Soma
Copyright 2026 Nicholas Seney

This product is licensed under the Apache License, Version 2.0.
See the LICENSE file for the full license text.

---

## Data Privacy Statement

Soma is a **local-only governance framework**. It installs
configuration files (rules, skills, hooks) into your local AI assistant
directory. It does not operate as a service and has no server component.

### What This Software Does NOT Do

- ❌ Collect, transmit, or store any user data
- ❌ Phone home, send telemetry, or track usage
- ❌ Access any network resources during normal operation
- ❌ Read, log, or exfiltrate file contents, project names, or user identities
- ❌ Require an account, registration, or authentication

### What This Software Does

- ✅ Installs markdown rule files and skill files (15 skills) to your local filesystem
- ✅ Runs local bash scripts (39 scripts) for installation, validation, and metrics
- ✅ Collects **aggregate counts only** (e.g., "11 rules", "15 skills", "39 scripts", "1.1% waste rate")
- ✅ All metrics are local-only and gitignored by default

### Network Access Disclosure

The optional `enzymes/token_census.py` script calls the **Google Gemini API**
(`client.models.count_tokens`) to measure accurate token counts for governance
files. This sends the content of rule and skill files (which are part of this
open-source repository) to the Gemini API for tokenization measurement only.

- This script is **optional** — the system falls back to local word-count
  estimation if the Gemini SDK is not installed or no API key is configured
- No user-generated content, project files, or private data is ever sent
- Only the open-source governance files from this repository are transmitted
- The Gemini API's own privacy policy governs how Google handles API requests

### Privacy Invariant

The governance system enforces a strict **Privacy Invariant** across all
scripts, metrics, and probes:

| ✅ Always Safe (Collected)         | ❌ Never Collected                    |
|:----------------------------------|:--------------------------------------|
| Rule count, skill count           | File paths, directory structures      |
| Aggregate token estimates         | Project names, repo names, org names  |
| Waste rate percentages            | User names, machine hostnames         |
| Install status (pass/fail)        | File contents, diffs, or patches      |
| Tool version numbers              | Session transcripts or logs           |
| Boolean environment flags         | Environment variables or secrets      |

### Genesis Environment Probes

The Genesis onboarding skill includes optional environment probes that detect
local development tools. These probes output **sanitized aggregates only**:

- ✅ Outputs: `python: 3.11, venv: true` or `tools: [make, npm, go]`
- ❌ Never outputs: raw file paths, `which` command output, usernames,
  hostnames, or environment variable values

---

## Attribution

This project was created and is maintained by Nicholas Seney.

The governance framework, review protocol architecture (Breeze through Tempest),
review prong system (Spores through Mulch), and biological naming conventions
(Cytogenesis, Natural Selection, Chloroplast/Vacuole/Cell Wall/Membrane/
Plasmodesmata) are original works by Nicholas Seney.
