What the app does not transmit
The repository defines no endpoint for uploading CAD, drawings, inspection files, declarations, passports, challenges, or evidence records. Runtime code and the CAD parser are served from the same origin.
Privacy notice
The DatumRelay qualification client has no application backend, account database, telemetry SDK, advertising tracker, or file-upload API. Selected artifacts are processed locally for the current browser session.
The browser, extensions, endpoint software, host, corporate network, and downloaded-file scanners operate outside DatumRelay and may process technical or file data under their own policies.
Artifacts are not sent to a DatumRelay service. Exports are created only when you request them.
| Data | Use | Location and lifetime |
|---|---|---|
| STEP, STP, or STL | Local parsing, preview, basic metrics, hashing, and optional export. | Browser memory until the page closes or reloads; included in a ZIP only at your request. |
| Drawing PDF | Presence, metadata, and SHA-256 hashing. Contents are not interpreted. | Browser memory for the session; optional ZIP inclusion. |
| Inspection artifact | Presence, metadata, and SHA-256 hashing. Contents are not interpreted. | Browser memory for the session; optional ZIP inclusion. |
| Requirements and notes | Rule comparison and evidence-record generation. | Browser memory and user-requested exports; not persisted by the current qualification client. |
| Capability passports | Comparison against declared supplier limits and exact qualified route tuples. | Origin-scoped localStorage and user-requested exports. |
| Challenges | Local exception and disposition tracking. Local dispositions are not authenticated release approvals. | Origin-scoped localStorage and buyer-record exports. |
| Rejected local state | Bounded quarantine of an invalid DatumRelay state value so a failed migration is not silently reused. | Origin-scoped quarantine-prefixed localStorage until the in-app reset or browser site-data clearing removes it. |
The repository defines no endpoint for uploading CAD, drawings, inspection files, declarations, passports, challenges, or evidence records. Runtime code and the CAD parser are served from the same origin.
The host necessarily receives requests for pages and static assets and may retain IP address, user agent, timestamp, and requested-path logs under its own terms.
Profiles, the selected profile, challenge records, and any bounded quarantine entry created after invalid local-state rejection remain in this origin's browser storage. Current CAD and release requirements do not persist across a reload.
Downloaded JSON and ZIP files are plaintext and may contain original artifacts. Your device, sync service, records system, and recipients control them after download.
DatumRelay has no server-side user account or application database to delete.
This notice describes the behavior of this qualification release. Before a public or enterprise launch, the deployment operator must publish its legal identity, contact channel, hosting and log-retention disclosures, and any required processor or subprocesser terms. Do not enter passwords, authentication codes, unnecessary personal data, or restricted engineering data.
Review the claims boundary and security model before using an organization-controlled release package.