Question every additional copy.

Private profile answers can pass through an application workflow and leave supporting records behind. Each copy adds information that must be protected and eventually handled when the workflow ends. A record used only to detect a change should have a narrower job.

In Earlydesk, the comparison field can tell whether an answer changed without retaining the raw answer in that field. That reduces the sensitive content kept for change tracking.

Bind the comparison to its context.

The Earlydesk change recorded on 11 October 2026 uses an HMAC-SHA256 digest under a derived key, bound to the relevant owner and row. The tracking value supports comparison in its intended context.

A digest does not recover the original answer. The application may still process or store profile information elsewhere in the workflow; the narrower claim here is that the change-detection field does not need another raw copy.

The same change clears relevant profile rows on retirement, preserves the final write outcome independently of temporary lease or application removal, and begins writes only against an active address. The working data and the outcome record have different jobs and different lifetimes.

Evidence for this change.

The change is present in the current Earlydesk repository, which contains related sending and account-connection test coverage. This note records a source review. Those tests were not rerun for the article, and deployment of this particular change to the hosted service was not verified.