> For the complete documentation index, see [llms.txt](https://faction-os.gitbook.io/faction-os-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://faction-os.gitbook.io/faction-os-docs/docs/privacy-and-security.md).

# Privacy And Security

## Posture

FactionOS is local-first by default. Core development does not require a hosted account, Supabase, Umami, PostHog, Cloudflare, Discord, Telegram, a generic webhook, Anthropic, or a database.

This does not mean the data is low sensitivity. Real hook sessions can include prompts, paths, command previews, tool metadata, summaries, local identifiers, and optional file content sent to LLM analysis endpoints.

The security record is `docs/SECURITY-COMPLIANCE.md`.

## Phase 08 Erasure Inventory

Phase 08 Session 02 adds an inventory-only trusted-erasure contract in `packages/protocol/src/erasure.ts` and the human-readable release inventory at `.spec_system/archive/phases/phase_08/unified_erasure_inventory.md`. This records local, browser, Worker, workspace, backup, export, archive, diagnostic, log, valid spool, runtime memory, and future hosted-placeholder boundaries with owners, authority requirements, dry-run expectations, verification plans, audit labels, blocked payload categories, and no-overclaim wording.

Session 03 adds local/browser runtime controls for the local and browser subset of that inventory. The local server can dry-run and confirm release-scoped filesystem cleanup for FactionOS home state, archives, memory, settings, lifecycle files, project-root state, logs, valid spool entries, exports, and diagnostics. It reports backups and malformed spool entries as manual-review boundaries, skips runtime-memory summaries that have no durable file target, requires the exact local confirmation phrase plus an idempotency key, records redacted audit entries, and verifies absence where possible. The web Settings drawer can dry-run and confirm browser-local cleanup for settings, faction hints, derived game projection storage, replay buffers, replay URL fragments, War Room hints, local auth hints, and in-memory cockpit context.

Session 04 adds scoped Worker room-state erasure evidence, and Session 08 records the release-candidate wording and gate evidence. This still does not close the active `P06-S07-ERASURE` finding as a broad claim. Trusted unified erasure remains unavailable for unproven hosted, public replay, analytics, push, remote, broad workspace-file, backup/log/archive, and future surfaces.

Cleanup-vs-erasure wording remains strict:

* Browser settings reset clears one browser boundary only.
* Browser War Room leave/reset clears local browser room context only.
* Worker socket disconnect or leave does not delete Durable Object room state.
* Diagnostics recovery removes stale listener PID files and malformed spool entries only.
* Quest Board cleanup is manual file deletion of `suggestions.json` while the local server is stopped; it is not trusted unified erasure.
* CLI uninstall restores or edits hook settings only.
* Manual file removal, archive deletion, export deletion, backup pruning, or one-boundary cleanup is not auditable trusted unified erasure.

