Version 1.0 · September 2026 Status: Draft for review keton.ir site Persian version

Ketonia ($KTN) — Tokenomics Litepaper

A Data-Backed DeSci Economy for Longitudinal Metabolic Health

This document supersedes the loyalty-oriented model and defines the transition path from the Bale pilot points economy to a data-asset-backed token economy.

Contents

1. Executive Summary

Ketonia operates a functional-medicine platform for reversing metabolic disease (primarily Type 2 Diabetes) through lifestyle intervention. Its decisive, non-replicable asset is not its brand, its community, or its token — it is a structured, longitudinal clinical database: 1,700+ complete clinical records of fully tracked patients (1,701 as of September 2026, growing daily) spanning multi-year metabolic trajectories (HbA1c series, medication tapering histories, fasting protocols, anthropometrics, lab panels).

Longitudinal outcome data of this kind is among the scarcest inputs in metabolic research, Health-AI model training, and payer-side risk modeling. Cross-sectional datasets are commoditized; multi-year per-patient trajectories with documented intervention outcomes are not.

$KTN is the access and settlement token for this data economy:

The design is deliberately non-gamified. Rewards are tied to durable clinical value, not engagement frequency — consistent with Ketonia’s serotoninergic (long-term well-being) philosophy and its 35–65 adult audience. The architecture is modular: verified device data (CGM, smartwatches) plugs in later as a higher-quality oracle tier, never as the core engine.

2. Strategic Pivot: From Loyalty Points to Data Infrastructure

2.1 What is being retired

The previous model (Ketonia Points on Bale) was a closed-loop loyalty system: points for daily check-ins, glucose logging, and challenge completion, redeemable for consultation discounts. Its structural limits:

LimitationConsequence
No external demandPoints had value only because the platform subsidized discounts; no market clearing price
Action-to-Earn mintingPaid for frequency of behavior, which correlates weakly with data value; inflationary and farmable
Closed loopNo path for the world’s most interested buyers (pharma, AI labs, DAOs, payers) to participate
Dopamine mechanicsDaily-streak rewards conflict with Ketonia’s stated philosophy and its adult clinical audience

2.2 What replaces it

A data-asset-backed token economy. The clinical database is treated as the reserve asset; $KTN is the instrument through which access to that reserve is priced, paid for, and governed.

Patient1,700+ longitudinal records
→
Informed consentanonymized record
→
Data reservecohorts · trajectories · outcomes
→
Institutional accessbuy / lock / burn $KTN
→
Revenue sharebuyback-burn + data dividend
  1. Supply is capped by biology and time. No competitor can retroactively create five-year metabolic trajectories. New entrants must recruit patients and wait years; Ketonia already holds the asset.
  2. Demand is non-discretionary. A Health-AI developer training a hypoglycemia-prediction model, or a DAO funding an RCT on fasting protocols, needs real outcome data. There is no synthetic substitute that passes clinical review.
  3. The token is the toll. All institutional access routes through $KTN acquisition, staking, or burn — creating structural, recurring demand proportional to the commercial value of the data.

2.3 Continuity with Ketonia philosophy

The pivot changes the economic engine, not the values. The 4P framework (Preservation, Cultivation, Connection, Inquiry) maps cleanly onto the data economy: Preservation becomes longitudinal data continuity; Inquiry becomes research access and validation; Connection becomes the consent-based data cooperative. Rewards remain sized to avoid crowding out intrinsic motivation — patients are compensated as data producers and research participants, a dignified framing, not a gamified one.

3. System Architecture Overview

Three layers, strictly separated:

LayerInstrumentTransferabilityFunction
Economic$KTN (ERC-20)LiquidSettlement for data licenses, staking for query rights, burn sinks, governance voting
ReputationKetonia Soulbound Tokens (KSBT, ERC-5192)Non-transferableClinical credentials, milestone attestations, data-quality score, governance weight multiplier, access tiers
Data & TrustConsent Registry + ZK Attestation Layer + Data VaultNot tokenizedThe clinical reserve itself: W3C Verifiable Credentials, zk-SNARK proofs of eligibility/outcomes, differential-private query engine
Data & Trust LayerClinical Data Vault (off-chain, encrypted) · Consent Registry (on-chain, revocable) · ZK Attestation Layer (milestone · eligibility · quality)
Reputation LayerKSBT Soulbound — credentials · tiers · governance weight
Economic Layer$KTN token — licenses · staking · burns · votes
Key separation principle: raw clinical data never touches the blockchain. Only hashes, commitments, proofs, and consent state are on-chain. The Data Vault is a permissioned, encrypted store; all external access passes through a query/attestation engine that enforces k-anonymity, differential privacy budgets, and consent scope. This mirrors the standard DeSci pattern (cf. VitaDAO’s IP-NFT abstraction) while respecting the far stricter sensitivity class of health data.

