// legal

Privacy Policy

Effective: July 2026

OpsVerdict is a self-appraisal tool for founders and operators. This page explains, in plain terms, what we collect and why.

Overview

This policy explains what information OpsVerdict collects when you use this site, why we collect it, and what rights you have over it ("we", "us"). opsverdict.com is the app you interact with, and it is built to handle the backend that stores your data and enforces access to it. This policy covers both.

Information you provide directly

Depending on how you use OpsVerdict, we collect:

  • Assessment answers — your self-reported responses to appraisal questions, plus any business name, website, or tagline you choose to add to a report.
  • Email address — to verify a one-time code, recover a report, or create an optional account with a password.
  • Sponsor (investor/advisor) profile — email, name, organization, and role, if you sign up to invite founders or view the curated founder showcase.
  • Reviews — your name, role, and quote, if you choose to leave a testimonial. Shown publicly only after we approve it.
  • Showcase opt-in — a short pitch and, optionally, a PDF pitch deck, if you choose to make your profile visible to sponsors. This never includes your assessment score — see "How we share information" below.
  • Repo access — a GitHub repo URL and, for private repos, either a personal access token you paste in or access granted through installing our GitHub App. See "GitHub repo signals" below for exactly what this does and doesn't give us access to.
  • Payment information — handled entirely by Stripe when you unlock a full report. We never see or store your card details.

Information collected automatically

We use a small number of functional cookies to keep you signed in (see "Cookies" below). We do not currently run advertising or behavioral-analytics tracking on this site. If that changes, we'll update this policy first.

How AI is used in scoring

Your self-reported answers are sent to AI models to help generate a per-question score and a short narrative for each dimension of your appraisal. Claude never sets your final score on its own — a fixed, published rubric (weighted scoring across dimensions) owns the actual math; Claude's output only feeds into it as a structured judgment plus justification per answer.

AI processes this data under its own API terms and does not use API inputs to train its models by default. We don't send your answers anywhere else for AI processing.

GitHub repo signals

Linking a repo is entirely optional and only ever pulls structural signals: primary language, whether CI is configured, whether tests are set up, dependency count and lockfile presence (both read from package.json), star count, open issue count, and last push date. We never read, store, or display your actual application source code, and nothing we fetch from GitHub is shown to a person or sent to an AI model.

For private repos, you can either paste a fine-grained personal access token or connect through our GitHub App, which you install and configure yourself — you choose exactly which repo to grant, with read-only access to that repo's contents and nothing else in your account. Either way, the credential is used once for that single check and is never stored, logged, or retained afterward.

How we share information

We don't sell your personal information. We share it only in the following ways:

  • Service providers who help us run OpsVerdict — AI providers (AI scoring), Stripe (payment processing), Mailtrap (transactional email delivery), and GitHub (repo signal checks, only when you link a repo) — each bound by their own data-processing terms.
  • The sponsor showcase — if you opt in, your pitch and (if provided) deck are included in a curated weekly digest sent to vetted investors/advisors. Your assessment score is never included; only what you wrote for that purpose. You can withdraw at any time from your dashboard, and future digests will no longer include you.
  • Legal or safety reasons — if required by law, to enforce our Terms, or to protect the rights, safety, or property of OpsVerdict, our users, or the public.
  • Business transfers — if OpsVerdict were involved in a merger, acquisition, or asset sale, your information may transfer as part of that deal, subject to this policy (or a policy at least as protective).

Cookies

We set signed, HTTP-only session cookies (ov_account, ov_sponsor) so you stay signed in between visits. These are strictly functional — they don't track you across other sites and aren't used for advertising.

Data retention

We keep your assessment and account data for as long as your account is active or as needed to provide the service you've requested. If you'd like your data deleted, contact us using the details below and we'll remove it except where we're required to keep it (e.g. financial records for tax purposes, or fraud-prevention records).

Data security

Passwords are hashed, not stored in plain text. Access to production data is limited to staff who need it to operate the service. No system is perfectly secure, but we take reasonable technical and organizational steps to protect your information.

Your rights

Depending on where you're located, you may have the right to access, correct, export, or delete the personal information we hold about you, or to object to or restrict certain processing (for example, opting out of the sponsor showcase without deleting your whole account). To exercise any of these rights, contact us using the details below.

International transfers

Our service providers (AI providers, Stripe, Mailtrap, GitHub) are based in or operate infrastructure in the United States. If you're located outside the US, your information may be transferred to and processed in the US and other countries with different data-protection laws than your own.

Children's privacy

OpsVerdict is intended for founders, operators, and investors evaluating a business — it isn't directed at, and we don't knowingly collect information from, anyone under 16. If you believe a child has provided us information, contact us and we'll delete it.

Changes to this policy

We may update this policy to reflect changes in our practices or for legal, operational, or regulatory reasons. We'll update the effective date below when we do, and for material changes, we'll make a reasonable effort to let you know.

Contact us

If you have questions about this policy or how your information is handled, email us at info@opsverdict.com.