Private and public data
Public GitHub distribution
Section titled “Public GitHub distribution”Sharing uses a public repository. Its source and Git history are already public, including anything you committed accidentally. Menlo does not make a private repository public on your behalf or sanitize its entire history.
The directory exposes the verified maker/repository identity, app link, registered Xcode recipe, selected commit, and listing metadata. Selected media in menloapp/ are public. Deploy authorizes publishing the metadata and preview assets it generates and pushes.
GitHub source reviews publish the reviewer’s verified GitHub identity, commit, recipe, statement, scopes, notes, and timestamp. Withdrawals preserve history. Do not put credentials or private findings in public review notes.
User access tokens are not stored in the public directory or its ledger. Browser review sign-in uses short-lived process memory; its authority ends on expiry, sign-out, or server restart.
Private work
Section titled “Private work”Private intents, references, local activity, absolute paths, dirty working-tree observations, execution receipts, pairing secrets, DeviceKey material, and Apple signing credentials are separate from GitHub registration. Private phone requests travel as encrypted envelopes.
A coding request can disclose necessary context to the configured agent/provider. Automatic Simulator preview generation sends the Simulator screen and accessibility structure to the configured local Codex route. Those are execution disclosures, not permission to publish unrelated personal data.
The public listing and a source recommendation do not prove or publish the recipient’s physical installation. Apple signing identity and phone selection stay in the recipient’s local environment.
Historical Ship and Claim
Section titled “Historical Ship and Claim”A historical Ship publishes a sanitized source artifact and a closed Companion-signed catalog binding release identity, commitments, recipe, permissions, and public checkpoint. Its narrow on-chain witness does not contain private lineage or intentions.
A historical Claim publicly relates one account and Shot at an exact release/checkpoint with a Claim-mark commitment and non-transferable receipt. It does not expose raw gesture points, physical devices, Apple identity, private prompts, or an install fact. These are separate from GitHub registrations and reviews.
App-local Git boundary
Section titled “App-local Git boundary”Generated .tohseno/ records include Git-visible continuity and exact ignored private/transient paths. Never blanket-ignore the directory. Excluding it from a source-tree commitment avoids self-reference; it does not establish publication permission.
When evidence is absent, the product records absent or unknown rather than inventing a private or physical fact.