What we count
A fixed allowlist accepts coarse product events. Everything else is rejected or removed before storage.
Allowed
Information:
Counts are not a file catalog
Usage counts cannot carry private library content, personal text, commercial payloads, or exact money values.
- Named screen and action events from the published allowlist.
- Fixed error, result, and reason codes.
- Counts, durations, sizes, byte totals, and amounts only as broad buckets.
- App, engine, and browser classes needed to diagnose compatibility.
Never included
- File names, paths, root labels, item identifiers, previews, hashes, or payload bytes.
- Searches, questions, answers, transcripts, notes, proposals, or any other free text.
- Email, phone, name, tax identity, exact place, coordinates, or address.
- Raw private-library or earnings quantities, evaluator results, scores, or census answers.
How the boundary is enforced
The validator rejects unknown event names and unknown properties. A first-party random session value is hashed by the server and rotates daily; it is not an account identifier. When usage counts are off, events are dropped instead of queued for later.