# VoiceMessage Type in Munder Difflin: How PII-Free Messages Are Constructed Before IPC

> Discover the VoiceMessage type in Munder Difflin. Learn how this PII-free representation is constructed before IPC transmission, ensuring privacy.

- Repository: [Chaitanya Giri/munder-difflin](https://github.com/chaitanyagiri/munder-difflin)
- Tags: internals
- Published: 2026-08-29

---

**The `VoiceMessage` type is a privacy-protected, lightweight representation of Hive messages defined in [`src/main/hive.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/main/hive.ts) that strips all PII and secrets via the `redactSecrets()` routine before IPC transmission to the renderer.**

The `VoiceMessage` interface serves as the secure data contract between Electron's main process and the realtime-voice subsystem in the **chaitanyagiri/munder-difflin** repository. By redacting sensitive content before inter-process communication (IPC), the architecture ensures that voice-driven UI components never access raw personal data or API secrets.

## Understanding the VoiceMessage Interface

The `VoiceMessage` type definition resides at **lines 71-94 of [`src/main/hive.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/main/hive.ts)**. This interface deliberately excludes any fields containing personally identifiable information (PII), exposing only metadata necessary for voice-driven interactions.

The structure contains these redacted-safe properties:

- **`id`** – Unique message identifier for tracking.
- **`conversation`** – The conversation UUID linking related messages.
- **`from`** / **`to`** – Sender and recipient agent IDs.
- **`act`** – The message action type from the `MessageAct` enum (values include `request`, `inform`, etc.).
- **`subject`** – **Redacted** subject line with PII and secrets removed.
- **`body`** – **Redacted** message body containing no personal data or secrets.
- **`requires_reply`** – Boolean flag indicating if the message demands a response.
- **`direction`** – String literal `"inbox"` or `"outbox"` indicating the source mailbox.
- **`owner`** – Agent identifier specifying whose mailbox contains this copy.
- **`archived`** – Boolean `true` when the message originates from an archived sub-folder.
- **`created_at`** – ISO-formatted timestamp of message creation.

According to the source code, the `subject` and `body` fields are explicitly sanitized before population, ensuring the renderer process receives only structural metadata.

## The Construction Pipeline for PII-Free Messages

The main process constructs `VoiceMessage` objects through the internal **`voiceMessages()`** helper function located at **lines 1797-1825 of [`src/main/hive.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/main/hive.ts)**. This function implements a four-stage sanitization pipeline:

1. **Load** – Reads raw `HiveMessage` objects from the agent's `inbox/` or `outbox/` directory structures.
2. **Redact** – Processes `subject` and `body` fields through the **`redactSecrets()`** routine, which scrubs API keys, personal data, and confidential content.
3. **Map** – Transforms the redacted data into new `VoiceMessage` objects, injecting derived fields including `direction`, `owner`, `archived` status, and timestamps.
4. **Return** – Outputs an array of sanitized objects ready for IPC transmission to the renderer-side voice subsystem.

Because redaction occurs within the main process before any IPC channel invocation, the renderer's voice read-layer operates exclusively on PII-free data, satisfying the application's security model requirements.

## Code Implementation: From HiveMessage to VoiceMessage

The transformation logic centralizes privacy protection at the data preparation layer. Below is the conceptual implementation illustrating how individual messages are converted:

```typescript
// Located in src/main/hive.ts within the voiceMessages() workflow
function makeVoiceMessage(
  msg: HiveMessage, 
  owner: string, 
  direction: 'inbox' | 'outbox', 
  archived: boolean
): VoiceMessage {
  const redacted = redactSecrets({ subject: msg.subject, body: msg.body });
  
  return {
    id: msg.id,
    conversation: msg.conversation,
    from: msg.from,
    to: msg.to,
    act: msg.act,
    subject: redacted.subject,   // ← PII-free output
    body: redacted.body,         // ← Secrets removed
    requires_reply: msg.requires_reply,
    direction,
    owner,
    archived,
    created_at: msg.created_at,
  };
}

```

The `voiceMessages()` function iterates across all inbox and outbox files, invoking this mapping logic for each `HiveMessage` to build the complete collection transmitted via IPC.

## IPC Security Architecture and File Flow

The end-to-end privacy architecture spans four critical files:

- **[`src/main/hive.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/main/hive.ts)** – Defines the `VoiceMessage` interface and implements the `voiceMessages()` builder with integrated `redactSecrets()` calls.
- **[`src/preload/index.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/preload/index.ts)** – Exposes the sanitized `VoiceMessage` type to the renderer through the preload bridge, ensuring the renderer never interfaces with raw message bodies.
- **[`src/renderer/src/realtime/tools.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/renderer/src/realtime/tools.ts)** – Consumes `VoiceMessage` objects to drive voice-enabled UI features such as brief message summaries.
- **[`src/renderer/src/components/SettingsModal.tsx`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/renderer/src/components/SettingsModal.tsx)** – Provides the configuration interface for the OpenAI API key required by the realtime-voice feature (stored securely in the main process, never transmitted with message data).

This architecture guarantees that sensitive content remains isolated to the main process while the voice subsystem operates on structurally complete yet data-minimal objects.

## Summary

- **`VoiceMessage`** is a privacy-first interface defined in [`src/main/hive.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/main/hive.ts) (lines 71-94) containing only metadata and redacted content fields.
- **PII-free construction** happens in the `voiceMessages()` helper (lines 1797-1825) via the `redactSecrets()` routine, which scrubs `subject` and `body` fields before object creation.
- **Security boundary** enforcement occurs at the main process level, ensuring IPC channels transmit only sanitized data to the renderer.
- **Directional context** is preserved through the `direction` field (`"inbox"` or `"outbox"`) and `archived` boolean, maintaining mailbox organization without exposing content.
- **End-to-end flow** spans from raw `HiveMessage` loading through redaction, mapping, IPC transmission via the preload bridge, and final consumption by [`src/renderer/src/realtime/tools.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/renderer/src/realtime/tools.ts).

## Frequently Asked Questions

### Where is the VoiceMessage interface defined in the codebase?

The `VoiceMessage` interface is defined at **lines 71-94 of [`src/main/hive.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/main/hive.ts)** in the **chaitanyagiri/munder-difflin** repository. This location also contains the `voiceMessages()` implementation (lines 1797-1825) that constructs these objects from raw Hive message data.

### How does the application ensure no PII reaches the renderer process?

The main process calls **`redactSecrets()`** on the `subject` and `body` fields during the `VoiceMessage` construction phase. This scrubbing occurs before any IPC transmission, ensuring that [`src/preload/index.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/preload/index.ts) and the renderer's [`realtime/tools.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/realtime/tools.ts) receive only metadata and redacted content strings.

### What is the difference between VoiceMessage and HiveMessage types?

`HiveMessage` represents the complete, raw message object stored in `inbox/` or `outbox/` directories containing potentially sensitive content. **`VoiceMessage`** is a derived, lightweight subset processed through the `voiceMessages()` pipeline that removes PII and adds contextual fields like `direction`, `owner`, and `archived` for voice-driven UI consumption.

### Which files handle the realtime-voice feature apart from the main hive.ts?

The voice feature involves **[`src/preload/index.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/preload/index.ts)** (IPC bridge exposure), **[`src/renderer/src/realtime/tools.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/renderer/src/realtime/tools.ts)** (voice UI consumption logic), and **[`src/renderer/src/components/SettingsModal.tsx`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/renderer/src/components/SettingsModal.tsx)** (API configuration interface). These files work together to process `VoiceMessage` objects while maintaining the security boundary established in the main process.