Candidate public notice · technical review 15 August 2026

Privacy Notice

This notice describes the VCP demonstration at valuecontextprotocol.org. It does not describe every independent implementation of the protocol.

This is a best-effort technical description pending approval by a named privacy authority and review of deployed processor, retention, and cross-border settings.

What the site stores in your browser

  • Portable demonstration preferences may use local storage.
  • Sensitive demonstration context uses session storage. It is scoped to the browser session and is normally discarded when that tab or window session ends, subject to browser restore behavior.
  • The site does not set advertising cookies or intentionally load behavioral analytics.
  • You can remove stored demonstration data through the relevant reset controls or your browser's site-data controls.

Optional chat

Scripted fallback chat works without a model provider. When live chat is configured, the server sends your message, selected constraint flags, and any personal-state values you explicitly consent to share to the configured provider. Raw private context and VCP tokens are excluded. Withdrawing the sharing control stops personal-state values from being included in later requests.

Operational processing

Cloudflare and Render process ordinary network and service metadata such as IP address, user agent, route, time, and response status to deliver and protect the site. The application accepts sampled Content Security Policy violation reports and normalizes them to a bounded set of technical fields. It is designed to exclude page content, chat content, VCP context, cookies, credentials, and query strings from those reports.

Hosting retention, access, processor agreements, and cross-border review remain explicit production-governance gates. This notice will be updated when those settings or providers change.

Your choices and contact

You can use the documentation and scripted demonstrations without live chat. Do not enter confidential, regulated, or third-party personal data. For a privacy question, access or deletion request, or suspected data exposure, email security@creedspace.com. Include only the minimum information needed to investigate.