Capability matrix
Updates, diagnostics, and privacy
The first-party anonymous website aggregates are separate from release-pending v0.9.7 desktop diagnostics and product analytics.
The v0.9.7 candidate can check a fixed HTTPS feed and defer restart while work is active. It is not part of the current public v0.9.6 build, and the production feed plus signed predecessor-to-candidate smoke are not yet verified.
- Public release
- Not in v0.9.6 · production verification pending
The candidate's first-run privacy prompt initially displays reliability diagnostics selected, but preselection is not consent: persisted consent stays false, its identifier stays null, and its SDK and network path stay off until the user explicitly saves the choices. Choosing “Keep both off” saves false/false. The candidate destination is Sentry's EU region. Error events ingested during the Business trial may remain for up to 90 days; new events ingested after the Developer-plan downgrade use 30 days, without retroactively shortening trial-era expiry. One-time reports remain separately authorised. The current public v0.9.6 build does not send desktop diagnostics.
- External service
- Sentry EU · 90-day maximum, then 30 days for new events
The same first-run prompt initially displays limited product analytics selected, but persisted consent stays false, its identifier stays null, and its SDK and network path stay off until the user explicitly saves the choices. The candidate sends only 24 fixed, content-free events to PostHog EU Cloud, which retains accepted events for up to one year on the current Free plan. Client IP storage, GeoIP enrichment, person profiles, autocapture, replay, and account linkage are disabled. Turning analytics off stops future sending; already accepted events follow the provider retention or deletion process. The current public v0.9.6 build does not send desktop product analytics.
- External service
- PostHog EU Cloud · up to one year
Public-page activity is combined directly into daily aggregate counts. The system uses no cookie, LocalStorage, visitor, session, advertising, or account identifier; stores no raw event stream or complete browsing journey; excludes account and work areas; and honours Global Privacy Control and Do Not Track.
- Measurement boundary
- First-party aggregate counts · not unique people