialization can never outvote patient protection.
7. Points-to-Token Transition (Bale Pilot Migration)
The existing Ketonia Points balances from the Bale pilot must convert fairly, transparently, and once.
7.1 Principles
- Honor earned value: pilot participants earned points under published rules; those balances are a liability Ketonia honors.
- Reprice, don’t invalidate: points were earned under Action-to-Earn logic; $KTN mints under Data-to-Earn logic. Conversion applies a transition exchange rate reflecting the different value basis — not 1:1, published in advance.
- No speculative windfall: conversion is vesting-gated so migration cannot be dumped at TGE.
- Reputation carries over fully: pilot ranks, challenge completions, and milestone history map 1:1 to Soulbound credentials and tier multipliers. Reputation migration is generous precisely because token migration is gated.
7.2 Mechanism
- Conversion window: a fixed 12-month window from TGE. Points convert at a governance-published rate (indicative: 100 points → 1 $KTN), calibrated so total pilot conversion draws only from the dedicated 6% Retroactive Allocation (§8.1) and cannot dilute other pools.
- Vesting: converted $KTN vests linearly over 12 months with a 3-month cliff. The same lock logic applies to team and investors.
- Milestone true-up: pilot users with verified clinical milestones receive an additional one-time M2-equivalent mint on migration — recognizing their real contribution was data, not check-ins. This is the single most important fairness lever.
- Soulbound migration: pilot rank history, forum publication record, empathy-circle participation, and peer-validation reputation convert to KSBT tier credits.
- Burned points honored: points already spent in the pilot are not re-converted; their historical purchases are respected as closed transactions.
- One-way, final: after the window, unconverted points lapse. The points ledger is snapshotted publicly (hashed balances) before TGE for auditability.
7.3 Communication frame
For the 35–65 clinical audience, the migration is framed as: “Your health progress and your data now own a share of what they produce.” No airdrop hype, no countdown timers — a plain statement of entitlement, rate, and vesting, delivered through the Bale group and forum.
8. Token Distribution, Governance & Sustainability
8.1 Supply and allocation
Total supply: 1,000,000,000 $KTN (fixed at genesis; all issuance beyond allocation comes only from the emission schedule below, capped within the Community/Data Treasury line).
Community & Data Treasury34%
DeSci Research Pool14%
Core Team12%
Ecosystem & Partnerships10%
Clinical Expert Pool8%
Liquidity8%
Strategic Reserve (DAO)8%
Patient Retroactive & Migration6%
| Allocation | Share | Tokens | Vesting / Release |
| Community & Data Treasury | 34% | 340M | Emitted over ~15 years per §8.2; funds all minting paths (M1–M3) and data-infrastructure grants |
| DeSci Research Pool | 14% | 140M | 4-year vesting; DAO-governed grants for external research on Ketonia cohorts, co-funding with partner DAOs; milestone-escrowed |
| Patient Retroactive & Migration | 6% | 60M | Points conversion (§7.2) + milestone true-ups; vests with migration schedule |
| Core Team | 12% | 120M | 4-year vesting, 1-year cliff |
| Clinical Expert Pool | 8% | 80M | 3-year vesting; physicians, nutritionists, exercise specialists as verification oracles; stake-and-slashing |
| Liquidity | 8% | 80M | DEX/CEX provisioning; market-making under governance-supervised mandate |
| Ecosystem & Partnerships | 10% | 100M | 4-year vesting; data-buyer onboarding, oracle integrations, compliance/legal, audits |
| Strategic Reserve (DAO-governed) | 8% | 80M | Locked 2 years minimum; deployed only by supermajority governance vote |
Combined community-facing lines (Treasury + Research + Migration) total 54% — the data producers and their research ecosystem hold the majority of the token, the structural claim that makes this a cooperative rather than an extraction platform.
8.2 Emission schedule and supply control
- The Community & Data Treasury emits on a decaying schedule: 8% annual decay of the prior year’s emission rate (smooth halving-equivalent; ~50% reduction every 8.3 years).
- Emission is category-capped (§5.3): weekly ceilings per minting path, enforced at contract level.
- Hard supply ceiling: cumulative issuance can never exceed the Treasury allocation; there is no inflation mechanism, ever. Net supply is designed to be deflationary from year ~4.
- Burned tokens go to a provably dead address; quarterly Proof-of-Burn reports publish burn totals against B2B revenue.
8.3 Velocity management
- Slowed by: T2 staking (90-day cooldown), T4 locks (12–36 months), team/investor/pool vesting, Data Dividend distributions with optional auto-restake.
- Sustained by: rolling API subscriptions, quarterly buyback-burn, grant escrows releasing on research milestones.
