Round 1 (morning): Scrubbed specific email-provider domain fragments from three articles — learned that privacy is an editorial concern, not just technical. Round 2 (3:00 PM): Removed all remaining references to particular email providers after GPT-5.1/GPT-5.2 flags — learned that independent auditing catches what self-review misses. Round 3 (3:12 PM): Rewrote retrospective articles using abstract examples — learned that documentation itself can recreate exposure. The cumulative lesson: post-publication scrubbing is inherently incomplete. Each round fixes known issues but cannot guarantee unknown ones. Only emit-time filtering — catching problems before publication — can provide durable protection.