Skip to content

feat(analytics): recover gateway and first-party diagnostic retention - #33

Merged
yaacovcorcos merged 4 commits into
mainfrom
codex/analytics-recovery-20260906
Sep 6, 2026
Merged

feat(analytics): recover gateway and first-party diagnostic retention#33
yaacovcorcos merged 4 commits into
mainfrom
codex/analytics-recovery-20260906

Conversation

@yaacovcorcos

@yaacovcorcos yaacovcorcos commented Sep 6, 2026

Copy link
Copy Markdown
Contributor

What changed

Recover the unfinished analytics gateway work onto current main. Keep strict generated desktop contract validation, D1-first delivery, bounded retries and export serialization, authenticated deletion/tombstones, retention maintenance and useful operator reporting.

The owner-approved split stores Diagnostic-class desktop records only in Scient's central D1 ledger for 30 days. Essential/Product-class copies may go to PostHog under truthful provider-managed retention wording. Diagnostics are accessible through bun run analytics:report, not stranded on users' machines. Reconciliation excludes deliberately first-party-only records. Provider erasure verification completes requests; submission alone does not.

Qualification

  • bun run check: passed (133 tests, 1 explicitly opt-in cross-repository test skipped).
  • Built desktop worker -> loopback gateway -> mocked PostHog proof: passed under Node and Electron's non-GUI runtime, including a repeat against the rebuilt final desktop candidate.
  • Exact generated validator/fixture parity: passed.
  • All prepared HogQL queries accepted by the live project in read-only validation.
  • Local Wrangler/D1 migration rehearsal: all six migrations applied successfully.
  • No production migrations, deployment, dashboard mutation or collection activation performed.

Review and rollout

Owner explicitly authorized merge after the requested copy shortening, accepting reliance on source/automated review instead of an additional hands-on preview. This is an owner-authorized review exception, not a claimed visual pass. Desktop ingress and PostHog export remain false in deployment configuration. Merge is authorized once required checks pass; no production collection activation.

Merge/deploy this compatible validator and migrations before releasing the dependent desktop producers. Then qualify live synthetic delivery/deletion, provisioning and maintenance before enabling the approved gates. A Pages deployment does not deploy this Worker. Pending/blocked legacy erasures require operator attention; no physical PostHog retention deadline is promised.

Documentation impact: Updated — README.md and src/pages/privacy.astro. Dependent PRs: desktop #256 and Scient plan #108.

Privacy preview for human review: https://d428bf52.scientfactory-website.pages.dev/privacy/ . Website CI and the Pages preview passed. The cross-repository proof was repeated successfully against the rebuilt final desktop candidate under Electron.

AI assistance: Codex (GPT-5-based agent), Codex desktop harness. Human privacy/product acceptance remains separate from automated and agent review.

Current privacy-copy update

Public copy now matches the single sharing switch and default-on preference when analytics is available, preserving saved Off/narrower choices. It does not promise a notification: the prepared desktop notice is disabled pending audience/timing decisions. The full data exclusions, first-party/PostHog storage distinction and asynchronous deletion limitations remain. bun run check rerun passed: 133 tests, one explicit opt-in test skipped, type/binding checks and both builds. The owner subsequently authorized the shortened copy without another hands-on review. No deployment or gate activation.

Final copy and integration review

Shortened the desktop section to four compact paragraphs without removing the data exclusions, sharing control/default, central storage/retention distinction or asynchronous deletion safeguard. The notification remains disabled and is not promised by public copy. Merged current main's qualified dependency updates (#27); full bun run check passed again (133 tests, one explicit opt-in test skipped, formatting, type/binding checks, website and edge builds). No source conflicts or unresolved review threads. Remaining GitHub/Pages checks must qualify the pushed head. The owner requested merge; this does not deploy the analytics Worker or enable its disabled ingress/export gates.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 6, 2026

Copy link
Copy Markdown

Deploying scientfactory-website with  Cloudflare Pages  Cloudflare Pages

Latest commit: 81b12eb
Status: ✅  Deploy successful!
Preview URL: https://c5efdbcd.scientfactory-website.pages.dev
Branch Preview URL: https://codex-analytics-recovery-202.scientfactory-website.pages.dev

View logs

@yaacovcorcos
yaacovcorcos marked this pull request as ready for review September 6, 2026 18:32
@yaacovcorcos
yaacovcorcos merged commit 18851bf into main Sep 6, 2026
2 checks passed
@yaacovcorcos
yaacovcorcos deleted the codex/analytics-recovery-20260906 branch September 6, 2026 18:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant