Local-first by default

Privacy

The MVP is designed so you can generate release documentation without creating an account or uploading model weights.

What stays in your browser

Your form responses and generated draft are stored in your browser's localStorage. They remain available after a refresh on the same browser until you use “Clear form” or clear site data in your browser.

What is not uploaded

Shared-device warning

Anyone using the same browser profile may be able to reopen the locally saved draft. Clear the form when using a shared or managed device.

Analytics boundary

The app emits coarse product events such as generator start, successful generation, copy, import, and download. No form values are included. The MVP does not configure a third-party analytics account; a deployment may connect these events to a privacy-preserving analytics system without transmitting full form responses.

Future hosted features

Accounts, project history, hosted red-team jobs, and API-key handling are not part of the MVP. Before any hosted feature is introduced, its retention, encryption, deletion, and logging behavior must be documented separately.