TRUST CENTER / NO MAGICAL CLAIMS

The boundary is the product.

MirrorKey narrows who can compute what on appearance data. It does not pretend processors disappear, screenshots are impossible, or past disclosures can be pulled back.

EXECUTION BOUNDARY

Bring the catalog to the face.

Protected mock/live path. The browser unlocks the `/wallet` VTO Key; live uploads once to the exact approved YouCam origin, while mock uploads no shopper bytes.

01Consumer browserEncrypted local VTO Key
Client-reported integrity proof
approved job→
02YouCam processorApproved inputs
Async task + durable cleanup
minimum output→
03MirrorKey viewerPrivate render
Typed claim projector
×NO MEDIA PATH
04Retailer / agentPredicate, SKU list, or completion
No capture or provider URL

CONDITION REPORT

Precise promise. Precise limitation.

WE CAN ENFORCEIN SCOPE
  • Retailer and shopping-agent responses exclude source pixels and provider URLs.
  • Unknown fields and raw-source requests fail closed before unit spend.
  • Each grant binds one requester, purpose, SKU set, output schema, expiry, and use.
  • One-use revocation blocks another execution; private-result expiry or consumption ends preview retrieval.
  • Terminal, ordinary-failure, and expired no-execution cleanup purge reversible operational provider mappings while retaining keyed digests, tombstones, signed evidence, and encrypted verified webhook payloads.
  • Durable cleanup retries and signed outcome evidence are implemented; credentialed live verification remains a deployment gate.
WE WILL NOT CLAIMOUT OF SCOPE
  • That an approved image never leaves the device. YouCam receives it for the task.
  • That deletion is cryptographic proof of physical backup erasure.
  • That a private preview cannot be photographed or screenshotted by a person.
  • That revocation retracts information already disclosed.
  • That the browser-reported subject digest independently proves the bytes stored by the provider.
  • That encrypted webhook payloads have automatic expiry; production still needs an enforced retention job.
  • That an uploaded provider file can always be deleted when no task ID is ever issued.
  • That VTO predicts physical fit or cosmetic skin analysis diagnoses disease.

SERVER-OWNED REGISTRY

Ask for a capability—not a profile.

Inspect a grant
Capability disclosure registry
CapabilityPrivate computeRequester receives
COLOR_MATCH_BOOLEANTone analysis + comparisonMatch / no match
SKIN_SCORE_BANDSkin Analysis v2.1Concern + coarse favorable-condition band
TOP_3_SKUSTone result + catalog rankingExactly three SKU IDs
VTO_RENDER_ONLYAI Clothes v4Completion boolean only; render stays private
RAW_SOURCENo provider workAlways denied

RETENTION / OFFICIAL PROVIDER POLICY

Cleanup is a state—not a slogan.

  1. 01
    Provider window

    Provider storage may last up to 30 days; signed download URLs last two hours; MirrorKey conservatively treats 24 hours as the feature recovery window.

  2. 02
    MirrorKey window

    An encrypted private preview expires after ten minutes or is consumed sooner. Provider cleanup is queued only after preview bytes are safely captured.

  3. 03
    Exact evidence

    HTTP 200 permits “provider deletion confirmed.” Invalid or absent task reports remain signed but explicitly unverified; both terminal paths purge reversible local provider identifiers.