# Release privacy audit The public distribution is a neutral model/tool release. It contains no personal project branding or identifying maintainer metadata. Attribution to NanoJev and Qwen remains because it describes the model's actual origin and preserves their license notices. ## Checked material - All public source, configuration, documentation, examples and evaluation summaries were scanned for machine-specific home paths, private account identifiers, access-token patterns and private-key blocks. - All **1,863 browser head training rows** were inspected as structured data and scanned for contact details, URLs, local paths and private identifiers. The rows describe abstract operations, visibility, assignment, busy states and acceptable actions. They do not contain user form values or conversation transcripts. - The safetensors header contains **322 tensors** and **no `__metadata__` author field or other author metadata**. - The released checkpoint retains the verified v5 weight hash. The recorded tensor audit establishes that the Qwen backbone was frozen during browser head training. - The tokenizer vocabulary, merge rules and added-token inventory exactly match the pinned upstream Qwen tokenizer. Saved pre-tokenizer/decoder settings differ; the verified v5 tokenizer is retained as-is. [Comparison record](../evals/tokenizer-provenance.json). No private tokens were added. - The inference response identifies `NanoJev-Web/browser-head-v5` instead of returning an absolute checkpoint directory. - Published benchmark evidence contains selected numeric results, model identities, reproducibility information, synthetic assigned values and allowlisted abstract decision traces. Private raw run files, machine paths and browser sessions are excluded. - Archive entries use blank owner/group names, numeric ownership zero and normalized timestamps. Publication uses an explicit manifest, not the contents of an installed runtime directory. The explicitly supplied synthetic benchmark screenshot and GIF are included as public report assets. The image metadata contains resolution, dimensions, a color profile and a generic Screenshot comment; the GIF contains animation timing and loop metadata. No identifying author/location metadata was found. Both files are preserved byte-for-byte. See [media provenance](demo/media-provenance.json). The machine-specific audit denylist itself is not published, because that would reintroduce the identifiers being removed. Findings are recorded as counts in [privacy-audit.json](../evals/privacy-audit.json). ## Excluded from the upload Credentials, environment files, local connection configuration, browser profiles, unreviewed recordings, private run receipts, screenshots from arbitrary sites, old workspaces, development archives, dependency installations and caches are not release files. Running the package later creates `.local/` evidence; that directory stays outside the manifest. The model and browser runtime require no hosted-model credentials. The comparison application and cloud-provider integrations are excluded from this distribution. The local model has no teacher or external model fallback. Package installation still needs network access to obtain dependencies. ## Limits of the audit This is a release-file and browser-head-data audit, not proof that pretrained neural weights cannot encode personal information. The inherited backbone and multilingual tokenizer have not been retrained or semantically scrubbed. Ordinary names or words in a tokenizer vocabulary are upstream model assets, not evidence of a local user's training records; deleting them would change tokenization and invalidate the checkpoint. The model's API is deliberately narrow, but the caller can still supply text. Hosts remain responsible for using appropriate data and authorized pages. Downloaders should use the verified release manifest rather than sharing their own working directory after running private tests.