Second Layer of Privacy: Data Types Enforce the Rules

In your restaurant's membership registration system, the "phone number" field has a required checkbox next to it: "I confirm this is not a dish name or table number." If a server doesn't check it, the system won't submit — it's impossible to accidentally enter a table number in the phone number field.

This is exactly index.ts's approach, except the confirmation box is placed at an even earlier stage — the compiler rejects incorrect usage at compile time, rather than waiting for a runtime check:

// src/services/analytics/index.ts
export type AnalyticsMetadata_I_VERIFIED_THIS_IS_NOT_CODE_OR_FILEPATHS = never

In TypeScript, the never type is the equivalent of that "required checkbox": setting a field type to never means no string value can legally be assigned to it. Developers must manually add a "confirmation signature" to pass compilation:

// Wrong: passing a file path directly — compilation error
// command: someFilePath,   ← Compiler: this field doesn't accept regular strings

// Correct: must manually add "I've confirmed this"
command_type: 'git' as unknown as AnalyticsMetadata_I_VERIFIED_THIS_IS_NOT_CODE_OR_FILEPATHS

This excessively long variable name is the text on that confirmation box — it's hard to type, so you can't write it unconsciously. Every time a developer writes this line, they're forced to pause and ask themselves: Is the value I'm passing really not code or a file path?

This design shifts verification responsibility from code reviewers (after the fact, subjective) to the compiler (before the fact, enforced).