From 12bba22dc95b5fbbdc0a26461d8aed5a65ea9ce0 Mon Sep 17 00:00:00 2001 From: Ben Barclay Date: Wed, 2 Sep 2026 07:16:57 +1000 Subject: [PATCH] docs(telemetry): state the consent containment rule on operator surfaces PR re-review caught that cli-config.yaml.example and the setup wizard still described the OLD day-stamp gate ("period starts on or after the day you opted in"). The actual gate (CONSENT_GATE_SQL) requires the entire package period to be contained in one recorded consent window - stricter, and privacy-significant at opt-in/revocation boundaries: a package straddling a revocation starts after opt-in yet is correctly held back. Both surfaces now state the containment rule literally; docs A.1 already did. --- cli-config.yaml.example | 7 +++++-- hermes_cli/setup.py | 8 +++++--- 2 files changed, 10 insertions(+), 5 deletions(-) diff --git a/cli-config.yaml.example b/cli-config.yaml.example index 0675156986..6cb99466dc 100644 --- a/cli-config.yaml.example +++ b/cli-config.yaml.example @@ -1792,8 +1792,11 @@ display: # Nothing is uploaded unless you also set `send: true`. That is a separate # opt-in and requires `enabled`; it never turns collection on by itself. # When sending is on: -# * only packages whose period starts on or after the day you opted in are -# ever transmitted, so data collected beforehand stays on this machine; +# * only packages whose entire collection period falls within one +# continuous recorded consent window are ever sent. Consent windows open +# when you enable sending and close when you disable it, so data +# collected before you opted in — or during any gap between opt-ins — +# stays on this machine; # * each package carries the profile-scoped ID as-is. It is a random UUID # with no hardware, account, or host-derived content, and deleting the # shared-metrics directory resets it. diff --git a/hermes_cli/setup.py b/hermes_cli/setup.py index 2ec08da8af..e1baacd0ca 100644 --- a/hermes_cli/setup.py +++ b/hermes_cli/setup.py @@ -2467,9 +2467,11 @@ def setup_telemetry(config: dict): print_info("service. Packages carry your profile-scoped install ID, a") print_info("stable random UUID that identifies this profile across days") print_info("(it contains no personal information and is reset by deleting") - print_info("the shared-metrics directory). Only packages from the day you") - print_info("opt in onwards are ever sent, and sending can be turned off") - print_info("again at any time.") + print_info("the shared-metrics directory). Only packages whose entire") + print_info("collection period falls inside a recorded consent window are") + print_info("ever sent — data from before you opt in, or from any gap") + print_info("while sending was off, stays on this machine. Sending can be") + print_info("turned off again at any time.") shared_metrics["send"] = prompt_yes_no( "Send shared metrics to Nous?", default=shared_metrics.get("send") is True,