- Retailer and shopping-agent responses exclude source pixels and provider URLs.
- Unknown fields and raw-source requests fail closed before unit spend.
- Each grant binds one requester, purpose, SKU set, output schema, expiry, and use.
- One-use revocation blocks another execution; private-result expiry or consumption ends preview retrieval.
- Terminal, ordinary-failure, and expired no-execution cleanup purge reversible operational provider mappings while retaining keyed digests, tombstones, signed evidence, and encrypted verified webhook payloads.
- Durable cleanup retries and signed outcome evidence are implemented; credentialed live verification remains a deployment gate.
TRUST CENTER / NO MAGICAL CLAIMS
The boundary is the product.
MirrorKey narrows who can compute what on appearance data. It does not pretend processors disappear, screenshots are impossible, or past disclosures can be pulled back.
EXECUTION BOUNDARY
Bring the catalog to the face.
Protected mock/live path. The browser unlocks the `/wallet` VTO Key; live uploads once to the exact approved YouCam origin, while mock uploads no shopper bytes.
Client-reported integrity proof
Async task + durable cleanup
Typed claim projector
No capture or provider URL
CONDITION REPORT
Precise promise. Precise limitation.
- That an approved image never leaves the device. YouCam receives it for the task.
- That deletion is cryptographic proof of physical backup erasure.
- That a private preview cannot be photographed or screenshotted by a person.
- That revocation retracts information already disclosed.
- That the browser-reported subject digest independently proves the bytes stored by the provider.
- That encrypted webhook payloads have automatic expiry; production still needs an enforced retention job.
- That an uploaded provider file can always be deleted when no task ID is ever issued.
- That VTO predicts physical fit or cosmetic skin analysis diagnoses disease.
SERVER-OWNED REGISTRY
Ask for a capability—not a profile.
| Capability | Private compute | Requester receives |
|---|---|---|
COLOR_MATCH_BOOLEAN | Tone analysis + comparison | Match / no match |
SKIN_SCORE_BAND | Skin Analysis v2.1 | Concern + coarse favorable-condition band |
TOP_3_SKUS | Tone result + catalog ranking | Exactly three SKU IDs |
VTO_RENDER_ONLY | AI Clothes v4 | Completion boolean only; render stays private |
RAW_SOURCE | No provider work | Always denied |
RETENTION / OFFICIAL PROVIDER POLICY
Cleanup is a state—not a slogan.
- 01Provider window
Provider storage may last up to 30 days; signed download URLs last two hours; MirrorKey conservatively treats 24 hours as the feature recovery window.
- 02MirrorKey window
An encrypted private preview expires after ten minutes or is consumed sooner. Provider cleanup is queued only after preview bytes are safely captured.
- 03Exact evidence
HTTP 200 permits “provider deletion confirmed.” Invalid or absent task reports remain signed but explicitly unverified; both terminal paths purge reversible local provider identifiers.