General audience
Understand the whole system before choosing a guide
MP-OPT separates local planning, deliberate publication, authenticated access, public schedules, infrastructure recovery and verifiable evidence. Each deployment declares its own controller, providers, countries, features and retention.
Complete MP-OPT ecosystem
Planning, authenticated access, public access, delivery, availability and evidence remain separate domains.
Desktop App
Local planning, optimisation, publishing and event-scoped processor signing
External recovery storage
Encrypted exported snapshots; private AGE identity stays with the operator
Self-hosted Server
Node A
Caddy, frontend, API and PostgreSQL
Node B (HA)
Verified peer recovery point and failover target
Cloudflare
DNS, load balancer and bounded witness
Evidence repository
Append-only public verification material
Browser and phone/PWA
Passkey-authenticated Masterplan or bearer Public Schedule
SMTP and Google Calendar
Optional controller-declared delivery and calendar providers
Audience and role boundaries
A role grants a bounded capability; root is a technical role and is not automatically the legal controller.
Participant
Views authenticated schedules and manages their own passkeys
Issuer / admin
Issues access and manages assigned events within policy
Root
Authorises privileged Server actions and final deletion closure
Controller
Declares purposes, providers, retention and governance facts
Two schedule audiences
The audience is fixed by the publication surface rather than selected field by field.
Public Schedule
Always public to anyone holding the intentionally published route or bearer link
Masterplan
Always restricted to authenticated people with an assigned event role
GDPR and Swiss FADP support
MP-OPT provides data-minimisation boundaries, deployment-specific notices, retention and erasure workflows, security controls and signed accountability evidence. The controller still decides applicability, purpose, legal basis, providers, transfers and organisational measures.
Read the data-protection overviewCanonical product documentation
This site explains the whole system by audience. Product-specific procedures remain canonical on the App, Server and Evidence-Public Pages sites.
What the evidence can—and cannot—prove
Signatures prove who signed an exact statement, whether records changed, and whether the required chain is complete. They do not prove physical deletion from undeclared devices, providers or copies outside the signer's controlled systems.
Read the security and key map