Alpha privacy
This is the one-page data-handling description for alpha candidates who may feed employer meeting content into a Phronesis workspace. It describes alpha behavior; it is not a formal privacy policy or legal advice.
The workspace is your directory.
Alpha Phronesis stores workspace state as plain Markdown on the operator's disk. V1 has no hosted workspace, no hosted product telemetry, and no hosted index. The local event log stays local, and message body capture is off by default.
Your AI surface is the processor.
Claude Code, Codex, or the AI surface you choose processes conversation and staged material under that vendor's terms. Phronesis's local harness decides which staged files enter a given session; Phronesis adds no second hosted processing pipe in alpha.
Untrusted material cannot become canonical by itself.
Imported material, including meeting transcripts from meetings you attended,
is untrusted by default. It lands in raw/. A compile from any
untrusted source produces a draft, and the operator must approve it before it
becomes canonical compiled/ state. Promotion into the shared codex
is a second approval gate.
Everything defaults private. Objects can be marked context-ok or
shareable only through explicit operator choice; nothing
auto-promotes beyond private.
Stage only what you are allowed to store and process.
Start with your own notes, sanitized examples, public or already-approved docs, and transcripts only where recording, storage, and AI-tool use are allowed. Do not stage secrets, regulated customer data, legal or privileged material, HR or compensation content, unreleased financials, or any work content your employer does not allow in the AI tool you chose.
If the policy is unclear, use redacted or synthetic material until you have an answer.
Leaving costs nothing.
The workspace is your directory. You can read it in Obsidian, VS Code, or any editor without Phronesis. Export packages durable files and strips transient state. Deleting the workspace is deleting files you own; agents do not have a delete action type for canonical state.