## Data Inventory

| Data                                                        | Source                                                                                                                                                                                    | Current storage or transfer                                                                                                                                                                                                                                                                                                                                                                                                            |
| ----------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Prompts and mission summaries                               | Hooks, `/event`, mock generator                                                                                                                                                           | Server memory, WebSocket, redacted local archive entries, browser replay, redacted exports.                                                                                                                                                                                                                                                                                                                                            |
| File paths and cwd                                          | Hooks and protocol models                                                                                                                                                                 | Server memory, WebSocket, redacted archive/export/replay-share surfaces, adapter payloads depending on formatter.                                                                                                                                                                                                                                                                                                                      |
| Tool and command previews                                   | Hooks                                                                                                                                                                                     | Server events, mission timeline, adapters when formatted.                                                                                                                                                                                                                                                                                                                                                                              |
| File contents for analysis                                  | `/llm/analyze`, `/llm/scan-codebase`                                                                                                                                                      | Server memory and optional Anthropic transfer only when provider transfer is explicitly enabled.                                                                                                                                                                                                                                                                                                                                       |
| Notice Board messages                                       | REST, WebSocket `post_notice`, CLI `factionos notice`, hook context lookup, automatic mission lifecycle posts, and optional War Room relay                                                | Local `notice-board.json` under `FACTIONOS_HOME` or the injected server state root; local WebSocket hydrate/message/resolve frames; optional Worker relay history when War Room is configured and used.                                                                                                                                                                                                                                |
| Command-center collaboration and handoff posture            | Local command-center REST routes, local WebSocket frames, Notice Board linkbacks, and optional War Room relay summaries                                                                   | In-memory command-center manager state with canonical Notice ids, visibility labels, readiness check labels, resume-source labels, lineage ids, room labels, and remote-access summary labels only. It does not store raw prompts, transcripts, command output, tunnel tokens, Worker payloads, file contents, diffs, logs, exports, or trusted erasure proof.                                                                         |
| Quest Board suggestions, issues, summaries, and scan status | Hero-idle lifecycle, session summary lifecycle, codebase scan orchestration, on-demand analysis, project scan, suggestion routes, issue-dismiss routes, and WebSocket `suggestion_update` | Local `suggestions.json` under `FACTIONOS_HOME` or the injected server state root. May contain relative file paths, code-derived titles/messages/prompts, IDs, timestamps, dismissed IDs, and compact scan status. Manual deletion is the current removal path; full trusted unified erasure remains no-claim.                                                                                                                         |
| Browser settings, replay, and game projection               | Web client                                                                                                                                                                                | localStorage for bounded browser preferences, replay fragments, and the derived `factionos-game-v1` projection aggregate. Projection data is aggregate-only for scanner camps, pending Quest Board links, mission-bound links, combat playback counters, live enemy display state, scrying hints, and alert focus state.                                                                                                               |
| Analytics runtime posture                                   | Protocol and web analytics helpers                                                                                                                                                        | Status labels, docs paths, consent state labels, allowed field labels, blocked payload labels, and synthetic test payloads. When public config and consent are ready, the browser may send approved minimized event envelopes to Umami `/api/send`; disabled, missing, denied, withdrawn, opted-out, malformed, or blocked-payload states send nothing.                                                                                |
| Hosted operation posture                                    | Protocol, server diagnostics, CLI, and web helpers                                                                                                                                        | Status labels, docs paths, surface labels, requirement labels, blocked payload labels, unsupported claim labels, booleans, and bounded counts only. No push subscription, tunnel, remote access, hosted diagnostic agent, or raw credential data is sent.                                                                                                                                                                              |
| Local/browser erasure posture                               | Protocol, local server, CLI, web helper, and Phase 08 inventory                                                                                                                           | Boundary ids, labels, status labels, authority labels, dry-run/confirm states, verification labels, audit labels, blocked payload labels, unsupported claim labels, docs paths, booleans, and bounded counts only. Local/browser deletion is available only after explicit confirmation; Worker, hosted, public replay, analytics, push, remote, workspace-file, and full trusted unified erasure claims remain unavailable.           |
| Production-hosted smoke evidence                            | Phase 08 hosted smoke script and release docs                                                                                                                                             | Target ids, labels, safe hostnames, statuses, booleans, timing buckets, docs paths, and issue codes only. No raw response bodies, dashboard output, Cloudflare account ids, zone ids, API tokens, request bodies, room payloads, prompts, local paths, exports, logs, backups, or replay buffers are tracked.                                                                                                                          |
| CLI lifecycle state                                         | CLI start/status/doctor                                                                                                                                                                   | Local `~/.factionos/server.pid`, `lifecycle.json`, and `project-root.json`; contains PID, port, local URLs, runtime root, and workspace root only.                                                                                                                                                                                                                                                                                     |
| Local orchestration state                                   | Server routes and WebSocket frames                                                                                                                                                        | In-memory queue entries, source-owned templates, mission graph nodes, guarded-action proposals/results, campaign/task execution state, command-center execution rows, managed lifecycle rows, file-intent metadata, channel command rows, compact browser state mirrors, and CLI diagnostics. Broad rows carry safe ids, labels, counts, state, queue/execution links, rollback metadata, unavailable reasons, and recovery copy only. |
| Hook/listener diagnostics and spool posture                 | Hook handlers, listener, CLI doctor/status                                                                                                                                                | Local logs, listener PID files, and bounded spool files under the FactionOS home; diagnostics summarize counts, status labels, durations, and sanitized identifiers.                                                                                                                                                                                                                                                                   |
| Codex hook config posture                                   | CLI installer and Codex user config                                                                                                                                                       | User-level `hooks.json` plus `hooks.backup.factionos.json` when a first-write backup is needed. FactionOS-managed commands are local hook config only; Codex `/hooks` trust decisions remain owned by Codex and the user.                                                                                                                                                                                                              |
| Media catalog and draft provenance                          | Phase 04 media tooling and docs                                                                                                                                                           | Tracked catalog records, redacted draft briefs, draft manifest records, and closeout evidence. Raw provider output remains ignored staging and is not runtime data.                                                                                                                                                                                                                                                                    |
| Room participants and relayed events                        | War Room Worker                                                                                                                                                                           | Cloudflare Durable Object storage when deployed and used.                                                                                                                                                                                                                                                                                                                                                                              |
| War Room authority metadata                                 | War Room Worker and web panel                                                                                                                                                             | Raw Worker-issued authority tokens return to the requesting browser and stay in memory only; Durable Object storage keeps token hashes, participant id, role, room code, room revision, generation, issued-at, expires-at, and idempotency metadata.                                                                                                                                                                                   |

## Game Projection Privacy Boundary

Phase 23 adds scanner camp presentation to the existing browser-local game projection, and Phase 24 extends that projection into Quest Board links, live tier presentation, combat playback, scrying hints, and alert focus. These additions do not add a new server store, hosted dependency, protocol event, storage key, reward ledger, or trusted-erasure claim.

Scanner camps are derived from current Quest Board codebase issues that arrive through the existing `suggestion_update` snapshot. Quest Board accept/assign actions can add pending prompt-link aggregates, and later `mission_start` events can bind those links to mission ids. The durable browser projection remains `localStorage["factionos-game-v1"]`. Projection records store aggregate fields only: camp ids, issue ids, safe relative sector labels, HP, tier, entrenchment counters, scar percentages, cells, timestamps, pending-link ids, mission ids, strike/counterattack/combo counters, display-only enemy HP, live enemy status labels, scrying hint labels, and alert focus ids.

Game projection state must not copy raw issue messages, suggested prompts, mission prompts, transcripts, replay entries, event bodies, terminal output, provider payloads, file contents, absolute paths, environment values, secrets, or token-like values. Quest Board cards may still display richer current issue details because Quest Board owns those local cards; the projection does not duplicate that detail. Pending links keep prompt intent labels only while they are needed for product presentation, and link binding scrubs prompt text before storage.

Replay, reconnect, and mock-mode traffic remain progress-inert for durable projection state. Replayed scanner snapshots and combat frames cannot persist kills, pending links, counters, scrying state, or alert focus changes. Mock scanner camps and mock combat can fold in memory only while `mockEnabled` prevents durable writes. Browser reset and browser-local erasure can remove the projection key for the current browser, but this remains local/browser cleanup only. Full trusted unified erasure, hosted deletion, cross-device deletion, production-hosted validation, public-demo synthetic proof, and legal/privacy certification remain no-claim boundaries.

Generated Phase 3 visual sheets under `assets/generated/game-design/phase03/` are implementation references for Phase 24 validation only. The app keeps their paths in typed reference records and media catalog blockers; runtime battlefield layers use CSS/DOM presentation with typed fallback labels and do not load those source paths as browser media until a later media-serving, slicing, optimization, fallback, accessibility, and privacy gate approves that promotion.

## Notice Board Privacy Boundary

The Notice Board is explicit active-room coordination, not automatic raw event logging. Allowed notice data is limited to concise `status`, `question`, `review`, `announcement`, `conflict`, `completion`, or `human` messages plus bounded metadata required for coordination: notice id, priority, tags, display author metadata, author session id, machine id, target session ids, room code, timestamps, resolution state, and safe relative related-file paths.

