CRUSETRA
Appendix E Privacy ← Back to the findings

Where your data can and cannot go, item by item.

A folder ajar: cream paper showing inside, a green tab on the cover: nothing leaves it.

Here is where your data can reach and where it cannot. It covers the tests that keep the network shut, the folder that never enters a repository, the scrubbing on what travels, and each mechanism's limit. Each limit listed here is one the source itself states. The last section says what you send us when you order a report, and how long it is kept.

No telemetry, and a test enforces it

Telemetry is code that reports usage to a vendor. Searching the sources for each telemetry pattern returns exactly one hit, the comment of the test that forbids them. That test goes through each source file and requires each network destination to be local or on an allow‑list of three entries. The three entries are the local model host, the public benchmark download, and the OCR language files that npm run tessdata -- --prime fetches once; none of the three runs during a measurement. A test enforces this, so it does not depend on a policy.

This test has a stated limit. It finds calls by pattern, so code built another way to send data out would escape this test. That is why the behavioral check below watches the running process and reads no source text.

Verify the allow-list test

The suite fails if any source file gains a network destination outside the list of two entries.

run it yourself
npm testfails on any new outbound destination

Where it livessrc/crusetra.test.ts:1066 · src/crusetra.test.ts:1095

Where your measurements live and stay

Each measurement on your data lands in a folder that git ignores, on purpose. The code spells this out in as many words, so no measurement can travel into a repository. The detailed attempt journals, which do hold extracted values, live under that same folder. For client cases they exist only on an explicit flag, and by default there is no journal. The tool also writes exactly one local marker, the date of its own first use, in a file you can read (~/.crusetra/premiere-utilisation.json; an earlier date under ~/.cascade, the former name, still counts). The thirty‑day evaluation clause reads that date to tell you where you stand. That file holds one labeled date, plus the former file's path when the date was carried over from it, and it is never transmitted.

A journal header records the CPU model, the platform and the load. The hostname, username and path never enter it.

What travels is scrubbed first

The only network record kept under version control is the egress observation, which lists what the measuring process connected to. Each path argument becomes a placeholder before that file is written, and the committed file shows it: the observed command reads --cases=<file>. Its answer, over 21 samples of one pass (one full measurement run), is no connection observed for the whole pass. The same file records its own limit, that sampling gives a lower bound and no kernel capture.

The local screen, served by npm start, puts its error messages through path‑scrubbing at both return points, and a dedicated test checks this. The source also names one assumed weakness: the scrubbed roots come from a fixed list, so a path under an unusual root would pass through.

Watch a measurement pass

The egress command watches the measuring process and publishes the hosts seen, its answer and its own limit.

run it yourself
npm run egresssamples connections during a pass, with the record committed and paths scrubbed

Where it livessrc/egress.ts:343 · egress.json:12

The screen stays on this machine

The local screen listens on this machine's loopback only, an address only this machine reaches. A test holds this in place. It sweeps each server in the repository and keeps no list of names. Any write request carrying a foreign origin, an origin other than the screen's own, is refused before it reaches the handler. The server keeps no request log at all. Its only console output is the startup line and port errors, so no body, no address and no access is written anywhere.

Verify the screen

Start it and probe it. It listens on loopback only and refuses writes from a foreign origin.

run it yourself
npm startserves on localhost only, no request log

Where it livessrc/server.ts:728 · src/server.ts:530

Two production dependencies, swept for telemetry too

The tool has two production dependencies, the model runtime library and tesseract.js, the OCR engine. A telemetry sweep across each of their installed packages finds hits only in a development tool's editor protocol, and none in the production path. Each library has one remote destination it could reach: the public weights host for the runtime, used once on first run, and the public language-file host for tesseract.js, which the tool never lets it reach: the engine is pointed at the folder npm run tessdata -- --prime filled once, with its cache off, and the egress check holds that no connection opens while it reads. The offline flag turns even that off by telling the library never to reach the network. The library disobeys for one public metadata file on each load. The tool now names that file and does not let it pass in silence. Sweeping the dependencies themselves found one more address. A package inside the runtime embeds a CDN host for WebAssembly (WASM) artifacts, on a code path this tool never exercises. It is named here because the allow‑list in our sources cannot see inside a dependency.

One limit is stated as well. Native binaries cannot be read by a text sweep, so a text search (grep) cannot verify that corner. The lower bound for that corner is the behavioral egress record above.

The report you receive

The measured report is written beside your CSV, and none of it goes into the tool's folders. It contains rates, confidence intervals (the range a true rate is likely to sit in) and the questions asked. The values extracted from your documents never enter it. It closes with the sentence it earns: measured on this machine, nothing left it.

A second file is written beside it, the sealed record (hashed, then frozen: its content hash is checked before a figure is shown), and it is the one file the extraction cost audit asks you to send us. It holds counts, a right, wrong or blank verdict per case and field, your file's name and its SHA-256 hash, and the prices and volume you declared. A declared price can be under a vendor contract: replace it with a list price before sending if it is. No document and no value read from one is in that file.

What you send us for a report

Two services run on our side, and for them you do send us something. For a Screening report, you email a list of company and vessel names, with the IMO number of a vessel when you have it: a CSV, a spreadsheet, or names in the body of the mail. For a Routing free test, you email the measured record the tool wrote beside your CSV, the file ending in -measured.json: counts, a right, wrong or blank verdict per case and field, your file's name and its SHA-256 hash, and the prices and volume you declared. In both cases nothing else is asked for, and no document of yours is.

What we receive is used for that report and for nothing else. Once the report is sent, your file and the mails that carried it go to the trash and are permanently deleted within 30 days. A weekly re-screen subscriber's list is kept for the re-screen and goes the same way when the subscription stops.

HS Industries LLC is responsible for this processing. Write to contact@crusetra.com to ask what we hold about you, to have it deleted earlier, or to object.