Expire records on the device by a real window, and say the server's out loud #4
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "claude/retention"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The last of the review's four foundations. Every manifest, the registry and the console said
-1, a test asserted it, and the decisions page called it settled. This reverses that decision on LNK's word, with the old words quoted in the page, and keeps the half of the reason that was true.What changes. Each manifest now carries two numbers and the console shows them side by side.
local_daysis how long a record stays on the device once the server has confirmed receiving it: 90 for content (screenshots, typed text, clipboard, shell commands, websites), 365 for timing (window activity, typing rhythm).remote_daysstays-1: the server copy is training data and is kept until deleted, declared out loud. The registry carries the local number,contracts-lintholds registry and manifests equal on both and refuses a local window under a day, andhere-contractasserts a finite local window and an indefinite, stated server one.What the gate does. Once at start and hourly, it sweeps by the registry's windows through the same deletion path a person's delete uses, under a receipt marked
retention. It does not expire a record the server has not confirmed: the device is a buffer, and a buffer does not discard what has not been read. Those are kept and counted, so a store growing because nothing uploads says so. It sends the server no deletion: local expiry is not erasure. Indicator health rows go after 30 days.Docs. Decisions page (reversal with the old text quoted), platform-team page, legal note item 7, README invariants, the byte's-journey page.
Proof. Store: an old uploaded frame expires with its pixels, an old unuploaded one and a young one stay, the receipt names the sweep and the server was not asked, a second sweep is a no-op. Gate: the same through the write path with the clock moved. Health log prunes past its window. Sending the server a deletion on expiry fails the store test, checked by making it. Linux verifier on the pinned toolchain: 282 Rust + 86 TypeScript = 368 tests, every stage, exit 0. Not run here:
verify.ps1and the end-to-end suite on Windows.The numbers are a choice. 90 and 365 are stated assumptions, one line each in a manifest, linted to the registry.