The server persists local notices to `notice-board.json` under `FACTIONOS_HOME` or the injected server state root. The local server owns validation, persistence, filtering, targeting, context generation, pruning, resolution, and automatic lifecycle posts. The web cockpit consumes local WebSocket `notice_board_hydrate`, `notice_board_message`, and `notice_resolved` frames. The CLI and hook packages expose bounded agent access through explicit commands and prompt-start context lookup.

Notice Board paths must not expose raw prompts, transcripts, terminal output, command bodies, command output, file contents, secrets, tokens, bearer values, credentialed URLs, broad or absolute local paths, logs, exports, replay buffers, scan payloads, diagnostics, backups, archives, media drafts, raw Worker payloads, or quarantined historical content. Related files must be safe relative paths normalized inside repository or worktree boundaries before display or relay.

Hook context lookup is read-only and failure-to-no-context. Empty context, malformed responses, non-2xx responses, unreachable servers, timeouts, oversized context, blocked fields, and unsafe markers do not write context to stdout or spool. Claude-compatible providers may receive bounded additional context; Codex and unknown providers stay silent and use CLI notice commands.

War Room Notice Board relay is optional external transfer. Relay frames carry only protocol-validated safe notice messages, resolution metadata, and filtered catch-up. Relay does not add hosted identity, hosted storage, analytics, public replay, production-hosted validation, remote execution, Docker execution, public collaboration safety, or trusted erasure claims.

## Command-Center Collaboration Privacy Boundary

Command-center collaboration and handoff state is local coordination metadata, not a remote-access control plane. Allowed handoff fields are bounded ids, target labels, visibility labels, readiness checks, resume-source labels, Notice linkbacks, lineage ids, room labels, timestamps, revision metadata, and remote-access summary labels such as `no_claim` or `unavailable`.

Context Notice routes may create canonical Notice Board messages for review requests, blockers, and completions. `commandCenterLinks` point back to safe command-center records only; they must not embed raw scaffold payloads, prompts, command bodies, terminal output, transcripts, diffs, file contents, secrets, tokens, authority values, logs, replay buffers, exports, or broad local paths.

War Room relay posture and catch-up summaries expose compact counts, timestamps, health labels, and safe family labels only. They do not expose raw Worker event history, room payloads, authority tokens, tunnel values, remote viewer state, command output, diagnostics, logs, or hosted account data.

Readiness and resume-source labels do not prove an operator can safely resume without reviewing local context, and remote-access summaries do not claim a tunnel, hosted Worker command bridge, production auditability, public collaboration safety, or trusted erasure. The no-claim boundary remains unchanged until a later scoped threat model adds consent, authorization, revocation, audit, redaction, tests, docs, and release evidence.

## Command-Center Execution Privacy Boundary

Phase 20 local execution state is evidence-backed only for terminal queue dispatch, Git status/stage/unstage, file mutation and rollback, bounded container isolated-spawn dispatch, campaign dispatch through queue entries, registered guarded executors, owned managed-session stop/restart/message actions, source-owned template queue creation, and proposal-first channel conversion. These are local manager-owned paths; they do not create hosted identity, hosted storage, public replay hosting, production-hosted validation, remote access, Worker command bridges, generic webhook/chat auto-execution, arbitrary Docker command execution, provider model/permission/isolation mutation, Git push execution, or trusted unified erasure.

Allowed broad command-center fields are compact ids, family/kind labels, status and state labels, safe summaries, relative or scoped labels, counts, revisions, queue ids, execution run ids, terminal/container ids when scoped, rollback metadata, unavailable reasons, retryability, recovery copy, and docs paths. Raw command text, terminal stdout/stderr/scrollback, Git output, diffs, patch bodies, file contents, backup contents, raw webhook bodies or headers, cookies, auth material, provider payloads, prompts, transcripts, Docker commands/output, env, mounts, broad absolute paths, tokens, secrets, logs, exports, and replay buffers must not appear in broad REST rows, WebSocket events, diagnostics, docs examples, session exports, or normal web rows. Scoped terminal detail and local backup content remain local recovery/detail surfaces, not release-safe broad evidence.

## Codex CLI Hook Privacy Boundary

Codex CLI hooks are supported as local user-level hooks installed by `factionos init --cli codex` or `factionos init --cli all`. The installer writes managed command hooks into `CODEX_HOME` when set, otherwise the Codex user config directory. It does not change Codex auth, provider, telemetry, model, profile, API key, account settings, trusted-project state, or hook trust decisions.

Users must review loaded Codex hooks with `/hooks` after install. FactionOS does not recommend bypassing hook trust as the normal local setup path, does not create project-local trusted `.codex/` state, and does not package a Codex plugin in this phase.

Codex hook payload handling follows the same local-first minimization posture:

* Prompt text may be summarized or truncated for local mission state, but raw prompt bodies must not be copied into docs, diagnostics, exports, logs, or hosted payloads.
* Transcript and agent transcript paths are treated as sensitive local state. FactionOS records compact metadata only and must not store transcript contents.
* MCP arguments and responses are reduced to safe tool names, ids, status labels, key counts, or compact summaries; argument bodies are blocked.
* `apply_patch` events may produce file-access or tool-result summaries, but raw patch bodies, diff bodies, and command output are blocked from logs, diagnostics, replay-share payloads, exports, and docs examples.
* Bash and other command previews stay bounded and redacted. Terminal output is not a FactionOS hook payload category.
* Token-like values, credential-bearing URLs, provider secrets, account ids, broad local paths, hook config bodies, and unrelated Codex config are not valid public docs or diagnostics content.
* Local FactionOS state under the configured FactionOS home remains local state. CLI uninstall removes managed hook entries only; it is not trusted unified erasure.

