Safety
Secrets, private trip data, and what Alcove will not do silently.
Secrets stay out of git
Never commit passwords, passport numbers, confirmation codes, card data, or API keys into a trip repository. Use a vault or connector for booking secrets. PR templates in the starter remind you before merge.
Private by default
Trip repos you connect remain under your GitHub visibility settings. Alcove does not publish private trip content to the marketing site or make private repos public.
Subject memory is account-scoped. Lessons are not applied to a trip until a human accepts a change that lands as a PR.
No silent mutation of main
Alcove review and watch propose. Only the traveler merges. Alcove does not auto-merge.
Provenance honesty
Claims about people or outcomes should carry a provenance label when recorded in memory or research: verified, connector-derived, repo-derived, user-reported, inferred, or unknown. Do not invent observed behavior from itinerary state alone.
Abuse and fair use
Automated review is rate-limited. Fair-use limits protect the service from bot loops; they are not a substitute for your own operational security.