Terms & Privacy

A diagnostic aid with an explicit evidence boundary

Effective 2026-09-05. GPTsApp provides explainable troubleshooting guidance, not a warranty, security audit, legal decision, or guarantee that a capability will work.

Use and limitations

Use the service only with evidence you are authorized to share. Do not submit credentials, private keys, cookies, access tokens, full environment files, personal data, private source, or production-sensitive payloads. The service does not execute, install, approve, authorize, or modify third-party capabilities.

Results are based only on sanitized supplied evidence and deterministic rules. They may be incomplete or wrong. Follow bounded steps, preserve backups where relevant, and stop when a result instructs you to stop. GPTsApp does not assign legal responsibility or publisher fault.

What leaves your browser

Raw text is processed by a browser worker that removes common secret, credential, path, private-address, hostname, and email patterns. You review the sanitized preview before submitting it. A defensive redaction pass runs again at the server boundary. Automated redaction is not perfect, so submit only a small reviewed excerpt.

Default diagnosis lifecycle

A normal diagnosis and structured recheck are analyzed without storing the submitted text as a report. Privacy-safe operational events may record the capability category, failing checkpoint, confidence, rule identifier, route, recheck status class, and timestamp. They do not contain diagnostic text, raw IP, user-agent string, cookies, or account identifiers.

Local Review Packs, Scope Links, notes, and screenshots

A Review Pack is generated and imported locally. It may contain sanitized evidence, selected scope, a deterministic result, an optional recheck, a local session note, and written screenshot annotations. Image bytes are never included. Local notes use session storage in the current browser tab/session and leave the browser only when you explicitly export the pack.

A Scope Link uses a URL fragment and is limited to category, surface, OS, recent-change class, checkpoint, rule identifier, and route. It excludes evidence, capability/provider names, versions, notes, report identifiers, management tokens, paths, hosts, and screenshot metadata. Opening it fills scope controls but does not submit a request.

Screenshot preview accepts only bounded PNG, JPEG, or WebP files through a local object URL. GPTsApp does not upload, OCR, retain, or analyze those image bytes. Review the image yourself and write only the visible success/failure boundary.

Local tool contract checks

The separate tool-definition checker processes your JSON definition, optional argument examples and short error excerpt in a bounded browser worker. It does not upload them, execute the described tools, contact external schemas, call a model, or store the draft in browser storage. Changes are candidates you explicitly select and review; the original remains unchanged. Downloads can include a reviewed candidate and its findings. The maintainer brief excludes the full definition and argument values; review it before sharing. Static and sample checks do not prove runtime compatibility or semantic equivalence.

Reported upstream evidence

GPTsApp Doctor may attach official release notes or machine-curated reports from the official upstream repository. These matches do not increase confidence, do not confirm a current incident, and do not establish behavior outside the listed environment. Machine-curated records remain noindex and non-publication evidence until human review and reproduction gates pass.

Optional private reports

Saving is explicit. A saved report contains the sanitized text, selected context, deterministic result, rule metadata, redaction counts, timestamps, and an optional outcome. It is accessed through an unguessable URL, excluded from indexing and caching, expires after seven days, and can be deleted immediately with the independent management token stored in the URL fragment.

Anyone who receives the read URL may view the sanitized report. Keep it private. Only a holder of the management token can delete it or record an outcome.

Abuse and security

Requests are size-bounded and rate-limited through an anonymous keyed daily IP digest; raw IP is not stored in the application database. Human verification may be required for report management. Automated abuse, attempts to evade limits, or submission of harmful/unauthorized material may be rejected.

Contact and changes

Operational contact details will be published only after a verified support channel is configured. Material privacy changes will update the effective date on this page. Existing saved reports retain their original seven-day maximum lifecycle.