← Files ClaraARCHIVED FILE

privacy/hosted-services/plugin-feedback.json

8.64 KB · Oct 2, 2026 · 00:29 UTC

↓ Download file

{
  "schema_version": 1,
  "service_id": "plugin-feedback",
  "display_name": "Mparanza Plugin Feedback",
  "provider_or_recipients": [
    "Mparanza plugin change-request service"
  ],
  "workflows": [
    "clara"
  ],
  "governed_paths": [
    "skills/clara/SKILL.md",
    "scripts/change_requests.py",
    "scripts/check_change_requests.py",
    "scripts/check_for_update.py",
    "hooks/cowork-hooks.json",
    "repository/modules/change_requests/api.py",
    "repository/modules/change_requests/store.py",
    "repository/modules/hosted_services/api.py",
    "repository/modules/pdp/legal_content.py",
    "repository/modules/hosted_interviews/api.py",
    "repository/modules/hosted_interviews/job_state.py",
    "repository/modules/hosted_interviews/review_service.py"
  ],
  "trigger": "In either the OpenAI or Claude Cowork Clara package, a sufficiently evidenced problem or a suggestion is submitted only after the user sees and approves the exact sanitized request. An incomplete problem is never created. After a receipt exists, SessionStart may automatically poll its opaque status token for a fixed-version or needs-information notification. Follow-up evidence is transmitted only after the user sees and separately approves it.",
  "automatic": true,
  "data_sent": [
    {
      "id": "approved-text-request",
      "when": "After explicit consent to transmit one sanitized problem or suggestion",
      "content": "Schema version, problem or capability kind, plugin name and version, idempotency identifier, and the selected JSON request. Problem reports must include occurred time, runtime, operation, reproduction, and at least one bounded diagnostic evidence string. The helper enforces that mechanical shape but does not detect personal data, judge semantic sufficiency, or anonymize the file. Clara's host-specific instructions require the assistant to show, sanitize, and obtain consent for the exact request. The shared API also admits partial diagnostics when every missing time/runtime/operation or reproduction value has an explicit reason and bounded evidence remains. Clara's existing client still requires its complete diagnostic shape; the broader server admission does not expand what that client submits."
    },
    {
      "id": "automatic-client-context",
      "when": "With an approved text problem or suggestion submission",
      "content": "Submission timestamp, operating-system family, Python version, and the fixed plugin-change-request client identifier. The helper does not collect a username, path, environment value, document, account identifier, or stable device identifier."
    },
    {
      "id": "approved-follow-up-evidence",
      "when": "After status polling returns a specific needs-information question and the user approves the exact sanitized answer",
      "content": "Change-request identifier, locally held opaque status token, idempotent evidence-update identifier, bounded summary, and one or more sanitized evidence strings. The original request and client or case material are not resent."
    },
    {
      "id": "optional-suggestion-interview",
      "when": "After the user separately chooses the short hosted voice route for a general improvement suggestion",
      "content": "Plugin name and version, generic client-free opportunity text, language, and submission identifier; the participant's later hosted explanation is outside the text-submission payload. The service creates a prepared Hosted Interviews session for the plugin-improvement campaign; subsequent microphone audio, transcript, events and review use that service, with its separately recorded retained-session boundary."
    },
    {
      "id": "automatic-status-poll",
      "when": "On SessionStart when stored request receipts exist",
      "content": "Change-request identifier and opaque status token for every locally stored receipt selected by the checker, including resolved requests; no original case or request text is resent by this poll."
    },
    {
      "id": "interview-recovery-events",
      "when": "During the hosted microphone interview and when the participant leaves its page",
      "content": "Connection recovery, browser playback-blocked and microphone mute/unmute events are stored by Mparanza with the active attempt. Page departure can finalise already received transcripts and audio for post-call processing. The microphone energy meter is computed and displayed locally in the browser; no meter samples are uploaded. Interrupted evidence remains stored and retryable under the existing interview retention arrangement."
    }
  ],
  "data_returned": [
    {
      "id": "submission-receipt",
      "when": "After a successful problem or suggestion submission",
      "content": "Change-request identifier, opaque status token, legacy open or fixed release status, explicit disposition, needs-information question when applicable, fixed version when available, and validated install URL"
    },
    {
      "id": "suggestion-interview-link",
      "when": "After creating the optional one-minute suggestion interview",
      "content": "Mparanza interview URL and associated durable receipt fields"
    },
    {
      "id": "status-update",
      "when": "During automatic polling of previously submitted requests",
      "content": "Whether each request exists, its legacy release status, explicit disposition, needs-information question when applicable, fixed version, and install URL"
    }
  ],
  "access": {
    "arrangement": "The client submits to fixed Mparanza HTTPS endpoints and stores the returned opaque status token locally. In Claude Cowork that state is stored under CLAUDE_PLUGIN_DATA; in the OpenAI package it uses the plugin's existing private local state. Plugin source does not establish who inside Mparanza can access request content. Optional suggestion interviews exist only in the OpenAI package and use a returned Mparanza browser URL. Exact-text consent and sanitization are workflow obligations; the CLI does not authenticate consent or detect identifying information. Status tokens authorize status and evidence operations and must be treated as credentials. The default HTTP transport can retry a specific certificate error using a normal verified TLS context with X.509 strict-mode validation disabled; hostname and certificate verification remain enabled. Base-URL validation is not DNS pinning or a general redirect sandbox.",
    "controls": [
      "Remote requests are restricted to HTTPS mparanza.com or www.mparanza.com outside local tests.",
      "Payload and response sizes are bounded.",
      "A durable idempotency record prevents a network retry from creating a second request.",
      "Problem files without the required bounded diagnostic shape are rejected before transmission.",
      "Claude Cowork does not package the hosted voice interview or custom version-update client.",
      "Follow-up evidence requires the locally stored opaque status token and a separate idempotent update identifier."
    ]
  },
  "retention": {
    "status": "documented",
    "statement": "Submitted feedback remains a Mparanza support record until administrative deletion. The plugin also stores local pending payloads, receipts, and status tokens for retry and status notification until local plugin state is removed. Hosted suggestion interview sessions have their own retained records/media under Hosted Interviews; finishing or expiring the link does not delete them. Local state writes use mode 0600 where supported and retain retry payloads, receipts and tokens; this does not erase separately saved approved request files or establish provider/log retention. Hosted interview temporary audio assembly is session-owned and removed on normal worker exit or the next lock-protected inspection/dispatch after interruption; active work is preserved and cleanup failure propagates. This does not delete the original retained interview media or establish a timed cleanup guarantee."
  },
  "security_controls": [
    {
      "id": "fixed-origin-and-bounded-payloads",
      "control": "The helper restricts remote requests to the Mparanza HTTPS origin and bounds request and response sizes before storing a receipt."
    },
    {
      "id": "bounded-diagnostic-contract",
      "control": "Clara's client rejects incomplete problem diagnostics. The shared service accepts complete diagnostics or explicitly explained missing values with bounded evidence; it rejects unexplained or contradictory missing fields. Token-authorized follow-up evidence remains bounded and idempotent."
    }
  ],
  "review": {
    "reviewed_at": "2026-09-30",
    "reviewed_by": "privacy-surface-review",
    "basis": "hosted_service_boundary_review_of_source",
    "source_fingerprint": "a8c5d1ef58fac38f50d93b3d2c7b12d30bbe43d151c554f7e9cd24dc77c10cf6"
  }
}

SHA-256: 7c8176f46abb5e5e25f6be314f10b70772fc64b6861f58b5f3644a49ec48f06e