- The dominant holder class by design is locked or staked institutional capital + vesting-aligned patients — a low-velocity, high-conviction base.
8.4 Governance
- Vote weight = staked $KTN × Soulbound reputation multiplier (capped ×3). Quadratic voting applies to Treasury allocation votes to dampen plutocracy.
- Governance scope: data-product registration and price bands, burn/lock tuning (above hard floors), emission category caps, Research Pool grants, Ecosystem spend.
- Out of governance scope (Ethics Council veto): consent-scope weakening, k-anonymity/DP relaxation, any product involving identifiable data, re-identification research — constitutional constraints.
- Proposal process: all proposals pass a public challenge/review period on the Ketonia forum before on-chain vote — preserving the existing “challenge room” culture as a deliberation layer.
8.5 Legal & jurisdictional note
Given the patient base’s jurisdiction and the international DeSci buyer profile, the token and
data-licensing entity should be structurally separated: a data-services entity (vault,
licenses, compliance) and a token-issuing foundation in a crypto-friendly jurisdiction, connected by the
buyback-burn and dividend contracts. $KTN is documented as a utility/access token with no
profit promise, no yield product, and no fractional claim on the company. Counsel review is a pre-TGE gate;
sanctions exposure and cross-border health-data transfer are explicit roadmap workstreams.
9. Dual-Layer System: $KTN + Soulbound (KSBT)
| Property | $KTN | KSBT (Soulbound) |
| Standard | ERC-20 | ERC-5192 (non-transferable) |
| Supply | Fixed genesis + capped emission | Issued per credential event |
| Role | Settlement, staking, burns, voting power base | Credentials, tier multiplier, governance weight, access gating |
| Tradeable | Yes | Never |
| Examples | — | “Documented T2D Remission”, “5-Year Longitudinal Contributor”, Clinical Expert credential, pilot-rank migration credit, DQS tier |
Access tiers (buyer-facing and patient-facing, both KSBT-gated):
- Patients:
Contributor → Verified Contributor → Senior Contributor → Remission Alumni — tier raises mint multiplier, dividend weight, and governance multiplier. Tier decays slowly (2%/month) without continued data contribution.
- Institutions:
Registered → Staked (T2) → Licensed (T1) → Partner (T4-locked) — each tier requires progressively larger locked $KTN and deeper compliance review.
Milestone badges as NFTs: kept deliberately minimal — one Soulbound credential class per verified clinical milestone, optionally rendered as a commemorative badge. Badges confer reputation and rights; never tradeable, never speculative.
10. Key Flows
10.1 Patient consent → mint → dividend
Patient1. sign scoped consent (W3C VC)
→
Consent Registry2. commitment recorded
→
Data Vault3. anonymized, DQS scored
→
Mint Contract4. M1/M2/M3 mint, caps enforced
→
Revenue split60% burn · 40% dividend (DQS-weighted)
Revoking consent propagates from the Registry to the Vault and voids future use.
10.2 Institutional access (T1/T2)
Institutionacquire $KTN (market / OTC)
→
Stake or pay feeT1 fee → 60% burn + 40% dividend · T2 stake, 90d cooldown
→
Data Vault / DP Query Enginelicensed extract under audit · DP aggregates (ε-budgeted)
→
T3 Validationbenchmark vs held-out outcomes; fee 100% burned
10.3 Milestone verification (ZK)
Clinical staff verify labs off-chain → sign attestation → circuit proves “HbA1c(t₀) − HbA1c(t₀+6mo) ≥ 1.0 ∧ record authentic ∧ consent active” against the Merkle-committed record → Mint Contract issues M2 reward + Soulbound “HbA1c Reduction” credential. No lab value, diagnosis, or identity appears on-chain at any step.
11. DeSci Investor Positioning (VitaDAO-class thesis)
The pitch to serious DeSci capital, stated without hype:
- Asset-backed, not narrative-backed. Token demand derives from licensing revenue on an existing 1,700+-record longitudinal reserve — inventory is on hand at TGE, unlike most DeSci protocols promising future data collection.
- Outcome data, the highest-value class. Documented intervention→outcome trajectories (fasting/ketogenic protocols → HbA1c, insulin dose) serve three concurrent buyer markets: metabolic pharma RWE, Health-AI training/validation, and longevity research — with payer/insurtech as a fourth.
- Structural sinks with hard floors. ≥ 40% of B2B token revenue is burned by constitutional rule; staking and T4 locks remove further float. Deflation is mechanical, not promotional.
