Data-flow ledger · current code and honest boundaries

This preview does not need to know who you are.

The explorer keeps its controls in the browser and its shareable state in the visible URL. App code sets no cookies, analytics, accounts, submissions or persistent profiles; browser, host and external-site boundaries remain explicit.

Meaning of zero

A zero-collection claim needs a boundary, not a slogan.

Zero application-controlled visitor records does not mean zero network metadata. The browser must request static files from a host, URL state can be present in that request and a reader-selected external destination applies its own systems after navigation.

Host review gated

7 data-flow records · recipient and persistence attached

Follow each signal to its real boundary.

Open one record at a time. The hash stores reading focus only; it does not change a privacy setting, start processing or hide the remaining static records.

All 7 data-flow records remain available. No privacy setting or processing state is calculated.
Network edge01local boundaryA host must deliver the static publication
Trigger

A reader requests a page, stylesheet, script, image or font.

Data or signal
Ordinary transport metadata can include an IP address, user agent, time and requested URL. A query string is part of the requested URL.
Recipient
Only the local preview server in the inspected build. No production host or processor is configured by this task.
Persistence
The application has no log store. A future host may operate infrastructure logs and must be reviewed before activation.
Current control
Static same-origin assets, restrictive security headers and no production binding.
Boundary
The interface cannot honestly promise zero network metadata or define a future host's retention before that service is selected.
How to reproduce
Inspect the build output, deployment configuration and network panel; review the chosen host's access, logging and retention controls before release.
Browser + URL02reader controlledResearch priorities and comparison weights live in a visible shareable URL
Trigger

A reader selects a pair, changes a research-priority slider or adjusts a weighted comparison; scripts replace the documented query state or build a copyable link.

Data or signal
Allowlisted pair and preset identifiers, schema versions, and bounded 0–10 numeric values. The schemas have no field for a name, email address, organisation or free text.
Recipient
The current browser, anyone the reader chooses to share the link with and potentially the page host when that URL is requested.
Persistence
Browser history, bookmarks and shared messages are controlled by the reader's browser and chosen communication service. The app creates no database record.
Current control
Allowlisted pairs and presets, bounded integer values, compact versioned schemas, separation of the two tool states and safe malformed-state recovery.
Boundary
Do not encode confidential research plans or personal information in a URL. A visible URL is not a private storage channel.
How to reproduce
Inspect history.replaceState and both URL parsers, search for storage and submission APIs, and confirm copied links contain only documented pair, preset, version and numeric state.
Browser feature03reader initiatedClipboard writing happens only after an explicit action
Trigger

A reader activates Copy research brief or Copy citation link.

Data or signal
The current page URL or an internal citation URL.
Recipient
The browser and operating-system clipboard selected by the reader.
Persistence
Clipboard lifetime and synchronisation are controlled by the browser, operating system and device settings; the site does not create a copy history.
Current control
Button-triggered write only, visible success or failure status and a text fallback when clipboard access is unavailable.
Boundary
The application cannot govern cloud clipboard synchronisation or what the reader does with a copied link.
How to reproduce
Activate each copy control, inspect its status output and confirm no clipboard read, form submission or app storage follows.
Page memory04transient localOpen panels and reading lenses are transient interface state
Trigger

A reader opens a details record, dialog, mobile menu or editorial lens.

Data or signal
Control identifiers, open/closed state and selected reading focus.
Recipient
The running page in the current browser tab.
Persistence
Ordinary disclosure state ends with the page session. A deliberately shareable lens may be represented in the URL instead.
Current control
Native controls, progressive enhancement, static fallbacks and no localStorage, sessionStorage or IndexedDB use.
Boundary
Browser extensions, assistive technologies and the browser itself operate outside the application's storage boundary.
How to reproduce
Reload representative routes, inspect browser storage, disable scripts and confirm substantive records remain in static HTML.
Page memory05transient localResearch-index text remains inside the open page
Trigger

A reader types a word or phrase into the global research index to filter locally rendered publication records.

Data or signal
The typed query and the resulting list of matching internal routes. The field accepts free text, so readers should still avoid entering personal or confidential information.
Recipient
Only the running page in the current browser tab; the query is compared with text already present in the static index.
Persistence
The query is cleared when the dialog closes and is not added to the URL, browser storage, clipboard, request body or application database.
Current control
No form wrapper, submit action, fetch request, analytics event or storage API; the input has a 120-character limit and filters an app-local allowlist.
Boundary
Browser extensions and assistive technologies can observe page content outside the application's control, so local-only is not a safe place for secrets.
How to reproduce
Type a query, inspect the visible URL and network activity, close and reopen the index, then confirm the field is empty and no storage or transport API was called.
External destination06reader initiatedOfficial sources receive a visit only after the reader leaves
Trigger

A reader opens an official source from the source drawer.

Data or signal
The destination receives ordinary network metadata for its own page request. DPDP.best sends no form payload or research-priority values.
Recipient
The selected government or regulator website, under its own technology and policy.
Persistence
Outside DPDP.best's control after navigation.
Current control
No embeds or prefetches, explicit click-to-open behavior, noreferrer links and a no-referrer page policy.
Boundary
The publication cannot guarantee the destination's cookies, logs, accessibility, security or retention behavior.
How to reproduce
Inspect the network panel before a click, open one official source deliberately and verify that no external host was contacted beforehand.
Empty intake07disabledNo visitor submission path exists
Trigger

No event: corrections, accessibility feedback, accounts, messages, uploads and payments are deliberately inactive.