4. Demand Side: Institutional Access Economics

This is the core of the redesign. Demand mechanisms are non-negotiable: there is no institutional access path that does not require holding, locking, or burning $KTN.

4.1 The Data Access Marketplace

Four product tiers, all priced and settled in $KTN:

T1 — Cohort Licenses

Time-boxed license to a defined anonymized cohort (e.g. “T2D, HbA1c ≥ 8 at baseline, ≥ 24 months tracked, insulin taper documented”).

Buyers: pharma, CROs, longevity institutes.

Settlement: fee in $KTN; 60% burned, 40% to Data Dividend Pool.

T2 — Query Rights (Staked)

Right to submit aggregate/statistical queries via the differentially private query engine.

Buyers: Health-AI devs, academia, DAOs.

Settlement: stake $KTN; query fees from stake yield; 90-day unstake cooldown.

T3 — Model Validation

Benchmark a trained model against held-out Ketonia outcome data (predictive-validity certification).

Buyers: Health-AI companies, digital-health vendors.

Settlement: fee 100% burned; passing models may carry a “Validated on Ketonia Data” attestation.

T4 — Priority Research Access

Queue priority for prospective collection: custom surveys, targeted panels, consented follow-up studies.

Buyers: DeSci DAOs (VitaDAO-style), sponsored RCTs.

Settlement: lock $KTN ≥ 12 months; locked tokens non-circulating.

4.2 API & Data Oracle Access

For Health-AI developers, the Data Vault exposes a metered API: aggregate endpoints (cohort statistics, outcome distributions) and, under stricter tiers, feature-level access for model training. API subscriptions are denominated in $KTN, purchased on a rolling basis. A future path — Ketonia as a verified metabolic-data oracle for other protocols (insurtech DAOs, underwriting models) — uses the same staked-access contract, with oracle fees settled in $KTN.

4.3 Token Sinks (structural, not discretionary)

SinkMechanismCharacter
License burn60% of every T1 cohort license feePermanent supply reduction
Validation burn100% of T3 model-validation feesPermanent
Query-fee burn20% of T2 query fees; remainder to Data Dividend PoolPermanent
Buyback & burn30% of all platform fiat revenue buys back and burns $KTN quarterlyPermanent, revenue-linked
Institutional locksT4 priority-access locks (12–36 months)Circulating supply reduction
Governance depositData-commercialization proposals require a refundable-but-slashed-on-bad-faith $KTN depositFriction sink

The burn share of B2B revenue is a governance parameter with a hard floor of 40% (of the token-denominated B2B revenue pool) — it cannot be voted below this, ensuring deflationary pressure is structural rather than political.

4.4 Utility summary (beyond any internal discount)

  1. Data licensing settlement — the only accepted payment for cohort access.
  2. Staking for query rights — stake size meters API/query throughput.
  3. Locking for priority research access — time-locked capital buys queue position for prospective studies.
  4. Governance — staked $KTN (weighted by Soulbound reputation) votes on price bands, consent-scope templates, burn/lock ratios, new data-product registrations, and Data Treasury grants.
  5. Collateral for research grants — DAOs can post $KTN as milestone-based escrow for funded studies on Ketonia cohorts.

Internal patient-facing discounts (the old points use case) are explicitly removed from the token’s utility set. Patients receive value via the Data Dividend Pool and milestone minting (§4.5, §5), not via subsidized consultations — keeping the demand side institutional and the supply side clinical.

4.5 Data Dividend Pool (patient revenue share)

40% of T1 license fees and 20% of T2 query fees flow to a Data Dividend Pool, distributed pro-rata to patients whose consented data was actually used in the licensed cohort/query, weighted by their Data Quality Score (§6.3). This is not a mint — it is revenue sharing. It creates a direct, legible link for patients between consenting to data use and receiving income — the honest framing of a data cooperative and a significant consent-rate driver.

5. Supply Side: Data-to-Earn Minting

5.1 Primary minting paths

Minting is reserved for events that create or certify data value:

M1 — Consent Grant

Patient signs informed, revocable consent to include their anonymized longitudinal record in the Data Reserve.

Verify: Consent Registry transaction + ZK proof of record completeness.

