Privacy notice
Effective September 1, 2026Minimal data, explicit purpose, Human-controlled follow-up.
This notice explains the information collected through VerShep public surfaces and how it is used.
What VerShep collects
The engagement-request form collects the work email, organization, audience category, requested entry point, and description that you submit. It also records a submission reference, consent version, status, and creation time.
What not to submit
Do not submit credentials, private keys, regulated personal data, proprietary source code, security findings, confidential evidence, or information you are not authorized to share.
How information is used
VerShep uses this information to evaluate the requested benchmark, pilot, ongoing assurance relationship, scope review, growth-partner interest; determine whether the request fits the current operating boundary; and respond to the requester.
Browser-only Opportunity Map
The small-business AI Outcome Opportunity Map evaluates answers in the visitor's browser and does not submit the selected workflow, concern, cadence, or Human-owner description to VerShep. VerShep may record an aggregate completion count without the answers when the visitor requests a recommendation.
Growth partner interest
A founding Growth Partner request uses the engagement form and may include the requester's work email, organization, partner audience, selected program, and the experience or market description they choose to provide. Do not submit confidential customer lists, income expectations, or information you are not authorized to share.
Partner referral attribution
An approved partner link may include a sanitized referral code. VerShep stores the code as an aggregate campaign label for the browser session and may carry it into DEP activation. The public website does not use the code to store a visitor's name, email, project, source material, or outcome content. A referral code does not establish compensation or partner authority.
Government and nonprofit requests
Government and nonprofit engagement requests use the same bounded form fields described above. Do not submit controlled, classified, procurement-restricted, donor, volunteer, beneficiary, patient, student, regulated, or other sensitive personal information through the public form.
Historical investor inquiry records
The website no longer accepts investor-specific inquiries. Historical investor inquiry records may exist in restricted storage. VerShep does not expose, migrate, reinterpret, or delete those records through this page change. Their existence, custody, and exact retention state are not established by this notice. Access or deletion requests use the privacy channel below.
Storage and access
Application records are stored in the website's managed database. Access is intended to remain limited to authorized VerShep reviewers. VerShep does not place submitted application content on a public blockchain.
Aggregate funnel measurement
VerShep records aggregate counts for a small set of product-funnel events, such as selecting a homepage action, starting the Explorer, reviewing a synthetic result, downloading a sample Passport, or completing an application. The measurement record contains the event, route, day, and sanitized campaign labels. It does not store a persistent visitor identifier, IP address, user agent, prompt, source material, evidence content, customer identifier, or outcome description.
Sanitized campaign labels may be retained in browser session storage so an entry path remains attributable while you move between VerShep pages. A random, session-scoped journey identifier may be added when you choose to continue from VerShep.com into DEP. The identifier contains no email, account name, prompt, source material, or evidence. DEP records it with account activation milestones only when the signed-in user has enabled aggregate product measurement. The website does not store this identifier in its aggregate funnel table or retain it beyond browser session storage.
When a signed-in DEP user has enabled aggregate product measurement, DEP may send VerShep.com a first-use milestone name, a consented one-day or seven-day return milestone, or a subscription-lifecycle event and sanitized source, medium, and campaign labels. Subscription events can include checkout started, checkout completed, subscription activated, renewed, changed, or canceled, and payment failed or recovered. It does not send the account key, journey identifier, email, project or review title, prompt, source, evidence, attachment, or decision content.
Hosting and security infrastructure may temporarily process ordinary request metadata, including IP address and user agent, to deliver and protect the service; VerShep does not write those fields into its aggregate funnel table.
The public MCP endpoint records aggregate request health by day, method, public tool name, protocol era, status class, and latency. It does not record request arguments, catalog responses, prompts, evidence, credentials, customer data, IP addresses, or user agents. A keyed, short-lived representation of the network source may be held in edge memory for one minute to enforce the public request limit; it is not written to the operational metrics table.
Retention and deletion
Records will be retained while the request is evaluated and while reasonably necessary for business, security, or legal purposes. A precise retention schedule remains under review. Until a dedicated privacy channel is published, request access or deletion by emailing admin@vershep.com with the subject "Privacy request."
Product applications
The public DEP Explorer on this website uses synthetic fixtures and requires no account. DEP Early Access at app.vershep.com is a separate account-based product experience. It uses ChatGPT sign-in for authentication; DEP does not receive or store your ChatGPT password.
DEP Early Access stores records associated with the signed-in account, including workspace names, outcome types, authoritative source descriptions, supplied context, allowed work, denied actions, required checks, acceptance ownership, decisions, event history, and bounded source-file attachments. The product currently accepts plain text, Markdown, or JSON attachments up to the limit shown in the workspace.
DEP provides account export, workspace and Passport export, retention preferences, and permanent account-data deletion controls. A recorded region preference is intended for future routing; the hosting platform controls current storage location. If aggregate product measurement is enabled, DEP records the first completed activation milestones with sanitized campaign labels and a pseudonymous account key. DEP excludes workspace titles, source content, evidence, prompts, email addresses, and attachment content from those milestones. Account deletion removes those account-associated milestone records.
If you choose the connected-project beta, DEP redirects you to a VerShep GitHub App installation flow and receives the installation, account, selected-repository, repository metadata, source, pull request, release, tag, commit, and check information needed for the bounded review. DEP validates the installation through a temporary GitHub user token and does not retain that user token. Installation access tokens are created when needed and are not stored in DEP. You can disconnect the association in DEP and revoke provider-side access in GitHub.
When VerShep-managed outcome analysis is enabled and selected, bounded source and contract context may be sent to the configured OpenAI API account to record separate Producer and Independent Verifier results. This is an API-backed product capability; a customer's consumer ChatGPT subscription is not used as model API entitlement. The interface identifies deterministic-only results when managed analysis is unavailable. Do not connect or submit source that you are not authorized to process through these providers.
A separately installed write-tier GitHub App may be offered to DEP Pro accounts. It is used only after a blocker-free Human-accepted outcome and an exact confirmation to create an isolated branch and draft pull request. DEP does not merge, deploy, sign, publish, or grant production authority. Ordinary hosting and security request metadata may still be processed to deliver and protect the product.
Subscription billing
When DEP subscription checkout is available, Stripe processes the payment method, billing details, charges, renewals, and customer portal. VerShep does not store complete payment-card numbers. DEP stores the account's Stripe customer and subscription identifiers, selected plan and billing interval, subscription status, current period end, and update time so it can reconcile entitlement and provide account controls. Stripe's own privacy terms apply to data processed through Stripe.
Changes
This notice may be updated as VerShep adds product persistence, payments, subscriptions, customer integrations, or additional measurement capabilities. Material changes will be reflected by the effective date above.