{"channels":{"approval_disclaimer":"Platform names describe compatible connection paths, not marketplace approval, endorsement, or universal availability.","statement":"PDFSight provides one guided document workflow through ChatGPT, Claude, and compatible MCP Apps hosts. The assistant is the interaction channel; PDFSight owns workflow state, deterministic PDF operations, and temporary artifact delivery."},"contract_version":"2026-08-14","deployment":{"source_commit":{"deployment_workflow":".github/workflows/cd.yml","reported_by":"/health","runtime_environment":"RELEASE_SHA","value":"48196d76b075102a4be5d834b04eef09bb2cb28e"}},"product":"PDFSight","providers":[{"name":"PDFSight","role":"Receives the files, tool inputs, and field values needed for the workflow; owns temporary workflow state, deterministic PDF construction and filling, and temporary artifact delivery."},{"name":"Google Gemini","role":"Receives rendered document-page images for field and document interpretation."},{"name":"OpenAI","role":"Processes hosted ChatKit and ChatGPT interaction data when those channels are used."},{"name":"Anthropic","role":"Processes Claude conversation and tool-interaction data when that channel is used."},{"name":"Amazon Web Services S3","role":"Stores temporary source and processed PDF artifacts when S3 storage is enabled."},{"name":"Postmark","role":"Delivers one-time account-verification emails. PDFSight sends the recipient address, display sender, subject, and verification-message content; PDF documents are never included."}],"public_fixture":{"field_types":["text","multiline","checkbox","date","signature"],"id":"community-event-volunteer-registration-v1","prohibited_content":["SSN or SIN","health identifiers or medical details","bank, card, or account numbers","real organizations or people"],"repository_path":"web/fixtures/test_form.pdf","route":"/review/sample-registration-form.pdf","schema_path":"web/fixtures/sample-forms.json","synthetic":true,"visible_label":"SYNTHETIC DEMO - NO REAL PERSONAL DATA"},"retention":{"form_session_state":{"configuration":"src/mcp_server.py::SESSION_TIMEOUT","default_seconds":1800,"display":"30 minutes of inactivity","enforcement":"src/mcp_server.py::SessionStore._cleanup_expired","mechanism":"bounded lazy cleanup during session operations","storage":"process-local memory"},"hosted_chatkit_state":{"cleanup_environment":"CHATKIT_CLEANUP_INTERVAL_SECONDS","cleanup_interval_seconds":60,"default_seconds":1800,"display":"30 minutes of inactivity","enforcement":"src/chatkit_server.py::MemoryStore","environment":"CHATKIT_THREAD_TTL_SECONDS","limitation":"Each application process has an independent store; history is neither durable nor shared across workers.","mechanism":"bounded lazy cleanup during thread and item operations","production_configuration":"config/deploy.yml","storage":"process-local memory"},"local_mcp_artifacts":{"default_seconds":21600,"display":"up to 6 hours","enforcement":"src/mcp_server.py::cleanup_persisted_entries and load-time expiry checks","environment":"MCP_PERSIST_TTL_SECONDS","mechanism":"lazy deletion during persistence and artifact access","production_configuration":"config/deploy.yml","storage":"local filesystem persistence fallback"},"one_time_download_tickets":{"default_seconds":300,"display":"5 minutes or one successful use, whichever comes first","enforcement":"src/auth.py::AuthService.consume_download_ticket","environment":"PDFSIGHT_DOWNLOAD_TICKET_TTL_SECONDS","mechanism":"identity-authorized minting, URL-fragment transport, SHA-256 digest at rest, and atomic one-time POST redemption","production_configuration":"config/deploy.yml"},"pending_account_verification":{"default_seconds":600,"display":"10 minutes to verify; expired records are eligible for bounded cleanup after 24 additional hours","enforcement":"src/auth.py::AuthService.complete_signup and AuthService.cleanup_expired_state","environment":"OAUTH_SIGNUP_TTL_SECONDS","mechanism":"one-time code stored only as a server-keyed HMAC-SHA-256 digest, bounded verification attempts, expiry enforcement, and bounded lazy cleanup","production_configuration":"config/deploy.yml","storage":"OAuth PostgreSQL database"},"presigned_download_urls":{"default_seconds":300,"display":"5 minutes","enforcement":"src/s3_storage.py::S3Storage.get_presigned_url","environment":"S3_URL_EXPIRY","mechanism":"expiry embedded in each generated presigned URL","production_configuration":"config/deploy.yml"},"request_and_infrastructure_logs":{"configuration":null,"default_seconds":null,"display":"No fixed retention period is enforced by this repository","enforcement":null,"mechanism":"Operational infrastructure controls apply; document contents and bearer/query credentials are excluded from application access logs by design."},"s3_pdf_artifacts":{"default_seconds":3600,"display":"up to 1 hour","enforcement":"src/s3_storage.py::S3Storage._exists_and_valid","environment":"S3_TTL_SECONDS","mechanism":"lazy expiry check and best-effort paired-object deletion on access","production_configuration":"config/deploy.yml","storage":"Amazon S3 temporary object storage"},"usage_and_cost_metadata":{"contents":"Account identifier, tenant and client channel, operation, outcome, provider/model, token counts, estimated provider cost, page/field counts, duration, and timestamp.","default_seconds":34560000,"display":"up to 400 days","enforcement":"src/admin_dashboard.py::UsageService.cleanup_expired","environment":"PDFSIGHT_USAGE_RETENTION_DAYS","excludes":"PDF bytes, filenames, form values, prompts, conversations, bearer credentials, and artifact identifiers.","mechanism":"bounded lazy cleanup during usage writes and dashboard reads","production_configuration":"config/deploy.yml","storage":"OAuth PostgreSQL database"}},"schema_version":1}