Reward*: one-time 500–2,000 $KTN, scaled by record depth.

M2 — Clinical Milestone

Documented, expert-verified outcome: HbA1c reduction ≥ 1.0 sustained 6 months; insulin dose −50%; full discontinuation; durable remission (HbA1c < 6.5 off meds ≥ 12 months).

Verify: clinical oracle signs a ZK attestation; labs stay off-chain.

Reward*: 1,000–10,000 $KTN by class; once per patient per severity level.

M3 — Longitudinal Continuity

Sustained high-quality contribution without a milestone (e.g. 12 consecutive months of structured logs meeting quality thresholds).

Verify: automated quality filters + periodic expert audit sample.

Reward*: 50–150 $KTN per qualified quarter; hard annual cap; diminishing marginal reward.

* All figures are initial parameters subject to governance calibration and the emission schedule (§8.2). Rewards are modified by the patient’s Soulbound tier multiplier (×1.0 – ×2.0).

M2 is the flagship: a verified diabetes-reversal event is exactly the outcome datum that pharma outcome studies, payers, and DeSci DAOs pay for. The milestone mint is Ketonia purchasing its own most valuable inventory with newly issued token, funded by the community treasury emission (§8).

5.2 What is explicitly NOT minted

5.3 Emission control on the mint side

5.4 Anti-sybil and clinical integrity

Health data has a natural sybil defense that open networks lack — you cannot fake a five-year HbA1c trajectory past clinical review:

  1. Clinical identity anchoring: mint eligibility requires a Ketonia medical record verified by licensed staff. Wallet↔patient binding is one-to-one, mediated by the clinic, privacy-preserving (only a commitment on-chain).
  2. Soulbound tiering: governance weight and mint multipliers attach to non-transferable KSBTs; bought accounts inherit nothing.
  3. Expert-oracle + slashing: clinical attestations are signed by credentialed experts; a falsified attestation slashes the expert’s stake and reputation and voids derived mints.
  4. Statistical anomaly detection: cohort-level outlier screening on incoming records before acceptance into the Data Reserve.
  5. Proof-of-personhood fallback: for future open cohorts, permissioned KYC or government-ID ZK attestation is a prerequisite — no anonymous minting path exists at any tier.

6. Privacy & Trust Infrastructure

6.1 Threat model

The asset is medical data of identifiable patients in a jurisdiction-sensitive context. A single de-anonymization event is an existential risk to both patients and the platform. Privacy is therefore load-bearing architecture, not a feature.

6.2 Stack

ComponentTechnologyPurpose
Consent RegistryOn-chain registry of scoped, revocable consent records (W3C VC + EIP-712)Per-purpose, per-buyer-class, time-boxed consent. Revocation propagates to the Vault and voids future use; already-sold aggregates are contractually irreversible (disclosed in consent text)
ZK Attestation Layerzk-SNARK circuits over Merkle-committed recordsProves “HbA1c fell ≥ 1.0 over 6 months”, “patient belongs to cohort X”, “record passes quality thresholds” without revealing the record, values, or patient
Data VaultOff-chain encrypted store, enclave-isolated query engineHolds raw records. External parties never receive row-level data at T1/T2; only DP aggregates or licensed extract under audit
Differential Privacy EnginePrivacy budget (ε) accounting per buyer, per queryOutputs cannot be reverse-engineered to individuals; k-anonymity floors on every cohort product (k ≥ 50)
Soulbound CredentialsERC-5192Milestone attestations issued as private credentials; the fact of the credential is provable via ZK without exposing clinical detail

6.3 Data Quality Score (DQS)

Every consented record carries an off-chain DQS (completeness, longitudinal span, verification depth, device-oracle backing once available). DQS determines mint scaling (§5.1), Data Dividend weight (§4.5), and cohort inclusion priority. DQS is reputation, held in the Soulbound layer — never tradeable.

6.4 Compliance posture

7. Points-to-Token Transition (Bale Pilot Migration)

The existing Ketonia Points balances from the Bale pilot must convert fairly, transparently, and once.

7.1 Principles

  1. Honor earned value: pilot participants earned points under published rules; those balances are a liability Ketonia honors.
  2. Reprice, don’t invalidate: points were earned under Action-to-Earn logic; $KTN mints under Data-to-Earn logic. Conversion applies a transition exchange rate reflecting the different value basis — not 1:1, published in advance.
  3. No speculative windfall: conversion is vesting-gated so migration cannot be dumped at TGE.
  4. Reputation carries over fully: pilot ranks, challenge completions, and milestone history map 1:1 to Soulbound credentials and tier multipliers. Reputation migration is generous precisely because token migration is gated.

