{
  "manifest_version": 1,
  "last_updated": "2026-08-03",
  "product": "Pocket Thesis",
  "evidence_status": {
    "efficacy_study": "planned_not_started",
    "claim": "No claim of improved learning, retention, or transfer has been established.",
    "local_dashboard_scope": "Activity on the current browser only; not a representative sample."
  },
  "privacy": {
    "scope": "local_outcome_ledger_only",
    "learning_record_storage": "browser_local_storage_only",
    "abuse_control_storage": {
      "system": "sites_managed_d1",
      "data": "Keyed hashes of the server-observed transport IP for per-minute limits, plus non-personal global minute and day counters. Raw IPs and learner answers are not fields.",
      "retention": "Rows carry short window expiries, stop affecting decisions after expiry, and are deleted opportunistically.",
      "purpose": "Abuse prevention and a hard daily AI-request ceiling only."
    },
    "application_analytics_sdk": false,
    "hosting_analytics_or_security_telemetry": "Hosting layers may add telemetry or essential security cookies; production must disable or separately disclose them.",
    "raw_learner_answers_stored": false,
    "app_cookies_or_account_ids": false,
    "ephemeral_lesson_receipt": "After one lesson, the learner's recall and Apply move can appear in a temporary Pocket Thesis Card held in the open page's memory. Creating the receipt causes no additional transmission and does not write either field to localStorage, the outcome ledger, or a server. If the optional AI check was requested, Pocket Thesis already tried to send each submitted recall draft to its server; a draft may have reached that server or its configured provider. The receipt discloses the submission count and processing boundary. Apply prose remains page-only. Dismissing the card clears the parent receipt state; Copy and Print create a learner-controlled copy only after an explicit action.",
    "abandoned_lesson_cleanup": "Leaving an unfinished lesson clears in-memory recall and Apply drafts, displayed feedback, support state, and the active response binding. A provider request that already started cannot be unsent and remains subject to the configured provider's terms.",
    "semantic_processing": "The default authored self-check has two parts: Recall requires an explicit covered-or-revise choice for every learning goal, and Apply requires an explicit comparison with the authored practice prompt. It is the complete public learning path, runs inside the lesson, creates no score, and does not send or save the learner's answer, move, or choices. A content-free recall_attempted event may complete a due return without recording correctness. The optional AI check is disabled in this public release. If enabled, the recall answer and card rubric would be sent server-side to exactly one configured evaluator: Lovable AI Gateway, direct Google Gemini, or direct Anthropic. There is no automatic retry to another paid provider. Direct Gemini requests set store=false. Users are told not to submit sensitive or personal information. The application does not intentionally persist the answer; provider processing and retention follow configured service terms.",
    "processor_terms": {
      "lovable": "https://lovable.dev/privacy",
      "google_gemini": "https://ai.google.dev/gemini-api/terms",
      "anthropic": "https://www.anthropic.com/legal/commercial-terms"
    },
    "tamper_evidence": "The local outcome ledger is user-modifiable and is not an audited or tamper-evident research dataset.",
    "rolling_event_cap": 5000,
    "delayed_recall_queue_cap": 1000
  },
  "measurement_definitions": {
    "active_study_time": "Sum of gaps of 60 seconds or less between local activity events, capped at two hours per session.",
    "session": "A local activity period. A 30-minute idle gap, a hidden or closed tab, or a clock change starts a new session.",
    "card_learned": "A card whose Learn step emitted a completion event. This does not establish retention.",
    "verified_recall": "A semantic-provider result that passed structural, exact-evidence, and concept-facet gates. Correct means result=pass; partial and retry remain in the denominator. A delayed grade also needs a matching due queue item. This is not human adjudication or proof of truth.",
    "excluded_recall": "Only verified semantic-provider results are eligible. Unverified results, self-checks, and human grades are excluded from AI-checked recall-rate metrics.",
    "delayed_recall": "A recall check scheduled one or seven days after the most recent recorded in-app lesson or source-bearing feedback exposure. While a check is pending, the app hides that card's teaching prose in its library and source map; opening in-app lesson or feedback prose restarts every pending delay. Reading the external source, another browser tab, or a copied or printed lesson receipt cannot be detected and does not restart the local queue. A preregistered study must define how outside exposure is collected and analyzed. Due is not the same as attempted. A private recall_attempted event can complete a due return but carries no score or correctness claim."
  },
  "guardrails": {
    "idle_session_boundary_ms": 1800000,
    "maximum_counted_event_gap_ms": 60000,
    "maximum_active_time_per_session_ms": 7200000,
    "maximum_future_clock_skew_ms": 300000,
    "delayed_grade_before_due": "rejected"
  },
  "content_provenance": [
    {
      "deck": "Situational Awareness",
      "source": "Situational Awareness: The Decade Ahead",
      "url": "https://situational-awareness.ai/www/wp-content/uploads/2024/06/situationalawareness.pdf?stream=top"
    },
    {
      "deck": "NIST AI Risk Management Framework",
      "source": "Artificial Intelligence Risk Management Framework (AI RMF 1.0)",
      "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf"
    }
  ],
  "planned_study": {
    "status": "planned_not_started",
    "registration_status": "not_preregistered",
    "minimum_recruitment_target": 30,
    "note": "The target is an operating minimum, not a statistical power claim.",
    "design": "Random assignment to Pocket Thesis or a static-summary control with the same source material and time budget, with condition-blinded outcome scoring.",
    "primary_outcome": "Human-adjudicated seven-day free-recall performance under a preregistered rubric, scored without condition labels.",
    "analysis_contract": {
      "primary_estimand": "Between-condition difference in human-adjudicated seven-day free-recall rubric performance.",
      "denominator": "All randomized participants remain visible; raw assigned and completed counts are reported separately by condition.",
      "required_condition_reporting": [
        "Randomized participants",
        "Completed seven-day assessments",
        "Missing, late, and withdrawn participants",
        "Detected in-app lesson or source-bearing feedback re-exposures"
      ],
      "contamination_policy": "Re-exposure is reported by condition and is not silently treated as clean retention. Any exclusion or sensitivity analysis must be preregistered."
    },
    "secondary_outcomes": [
      "Immediate human-adjudicated recall",
      "Performance on a novel decision scenario",
      "Completion and active study time"
    ],
    "reporting_commitments": [
      "Publish exclusions, attrition, missing data, and all preregistered outcomes.",
      "Report uncertainty and effect sizes, not only statistical significance.",
      "Do not replace the seven-day endpoint with engagement metrics."
    ]
  }
}
