Privacy boundary

The website informs. It does not own the computer.

Sentinel Linux should remain downloadable and usable without a mandatory online account. The public website exists to provide information, releases, package records and verification material.

No required account

Core downloads, documentation and verification records should remain available without signing in.

No remote control layer

The website is not designed to manage local Sentinel Linux installations, silently push policy or become a cloud ownership dashboard.

Minimal, disclosed measurement

Any future analytics should be privacy-respecting, clearly disclosed and unnecessary for normal use.

Local-first

Online services support the system; they do not replace it.

The repository supplies packages and updates. Public pages explain releases and trust records. Files, applications, settings and ordinary user workflows remain centred on the local machine.

Third-party application boundary

Local-first does not automatically make external software private.

Sentinel-owned applications are intended to work locally without compulsory telemetry. Third-party applications keep their own network behaviour and data practices. The current baseline does not universally strip telemetry or deny every outbound connection.