TECHNICAL TRANSPARENCY

Minimize identity. Preserve utility.

This page describes application-level data handling for security and infrastructure review. It is deliberately factual and is not presented as a substitute for a formal legal privacy notice.

IDENTITY

Pseudonymous by design.

Transport IP hint + user-agent + optional x-seenrelay-client are privacy-salted and hashed for frictionless lease continuity. When configured, a short-lived server-verified marker can classify first-party operational probes without storing the marker or signing secret.

Transport materialRaw IP and user-agent are not used as database identity; the application derives privacy-salted operational fingerprints.
Observer provenanceSelf-asserted IDs and Ed25519 public keys are salted before persistence. Cryptographic proof still means key possession, not real-world identity.
Persistent evidenceObservations persist deterministic value fingerprints and bounded evidence metadata rather than the submitted raw value. Active Production raw-value columns have been purged and constrained; historical database branches or provider recovery snapshots are managed separately under backup or retention controls.
Shared response boundaryCHECK exposes comparison status and bounded freshness evidence, not another observer's submitted raw value. Do not submit credentials, private keys or unnecessary sensitive personal data.
Environment integrityPreview/CI uses an isolated database. Production metrics are reserved for actual Production activity.
RETENTION

Keep evidence only as long as it serves a purpose.

Observation rows
7d
configured evidence horizon
Observer/fact state
7d
aligned pseudonymous state
Hive leases
30d
operational retention
Reuse events
90d
network utility evidence

Fact summaries remain available for STALE/latest-observed semantics until an explicit deletion policy removes them. Aggregate operational metrics are separate from retained observation evidence.

MACHINE REVIEW

Prefer structured disclosure?