Privacy

Your text stays in your browser

The guest workflow is designed so document content does not need to cross a network boundary.

Open the local text workspace

Document processing

Pasted, sanitized, and harmonized text is held in browser memory for the current workspace. It is not posted to application APIs, written to the admin database, placed in a URL, or included in logs or error reports. Clearing or closing the workspace releases it. Draft persistence is not enabled by default.

Offline rules

The approved ruleset is public configuration, not user content. It can be cached in IndexedDB so scans work offline. Online clients may check for a newer published ruleset, but the request contains no document text.

Analytics

Analytics is optional and consent-controlled. Allowed events use coarse values such as a word-count bucket, finding-count bucket, score band, document mode, ruleset version, provider type, and offline status. Text, matched phrases, names, URLs, and fragments are prohibited.

Administration

Admin APIs store rulesets, source snapshots, revision checks, and audit history. They are protected by server-side sessions. Administrative rule-test fixtures are configuration data; guest documents do not enter this system.