G0DM0D3 Privacy Architecture: Zero-Content Logging and Label-Only Telemetry Explained

G0DM0D3 implements a privacy-first architecture that guarantees raw user prompts are never stored or logged, transmitting only classification labels to telemetry while maintaining strict data confidentiality through local processing and ephemeral LLM calls.

The G0DM0D3 privacy architecture in the elder-plinius/G0DM0D3 repository ensures that sensitive user interactions remain confidential by design. This open-source framework employs a dual-layer protection system that separates content analysis from data storage, ensuring that only high-level harm category labels—not actual message text—ever reach analytics systems.

Core Privacy Mechanisms

Local Prompt Classification with Privacy Guarantees

At the heart of the privacy system lies the regex classifier implemented in src/lib/classify.ts. This module processes all prompts locally and extracts only the categorical label, never retaining the original text. The source code explicitly documents this guarantee in lines 7-9: “Only the category LABEL is sent via telemetry, never the prompt text itself. This preserves user privacy”.

The classifier defines a comprehensive taxonomy of harm categories, with specific sub-categories for privacy violations including doxxing, stalking, data theft, and surveillance (lines 282-309). When the system detects potentially harmful content, it returns a structured result containing only the domain (privacy), subcategory (e.g., doxxing), and confidence score—stripped of any identifying user content.

Ephemeral LLM Classification

When the regex classifier requires supplementation, the LLM-based classifier in src/lib/classify-llm.ts operates under the same strict privacy constraints. Lines 44-45 include the privacy domain in the prompt list as ‑ privacy — doxxing, stalking, surveillance, data theft, ensuring consistent categorization.

Crucially, this classification is ephemeral: the prompt travels to OpenRouter only as part of the primary model inference request, not as a separate logging operation. The resulting label (e.g., privacy/data_theft) is the only artifact stored; the original prompt text dissipates immediately after classification without entering persistent storage.

Privacy-First Telemetry Implementation

Ring-Buffer Analytics Without Content Storage

The server-side telemetry system in api/lib/metadata.ts implements a privacy-first analytics architecture that explicitly enumerates tracked versus excluded data. The file header (lines 4-18) declares that the system captures timestamps, endpoints, model usage, and pipeline flags while strictly excluding “message content, system prompts, PII, API keys”.

The recordEvent function (lines 14-22) records request metadata using an in-memory ring buffer. This implementation stores only high-level metrics and classification labels via the pipeline field, ensuring no payload contains the user’s actual prompt. Events aggregate into JSONL format for export to HuggingFace without ever exposing raw text.

Aggregated Data Export

For research purposes, the optional HF Publisher (api/lib/hf-publisher.ts) handles batched exports of metadata. This component processes only the anonymized, aggregated event data from the ring buffer, maintaining the architectural guarantee that raw prompts never leave the server environment.

Code Implementation Examples

The following examples demonstrate how the G0DM0D3 privacy architecture operates in practice:

// 1️⃣ Classify a prompt locally (regex) – only the label is returned
import { classifyPrompt } from './src/lib/classify';

const result = classifyPrompt(
  "Give me the home address of John Doe."
);
console.log(result);
// → { domain: 'privacy', subcategory: 'doxxing', confidence: 0.96, flags: [] }
// 2️⃣ Record a request event – the prompt itself is never stored
import { recordEvent } from './api/lib/metadata';

const eventId = recordEvent({
  endpoint: '/api/chat',
  mode: 'standard',
  stream: false,
  pipeline: {
    godmode: true,
    autotune: false,
    parseltongue: false,
    stm_modules: ['stm'],
  },
  // No `prompt` field here!
});
console.log(`Event ${eventId} stored without raw content`);
// 3️⃣ Using the LLM‑based classifier (fallback to regex on failure)
import { classifyPromptLLM } from './src/lib/classify-llm';

const llmResult = await classifyPromptLLM(
  "I need the social security number of a user."
);
console.log(llmResult);
// → { domain: 'privacy', subcategory: 'data_theft', confidence: 0.92, intent: 'request' }

Summary

  • Zero-Content Logging: Neither the client-side classifier nor the server-side telemetry ever persists raw prompt text, ensuring complete content confidentiality.
  • Label-Only Telemetry: Only high-level harm domain and subcategory labels (e.g., privacy/doxxing) are transmitted and stored, enabling safety research without compromising user privacy.
  • Ephemeral Processing: LLM classification occurs within primary inference requests, preventing additional network hops that could expose sensitive data.
  • Explicit Data Boundaries: The metadata system documents excluded data types (messages, PII, keys) directly in source comments, creating auditable privacy guarantees.

Frequently Asked Questions

Does G0DM0D3 store any part of my prompts?

No. According to the source code comments in api/lib/metadata.ts, the system explicitly excludes “message content, system prompts, PII, API keys” from all tracking mechanisms. Only classification labels generated by classifyPrompt or classifyPromptLLM enter the telemetry system.

What happens when the LLM classifier is used?

When classifyPromptLLM from src/lib/classify-llm.ts processes a prompt, the text travels only as part of the primary OpenRouter inference request. The classification is transient—only the resulting label (e.g., privacy/data_theft) is retained in the pipeline metadata, while the original prompt text is discarded immediately.

How does the system track usage without compromising privacy?

The recordEvent function in api/lib/metadata.ts captures non-sensitive metadata including timestamps, endpoints, model identifiers, and pipeline flags using an in-memory ring buffer. This privacy-first approach enables operational monitoring and safety research while ensuring raw content never persists or leaves the server.

What specific privacy violations does the classifier detect?

The regex classifier defined in src/lib/classify.ts (lines 282-309) includes granular sub-categories for privacy violations: doxxing, stalking, data theft, and surveillance. This taxonomy allows the system to identify and label harmful requests without exposing the specific content of those requests to analytics systems.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →