Public records
Public machine descriptions, operator wallet addresses, published telemetry, births, and governance records can be viewed by others. Do not publish exact locations, private images, or sensitive sensor readings.
Sessions and credentials
Authentication uses an expiring HTTP-only session cookie. Device private keys stay on the gateway. Service credentials are server-side only.
Retention and removal
Operators can decommission machines and revoke paired keys. Blockchain records cannot be deleted. Contact the repository maintainers for offchain removal requests; deployment operators must configure their retention policy.