Candidate notice · updated 26 September 2026

Privacy notice

This notice describes the VCP demonstration at valuecontextprotocol.org, which Creed Space operates. It does not describe other implementations of the protocol.

It is a candidate notice: a best-effort technical description of what the site does, not yet formally approved by Creed Space and not yet checked against the hosting providers' retention, processor, and cross-border settings.

What the site stores in your browser

  • The site keeps two items in your browser's local storage: the accent color you pick in the Preferences panel (vcp-prefs), and which Learn modules you mark complete (vcp-course-progress).
  • What you enter in the demos and the Playground, such as constraints, personal state, and context, stays in page memory and is lost when you reload or leave the page. The site does not use session storage.
  • The site sets no cookies and loads no analytics or advertising scripts.
  • To remove the two stored items, clear this site's data in your browser settings; unmarking a Learn module also removes it from your progress. The Reset buttons in the demos clear only what is on screen.

What goes into page addresses

The Playground records the open tab and any example preset (for example ?preset=crisis) in the address bar. If you copy a Playground share link, the profile, constraints, preferences, and constitution you chose are placed in that link's address, base64-encoded but not encrypted, so anyone with the link can read them. Personal state and private fields are never put in the link.

Optional chat

Each message you send from a demo's or the Playground's chat box goes to this site's server, one message at a time; earlier messages are not resent. With it go the demo's constitution ID, its persona name, and its constraint flags, which are sent whether or not you check the sharing box. When no model provider is configured, as is currently the case, messages stop at this server and the chat shows a pre-scripted reply.

When a provider is configured (by default, OpenAI's chat API), the server forwards that one message, the constitution ID, the persona name, and the constraint flags to it. Personal-state values reach this site's server only if you check the sharing box in the chat. The server reduces them to a single protection level (standard, elevated, high, or critical) and the provider receives only that level, never the values. Unchecking the box stops personal state from going with later messages. Raw private context and VCP tokens are never sent.

In browsers that expose document.modelContext, the site also registers VCP tools that AI agents running in your browser can call. Its chat tool sends whatever context the agent supplies to this site's server, which keeps only the constraint flags and personal state from that context and handles them as above. The chat box's sharing checkbox does not govern what an agent sends.

Operational processing

Cloudflare and Render process ordinary network and service metadata such as IP address, user agent, route, time, and response status to deliver and protect the site. Page addresses, including any Playground share link or preset, pass through these providers when a page is opened. For chat, the application also uses your IP address briefly, in memory only, to rate-limit requests; it is not logged. Chat logs record operational fields such as request ID, status, and response time, never message content or IP addresses.

The application accepts sampled Content Security Policy violation reports and normalizes them to a bounded set of technical fields. It is designed to exclude page content, chat content, VCP context, cookies, credentials, and query strings from those reports.

How long the hosting providers keep logs, who can access them, the processor agreements, and any cross-border transfers are still under review. This notice will be updated when those settings or providers change.

Your choices and contact

You can use the documentation and scripted demonstrations without live chat. Do not enter confidential, regulated, or third-party personal data. For a privacy question, access or deletion request, or suspected data exposure, email Creed Space at security@creedspace.com. Include only the minimum information needed to investigate.