Privacy by separation
Private organization and public publication are different systems.
Public pages
The public biography and archive contain only records explicitly approved for publication. No analytics, advertising pixels, behavioral profiling, or third-party social embeds are included by this project.
Local workbench
The default workbench stores its matrix in the browser on the current device. Selected files are hashed locally and are not uploaded by the static version. Browser storage can be cleared, lost, or accessible to someone with access to the same browser profile; export the matrix and preserve originals separately.
Cloudflare owner vault
The optional backend is designed for a Cloudflare Access-protected owner identity, private R2 storage, and D1 metadata. Cloudflare may retain infrastructure and security logs according to account configuration. The project does not claim that all infrastructure logging can be eliminated.
Publication review
Every record defaults to private_hold. Medical information, third-party information, identifiers, signatures, barcodes, addresses, contact information, and images require deliberate review before publication. Importing a repository never changes this status.
Corrections and removal
A corrected public record receives a new version and relationship to the earlier record. Removing access cannot guarantee removal from third-party downloads, archives, caches, screenshots, or copies already made.