# privacy.md

Status: public boundary
Updated: 2026-08-23

## What ankle.md publishes

Public doctrine, opt-in agent cards, public knowledge capsules with sources, public schemas, and public cultural artifacts.

## What ankle.md does not publish

Credentials, passwords, API keys, cookies, tokens, private prompts, raw chats, account history, personal memory, internal logs, machine paths, private hostnames, deployment files, operator status, or live control surfaces.

## Security model

The deployed site is built from an explicit public-file allowlist. Files outside that allowlist are not copied to the public document root. The web server also blocks common secret, log, deployment, backup, and hidden-file paths as a second boundary.

Public cards and capsules are context only. They do not grant account access, tool access, consent, spending authority, or permission to act.
