Data boundaries · updated 28 July 2026
Privacy and Access Boundaries
Public documentation should make it easier to understand the system without exposing manuscripts, customer data, credentials, or non-public releases.
Public
Approved descriptive metadata, permitted public destinations, release versions, access conditions, and explicit exclusions may be public when the rights holder approves them.
Private and authorized
Manuscripts, excerpts not cleared for release, private source-record JSON, customer and reader data, authorization credentials, contracts, and editorial drafts remain private. Authorized-reader delivery must verify entitlement before protected material is made available.
Privacy is not an afterthought
A future interactive reader or MCP integration must minimize data movement, show what content it can access, and avoid silently collecting unrelated local project data.
Related documentation
For a concrete public record, inspect the metadata-only Context Pack demo. It remains separate from protected manuscript content and private editorial systems.