Claude & privacy MVP2 / foundation

Keys, history & deletion

Separate API key lifecycle, sanitized local history, and integration removal.

Development previewMVP2 foundation complete. Live hooks, enforcement, and Anthropic BYOK are pending. Planned behavior is labeled separately from working features.

API keys belong in Keychain

The planned BYOK implementation stores its API key in macOS Keychain with appropriate login accessibility and signed-app-family access restrictions. The service reads the value only when required for an authenticated request.

Keys must not go into UserDefaults, SQLite, fixture JSON, logs, or the static website. The app needs distinct replace, validate, and delete operations with accurate errors and no full-key redisplay. Keychain integration is pending in the current build.

The intended local store

The per-user service is the sole SQLite writer. Its database path is ~/Library/Application Support/TraceRook/data/tracerook.sqlite, with a 0700 parent directory and 0600 database file.

Use WAL, prepared statements, foreign keys, migrations, indexes, and transactional approval updates. Session identities must handle nullable subagent IDs correctly: a plain nullable UNIQUE key can permit duplicate logical sessions.

MVP1 relies on macOS file permissions and minimization. Database encryption is a future consideration, not a current claim.

Default retention

DataDefaultNotes
Sanitized event summaries14 daysDaily purge; shorter user settings permitted
Incidents and approvals30 daysKeep explanations and decision audit
Session recordsUntil references expireRemove after retained events/incidents are gone
API keyUntil user deletes or replaces itKeychain; independent from history
Raw tool JSON / transcriptsDo not persist by defaultTemporary decision memory only

Durable retention and purge are pending MVP2.1 functionality. The current fixture experience is not a live activity archive.

Three separate operations

  • Delete All Local History: remove retained session, event, finding, and approval records under a defined safe operation.
  • Delete API Key: remove the Keychain credential and make BYOK unavailable.
  • Uninstall Integrations: remove only TraceRook-owned hook entries and optionally unregister the helper.

Uninstalling an integration must not silently erase history or another agent’s settings. Deleting history must not imply deleting data Anthropic already received.

Cloud and diagnostics

Cloud Demo account and usage data are bundled samples. No real enrollment, billing record, or cloud history exists. Diagnostics exports are local and sanitized unless the user explicitly chooses a destination.

Local history settings and provider terms are separate privacy boundaries. See Anthropic consent and analysis and safe uninstall behavior.

Based on the MVP1 specification, the additive MVP2 specification, and the acceptance matrix · October 8, 2026.