//AGENT-NATIVE APPLICATION VOCABULARY
Declared data custody
Declared data custody is the agent-native app's stated, verifiable answer to 'who holds which data': declared in the package rather than buried in a policy page. The category's design intent is that users keep their data, context, corrections, and customizations, with exit rights, and that the publisher doesn't have to hold user data at all. Custody declaration is an architecture claim users can check, not a security guarantee.
Custody is declared per app because deployments legitimately differ: an in-house app on a local model can declare full user custody with controlled egress, while a Host-mounted app declares exactly which state lives where. The point is that the answer is stated, inspectable, and part of the contract.
Declared custody is also what makes the category's economics honest. 'The publisher doesn't hold your data' only means something if the package says so in a field that a registry can verify and a record can contradict.