Release 1.0: platform and standard live; no real packet audits yet August 6, 2026
CAL · syntheticdestination identified; fields unknown

The destination was identified; transmitted fields could not be established.

This example shows why “contacted a domain” does not automatically mean “sent location”.

Download receipt JSON
Version
7.1.2 · org.example.transporttest
Institution
Operator fictiv de transport
Supplier
Furnizor fictiv pentru calibrare
Journey
Planning a journey after refusing location
Device
Pixel 8a (laborator) · Android 16 · ro-RO
Lanes
stock + instrumented
Tested
August 5, 2026
Method
PPR-1.0
Choice reality

What changed when you said no?

We compare the service outcome and connections after refusal with the state before choice. A non-observation remains a non-observation; it does not become a claim that a service can never appear.

After refusal

The journey could be entered manually.

Permission was not granted. transit-cloud.example remained contacted when the manual route was calculated.

Three-track replay

The journey, moment by moment

Select a state to compare the three sources at the same moment. All states remain available when JavaScript is disabled or the receipt is printed.

Before choice

The map loaded at city level.

1 events
App launch

The policy names the mapping provider.

The store label declares optional approximate location.

The phone contacted tiles.maps.example and transit-cloud.example.

connection observed

Limit: Traffic to transit-cloud.example remained encrypted and pinned.

After refusal

The journey could be entered manually.

1 events
location refused

The policy promises manual entry of points.

The store label declares location as optional.

Permission was not granted. transit-cloud.example remained contacted when the manual route was calculated.

permission and connection

Limit: Continued contact does not establish that device location was transmitted.

After acceptance

The origin was filled from device position.

1 events
location accepted

The policy describes using position for the origin.

The store label declares approximate location.

The connection to transit-cloud.example had a different size, but the payload could not be read.

metadata only

Limit: A different size does not prove that position was transmitted.

After withdrawal

After permission revocation, manual journeys remained available.

1 events
permission revoked

The policy says the user can revoke permission in system settings.

The store label does not detail withdrawal.

The app requested permission again only when “my location” was used.

screen and permission

Limit: Server-side journey retention was not tested.

Network layer

Observed destinations

A domain, infrastructure owner and legal recipient are different propositions. Each relationship carries its own provenance state.

tiles.maps.examplethird party
Apparent owner
Hărți Exemplu
Role
documented mapping service
First seen
App launch
States seen
Before choice, After refusal, After acceptance, After withdrawal
Payload evidence
connection only
Attribution
documented

Map-tile requests were observed; no readable personal data.

transit-cloud.exampleunresolved relationship
Apparent owner
Cloud Tranzit SA
Role
route backend; exact role needs confirmation
First seen
App launch
States seen
Before choice, After refusal, After acceptance
Payload evidence
encrypted content unknown
Attribution
inferred

The destination was observed; TLS pinning prevented field-level determination.

Claim register

Publishable claims

Claims are stored separately so a response, correction or retest can change one proposition without silently rewriting the rest.

CAL-201destination identified; fields unknown

The route backend was contacted both without and with location permission.

Maximum wording: We cannot say location was transmitted in either state.

Repair ledger

Smallest repair

The actor, minimum change and verification test remain attached to the original claim.

proposed

REP-CAL-201

Operator fictiv

Publish the route backend’s contractual role and data categories.

Verification

Documentary verification; no app change is necessarily required.

What this receipt does not establish

  • The app and all data are fictional.
  • TLS pinning limited inspection.
  • Size metadata is not evidence of content.
SHA-256 · calibration placeholder

bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb

A real receipt would link every public claim to a sanitised evidence artefact and retain raw captures in a restricted vault.