CoalWash Privacy Policy
August 8, 2026 · View on GitHub
CoalWash collects nothing and phones nowhere — and it treats your memory as the private data it is.
- No telemetry. No usage data, analytics, or identifiers are collected, stored, or transmitted — by the hook, the engine scripts, or the skill.
- No network calls. The hook and every engine script are offline by design (Phoenix #7): local filesystem only, no sockets, no requests. (The self-update check is the agent's
/coalwash:updateprocedure, run only with your consent — never the hook.) - Your memory IS the data under management — CoalWash minimizes its movement. Files are processed in place; backups (snapshots) stay in the project's own
.claude/coalwash/dir and are never transmitted. That dir self-ignores by construction — the engine drops a catch-all.gitignoreinside it, so snapshots stay out of version control even in a project that tracks.claude/. The only party that ever reads memory content is your own session's model — the same trust boundary your platform already established by loading those files into context. localOnlyis the trade-secret mode — an agent-honored contract, not a code-enforced transmission block. SetlocalOnly: trueand the SKILL contract runs mechanical Quick only, skipping the semantic tier entirely (no content-bearing sub is spawned) — but no executable intercepts a tool call; the no-sub behavior depends on the agent honoring this setting, the same as its memory-is-DATA-never-instructions rule. What IS code-enforced: the flag itself can't be weakened by a project config once a globallocalOnly: trueis set (mergeSafety,config-load.mjs).- Receipts are metrics, never content. Every receipt and gauge line carries sizes, counts, and estimates — never memory-content snippets. Token figures are a local char-heuristic estimate, labeled
~est, not a platform-verified read. - Error reports are manual and scrubbed. When something misbehaves, your agent may offer to open a GitHub issue; nothing is submitted automatically, you see and edit the contents first, and the report template carries mechanical facts only (operation, counts, error class) — never the memory text.
- Local files only. All state lives in files you can read: the caliper state
~/.claude/projects/<slug>/coalwash/state.json(per-project lean floor, session timestamps, the last recorded gauge verdict, and the pending once-per-crossing ask state — numbers, no content, no time-based snooze), the transaction dir[project]/.claude/coalwash/(lock, WAL journal, snapshots, retention bins,keeps.jsonkeep-verdicts — copies of your own files and your own keep decisions, on your own disk), the config (~/.claude/.coalwash.jsonglobal, optional per-project override under[project]/.claude/coal/coalwash.jsonor the legacy[project]/.coalwash.json— see README's Configure section for the full read order), and the self-update throttle stamp~/.claude/coal/coalwash/update-check(a timestamp, nothing more).
Questions: open an issue at https://github.com/TheColliery/CoalWash/issues.