The trust boundary is structural
The system that helps you delete your data is built not to expose it. The telemetry rule is structural, not a policy memo: identifiers and counts, never client content.
From mcp/src/tools — the rule the whole codebase enforces: a notation_id, a service name, an outcome, a duration,
and a status code may enter a span or a log. A client name, an answer body, an email address, or a document body may
not.