Transparency Report
About this report
Data minimization is an architecture commitment, not a claim that the Service has zero server contact. This quarterly page summarizes what records the reference build may create and what stays on a user's device; see the Privacy Notice for the complete boundary.
This is not a legal-demand statistics report and does not include a warrant canary. Any statement about demands received, disclosures made, or canary status requires review by licensed counsel, which remains an explicit, open launch gate (see Terms of Use). No canary status — present or absent — should be inferred from this page.
Q2 2026 architecture snapshot (reviewed July 12, 2026)
This is a code-and-infrastructure inventory for the reference build, not a representation about any production legal demand. As documented in docs/audits/dpia.md:
Records that may exist: request URLs carrying checklist selections and an optional question; bounded in-memory selection-only render-cache entries; allowlisted application logs containing route and selection metadata (14-day retention in the live preview, 30 days in the production template); and hosting-provider network, account, or access metadata under provider-controlled retention. Raw questions are excluded from the application cache, application logs, and rendered response, but a full GET URL may still appear in browser history or upstream access records.
Local-storage boundaries: identity details typed into the form helper and the encrypted “save your progress” blob are not transmitted by those features. “Save for offline” explicitly requests the listed same-origin pages and shell assets, then keeps the resulting unencrypted copies in browser storage; it performs no background sync. None of these statements is an absolute claim about provider records, and users should not enter identifying details in an optional question.