Release 1.0: platform and standard live; no real packet audits yet August 6, 2026
CAL · syntheticobserved, not clearly described

An analytics service started before the optional choice was shown.

Synthetic example showing how the product separates an observed connection from a conclusion about transmitted content.

Download receipt JSON
Version
4.8.1 · org.example.orastest
Institution
Instituție fictivă pentru calibrare
Supplier
Furnizor fictiv pentru calibrare
Journey
Submitting a street-lighting report
Device
Pixel 8a (laborator) · Android 16 · ro-RO
Lanes
stock + instrumented
Tested
August 5, 2026
Method
PPR-1.0
Choice reality

What changed when you said no?

We compare the service outcome and connections after refusal with the state before choice. A non-observation remains a non-observation; it does not become a claim that a service can never appear.

After refusal

The report could be submitted without optional analytics.

After refusal, no further connections to analytics.example were observed in two runs. The synthetic value LAMPA-7Q2 was observed in the request to api.orastest.example.

Three-track replay

The journey, moment by moment

Select a state to compare the three sources at the same moment. All states remain available when JavaScript is disabled or the receipt is printed.

Before choice

The app opened. The form had not yet been used.

2 events
App launch

The policy describes optional analytics after consent.

The store label declares app activity for analytics.

The phone contacted analytics.example 420 ms after launch, before the choice screen.

connection observed

Limit: The full content was encrypted; only destination and connection metadata were established.

Choice screen

Consent is described as optional.

The store label does not describe initialization timing.

The choice screen appeared after the first analytics connection.

screen + connection

Limit: This does not establish that a personal identifier was transmitted.

After refusal

The report could be submitted without optional analytics.

2 events
Refusal

The policy says refusal does not affect the core service.

The store label says deletion can be requested.

After refusal, no further connections to analytics.example were observed in two runs.

repeated non-observation

Limit: Absence in one journey does not prove the service cannot appear in other features or under remote configuration.

Data submission

The policy describes sending the photo, location and text to the institution.

The store label declares photos and location for app functionality.

The synthetic value LAMPA-7Q2 was observed in the request to api.orastest.example.

exact synthetic token

Limit: The value establishes transmission to the service endpoint; it does not by itself establish each operator’s legal role.

After acceptance

The core service and optional analytics operated.

1 events
Acceptance

The policy describes pseudonymous usage events.

The store label declares app activity.

Connections to analytics.example continued. A readable event_name=report_submitted field was observed; the full identifier was not interpreted.

readable data category

Limit: An event name does not show whether the provider can link it to a person.

After withdrawal

Reporting remained available.

1 events
Withdrawal

The policy promises to stop future analytics.

The store label gives no withdrawal detail.

After withdrawal and restart, analytics.example was not contacted in two runs.

repeated non-observation

Limit: The test does not verify deletion of data already held server-side.

Network layer

Observed destinations

A domain, infrastructure owner and legal recipient are different propositions. Each relationship carries its own provenance state.

api.orastest.examplefirst party
Apparent owner
Instituția fictivă
Role
Reporting-service API
First seen
App launch
States seen
Before choice, After refusal, After acceptance, After withdrawal
Payload evidence
exact synthetic token
Attribution
documented

The synthetic report text was observed in the payload.

analytics.examplethird party
Apparent owner
Analiză Exemplu SA
Role
commercial analytics service
First seen
App launch
States seen
Before choice, After acceptance
Payload evidence
readable data category
Attribution
documented

The destination and an event name were observed; the full identifier was not established.

Claim register

Publishable claims

Claims are stored separately so a response, correction or retest can change one proposition without silently rewriting the rest.

CAL-001observed, not clearly described

The analytics service was contacted before the optional choice was shown.

Maximum wording: We can state when the connection began; we cannot state that profiling occurred.

CAL-002declared and observed

The synthetic report text was sent to the service’s documented API.

Maximum wording: The exact value left the device in the observed request.

Repair ledger

Smallest repair

The actor, minimum change and verification test remain attached to the original claim.

proposed

REP-CAL-001

Furnizor fictiv

Initialize the analytics SDK only after explicit acceptance, or remove it from the core journey.

Verification

Repeat the journey on a clean install and confirm no pre-choice connection.

What this receipt does not establish

  • The app and all data are fictional.
  • Two runs do not cover every feature.
  • Legal attribution does not follow from traffic alone.
SHA-256 · calibration placeholder

ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff

A real receipt would link every public claim to a sanitised evidence artefact and retain raw captures in a restricted vault.