# Contributing Keep changes inside the application-level, local-first boundary. Do not add URL collection, window-title persistence, analytics, or network calls without an explicit product and privacy review. Before submitting a change: ```bash npm run check npm run qml:check npm run omarchy:validate ``` State-machine changes need a synthetic timeline test. QML changes need the manual Omarchy smoke test in `docs/manual-validation.md`. Never remove or hide the emergency dismissal path.