Data or signal
No visitor-provided field exists for the application to receive.
Recipient
None within the application.
Persistence
None within the application.
Current control
No forms, endpoints, account system, inbox integration, database or persistent data model; CSP form-action is none.
Boundary
An absent intake path is not a response promise and does not establish that the publication has no accessibility, editorial or legal issue.
How to reproduce
Inspect every built route for forms and submission controls, and keep future intake behind purpose, owner, notice, security and retention review.

Five app-local controls

Inspect the implementation, then keep its limit beside it.

These controls describe the production bundle generated here. They are not a host audit, legal opinion, privacy certification or guarantee about a reader's browser.

C1Inspected locally

No application storage APIs

Production source and build checks find no localStorage, sessionStorage, IndexedDB or application cookie assignment.

Limit

Browser history, cache and clipboard remain browser-controlled. Cookies are host-scoped rather than port-scoped, so loopback QA can inherit unrelated cookies from another local service using the same host name.

C2Inspected locally

No runtime collection transport

The app has no fetch, XMLHttpRequest, sendBeacon, WebSocket, EventSource, form submission or upload path.

Limit

Static asset delivery still uses ordinary HTTP requests to the selected host.

C3Inspected locally

No automatic external content

Official records are local structured data; government pages open only after an explicit reader action.

Limit

The selected destination operates independently once the reader leaves.

C4Inspected locally

Referrer minimisation

The page and preview headers use a no-referrer policy; external source links also use noreferrer.

Limit

The destination still receives its own request's network metadata.

C5Inspected locally

Private-preview indexing boundary

Page metadata, robots rules and headers all request no indexing, following, caching snippets or archiving.

Limit

Noindex is a crawler instruction, not authentication or a substitute for a private-access layer.

Service quarantine

Inactive means absent—not pre-approved.

No service below can receive visitor data in this build. Each row states the review needed before activation.

01
Capability

Production hosting

Not configured

Approve provider, access model, logging, retention, security headers and rollback.

02
Capability

Analytics or monitoring

Not present

Separate product approval, purpose/minimisation review, accurate notice and default-off implementation.

03
Capability

Forms, accounts or messaging

Not implemented

Approve owner, fields, purpose, notice, security, response standard and event-based retention.

04
Capability

Persistent storage

Not implemented

Approve data model, access controls, deletion/export design, processor terms and threat review.

Release ledger

One local baseline. Five gates remain.

Production behavior must be inspected on the exact host. Local absence of collection cannot silently become a deployed privacy promise.

G1
Current evidence

Reproduce the static baseline

App source, production build, network/storage inspection and focused integrity checks.

Reproduced locally
G2
Release gate

Select and review a private-preview host

No production host, project, binding, access plan or credential is configured.

Gated
G3
Release gate

Approve infrastructure logging and retention

No provider-specific log inventory, purpose, access owner or deletion event exists.

Gated
G4
Release gate

Repeat browser storage and request inspection

Must be reproduced against the exact deployed build and host, not inferred from local output.

Gated
G5
Release gate

Approve any new visitor-data capability

Analytics, forms, accounts, messages, uploads and persistent storage remain outside scope.

Gated
G6
Release gate

Complete human privacy and security review

The local engineering record is not a legal assessment, certification or production guarantee.

Gated

Active application processors

No processor or visitor-data service is configured.

This is an inspected local-build statement, not a promise about a future host. Update the processor, retention and threat records before any service is connected.

Read the use boundaryInspect access limits

Carry the boundary forward

Keep sensitive information out of shareable URLs.

The explorer accepts only pair identifiers and bounded research-priority values. A copied link is intentionally portable, not confidential storage.

Inspect the URL explorerOpen publication controls

Article revision record

What changed on this page.

This register begins with the private-preview editorial rebuild. It records material content, method, interface and trust-policy changes without inventing a history that predates the available repository evidence.

ROUTE/privacy
ENTRIES03
Inspect the full revision register
Publication, privacy, correction, accessibility or use policy changedAdded a seventh data-flow record for the global research index, including its free-text boundary, transient recipient, clearing behavior and explicit absence of transport or storage.
Why this changed
A local-only search field still accepts reader-provided text, so the privacy ledger must state where that text exists, how long it lasts and why it should not contain secrets.
Claim impact
The zero application-record claim remains unchanged; the notice now distinguishes transient on-page query text from visible URL state and ordinary static-host requests.
Review state
Human legal or editorial review still required
Change ID
PRIVACY-20260828-03
Source impact

No legal source changed; this entry records method, interface or trust policy.

Publication, privacy, correction, accessibility or use policy changedReplaced the generic notice with a six-flow browser, host, clipboard and external-navigation ledger plus five implementation controls, four inactive services and six release gates.
Why this changed
A truthful zero-collection statement must distinguish application-controlled records from browser history, requested URLs, hosting metadata and reader-selected external destinations.
Claim impact
The revision narrows the prior no-transmission wording: app code creates no visitor database, but URL and network surfaces remain visible and a production host requires separate review.
Review state
Human legal or editorial review still required
Change ID
PRIVACY-20260826-02
Source impact

No legal source changed; this entry records method, interface or trust policy.

Publication, privacy, correction, accessibility or use policy changedRecorded the browser-only URL state, absence of analytics and absence of persistent personal-data storage in the private preview.
Why this changed
The publication should model data minimisation and disclose the actual local static behavior rather than a future production policy.
Claim impact
The notice describes only the inspected preview; any later data collection requires a new review and dated change entry.
Review state
Reviewed for this private preview
Change ID
PRIVACY-20260821-01
Source impact

No legal source changed; this entry records method, interface or trust policy.

Source record

Source record

Authority
Pinpoint
Legal status
Checked
Basis

Official guidance can explain a rule, but it does not replace the controlling legal text.