Privacy Policy & Zero-Cloud Architecture Specification

At RamenTask, privacy is not a user setting or a vague legal disclaimer: it is a core engineering principle built into our software architecture. This policy details how we enforce 100% client-side processing and technical data protection.

1. 100% Client-Side Processing (Zero-Server Architecture)

All files and inputs (PDFs, images, JSON structures, signatures, passwords) are processed exclusively in your device's RAM using JavaScript and WebAssembly (WASM). Application logic executes locally in your browser's V8 or JavaScriptCore engine. Zero bytes of your documents are ever transmitted across the network to our servers or any third-party infrastructure.

2. Network Security & HTTP Header Enforcement (CSP)

Our infrastructure enforces a strict Content Security Policy (CSP) with `connect-src 'self'`. This instructs your browser to block any unauthorized network transmissions to external endpoints. Additionally, we implement Strict-Transport-Security (HSTS), X-Frame-Options: DENY, and Permissions-Policy to disable hardware access (camera, microphone, geolocation).

3. RAM Memory Hygiene & Instant Garbage Collection

RamenTask does not store or persist processed files in local databases like IndexedDB. Temporary Object URLs (`blob:http...`) created for file downloads are explicitly revoked via `URL.revokeObjectURL()` immediately upon completion. When closing the tab, your browser's Garbage Collector reclaims and wipes all associated memory buffers.

4. Air-Gap Isolation Guarantee (Full Offline Support)

Our web application supports full Air-Gap offline operation via Service Workers. You can load RamenTask, disconnect your Wi-Fi or network connection, and process sensitive documents completely offline. Physical network isolation provides non-repudiable mathematical proof that no data is intercepted or exfiltrated.

5. Local Storage & GDPR / ePrivacy Compliance

RamenTask uses zero tracking or advertising profiling cookies. We only utilize browser `localStorage` to save your preferred language (`ramentask_preferred_locale`). This technical storage falls under the Strictly Necessary exemption (Article 5(3) of the EU ePrivacy Directive and GDPR) and requires no intrusive consent banners.