Privacy

What CERES collects.

Research captures and operational diagnostics are separate. CERES never sends recordings or task content to PostHog.

01

Operational diagnostics

CERES uses a deployment-scoped US or EU PostHog project to understand whether the public site, capture surface, monitor and hosted export operations are working.

Browser events contain the CERES surface, Solo or Duet mode, build version, the name of a public page, fixed website interactions and coarse transitions for pairing, connection profile selection, invitation pickup, WebRTC, export and recorder finalisation. Website interactions distinguish only capture-menu opens, capture or workflow mode selections, printing the instructions and opening the CERES GitHub page. Recorder finalisation diagnostics contain only a fixed lifecycle state and stage together with bucketed sequence progress, queue depth and elapsed duration. Export media diagnostics contain only fixed encoder backend, remux decision and hardware-attempt categories together with a bucketed elapsed duration. A failure can contain a fixed diagnostic code or a sanitised JavaScript error type, allowlisted normalised technical message, normalised cause, operation stage, worker name, episode count and same-origin script coordinates. Unknown free text becomes "JavaScript error". This privacy page is excluded from page-view and website-interaction events. Hosted export logs contain a fixed operation name, outcome, HTTP status, route template, request method, deployment environment and service version together with sanitised JavaScript error details.

PostHog's cookieless server mode derives a privacy-preserving identifier during ingestion rather than using an account, session or browser-device identifier. The service may use the request IP address to derive that identifier, then discards the address before the event is processed. CERES also disables GeoIP enrichment and does not add an IP address to event properties. PostHog adds a fresh non-personal event UUID for transport de-duplication.

02

What diagnostics exclude

CERES disables session replay, automatic click and form capture, dead-click and rage-click detection, heatmaps, performance capture, feature flags, surveys, persistent browser storage, campaign attribution, referrer capture and device-model collection.

Diagnostic events do not include account names, email addresses, task, prompt, transcript or capture content, raw run, session, episode, job or device identifiers, absolute recorder sequence numbers, exact queue depths, exact finalisation durations or exact export-media durations, Hugging Face usernames or repository names, page URLs, query strings, referrers, clicked text, request bodies or headers, private tokens, credentials, absolute filesystem paths or cross-origin stack frames. Local recording quality is reduced to fixed frame, gap, slow-hand and tracking-loss buckets. Technical exception messages are scrubbed before transmission and stack data is restricted to script-relative coordinates. The public PostHog project token remains in event transport because the ingestion service requires it.

03

Research capture data

When a recording starts, CERES can collect outward video, microphone audio when enabled, WebXR head pose, hand joints, timestamps, explicit gap records and the run and task metadata specified by the research team.

Local capture keeps raw recording data in browser storage until the selected export is run. Data is sent to Hugging Face only when that export destination is selected. Research capture data is never sent to PostHog.

04

Storage and control

CERES uses PostHog in cookieless mode and does not use cookies, local storage or session storage for analytics data or identifiers. It therefore does not display an analytics cookie banner. Browser Do Not Track and Global Privacy Control preferences are respected.

You can also disable anonymous operational diagnostics in this browser. CERES stores only this preference locally.

Checking this browser's diagnostics preference.

The research team operating CERES controls participant consent, access to captures, export destinations and retention. Contact that team for access, correction or deletion requests concerning a research capture.

Last updated 7 August 2026.