Skip to main content

Privacy

What CERES collects.

Research captures and operational diagnostics are separate. CERES never sends recordings or task content to PostHog.

01

Operational diagnostics

CERES uses a deployment-scoped US or EU PostHog project to understand whether the public site, capture surface, monitor and hosted export operations are working.

In standard mode, browser events contain the CERES surface, Solo or Duet mode, build version, the name of a public page, fixed website interactions and fixed transitions for pairing, WebRTC, recording, export and Hugging Face delivery. Recording events cover arming, durable start, pause, resume, stop, final acknowledgement, publication and authoritative completion or failure. Export and upload events include cancellation and recovery outcomes. Durations are converted to broad ranges before transmission, including recording duration, LeRobot export duration, Hugging Face delivery duration, batch recording duration and the export-to-recording ratio. This lets the project identify slow exports without receiving an exact time.

Task-shape events contain only count ranges for defined and scheduled recordable, timed and open-ended subtasks, cycles and pauses after repetitions and cycles are applied. A broad duration shape reports one short task, one medium task, one long task, mostly short tasks, mixed tasks or mostly long tasks, weighted by scheduled repetitions. These events do not contain task titles, instructions, exact counts or individual task durations. A task-shape event is emitted once at the first recording in a run.

Workflow events can contain the final eight hexadecimal characters of a validated recording UUID and the final eight characters of its frozen protocol hash. A protocol name is included only when CERES has verified that the imported catalogue entry or GitHub Gist is public and its complete hash still matches the recording. Private and unlisted Gist names, local file names and manually entered names are never included.

Recorder finalisation diagnostics also contain bucketed sequence progress, queue depth and elapsed duration. Export media diagnostics contain fixed encoder backend, fallback reason, remux decision and hardware-attempt categories. Website interactions distinguish only capture-menu opens, capture or workflow mode selections, printing the instructions and opening the CERES GitHub page. A failure can contain a fixed diagnostic code or a sanitised JavaScript error type, allowlisted normalised technical message, normalised cause, operation stage, worker name, episode count and same-origin script coordinates. Unknown free text becomes "JavaScript error". This privacy page is excluded from page-view and website-interaction events. Hosted export logs contain a fixed operation name, outcome, HTTP status, route template, request method, deployment environment and service version together with sanitised JavaScript error details.

In standard mode, PostHog's cookieless server mode derives a privacy-preserving identifier during ingestion rather than using an account, session or browser-device identifier. CERES sends the cookieless sentinel, a bounded page hostname and a bounded browser user-agent string required by that mode. The service may use the request IP address, page hostname and browser user-agent to derive the identifier, then discards the address before the event is processed. CERES also disables GeoIP enrichment and does not add an IP address to event properties. PostHog adds a fresh non-personal event UUID for transport de-duplication.

02

What diagnostics exclude

CERES disables session replay, automatic click and form capture, dead-click and rage-click detection, heatmaps, performance capture, feature flags, surveys, persistent browser storage, campaign attribution, referrer capture and device-model collection.

Diagnostic events do not include account names, email addresses, task, prompt, transcript or capture content, raw run, session, episode, protocol, job or device identifiers, exact task counts, exact task or workflow durations, absolute recorder sequence numbers, exact queue depths, Hugging Face usernames or repository names, page URLs, query strings, referrers, clicked text, request bodies or headers, private tokens, credentials, absolute filesystem paths or cross-origin stack frames. They do not include exact finalisation durations or exact export-media durations. Local recording quality is reduced to fixed frame, gap, slow-hand and tracking-loss buckets. Technical exception messages and parameter values are scrubbed before transmission and stack data is restricted to script-relative coordinates. The public PostHog project token remains in event transport because the ingestion service requires it.

03

Research capture data

When a recording starts, CERES can collect outward video, microphone audio when enabled, WebXR head pose, hand joints, timestamps, explicit gap records and the run and task metadata specified by the research team.

Local capture keeps raw recording data in browser storage until the selected export is run. Data is sent to Hugging Face only when that export destination is selected. Research capture data is never sent to PostHog.

04

Incognito capture

The Incognito button beside the Solo and Duet selector is off by default. When it is on, CERES sends no page, surface, recording, workflow, export, upload, timing, task-shape or identifier-suffix events to PostHog. Authenticated account-export requests carry only the closed privacy mode needed to suppress hosted Hugging Face operation logs. That suppression is retained on a durable upload job and rechecked before deferred finalisation, status recovery or scheduled recovery telemetry. Changing a preference stops new telemetry decisions but cannot recall a browser or hosted operation already authorised and in flight under the previous setting.

Incognito retains a deliberately minimal reliability signal: a coarse device class, one fresh random twelve-character visit hash and parameter-scrubbed errors. The hash is created for the current page visit, is not derived from an account, device, session, recording, protocol or network address and is neither stored nor reused on a later visit. It is used only to form a personless ceres-incognito-<visit-hash> identifier for that visit. Incognito events disable person processing and GeoIP enrichment. They do not carry the standard cookieless sentinel, page hostname or raw browser user-agent, and the hosted proxy does not forward the browser user-agent to PostHog. Incognito errors use the same allowlisted error types and normalised messages as standard diagnostics. They do not include the exact episode count, CERES surface, Solo or Duet mode, build, browser, operating system, recording suffix, protocol suffix or public protocol name.

Incognito is not the absolute opt-out because those minimal reliability reports still pass to PostHog. For zero PostHog traffic, including no visit signal, error report or hosted Hugging Face operation event, disable anonymous diagnostics below or enable Do Not Track or Global Privacy Control in the browser.

05

Storage and control

CERES uses PostHog in cookieless mode and does not use cookies or session storage for analytics identifiers. It therefore does not display an analytics cookie banner. Browser Do Not Track and Global Privacy Control preferences are respected.

CERES stores the full opt-out and Incognito preferences locally. In standard mode it can also retain a bounded registry of verified-public protocol names and hashes so the correct public name can be recovered for a recording. Turning on Incognito, disabling diagnostics, Do Not Track or Global Privacy Control clears that registry. The Incognito visit hash is held only in memory.

You can disable anonymous operational diagnostics completely in this browser without changing pairing, recording or export behaviour.

Checking this browser's diagnostics preference.

The research team operating CERES controls participant consent, access to captures, export destinations and retention. Contact that team for access, correction or deletion requests concerning a research capture.

Last updated 16 August 2026.