- Cooperative legitimacy. 54% of supply to community/research lines, consent-registry-gated data use, and an Ethics Council veto give the protocol the social license that institutional buyers and DAOs increasingly require for health data.
- Compatible with existing DeSci rails. Research Pool grants and T4 priority access are designed for co-funding structures and IP-NFT-style abstraction familiar to VitaDAO, AthenaDAO, and DeSci Nodes; joint cohort studies can be escrowed milestone-wise in $KTN.
12. Modularity & Future Extensibility
Clean hooks, explicitly non-core:
- Device Data Oracles (CGM, smartwatches, health apps): a pluggable Oracle Adapter interface — any verified device feed maps into the DQS pipeline as a higher-assurance source. Device backing raises DQS, cohort eligibility, and (once governance approves equivalence studies) can co-sign milestone attestations. Move-to-Earn and raw device metrics are permanently excluded from minting by §5.2; devices improve proof quality, never activity rewards.
- Prospective data collection: T4 priority access already provides the commercial hook for sponsored prospective studies without new token design.
- Milestone NFTs/badges: the Soulbound credential class is extensible; new badge types are governance-registered metadata over the same ERC-5192 infrastructure.
- Cross-protocol oracle role: the staked-access contract (§4.2) generalizes to selling verified aggregate signals to other protocols — same staking, burn, and privacy envelope.
- L2/chain migration: token is standard ERC-20; vault, registry, and proof layer are chain-agnostic, permitting relocation to a lower-cost L2 as query volume grows.
13. Roadmap
| Phase | Window | Deliverables |
| 0 — Foundation | Months 0–6 | Legal structuring (issuing foundation + data entity); consent registry v1 + W3C VC schema; DQS spec; pilot points snapshot; migration rate & terms published; Data Ethics Council seated |
| 1 — Migration & TGE | Months 6–12 | Points→$KTN conversion window opens; Soulbound migration; treasury emission contracts live; M1/M2 minting active for consenting patients; liquidity provisioning |
| 2 — Marketplace | Year 1–2 | Data Product Registry + first T1 cohort products; T2 staked query engine with DP budgeting; ZK milestone circuits in production; first buyback-burn quarter; T3 validation service |
| 3 — Institutional scale | Year 2–4 | T4 lock-based priority access; first DAO co-funded studies (Research Pool grants); device-oracle adapter pilots (CGM); governance handover of parameter tuning; Proof-of-Burn quarterly cadence |
KPIs the token design is judged by (not price): consent rate among eligible patients (%), longitudinal retention (months tracked per consenting patient), B2B licensing revenue ($KTN-denominated), burn-to-emission ratio, cohort product count, and verified milestone count per quarter.
14. Risks & Mitigations
| Risk | Class | Mitigation |
| Re-identification of cohort members | Existential | DP engine with ε budgeting, k ≥ 50 floors, aggregate-only T2 outputs, T1 extracts under audit + contractual use limits, Ethics Council veto |
| Regulatory (health data + token, multi-jurisdiction) | High | Entity separation (§8.5), utility-token documentation, counsel gate pre-TGE, GDPR/HIPAA-aligned architecture from day one |
| Weak early B2B demand → burn underperforms | High | TGE inventory already exists (no data-collection lag); Research Pool co-funds first studies; emission floor keeps patient incentives funded at low revenue |
| Patient distrust of “selling data” | High | Consent-first framing, revocability, transparent dividend attribution, Ethics Council with veto, no identifiable products ever; migration honors pilot balances |
| Mint farming via fake records | Medium | Clinical-oracle verification, expert staking + slashing, statistical anomaly screening, one-to-one wallet binding (§5.4) |
| Token speculation distorting access pricing | Medium | Governance-set price bands in $KTN with fiat-reference adjustment; T4 locks favor long-horizon research buyers |
| Key-person / oracle centralization (clinic staff) | Medium | Multi-sig expert panels for attestations, Expert Pool stake economics, progressive decentralization to partner clinics |
| Emission outpaces burn longer than modeled | Low–Med | 8%/yr decay, category caps, hard ceiling; governance may tighten caps (floor-protected burn share cannot weaken) |
15. Design Principles (recap)
- The database is the reserve; the token is the toll. Every mechanism prices access to a real, existing, non-replicable asset.
- Data-to-Earn, never Action-to-Earn. Mints attach to consent and verified clinical outcomes — not engagement.
- Privacy is load-bearing. ZK + DP + consent registry are prerequisites, not roadmap items.
- Deflation by construction. Burn floors, staking, locks, and decay make supply reduction mechanical.
- Serotoninergic economics. Durable rewards, reputation over speculation, governance that cannot outvote patient protection — the token behaves like the medicine Ketonia practices.