7.2 Mechanism

7.3 Communication frame

For the 35–65 clinical audience, the migration is framed as: “Your health progress and your data now own a share of what they produce.” No airdrop hype, no countdown timers — a plain statement of entitlement, rate, and vesting, delivered through the Bale group and forum.

8. Token Distribution, Governance & Sustainability

8.1 Supply and allocation

Total supply: 1,000,000,000 $KTN (fixed at genesis; all issuance beyond allocation comes only from the emission schedule below, capped within the Community/Data Treasury line).

Community & Data Treasury34%
DeSci Research Pool14%
Core Team12%
Ecosystem & Partnerships10%
Clinical Expert Pool8%
Liquidity8%
Strategic Reserve (DAO)8%
Patient Retroactive & Migration6%
AllocationShareTokensVesting / Release
Community & Data Treasury34%340MEmitted over ~15 years per §8.2; funds all minting paths (M1–M3) and data-infrastructure grants
DeSci Research Pool14%140M4-year vesting; DAO-governed grants for external research on Ketonia cohorts, co-funding with partner DAOs; milestone-escrowed
Patient Retroactive & Migration6%60MPoints conversion (§7.2) + milestone true-ups; vests with migration schedule
Core Team12%120M4-year vesting, 1-year cliff
Clinical Expert Pool8%80M3-year vesting; physicians, nutritionists, exercise specialists as verification oracles; stake-and-slashing
Liquidity8%80MDEX/CEX provisioning; market-making under governance-supervised mandate
Ecosystem & Partnerships10%100M4-year vesting; data-buyer onboarding, oracle integrations, compliance/legal, audits
Strategic Reserve (DAO-governed)8%80MLocked 2 years minimum; deployed only by supermajority governance vote

Combined community-facing lines (Treasury + Research + Migration) total 54% — the data producers and their research ecosystem hold the majority of the token, the structural claim that makes this a cooperative rather than an extraction platform.

8.2 Emission schedule and supply control

8.3 Velocity management

8.4 Governance

8.5 Legal & jurisdictional note

Given the patient base’s jurisdiction and the international DeSci buyer profile, the token and data-licensing entity should be structurally separated: a data-services entity (vault, licenses, compliance) and a token-issuing foundation in a crypto-friendly jurisdiction, connected by the buyback-burn and dividend contracts. $KTN is documented as a utility/access token with no profit promise, no yield product, and no fractional claim on the company. Counsel review is a pre-TGE gate; sanctions exposure and cross-border health-data transfer are explicit roadmap workstreams.

9. Dual-Layer System: $KTN + Soulbound (KSBT)

Property$KTNKSBT (Soulbound)
StandardERC-20ERC-5192 (non-transferable)
SupplyFixed genesis + capped emissionIssued per credential event
RoleSettlement, staking, burns, voting power baseCredentials, tier multiplier, governance weight, access gating
TradeableYesNever
Examples—“Documented T2D Remission”, “5-Year Longitudinal Contributor”, Clinical Expert credential, pilot-rank migration credit, DQS tier

Access tiers (buyer-facing and patient-facing, both KSBT-gated):

Milestone badges as NFTs: kept deliberately minimal — one Soulbound credential class per verified clinical milestone, optionally rendered as a commemorative badge. Badges confer reputation and rights; never tradeable, never speculative.

10. Key Flows

10.1 Patient consent → mint → dividend

Patient1. sign scoped consent (W3C VC)
→
Consent Registry2. commitment recorded
→
Data Vault3. anonymized, DQS scored
→
Mint Contract4. M1/M2/M3 mint, caps enforced
→
Revenue split60% burn · 40% dividend (DQS-weighted)

Revoking consent propagates from the Registry to the Vault and voids future use.

10.2 Institutional access (T1/T2)

Institutionacquire $KTN (market / OTC)
→
Stake or pay feeT1 fee → 60% burn + 40% dividend · T2 stake, 90d cooldown
→
Data Vault / DP Query Enginelicensed extract under audit · DP aggregates (ε-budgeted)
→
T3 Validationbenchmark vs held-out outcomes; fee 100% burned

10.3 Milestone verification (ZK)

Clinical staff verify labs off-chain → sign attestation → circuit proves “HbA1c(t₀) − HbA1c(t₀+6mo) ≥ 1.0 ∧ record authentic ∧ consent active” against the Merkle-committed record → Mint Contract issues M2 reward + Soulbound “HbA1c Reduction” credential. No lab value, diagnosis, or identity appears on-chain at any step.