## War Room Federation Transfer Boundary

The Cloudflare Worker War Room surface is optional external transfer. It is separate from the local server and is not required for core local cockpit use. The web panel can use a configured Worker URL for room lifecycle, health diagnostics, join approval, presence, reconnect, bounded catch-up, and allowlisted redacted federation. Empty, invalid, unreachable, timed-out, rate-limited, and malformed Worker states keep the local cockpit usable.

Worker federation uses explicit payload allowlists. Allowed room data is limited to compact room codes, participant ids, display names, roles, colors, online flags, bounded timestamps, approval state, room revision, authority hash metadata inside the Durable Object, idempotency metadata, compact health metadata, and diagnostic status. Raw authority tokens are browser-held bearer values for room requests only; they must not be stored in localStorage, displayed, exported, replayed, logged, or copied into diagnostics. Redacted collaboration events are schema-validated before persistence or catch-up. The only persisted collaboration frame families are presence, cursor, focus, hero state, mission state, and room notice. Notice Board relay history is a separate filtered history for protocol-validated `notice_board_message`, `notice_resolved`, and `notice_board_catchup` frames only. `ping` is non-persisted liveness traffic. Catch-up and browser summaries expose counts, timestamps, and safe family labels only, not raw ids, prompts, paths, commands, diagnostics, exports, replay buffers, logs, media drafts, settings, or adapter data.

By default, Worker federation must not transfer prompts, file contents, command bodies, terminal output, transcripts, secret values, broad local paths, exports, replay buffers, media drafts, scan payloads, local diagnostics, PID files, spool entries, backups, or local logs. Durable Object room data has scoped room deletion evidence only; full trusted unified erasure remains no-claim unless a later release record proves every claimed boundary.

## Current Controls

* LLM engines return deterministic fallbacks when no provider key is configured, when provider transfer is not explicitly enabled, or when the provider call fails.
* Hook handlers use timeout-bounded fire-and-forget calls.
* Hook logs avoid full payload logging in normal paths.
* CLI status and doctor avoid raw hook payloads, prompts, command bodies, terminal output, file contents, tokens, and spool entry data. Lifecycle diagnostics are limited to PID, port, local URLs, and workspace/runtime roots.
* Codex hook install backs up an existing user-level `hooks.json` before the first managed write, preserves user-owned hooks, and reports trust posture through compact status and `/hooks` guidance only. It does not copy Codex hook config bodies, trust records, transcripts, provider settings, account settings, or unrelated local config into diagnostics.
* Server JSON body size is capped at `2mb`.
* Local and Worker rate limits default to 240 requests per 60 seconds.
* The local server binds to loopback by default, restricts default CORS and WebSocket origins to local Vite dev origins, and can require `FACTIONOS_AUTH_TOKEN` for HTTP and WebSocket access.
* Codebase scans refuse filesystem root, require roots under the server working directory or `FACTIONOS_SCAN_ROOTS`, skip symlinks, ignore generated and historical artifact directories, cap files, cap file size, truncate content, and redact absolute roots from responses and progress events.
* Quest Board persistence is local-only. `suggestions.json` stores manager snapshots and compact scan status but does not by itself transfer data to providers, hosted storage, analytics, entitlement services, Worker federation, or public replay. Operators can delete the file from `FACTIONOS_HOME` or `~/.factionos` while the server is stopped.
* Provider-bound LLM text is redacted for prompts, paths, commands, tokens, URLs, and transcript-like values before optional SDK calls. LLM responses include provider mode and privacy headers.
* Memory route output redacts finding text, tags, and source task identifiers before broad route exposure.
* Session exports preserve CSV/JSON schemas while redacting prompt, path, command, token-like, URL, terminal, and transcript-sensitive values.
* Local session archive writes apply the same archive-boundary redaction before JSONL persistence and fail with compact one-time warnings if filesystem or serialization errors occur.
* Browser WebSocket frames and replay links are shape-filtered. Generated replay-share links redact sensitive fields and cap per-event size before encoding. Boot consumes valid hashes once and strips malformed replay hashes so refreshes do not repeat invalid replay attempts.
* Notice Board routes and WebSocket events validate canonical and compatibility payloads before state mutation. Related files are normalized to safe relative paths, target visibility is enforced by room and session filters, context lookup is bounded, and automatic lifecycle posts use privacy-safe summaries and dedupe.
* Browser settings localStorage is normalized on read. Empty, malformed, partial, stale, invalid enum, and storage-unavailable snapshots fall back to bounded defaults.
* Local erasure routes `POST /erasure/local/preview` and `POST /erasure/local/confirm` inherit local bearer auth, use `Cache-Control: no-store`, require explicit confirmation for deletion, and never return raw paths, prompts, exports, backups, logs, spool payloads, diagnostics, or tokens.
* The CLI `factionos erase` command previews by default, refuses non-loopback server URLs, requires `--confirm "ERASE LOCAL FACTIONOS STATE"` before destructive local execution, and formats only redacted counts, labels, and statuses.
* The web Settings local erasure panel separates browser-local cleanup from local-server filesystem cleanup, disables duplicate confirm actions while in flight, clears derived projection storage with other browser-local state, and keeps Worker, hosted, workspace-file, public replay, analytics, push, remote, and full trusted erasure claims unavailable.
* Outbound adapter formatter output redacts common local paths, command previews, webhook URLs, bot tokens, bearer values, and auth-header values.
* Browser notifications are opt-in, local-only, and backed by in-app fallback feedback for unsupported, denied, default, throttled, and constructor-failure states. No push backend, push subscription endpoint, VAPID use, or backend delivery route is shipped.
* Hosted operation diagnostics report push, Web Push, VAPID, remote access, tunnel, and operator diagnostics posture through compact labels and counts only. They do not expose subscriptions, VAPID private keys, Cloudflare ids, zone ids, tunnel tokens, local paths, prompts, commands, room payloads, logs, backups, exports, archives, replay buffers, scan payloads, or media drafts.
* Browser analytics readiness is consent-gated and disabled by default. Config alone, consent alone, website ids, or API keys do not activate capture. Opt-out wins, payload helpers are allowlist based, and the only active transfer path is the approved minimized Umami `/api/send` sender. No tracking script, beacon, SDK import, dashboard, recorder, heatmap, or server ingestion is active.
* War Room Worker rooms cap participants and retained recent events.
* War Room Worker health diagnostics expose only service, server time, app-level rate-limit metadata, and deployment type labels. They do not expose account ids, zone ids, tokens, request headers, client IPs, request bodies, room payloads, prompts, command output, local paths, exports, scans, media drafts, logs, or local diagnostics.
* Production-hosted smoke validation is sanitized by default. It rejects unsafe target URLs, credential-bearing URLs, query strings, fragments, localhost production targets, malformed responses, sensitive output, and raw repository or local endpoint leaks. `--no-network` records unavailable no-claim states without credentials or public fetches.
* Phase 08 Session 08 records passing local release-candidate gates and no-network hosted smoke, but live hosted smoke still blocks deployed public demo and Worker claims and keeps the optional production app shell unavailable. Local browser and no-network evidence must not be described as production-hosted validation.
* War Room Worker web integration uses shared schemas, duplicate-action guards, room-local authority checks, hashed authority storage, expected room revisions, idempotency keys, redacted event allowlists, catch-up filtering, sender exclusion, and visible unavailable states.
* War Room authority proves only possession of a Worker-issued room token for one participant in one room. It is not hosted account proof, SSO, organization membership, production auditability, public collaboration safety, or trusted erasure.
* Phase 04 media gates keep generated drafts non-runtime, preserve `EXAMPLES/` quarantine, require visible equivalents for audio, keep public-demo music lazy-loaded, and fail sensitive-output patterns in media docs and validation notes.

