Privacy

Minimal telemetry. No advertising tracking.

The public evaluation experience collects only the product telemetry needed to understand usage, friction, and evaluation progress. Analytics is never Truth Engine evidence.

What we do not use

No advertising surveillance layer.

No advertising trackers
No Meta Pixel
No Google Ads tracking
No Truth Engine device fingerprinting
No cross-site identity
No raw IP copied into Supabase

Access protection

Security traffic is separate from product telemetry.

The public Playground uses Cloudflare at the edge, Turnstile for access protection, and a short-lived first-party session to enter the evaluation environment.

Turnstile protects access

It is used to reduce automated abuse before traffic reaches the private Playground service.

Session state is functional

A temporary first-party access session is used to keep an authorized evaluator inside the Playground.

Security controls are not truth evidence

Edge protection, access checks, and rate controls do not determine engine truth or proof.

Data boundary

Evaluation data only.

No API secrets in analytics

Credentials are not product telemetry.

No production/customer/payment/health/order data

The public evaluation environment is not designed to receive those categories of data.

Product telemetry is non-authoritative

It can describe product use, but it cannot create or modify Truth Engine authority, evidence, proof, or occurrence history.

Telemetry ≠ Truth Engine evidence

Analytics never determines SATISFIED, NOT_SATISFIED, UNKNOWN, retry authority, provider occurrence, release lineage, or Runtime history.

Non-authoritative telemetry

Supabase does not control the engine.

Supabase is used only for product and external-validation telemetry. It is outside the authoritative truth path.

truthevidenceproofauthorityretry authorityprovider occurrencerelease lineageRuntime history

None of these may be written or controlled by product analytics.