RCC EXPEDITION PRIVACY CONTRACT
===============================

Principle: Datenminimierung / Datensparsamkeit.

RCC Expedition has no learner backend.

LOCAL ONLY
----------
Browser:
  - mission status;
  - hints revealed;
  - optional Mac/Windows override.

Local course directory:
  - coarse workstation readiness state;
  - RCC SSH/Slurm exercise state as PASS/FAIL/NOT_TRIED.

NOT COLLECTED
-------------
  - name or institutional identifier;
  - files or filenames;
  - shell/PowerShell history;
  - raw Wi-Fi network name;
  - FileVault or BitLocker recovery keys;
  - backup passwords;
  - UDE/UME passwords;
  - MFA seeds/recovery codes;
  - SSH private-key contents;
  - research, clinical, or patient data.

The local HTML application uses:
  connect-src 'none'

External reference links and RCC SSH actions occur only after explicit
user action. Progress export/import is local JSON, not synchronization.
