An unknown owner stays unknown.

Five parts, no transcript dump

The meeting-recap contract now separates what changed, what was decided, commitments, next moves and points that still need confirmation. A decision, commitment or next move carries an owner and date when the source supports them; an unknown value remains empty rather than being completed by tone or probability.

Each item links to the meeting capture receipt and is marked derived and unverified. The service also keeps a digest of the source used by the capture client, without keeping a second copy of the raw transcript.

A false recap is worse than no recap

The previous background path could reach a language model with the meeting duration but not the conversation. That path now fails clearly as source unavailable. Metadata cannot become a plausible account of a private conversation.

The Worker does not send the raw transcript to a new model provider. The authenticated capture client supplies the structured derivative; the existing meeting expiry and deletion controls remove it with its source.

The private-pilot boundary

The structured service contract and reference-device acceptance path are built. The production capture-client integration and repeated-session accuracy work remain in development.

This release defines and protects the useful result. It does not claim that names, dates or commitments are accurate until real sessions verify them, and it never turns a recap into permission for an outward action.