Work / Chitragupt / Wiki / Decisions
2026-06-10-no-recaptcha-ever
Decisioncanonicalverified 2026-06-26
DECISION.2026-06-10.NO-RECAPTCHA-EVERNo ReCaptcha (any flavour) — ever
Decision
Do not use ReCaptcha (v2, v3, Enterprise) anywhere in chitragupt — not as the App Check provider, not as a sign-up bot guard, not as a public-form spam filter. If anti-abuse defence is needed, use server-side rate limiting + App Check device attestation (DeviceCheck on iOS, Play Integrity on Android, custom provider on web if ever justified).
Why
ReCaptcha (v2, v3, Enterprise) is a non-starter for chitragupt: third-party Google script load on every page, DPDP-questionable cross-border data flow (user IP + behaviour fingerprint to Google), real user friction on slow / mobile / privacy-tooled browsers, and a brand mismatch with a tax product that positions itself on data minimalism. This rule supersedes any earlier proposal — never reintroduce ReCaptcha.
Impact
apps/website/src/api/firebase.tsdoes NOT callinitializeAppCheckwith a ReCaptcha provider. Imports offirebase/app-checkremoved.- Any future App Check enablement on web must use Firebase's CustomProvider with a homegrown attestation service — that work is deliberately out of scope until the team has appetite for the operational cost.
- The grep "recaptcha" should always return zero hits in source.
- Connects to 2026-06-10-app-check-enforcement-deferred (web App Check enforcement stays deferred because no non-ReCaptcha provider exists).
- Affects infra-sub-processors (Google is excluded from this anti-abuse surface).
Status
Active. DO NOT REVISIT.
Sources
- .context/wiki/decisions/* § "2026-06-10 — No ReCaptcha (any flavour) — ever"
Every project of mine is written down like this.
Read the résumé