Talk With Jamie v2 stores account identifiers, password hashes, chat messages, generated replies, timestamps, administrator contact notes and a distilled context pack in Netlify Blobs.
Raw exports are not deployed or committed. A local builder creates a smaller JSON pack that:
- uses only Jamie-authored messages for style examples
- creates admin-only relationship summaries and short conversation capsules from redacted messages on both sides
- excludes media and keeps raw export files local
- redacts obvious email addresses, phone numbers, links and long identifiers
- rejects common credential and banking-secret patterns
- labels deeper evidence as admin-only
The administrator must review the generated pack before importing it.
Public chat can retrieve only public chunks. Jamie's authenticated admin chat and drafting
workspace can retrieve admin chunks. There is no API route for downloading the stored pack.
The current message, recent conversation, visitor facts explicitly remembered by the service and
selected context are sent to the configured model provider to generate a reply. Raw export files
are not sent. The OpenAI integration sets store: false, but provider-side abuse monitoring and
legal retention rules may still apply. Production deployment must accurately identify the provider,
retention behaviour and the contact route for access or deletion requests.
- Passwords are hashed.
- Sessions use signed
HttpOnly,SameSite=Strictcookies. - Chats can be reviewed and deleted by the administrator.
- Accounts can be blocked.
- The active context pack is replaced or removed only through the private maintenance workflow, never from the deployed admin screen.
No credential, production data, raw export or generated context pack belongs in Git.
The same applies to real contact names, aliases and relationship details: they live in
an untracked local config (tools/context-config.example.json shows the shape) and in
the privately imported pack, never in this repository.