11. DeSci Investor Positioning (VitaDAO-class thesis)

The pitch to serious DeSci capital, stated without hype:

  1. Asset-backed, not narrative-backed. Token demand derives from licensing revenue on an existing 1,700+-record longitudinal reserve — inventory is on hand at TGE, unlike most DeSci protocols promising future data collection.
  2. Outcome data, the highest-value class. Documented intervention→outcome trajectories (fasting/ketogenic protocols → HbA1c, insulin dose) serve three concurrent buyer markets: metabolic pharma RWE, Health-AI training/validation, and longevity research — with payer/insurtech as a fourth.
  3. Structural sinks with hard floors. ≥ 40% of B2B token revenue is burned by constitutional rule; staking and T4 locks remove further float. Deflation is mechanical, not promotional.
  4. Cooperative legitimacy. 54% of supply to community/research lines, consent-registry-gated data use, and an Ethics Council veto give the protocol the social license that institutional buyers and DAOs increasingly require for health data.
  5. Compatible with existing DeSci rails. Research Pool grants and T4 priority access are designed for co-funding structures and IP-NFT-style abstraction familiar to VitaDAO, AthenaDAO, and DeSci Nodes; joint cohort studies can be escrowed milestone-wise in $KTN.

12. Modularity & Future Extensibility

Clean hooks, explicitly non-core:

13. Roadmap

PhaseWindowDeliverables
0 — FoundationMonths 0–6Legal structuring (issuing foundation + data entity); consent registry v1 + W3C VC schema; DQS spec; pilot points snapshot; migration rate & terms published; Data Ethics Council seated
1 — Migration & TGEMonths 6–12Points→$KTN conversion window opens; Soulbound migration; treasury emission contracts live; M1/M2 minting active for consenting patients; liquidity provisioning
2 — MarketplaceYear 1–2Data Product Registry + first T1 cohort products; T2 staked query engine with DP budgeting; ZK milestone circuits in production; first buyback-burn quarter; T3 validation service
3 — Institutional scaleYear 2–4T4 lock-based priority access; first DAO co-funded studies (Research Pool grants); device-oracle adapter pilots (CGM); governance handover of parameter tuning; Proof-of-Burn quarterly cadence

KPIs the token design is judged by (not price): consent rate among eligible patients (%), longitudinal retention (months tracked per consenting patient), B2B licensing revenue ($KTN-denominated), burn-to-emission ratio, cohort product count, and verified milestone count per quarter.

14. Risks & Mitigations

RiskClassMitigation
Re-identification of cohort membersExistentialDP engine with ε budgeting, k ≥ 50 floors, aggregate-only T2 outputs, T1 extracts under audit + contractual use limits, Ethics Council veto
Regulatory (health data + token, multi-jurisdiction)HighEntity separation (§8.5), utility-token documentation, counsel gate pre-TGE, GDPR/HIPAA-aligned architecture from day one
Weak early B2B demand → burn underperformsHighTGE inventory already exists (no data-collection lag); Research Pool co-funds first studies; emission floor keeps patient incentives funded at low revenue
Patient distrust of “selling data”HighConsent-first framing, revocability, transparent dividend attribution, Ethics Council with veto, no identifiable products ever; migration honors pilot balances
Mint farming via fake recordsMediumClinical-oracle verification, expert staking + slashing, statistical anomaly screening, one-to-one wallet binding (§5.4)
Token speculation distorting access pricingMediumGovernance-set price bands in $KTN with fiat-reference adjustment; T4 locks favor long-horizon research buyers
Key-person / oracle centralization (clinic staff)MediumMulti-sig expert panels for attestations, Expert Pool stake economics, progressive decentralization to partner clinics
Emission outpaces burn longer than modeledLow–Med8%/yr decay, category caps, hard ceiling; governance may tighten caps (floor-protected burn share cannot weaken)

15. Design Principles (recap)

  1. The database is the reserve; the token is the toll. Every mechanism prices access to a real, existing, non-replicable asset.
  2. Data-to-Earn, never Action-to-Earn. Mints attach to consent and verified clinical outcomes — not engagement.
  3. Privacy is load-bearing. ZK + DP + consent registry are prerequisites, not roadmap items.
  4. Deflation by construction. Burn floors, staking, locks, and decay make supply reduction mechanical.
  5. Serotoninergic economics. Durable rewards, reputation over speculation, governance that cannot outvote patient protection — the token behaves like the medicine Ketonia practices.