Genesis PreviewE1 admittedSemantic Snapshot implemented500 Atlas identitiesQuery Lab: liveRead-onlyNo arbitrary URLsHosted CI: startup blocked

Live read-only Genesis baseline plus protected E4.7 agent, ontology and model candidates. Public MCP, frontier-model execution and TNOE training are not deployed; no arbitrary URLs.

TWIRX Reference implementation and public service of the Typed Web Commons

Privacy-preserving activity

Measure whether the public proof is useful without tracking people.

The deployed aggregate-only collector counts coarse page, Lab, proof and funding events without raw IPs, cookies, fingerprints, user identifiers or retained questions. Counts are private, expire after 90 UTC date buckets, and are not unique-person analytics.

Aggregate collection active; person-level analytics absent

coarse private daily aggregates only; no unique-person count. The first-party module reports only bounded event classes to a Unix-socket collector. The operator dashboard is private and is not routed by Caddy.

Counts are not people

TWIRX does not publish a visitor count or pretend that page events identify humans. Bots can inflate aggregates, JavaScript-disabled visits are missed, and one person can generate several events.

Coarse operational counters only

Public pages

Page views, FUTO visits and funding visits.

Lab

Anonymous session starts, queries and proof downloads.

Agent

Aggregate agent-run count on the agent surface only.

Outbound

GitHub clicks and coarse referrer classes.

Reliability

Errors plus latency count, sum and maximum.

Date

Daily UTC buckets retained for at most 90 days; no per-person history.

Data the collector does not retain

Network identity

  • Raw IP addresses: no
  • Hashed IP addresses: no
  • User-agent strings: no
  • Raw referrer URLs: no

Behavioral identity

  • Cookies: no
  • Fingerprints: no
  • User or session IDs: no
  • Questions, answers or result content: no

Private operator boundary

  1. Unix socket onlyThe candidate collector does not open a public TCP listener.
  2. Aggregate validationOnly bounded event, surface, status and coarse-referrer classes are accepted.
  3. Durable or failAn event is rolled back when aggregate persistence fails.
  4. Mode 0600State and generated operator dashboard are private to the service account.
  5. No public dashboardThe dashboard is noindex,nofollow and not served by the public website.
  6. Operator exclusion?twirx_operator=1 stores one constant, origin-local browser flag and suppresses events until it is cleared. The flag is never sent to the collector and is not an identifier.
  7. Bounded retentionOnly the most recent 90 UTC date buckets survive state restoration or a new event.

Known limits

  • Anonymous counters can be inflated by bots and are not unique-person analytics.
  • Coarse referrer classification is performed transiently in the browser; the raw referrer is never sent.
  • Count, sum and maximum do not provide a true latency percentile.
  • The operator exclusion is browser-local and must be enabled separately on twirx.org and lab.twirx.org. Clearing site data clears the exclusion.
  • Events can be forged or blocked, so these aggregates are operational signals rather than audit evidence.

Collector design evidence