No Record
Litepaper

No Record litepaper

The online architecture in a compact form.

No Record · online protocol 2026-08-27.2 · norecord.app

Problem

Useful AI work creates sensitive prompts, histories, media, project source, credentials, and tool arguments. Centralizing all of that as plaintext application state expands the blast radius.

Design

No Record separates local workspace custody from edge inference. The browser owns displayed history and restoration maps. The Worker validates, routes, meters, and returns results without writing request content to application storage.

Routing and orchestration

No Record Auto selects only from the current text allowlist and returns a route reason. Council keeps independent answers. Loom applies bounded one-to-four-call policies and returns a content-free receipt.

Storage boundary

D1 holds quotas, aggregate usage, credential verifiers, preview credit metadata, and optional encrypted sync envelopes. It does not hold plaintext prompts, outputs, media bytes, or code source.

Limits

Pattern-based minimization is incomplete; provider and network behavior are outside No Record application proof; online payments, Browser Run capacity, cloud containers, provider video/audio, App Store distribution, and signed desktop installers are not live. Native iOS/desktop and private-economy source contracts are present and labeled separately from releases.