Privacy and observability

Collection status: disabled. No public-web observability provider is currently allowed to load or receive data. Activation remains blocked pending authority review of provider identifier behavior and an explicit production gate.

The limits are part of the contract

Any future observability must remain anonymous and aggregate. It must not use cookies, visitor, session, or device identifiers, fingerprinting, or session replay.

It must not send raw URLs, queries, hashes, referrer paths, error messages or stacks, application or simulation state, share tokens, or laboratory handoff payloads. Routes are reduced to pathnames; client failures are reduced to a small published code list; event properties are finite and bounded.

Planned providers, still off

The programme intends to use Plausible Business for manual pageviews, bounded product events, and sanitized client failure codes, and Vercel Speed Insights for Core Web Vitals only. Neither provider may be activated unless the locked privacy limits are proven end to end.

Campaign attribution is limited to exact values in a site-owned registry. Unregistered values are discarded. Campaign fields are never copied into generated simulation, runtime, or share state.

Planned retention

No observability data exists for this programme while collection is disabled. If activation is later authorized, the planned Plausible Business plan currently publishes a five-year data-retention limit. Vercel Hobby currently provides a seven-day Speed Insights reporting window.

When the programme is retired, or an authorized deletion decision is made, the site runbook requires the Plausible site to be reset or deleted. Committed evidence is limited to sanitized request shapes, aggregate counts, deployment identity, and timestamps—never visitor-level records, credentials, dashboard exports, or raw URLs.

Programme PUBLIC-WEB-OBSERVABILITY-001 · disclosure reviewed 11 August 2026

Privacy