Evidence method
SkillCodex maintains a versioned multi-atlas catalog of 60 sourced entries. Public availability follows one deterministic path based on rights, non-withdrawn sources, schemas, references, and reproducible digests.
Every definition, accessibility rule, and technical binding is connected to a verifiable source.
A search never changes the ontology. Explicit feedback may inform a later change, which goes through the same deterministic checks.
The resolver can abstain. A search score is never presented as a confidence probability.
Each concept page lists its own sources, source revisions, and reproducible digests when available.
Privacy
New Explore searches keep your description in a URL fragment (/explore#q=…), outside the HTTP request target and Referer. While that fragment is present, consented Google Analytics is suspended and Speed Insights removes the fragment and any legacy q parameter before sending an event. Speed Insights is a separate technical measurement and is not controlled by this audience-measurement consent. The fragment remains visible to browser history, the clipboard, extensions, and authorized same-origin scripts; old /explore?q=… links still send q to the server for compatibility. In the guided Identify flow, your description passes once through browser session storage and is removed when guided search opens. Ranking uses an immutable index locally; Packs are pre-written text whose bytes never depend on your request. With your consent, first-party journey counters record only the milestone, release and Search identity, Search resolution language (EN/FR), surface, resolution state, viewport class, in-memory runtime cache class, and milestone-specific duration class. Identify resolutions in ES or PT-BR are omitted rather than relabeled. The cache class is a page-runtime proxy, not proof of HTTP or browser cache state. A short-lived signed receipt, bound only to aggregate dimensions and a coarse time window, is required before the destination milestone and removed before D1; the Worker atomically prevents destination totals from exceeding accepted result totals. No query, candidate, entry, session identifier, event identifier, or individual timestamp enters the counter table. A short-lived anti-abuse HMAC derived from the trusted edge address is stored separately for rate limiting and purged; the raw address is not stored. Automated clients can still fabricate both milestones, so these counters remain directional. Useful, Almost, and Not found send no search text by default. Older clients that still send a bounded query have it redacted, hashed, and deleted before any durable write. The sink can retain a pseudonymous event for up to 30 days: query and trusted-edge network pseudonym hashes, event time, surface, locale, outcome, resolution, coarse duration, candidates and selection, rule identifiers, and served build/search identity. The raw query cannot reach durable storage. A separately confirmed anonymous topic signal stores only a hash of filtered text, for 30 days in the EU, and is never auto-published. Lack of volume is not positive proof. Operator aggregates remain hidden below five network pseudonyms; this is a disclosure threshold, not proof of five people. A configured sink is not a guarantee inferred from configuration alone: feedback remains disabled until production evidence proves a durable HTTPS sink in the EU; this does not affect atlas availability.
Audience measurement
With your consent, Google Analytics and aggregate first-party counters measure site usage to help us improve it. These counters contain no search text, candidate, session identifier, or event identifier. You can change your choice anytime via “Cookies” in the footer.