Terms & Privacy

A diagnostic aid with an explicit evidence boundary

Effective 2026-08-31. Capability Lab provides explainable troubleshooting guidance, not a warranty, security audit, legal decision, or guarantee that a capability will work.

Use and limitations

Use the service only with evidence you are authorized to share. Do not submit credentials, private keys, cookies, access tokens, full environment files, personal data, private source, or production-sensitive payloads. The service does not execute, install, approve, authorize, or modify third-party capabilities.

Results are based only on sanitized supplied evidence and deterministic rules. They may be incomplete or wrong. Follow bounded steps, preserve backups where relevant, and stop when a result instructs you to stop. Capability Lab does not assign legal responsibility or publisher fault.

What leaves your browser

Raw text is processed by a browser worker that removes common secret, credential, path, private-address, hostname, and email patterns. You review the sanitized preview before submitting it. A defensive redaction pass runs again at the server boundary. Automated redaction is not perfect, so submit only a small reviewed excerpt.

Default diagnosis lifecycle

A normal diagnosis is analyzed without storing the submitted text as a report. Privacy-safe operational events may record the capability category, failing checkpoint, confidence, rule identifier, route, status class, and timestamp. They do not contain diagnostic text, raw IP, user-agent string, cookies, or account identifiers.

Optional private reports

Saving is explicit. A saved report contains the sanitized text, selected context, deterministic result, rule metadata, redaction counts, timestamps, and an optional outcome. It is accessed through an unguessable URL, excluded from indexing and caching, expires after seven days, and can be deleted immediately with the independent management token stored in the URL fragment.

Anyone who receives the read URL may view the sanitized report. Keep it private. Only a holder of the management token can delete it or record an outcome.

Abuse and security

Requests are size-bounded and rate-limited through an anonymous keyed daily IP digest; raw IP is not stored in the application database. Human verification may be required for report management. Automated abuse, attempts to evade limits, or submission of harmful/unauthorized material may be rejected.

Contact and changes

Operational contact details will be published only after a verified support channel is configured. Material privacy changes will update the effective date on this page. Existing saved reports retain their original seven-day maximum lifecycle.