## Phase 02 Browser Closeout

Session 07 validated the browser-facing product surface without adding new hosted data flows. The app evidence covers local browser state, fallback art, replay/export/scan UI boundaries, and browser guards for unexpected page errors, console errors, failed local requests, and failed asset requests. The public demo evidence covers synthetic data only, path-prefixed service-worker scope, offline reload after one online visit, limitation copy, and no workspace imports.

The current public demo cache version is `factionos-demo-v9`. That cache still stores only static demo shell files and approved or conditional demo assets; it does not cache real local sessions, prompts, hooks, replay uploads, hosted account state, or War Room room data. Background music remains lazy-loaded and outside the shell precache.

## Phase 03 Orchestration Closeout

Phase 03 ships a local, in-memory, non-executing orchestration subset. The reviewed surfaces are task queue entries, source-owned agent templates, typed subagent lineage, mission graph frames, guarded-action proposals and decisions, local REST snapshots, compact WebSocket frames, web cockpit controls, CLI status/doctor output, hook/listener diagnostics, server diagnostics, replay and export adjacency, and narrow local recovery.

The shipped subset inherits loopback-first defaults, optional bearer auth where applicable, Origin/CORS controls, rate limits, compact validation errors, deterministic unsupported-route behavior, redaction, duplicate-action guards, and explicit unavailable or failed states. Diagnostics report counts, availability, status labels, durations, categories, and sanitized identifiers only. `factionos doctor --recover-orchestration` removes stale listener PID files and malformed spool JSON entries only; it is not trusted erasure.

War Room federation, hosted collaboration, hosted queues, inbound chat commands, public sharing, analytics, Docker isolation, broad remote execution, future media release expansion, and release decommission remain deferred or excluded until a later approved scope defines consent, authorization, scrubbing, audit, and validation requirements.

## Phase 04 Media Closeout

Phase 04 closes the local media catalog and audio/visual pipeline. It does not add hosted transfer, provider upload during runtime, analytics, public media hosting, War Room media federation, new full-app file-backed audio, or new personal data processing.

Media catalog, preview, promotion, runtime error, diagnostics, replay/export, public demo, and future hosted paths must treat these as sensitive until explicitly scrubbed or excluded:

* Raw prompts, transcripts, provider prompts, command bodies, terminal output, and raw request bodies.
* Tokens, OAuth IDs, bearer values, webhook URLs, service probes, and provider details.
* Sensitive local paths, home paths, workspace roots, transcript paths, and generated absolute output paths.
* Metadata that can reveal author, device, geolocation, source path, generator, or other private creation details.
* Copied historical excerpts, copied bundled code, copied media, or direct generation inputs from `EXAMPLES/`.

The media gap matrix at `.spec_system/archive/phases/phase_04/media_gap_matrix.md` is the current routing record for media provenance, risk, blockers, and owner sessions.

## Phase 04 Session 07 Media Gate

The Session 07 media gate remains the root release-readiness check for Phase 04 media. Session 08 reran it during closeout and kept its required docs token visible so future edits cannot silently drop the release gate reference.

Session 08 recorded local, credential-free media closeout evidence. The media release gate verifies catalog records, docs references, visual and public-demo media gates, draft manifest blockers, service-worker cache policy, browser evidence tokens, and sensitive-output patterns.

The gate fails release claims if checker output, docs, browser diagnostics, or validation notes expose raw prompts, provider prompts, command bodies, raw request bodies, tokens, broad local paths, provider secret assignments, or long `EXAMPLES/` excerpts. It keeps generated drafts and historical intake non-runtime unless a later reviewed promotion closes source, rights, attribution, metadata, accessibility, privacy, fallback, and budget blockers.

## Phase 05 War Room Closeout

Phase 05 closes the optional Worker-backed War Room subset. The validated surface includes room lifecycle, health diagnostics, leader approval, presence, reconnect, bounded catch-up, sender-excluded broadcasts, and allowlisted redacted remote context. Browser evidence covers local app desktop and mobile states for disabled, diagnostics, join, pending, create, approved, connected, reconnecting, unavailable, and redacted remote-context behavior.

The closeout does not add hosted auth, hosted storage, analytics, public replay hosting, inbound commands, remote execution, production-hosted app validation, mobile certification, or trusted erasure. Durable Object room data, browser hints, local logs, archives, exports, replay buffers, backups, and future hosted data still need release-record erasure evidence before any trusted deletion claim.

## Phase 06 Collaboration And Isolation Baseline

Phase 06 Session 01 adds source-backed requirements only in `.spec_system/archive/phases/phase_06/collaboration_isolation_safety_baseline.md`. It does not add new external transfer, hosted storage, analytics, public replay hosting, real execution, Docker isolation, production-hosted validation, mobile certification, or trusted erasure.

The baseline requires Worker collaboration to stay optional, compact, allowlisted, sender-aware, and bounded for catch-up. It blocks prompts, file contents, command bodies, terminal output, transcripts, secrets, broad paths, exports, replay buffers, scan payloads, media drafts, diagnostics, logs, backups, archives, memory, settings, PID files, spool entries, and quarantined historical content from shared collaboration payloads.

Future file, git, terminal, Docker, remote, or hosted executors require a separate threat model with consent, authorization, audit, rollback, redaction, tests, and docs before any mutation or command execution is shipped.

## Phase 06 War Room Authority

Phase 06 Session 02 adds room-local bearer authority to reduce participant spoofing and stale leader decisions without adding hosted accounts. Create and join responses return raw authority only to the requesting browser; the web store keeps it in memory and clears it on hydration changes, Worker URL or participant changes, leave/reset, rejected joins, expired authority, invalid authority, missing authority, and authority mismatch. Stale revisions and replayed decisions surface as stale authority until the browser rejoins or creates a room again.

Durable Object storage keeps authority hashes and metadata, not raw authority tokens. Snapshot, duplicate join, approve, reject, and socket setup require authority. Approve/reject also require expected room revision and idempotency metadata so duplicate retries are deterministic and stale or replayed decisions fail with compact errors.

The same sensitive-output exclusions still apply. Authority errors, health checks, browser copy, tests, docs, logs, incident notes, replay state, exports, and diagnostics must not expose raw authority tokens, request bodies, URLs, account ids, Cloudflare secrets, local paths, prompts, command output, replay buffers, exports, scans, media drafts, or local diagnostics.

## Phase 06 Closeout

Phase 06 closes the local collaboration, isolation, and mobile evidence scope. Focused tests and local app desktop/mobile Playwright evidence validate room-local authority, safe collaboration frame allowlists, sender exclusion, bounded catch-up, remote-context UI separation, non-executing isolation diagnostics, explicit unsupported-route envelopes, compact CLI/hook diagnostics, mobile layout reachability, focus behavior, pointer behavior, screen-reader labels, reduced-motion behavior, and long-text fit.

This closeout does not add hosted account identity, hosted storage, analytics, public replay hosting, push, remote runners, real file/git/terminal/Docker execution, production-hosted validation, mobile or WCAG certification, or trusted erasure. Phase 07 owns hosted service and identity guardrails. Phase 08 records release-hardening evidence, while unproven trusted-erasure, production-hosted app validation, and decommission claims remain no-claim.

## Phase 07 Hosted Transfer Baseline

Phase 07 Session 01 adds documentation-only hosted-service and payload privacy baselines under `.spec_system/archive/phases/phase_07/`. The baseline keeps hosted identity, hosted storage, analytics, public replay hosting, push, remote access, hosted diagnostics, production-hosted validation, and trusted erasure out of shipped claims until the owning session adds source, tests, consent, minimization, redaction, authorization, local fallback, and docs evidence.

Blocked hosted payload categories include prompts, provider prompts, file contents, command bodies, terminal output, transcripts, secrets, tokens, webhook URLs, auth headers, OAuth secrets, broad paths, exports, replay buffers, scan payloads, media drafts, diagnostics, logs, backups, Cloudflare account ids, zone ids, tunnel tokens, Supabase service-role values, Umami API keys, VAPID private keys, and quarantined historical content.

Publishable browser config is still browser-visible metadata, not a secret container. Server-only secrets and deploy-only credentials must stay out of browser bundles, logs, health responses, diagnostics, replay fragments, exports, archives, public demo code, and docs examples.

### Hosted Config Diagnostics Privacy

`GET /diagnostics/hosted-config` is local diagnostics only and inherits the local server auth boundary. It reports compact posture only: status labels, counts, categories, exposure labels, and docs paths. It must not return raw env values, Cloudflare account ids, zone ids, API tokens, tunnel tokens, provider keys, webhook URLs, bearer values, auth-header values, local paths, replay buffers, exports, archives, logs, backups, request bodies, prompt content, file contents, or terminal output.

Browser hosted config helpers accept only documented public-client values. Malformed URLs, credentialed URLs, query strings, fragments, reserved hosted placeholders, and blocked secret-like `VITE_` mirrors degrade to local-only status rather than enabling hosted auth, analytics, storage, push, public replay, remote access, or hosted diagnostics upload.

### Hosted Identity Privacy Guardrails

Phase 07 Session 03 keeps hosted identity planned or unavailable. The current source exposes only shared vocabulary, browser helper copy, and local diagnostics for the required posture. It does not store account sessions, OAuth codes, refresh tokens, ID tokens, account ids, organization ids, profile records, Supabase auth state, or account-backed consent state.

Before hosted identity can become active, a later session must prove explicit consent, session expiry, logout, revocation, account export, deletion handoff, role mapping, authorization checks, audit events, abuse controls, and local-only fallback. Analytics preferences, public replay, push, remote access, hosted storage, and operator diagnostics must each require their own consent or authorization boundary; room-local Worker authority does not grant any of them.

`GET /diagnostics/hosted-identity` inherits local server auth and returns only status labels, requirement labels, unsupported claim labels, non-overclaim labels, counts, and docs paths. It must not return raw account tokens, OAuth values, refresh tokens, ID tokens, account ids, organization ids, raw Worker authority tokens, request bodies, local paths, prompts, commands, replay buffers, exports, archives, diagnostics, logs, backups, or env values.

