Skip to content
DeliverX
Start

DeliverX Ltd · Legal · Interim pilot policy

Privacy Policy

Effective for the open pilot · Last updated 25 July 2026 · Marker: interim-pilot-privacy

1. Interim policy status

This is an interim privacy policy for the DeliverX open pilot. It describes practices that are implemented in the product today. It is not a claim of formal GDPR certification, ISO certification, or completed legal counsel review. We will replace or extend this policy when commercial packaging ships or when counsel provides a full draft.

Privacy requests and questions: privacy@deliverx.dev

2. Who we are

DeliverX Ltd operates the DeliverX platform (including Experience, Launchpad / Career Intelligence, Professional Workspace, and Professional Intelligence surfaces) at deliverx.dev and related subdomains.

3. What we collect

Account data: email, name and authentication records via Supabase Auth when you create an account.

Professional Intelligence (PI) data you create or generate: profile and career goals, evidence ledger entries, artefacts and versions, capability assessments (ScoreRuns) produced by the Capability Engine, SnapshotClaims, Experience planner activity, learning items, real-world outcome notes, Verified Portfolio entries, and related review or notification records.

Workspace and delivery data when you use Professional Workspace: projects, meetings, tasks, decisions, risks, contributions and similar operational records tied to your organisation membership.

Attestation data when you request external verification: attestor contact details and attestation confirm/dispute outcomes for a specific portfolio claim.

Technical logs needed to operate the service (for example request metadata and AI interaction records used for orchestration trust and cost observability).

4. How we use data

To provide the product you signed up for, including evidence tracking, capability scoring via the Capability Engine, career readiness views, portfolio packaging and workspace collaboration.

To enforce trust rails: append-only evidence transitions, Capability Engine-only assessment writes, and Verified badges that require independent attestation.

To send in-product notifications about review, intervention or privacy actions you take.

AI features draft suggestions and observations. AI-generated observations are not automatically treated as verified evidence. Consequential changes require human approval where the product enforces that rule.

5. Observation consent (default OFF)

Continuous Workspace observation and related coach interventions require explicit consent. If no consent record exists, observation is denied. Observation is not evidence and does not assign capability.

6. Sharing and attestation

Evidence is private by default. Public or share-token portfolio views exclude private and confidential evidence and do not expose attestor personal data.

When you request attestation, we share a limited claim summary with the named attestor via a tokenised link so they can confirm or dispute that claim. Self-attestation of your own claim is rejected.

We do not sell personal data. We do not operate an employer marketplace that lists your profile for hire in this pilot.

7. Processors and hosting

We use infrastructure providers to run the product, including Supabase (authentication and PostgreSQL) and Vercel (application hosting). On production deploys we may load Vercel Web Analytics and Speed Insights for aggregate product usage (see the Cookies page). We do not use those signals as Professional Intelligence capability truth.

8. Export and delete

Signed-in users can export their person PI data and request deletion from account privacy controls (T1). Deletion uses a privileged purge path that removes person PI rows while preserving append-only ledger integrity rules where applicable. Organisation or shared project records may remain where other members still need them.

9. Retention

We retain account and PI data while your account is active and as needed to operate the pilot, meet security obligations, and honour export/delete requests. After a successful delete request, person PI data covered by the purge path is removed from the production database.

10. Your choices

You may update profile information in product settings, withhold observation consent, avoid requesting attestation, and use export/delete controls. For other privacy requests, email privacy@deliverx.dev.

11. Changes

We will update this page when practices change materially. Continued use of the pilot after a published change means you should review the updated text.

Related: Terms · Cookies

← Back to home