> For the complete documentation index, see [llms.txt](https://docs.thecolliery.org/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.thecolliery.org/tools/coalwash/privacy.md).

# Privacy

**CoalWash collects nothing and phones nowhere — and it treats your memory as the private data it is.**

* **No telemetry.** No usage data, analytics, or identifiers are collected, stored, or transmitted — by the hook, the engine scripts, or the skill.
* **No network calls.** The hook and every engine script are offline by design (Phoenix #7): local filesystem only, no sockets, no requests. (The self-update *check* is the agent's `/coalwash:update` procedure, run only with your consent — never the hook.)
* **Your memory IS the data under management — CoalWash minimizes its movement.** Files are processed in place; backups (snapshots) stay in the project's own `.claude/coalwash/` dir and are never transmitted. That dir **self-ignores by construction** — the engine drops a catch-all `.gitignore` inside it, so snapshots stay out of version control even in a project that tracks `.claude/`. The only party that ever reads memory content is your own session's model — the same trust boundary your platform already established by loading those files into context.
* **`localOnly` is the trade-secret mode — an agent-honored contract, not a code-enforced transmission block.** Set `localOnly: true` and the SKILL contract runs mechanical Quick only, skipping the semantic tier entirely (no content-bearing sub is spawned) — but no executable intercepts a tool call; the no-sub behavior depends on the agent honoring this setting, the same as its memory-is-DATA-never-instructions rule. What IS code-enforced: the flag itself can't be weakened by a project config once a global `localOnly: true` is set (`mergeSafety`, `config-load.mjs`).
* **Receipts are metrics, never content.** Every receipt and gauge line carries sizes, counts, and estimates — never memory-content snippets. Token figures are a local char-heuristic estimate, labeled `~est`, not a platform-verified read.
* **Error reports are manual and scrubbed.** When something misbehaves, your agent may *offer* to open a GitHub issue; nothing is submitted automatically, you see and edit the contents first, and the report template carries mechanical facts only (operation, counts, error class) — **never the memory text**.
* **Local files only.** All state lives in files you can read: the caliper state `~/.claude/projects/<slug>/coalwash/state.json` (per-project lean floor, session timestamps, the last recorded gauge verdict, and the pending once-per-crossing ask state — numbers, no content, no time-based snooze), the transaction dir `[project]/.claude/coalwash/` (lock, WAL journal, snapshots, retention bins, `keeps.json` keep-verdicts — copies of your own files and your own keep decisions, on your own disk), the config (`~/.claude/.coalwash.json` global, optional per-project override under `[project]/.claude/coal/coalwash.json` or the legacy `[project]/.coalwash.json` — see README's Configure section for the full read order), and the self-update throttle stamp `~/.claude/coal/coalwash/update-check` (a timestamp, nothing more).

Questions: open an issue at <https://github.com/TheColliery/CoalWash/issues>.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.thecolliery.org/tools/coalwash/privacy.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