Room-local Worker authority remains one room-scoped bearer proof. It is not hosted account identity, SSO, organization membership, public collaboration safety, analytics consent, production audit proof, or trusted erasure.

### Hosted Persistence And Public Replay Privacy

Phase 07 Session 04 keeps hosted persistence planned or unavailable and public replay hosting disabled. The current source exposes shared vocabulary, browser helper copy, and local diagnostics only. It does not create a hosted database, storage bucket, migration, upload endpoint, browser direct storage write, account-backed persistence, public replay page, public replay index, takedown runtime, release-grade deletion, or trusted erasure workflow.

Blocked categories for hosted persistence and public replay include prompts, transcripts, file contents, code contents, command bodies, terminal output, secrets, credentials, broad local paths, raw env dumps, replay buffers, export bodies, archives, backups, diagnostic payloads, logs, scan payloads, media drafts, War Room payloads, cloud account identifiers, and quarantined historical content. Future hosted storage or replay publication must reject, redact, or minimize those categories before transfer and prove the behavior with focused tests.

Current replay links are local URL fragments. They cap event count and per-event size, redact sensitive fields, and do not upload replay data or create public replay records. Future public replay hosting must add explicit consent, payload caps, redaction, expiration, takedown handling, no-index posture, abuse controls, public-safe errors, authorization, and local-only fallback before activation.

Current exports and archives are local-first audit artifacts. Future hosted retention, export, deletion, expiration, and takedown wording is a requirement baseline only. It does not prove account deletion, storage deletion, backup purge, Worker state deletion, browser state cleanup, or trusted unified erasure; those remain no-claim unless a release record proves the exact boundary.

`GET /diagnostics/hosted-persistence` inherits local server auth and returns only status labels, eligibility labels, requirement labels, unsupported claim labels, blocked payload labels, counts, booleans, and docs paths. It must not return raw env values, tokens, service-role keys, storage keys, account ids, request bodies, local paths, prompts, commands, terminal output, replay buffers, exports, archives, logs, backups, scan payloads, media drafts, War Room payloads, or file contents.

### Hosted Analytics Privacy Guardrails

Analytics stays disabled unless public browser config and consent requirements are both satisfied. The current source exposes shared analytics vocabulary, browser readiness helpers, passive Settings copy, payload scrubbing tests, and an optional Umami `/api/send` sender for approved minimized events only. Local setup and verification evidence lives in `docs/runbooks/local-umami-analytics.md`.

Analytics may represent only coarse product posture fields: event id, surface, route id, status, feature, action, provider, consent state, bounded count, duration bucket, category, reason code, version labels, and docs path. Local helper output may include `localOnly: true`, but the runtime sender strips that field before network transfer. Payload helpers drop unknown fields and block prompts, provider prompts, transcripts, assistant messages, file contents, code bodies, diffs, patches, command bodies, terminal output, secret and credential values, full or credentialed URLs, broad local paths, raw env dumps, replay buffers, export bodies, archives, backups, scan payloads, diagnostics, logs, media drafts, War Room payloads, account identifiers, zone identifiers, tunnel tokens, and quarantined historical content.

Analytics config values are not consent. `FACTIONOS_ANALYTICS_ENABLED=true`, `UMAMI_HOST_URL`, `UMAMI_WEBSITE_ID`, and `UMAMI_API_KEY` cannot activate browser analytics by themselves; the sender uses browser-safe `VITE_` provider, enabled, host URL, website id, and consent values. Opt-out overrides config and prior consent. Website ids are represented only as configured or missing in browser helper output.

No analytics helper output should expose raw prompts, file/code content, commands, terminal output, transcripts, tokens, local paths, exports, replay buffers, scans, diagnostics, logs, backups, account ids, zone ids, tunnel tokens, media drafts, War Room payloads, provider secrets, website id values, or historical intake content.

The 2026-06-07 local browser verification checked that browser-originated events persisted only allowlisted posture keys such as `action`, `appVersion`, `buildVersion`, `category`, `consent`, `feature`, `provider`, `reasonCode`, `routeId`, `status`, and `surface`. That verification does not authorize broader analytics payloads or any production-hosted analytics claim.

### Hosted Operations Privacy Guardrails

Phase 07 Session 06 keeps push, remote access, tunnels, and hosted diagnostic agents planned, disabled, unavailable, or local-only. The current source exposes shared operation vocabulary, browser helper copy, local server diagnostics, CLI loopback-only status output, local notification copy, and bounded service worker backstop handling only.

Browser notifications remain local OS notifications. They require browser permission and app opt-in, but that opt-in is not push subscription consent. The web client does not create push subscriptions, call a push backend, read VAPID keys, or treat `VAPID_SUBJECT` as activation proof. Future push payloads must exclude prompts, transcripts, file/code content, command bodies, terminal output, secrets, credentials, local paths, raw env dumps, replay buffers, exports, archives, backups, diagnostics, logs, scan payloads, media drafts, War Room payloads, Cloudflare ids, zone ids, tunnel tokens, and account identifiers.

Remote access and Cloudflare Tunnel remain unavailable. `CLOUDFLARE_ACCOUNT_ID`, `CLOUDFLARE_ZONE_ID`, `CLOUDFLARE_API_TOKEN`, and `CLOUDFLARE_TUNNEL_TOKEN` are deploy-only or secret-bearing operational values. They must not be returned by browser config, health checks, diagnostics, CLI output, logs, replay, exports, archives, or docs examples. Remote access is not remote execution; file, git, terminal, Docker, Worker, hosted, and tunnel executors remain inactive until a later threat model ships.

`GET /diagnostics/hosted-operations` inherits local server auth and returns only status labels, surface labels, requirement labels, unsupported claim labels, blocked payload labels, counts, booleans, and docs paths. CLI status and doctor fetch that route from loopback URLs only. Non-loopback URLs fail closed with sanitized failure text.

