Plain English
Short payloads can still carry sensitive meaning.
Technical summary
Tools should avoid hidden logging of source text, compact payloads, registry choices, or validator reports unless a public policy explicitly says otherwise.
Deep spec
Future hosted tools need a data-retention policy before accepting real user payloads.
Data boundaries
- Browser prototypes run locally in the page.
- Do not submit secrets or private payloads into prototype tools.
- Do not treat screenshots as durable validation evidence.