Privacy & Telemetry (MVP) β
Modes:
- Off: no telemetry stored.
- Minimal (default): aggregated signals only (method used, p95 latency, utility flag), pseudonymous IDs.
- Enhanced (opt-in): extended metrics per project/team.
Principles:
- Data minimization: avoid raw content; store utility signals and timings.
- Pseudonymization: user/project IDs hashed locally; keys stay with the user/org.
- Retention: raw events 30β90 days; aggregates longer; manual delete supported.
- Consent: per-project opt-in/out; transparent docs.
Touchpoints:
- L1: search method metrics, success proxy.
- L4: experience records (task, nodes, result, validation) without sensitive payloads.
API Notes:
- Feedback endpoints must accept utility signals; deletion endpoints must exist.