Document processing
Pasted, sanitized, and harmonized text is held in browser memory for the current workspace. It is not posted to application APIs, written to the admin database, placed in a URL, or included in logs or error reports. Clearing or closing the workspace releases it. Draft persistence is not enabled by default.
Offline rules
The approved ruleset is public configuration, not user content. It can be cached in IndexedDB so scans work offline. Online clients may check for a newer published ruleset, but the request contains no document text.
Analytics
Analytics is optional and consent-controlled. Allowed events use coarse values such as a word-count bucket, finding-count bucket, score band, document mode, ruleset version, provider type, and offline status. Text, matched phrases, names, URLs, and fragments are prohibited.
Administration
Admin APIs store rulesets, source snapshots, revision checks, and audit history. They are protected by server-side sessions. Administrative rule-test fixtures are configuration data; guest documents do not enter this system.