Phase 07 Session 07 closeout re-verified the hosted-payload privacy posture across every Phase 07 boundary (hosted config, identity, persistence, public replay, analytics, push, remote access, tunnel, operator diagnostics, Worker, exports, archives, logs, and backups). The secret scan passed over 886 tracked text files, focused payload tests use synthetic probes, and no blocklisted category (prompts, file/command/terminal content, secrets, tokens, account/zone ids, tunnel tokens, broad paths, replay/export/archive/backup content, scan payloads, media drafts, or diagnostics) surfaced at any boundary. Phase 07 collects no personal data by default and makes no trusted-erasure or production-hosted claim; Phase 08 Session 08 keeps those claims no-claim or blocked where live smoke did not pass.

## Open Release Risks

Phase 08 Session 01 records the current release risk baseline in `.spec_system/archive/phases/phase_08/phase08_release_risk_matrix.md` and the claim-gate baseline in `.spec_system/archive/phases/phase_08/release_requirements_risk_baseline.md`. Those artifacts map open findings to owner sessions but do not close them.

Phase 08 Session 07 adds a sanitized legacy-evidence and media decommission record at `.spec_system/archive/phases/phase_08/legacy_decommission_media_release_gate.md`. It preserves posture conclusions only: retained ignored evidence, blocked media promotion, blocked raw sensitive output, tracked `docs/PROGRESS.md` retention, and retained archive records. It does not copy raw prompts, probes, OAuth values, token values, account ids, zone ids, provider payloads, command output, sensitive local paths, copied code, logs, backups, replay buffers, or quarantined media excerpts into stable docs.

The Session 07 cleanup posture is not trusted erasure. Retaining ignored evidence, keeping `docs/PROGRESS.md`, or blocking raw historical evidence does not delete local archives, browser state, Worker state, hosted placeholders, media staging, backups, logs, or workspace files. Final release copy must keep that distinction through Session 08.

* Route-specific authorization and runtime schemas are not complete for all future route families.
* Prompt, path, command, and event redaction still needs review for generic webhook full mode, future active analytics capture, federation, and any future hosted replay surface.
* Generic webhook full mode can forward raw event data when explicitly enabled.
* Local retention and erasure controls are not complete. Redacted archives are still retained local audit artifacts until the user removes them. Memory findings, settings, and browser replay state also need a unified erasure workflow before a trusted release.
* War Room trust boundaries still need hosted-grade identity, consent, revocation, and audit controls before broad hosted use; current authority is room-local bearer proof only.
* War Room Durable Object room-state deletion now has a Phase 08 Session 04 leader-authorized runtime for one room record: preview, exact confirmation, idempotency, redacted receipt, socket closure, partial failure, and verification are covered by focused tests. This is not full trusted unified erasure, not browser hint erasure, not local filesystem erasure, and not a hosted identity or production-hosted validation claim.
* Hosted auth and analytics capture must not be enabled without account lifecycle controls where applicable, consent, revocation or opt-out, audit events, scrubbing, authorization tests, payload tests, and local-only fallback.
* Push delivery, Cloudflare Tunnel, remote access, and hosted diagnostic agents must not be enabled without explicit opt-in, authorization, token expiration and revocation, rate limits, Origin/CORS controls, audit, abuse controls, payload tests, redaction, and local-only fallback.
* Phase 03 orchestration state needs unified erasure review across queue, lineage, guarded-action, diagnostics, valid spool files, replay, exports, archives, memory, settings, browser state, and local runtime files before a trusted release.
* Conditional media records still need source, rights, attribution, metadata cleanup, browser support, fallback behavior, accessibility, size budgets, public demo cache behavior, and sensitive-path minimization before release expansion.

## External Transfers

| Service                        | Trigger                                                                                                   | Notes                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| ------------------------------ | --------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Anthropic                      | `ANTHROPIC_API_KEY` plus `FACTIONOS_ALLOW_LLM_PROVIDER_TRANSFER=true` and LLM endpoints or engines        | May receive redacted prompt, recent activity, relative file paths, and file contents after local scrubbing. Without the transfer flag, routes use deterministic local fallback.                                                                                                                                                                                                                                                                                                                                             |
| Discord                        | Discord adapter configured                                                                                | Receives formatted event summaries.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| Telegram                       | Telegram adapter configured                                                                               | Receives formatted event summaries.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| Generic webhook                | Webhook adapter configured                                                                                | Receives compact summaries or raw event envelopes depending on config.                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Cloudflare                     | War Room Worker deployed and used                                                                         | Stores participant metadata, authority hashes and metadata, idempotency metadata, allowlisted recent room events, and filtered Notice Board relay history when used. Browser diagnostics can call `/health` and receive compact service, time, rate-limit, and deployment type metadata. The web cockpit sends authority tokens only for room lifecycle and socket requests, and sends only allowlisted redacted federation context or protocol-validated Notice Board coordination frames when a Worker URL is configured. |
| GitHub Pages and CDNs          | Static demo opened                                                                                        | Demo asset request metadata; no real local session data.                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| fal.ai and ElevenLabs          | Future/local media draft generation only when credentials and explicit provider-run selection are present | Not used by current runtime. Draft records must remain redacted and non-runtime until promotion gates pass.                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Supabase and Umami             | Optional hosted surfaces                                                                                  | Supabase is not active. Umami is the optional default analytics provider; the browser sender posts approved minimized events only when public config and consent are ready, and sends nothing for missing, denied, withdrawn, opted-out, malformed, or blocked-payload states.                                                                                                                                                                                                                                              |
| Web Push and Cloudflare Tunnel | Future hosted phases                                                                                      | Not active. VAPID and tunnel variables are reserved or deploy-only placeholders; current diagnostics and CLI output report posture only and do not contact push providers or start tunnels.                                                                                                                                                                                                                                                                                                                                 |

## Documentation Rule

Do not repeat raw public tokens, OAuth client IDs, probe responses, service-role values, webhook tokens, or local secrets in user-facing docs. Capture posture conclusions only.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://faction-os.gitbook.io/faction-os-docs/docs/privacy-and-security.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
