consume method
Drop a terminal once its owed report has been DELIVERED (duress hygiene, debt closed).
The retention above is deliberate and stays: an UNDELIVERED outcome must survive an identity flip. But once the host has been told, the payload has done its whole job — and what it holds is the previous identity's TXIDS, resident in a ROOT provider that outlives the screen. The send screen clears its draft on a flip precisely so a coercer cannot read it; leaving payment identifiers here defeats that for the same threat.
Flow-scoped on purpose: clears only if the resident terminal is the one named, so a screen can never drop a sibling flow's undelivered report.
Implementation
void consume(int flowId) {
if (state?.flowId == flowId) state = null;
}