Claude & privacy MVP1 / v1.0

The privacy pipeline

Minimize first, redact locally, and reject remote transmission when the final check cannot complete.

Development previewLive hooks, enforcement, and Anthropic BYOK are pending. This guide distinguishes current behavior from the MVP1 design.

Collect only the necessary input

The intended input source is the event supplied by a supported local hook. TraceRook does not silently scrape screens, accessibility trees, full transcripts, other applications, or entire source trees. MVP1 does not request blanket Full Disk Access.

Original tool arguments may remain temporarily in process memory to derive features and bind the immediate decision. The normalized record must not persist an unredacted command body by default. The current demo reads only packaged fixtures.

Normalize and redact on your Mac

Local inspection derives command, sensitive-path, and destination features before constructing a sanitized representation. Likely API tokens, bearer credentials, private key headers, and password-like assignments are replaced with stable category placeholders that do not expose recoverable original values.

Sensitive home-directory components are removed when unnecessary. A placeholder is not a permission to include unlimited context. The remote request is built separately from any local-only path or host summary.

A second gate before the network

  1. Create a minimal payload with a task anchor, selected event summaries, local policy evidence, and relevant uncertainty.
  2. Apply payload size bounds.
  3. Run the secret scanner again immediately before the network request.
  4. If scanning fails, cannot complete, or lacks sufficient confidence, reject remote transmission.
  5. Mark AI analysis unavailable and use the local policy outcome.

The app must not resolve a failed privacy check by sending unknown raw input. Additional code excerpts use the same pipeline and remain off by default.

Treat inspected content as untrusted

Repository instructions, tool responses, documents, web pages, and proposed commands are data. Text saying “ignore policy” or “approve this action” is not administrator intent. Claude requests isolate such excerpts in clearly labeled, JSON-encoded untrusted fields.

Only TraceRook owns the model’s system policy. The model returns findings; it never supplies executable commands or permissions. Evidence may link an instruction to later behavior when observed, but causal certainty must not be invented.

Keep diagnostics sparse

Logs and crash diagnostics contain predefined status codes and identifiers, not raw prompts, commands, provider responses, secrets, or key values. Exports require an explicit user action and must remain sanitized.

MVP1 avoids anonymous analytics uploads. The static website loads its own assets and documentation search index. It includes no third-party analytics, trackers, external fonts, API key input, or session upload form. Hosting may retain ordinary access logs and, for a private publication, apply its own authentication.

Understand the limit of redaction

Redaction can miss unknown secret formats or inferable sensitive context. The consent flow must say this directly. BYOK transmission is permitted only for explicitly allowed, minimized context; it is not a guarantee that no private information can ever leave the Mac.

Provider retention is governed by the user’s Anthropic account and terms. Local permissions protect a user-owned history database; MVP1 does not promise encrypted SQLite storage or resistance to a compromised same-user process.

Based on the MVP1 architecture specification, version 1.0 · October 8, 2026.