OpenAI ChatGPT Directory & MCP Compliant
Privacy Policy
Effective Date: October 2, 2026 | Last Updated: October 3, 2026
1. Scope & Overview
This Privacy Policy explains how Hardik Sapra ("we", "us", or "our") collects, uses, protects, and discloses personal data and interaction data when you visit hardiksapra.com or use our ChatGPT Plugins and Model Context Protocol (MCP) tools, specifically:
- MVP Architect & PRD Specifier: Tools for engineering PRD generation, Mermaid architecture diagrams, database schema design, and consultation requests (
generate_architecture_spec, estimate_mvp_sprint, request_mvp_consultation).
- DocExtract JSON Engine: Heuristic extraction from supplied invoice and contract text, arithmetic discrepancy checks, preview-only webhook validation, and explicitly requested pipeline inquiries (
parse_invoice, parse_contract, export_webhook, request_pipeline).
This policy complies with the official OpenAI Developer Guidelines, ensuring privacy by design, minimal data collection, and robust user controls.
2. Data Minimization & Task-Linked Collection
In accordance with OpenAI plugin policies, we practice strict collection minimization:
- We request and process only the minimal, narrowly scoped data required to execute the active task requested by the user.
- Our tools never pull, reconstruct, or infer full conversation histories, prior chat turn logs, or broad contextual user profile data.
- Inputs are processed strictly within the boundaries of the specific function invoked.
3. Categories of Data We Collect
We process only the following three distinct categories of information:
A. In-Chat Task Inputs
When you prompt our tools within ChatGPT or Codex, you provide inputs such as product specifications, architecture criteria, or document text excerpts. These inputs are processed in real-time memory solely to generate the requested technical specification, diagram, or structured JSON response.
B. Voluntary Consultation & Lead Information
Certain actions within our tools (such as calling request_mvp_consultation or request_pipeline) allow you to voluntarily request follow-up from senior engineers after explicit user intent. In those instances, we collect:
- Contact Details: Your name and business email address.
- Project Scope: The app or document-pipeline summary, document types, monthly volume, company, budget, or other details you choose to provide.
This information is collected exclusively when you explicitly ask to submit a consultation inquiry. The tools do not schedule a meeting or guarantee a response time.
C. Technical & Security Telemetry
To ensure server reliability, prevent distributed denial-of-service (DDoS) attacks, and enforce fair rate limits, our reverse proxy logs minimal operational metadata: client IP address, request timestamp, HTTP status code, and tool invocation endpoint. This operational telemetry is never tied to your personal identity or chat transcripts.
4. Restricted Data — Strict Prohibition
Explicit Exclusion of Restricted Data: In strict compliance with OpenAI Guidelines, our plugins do NOT collect, solicit, or process:
- Payment Card Information (PCI DSS data, credit/debit card numbers, CVVs).
- Protected Health Information (PHI) under HIPAA or health records.
- Government Identifiers (Social Security Numbers, national identity cards, passport numbers).
- Access Credentials & Authentication Secrets (user passwords, private keys, MFA/OTP codes, secret tokens).
Users must not input any Restricted or Regulated Sensitive Data into any tool prompt or document upload.
5. Purposes of Use
We use collected data solely for the following explicit purposes:
- Real-Time Deliverable Generation: To compute and return PRDs, Mermaid diagrams, database schemas, invoice JSON, contract-clause signals, and preview-only webhook validation.
- Consultation Scoping: To review voluntarily submitted project parameters and respond to an explicitly requested follow-up inquiry.
- Infrastructure Health: To maintain system uptime, prevent abusive traffic spikes, and enforce rate limits.
6. Prohibition of Model Training & Data Monetization
We respect the confidentiality of your intellectual property and project blueprints:
- We do not sell, rent, lease, or monetize your personal data or project specifications to any third party.
- We do not use your proprietary inputs, generated PRDs, or extracted documents to train public AI, foundational models, or machine learning datasets.
- We do not perform behavioral tracking, cross-site surveillance, or commercial user profiling.
7. Categories of Recipients & Data Disclosures
We do not share your personal information with third parties except under the following strictly limited circumstances:
- Infrastructure Service Providers: Cloud hosting (datacenter virtual private servers) and Cloudflare edge proxies under strict confidentiality, operating solely as data conduits for TLS termination, DDoS mitigation, and network routing.
- Legal Obligations: If strictly required by valid legal subpoena, court order, or binding applicable law.
8. Data Retention, Storage & Security
- Ephemeral Computation: In-chat task calculations (PRD generation, JSON parsing) are processed dynamically in memory and discarded upon completion of the response.
- Consultation Records: Voluntary inquiry records (name, email, company, and supplied project summary) are retained for up to ninety (90) days for requested follow-up, or until you request deletion.
- Encryption & Sandboxing: All data in transit is protected using industry-standard HTTPS encryption (TLS 1.2 and TLS 1.3). Our backend services operate under isolated OS-level sandboxing (
ProtectSystem=strict, NoNewPrivileges=true) bound to local loopback interfaces.
9. User Rights & Data Deletion Controls
You have full ownership and control over your personal data. You have the right to:
- Access & Review: Inquire what personal or consultation data we maintain about you.
- Rectification: Request correction of inaccurate contact information.
- Erasure (Deletion): Request immediate, permanent deletion of your consultation records and contact details.
To exercise any of these rights, email us at [email protected] with the subject "Data Deletion Request". Requests are verified and processed within 48 hours without fees.
10. Developer Verification & Support Contact
The data controller responsible for these tools is Hardik Sapra.