Privacy Policy
Last updated: September 7, 2026
Overview
Vertical Bar Agent and the ChatGPT app
When you connect Vertical Bar Agent to ChatGPT or another MCP client, the app receives the inputs that client supplies to our tools and uses your authorized CrossCheck and Vertical Bar access to carry out the request. These inputs can include workspace and environment selections, dates, filters, record references, queries, test definitions, release-package content, and briefing content. We receive conversation content when the client includes it in a tool input, such as the prompt used to create a briefing.
Account and access information: authentication tokens and session records, user and OAuth subject identifiers, OAuth client identifiers, granted scopes, email address or display name, account status, roles, and permissions. These support sign-in, access control, and identifying the connected account. Account-identification responses may include your email address and granted scopes. Tokens are used for authentication, not as business-analysis output.
Organization and workspace information: organization, workspace, project, environment, and NetSuite account names and identifiers; workspace membership and access; configuration and status; and links to authorized records. These identify which customer data a request may access and where results belong.
Business records and people represented in them: query rows, transaction identifiers, dates, amounts, invoice or payment status, accounting classifications, customer and vendor records, contact names, email addresses, phone numbers and business addresses, employee identifiers, names, email addresses, departments, roles, and activity actors. The fields returned depend on the selected tools, authorized source data, and query. Authorized business data may also contain employment or compensation fields, credit limits, or business tax identifiers.
Analysis and technical records: process cases and events, actor and timestamp information, transaction relationships, paths, variants, exceptions, performance measures, snapshot and customization metadata, script or configuration source, dependencies, execution telemetry, test definitions and revisions, test results, release-package items, Git repository or revision references, workflow stages, deployment evidence, and creator or approver information. These may contain the same personal or business information as the underlying records.
Prompts, artifacts, and activity history: briefing titles, HTML and report contents, the basis prompt supplied by the client, model and host identifiers, and provenance describing how an artifact was produced. Tool activity includes tool names, timestamps, status, sequence, correlation identifiers, and digests of inputs. Publishing a briefing stores its content and provenance in the selected workspace, where authorized users can view it; publishing a new version can replace the topic’s latest-version reference.
Nested metadata and diagnostics: information in nested objects and arrays is included in these categories, even when it is not displayed in the chat answer. Examples include job and run identifiers, idempotency keys, workspace and record references, provenance, summaries, counts, limits, timing, status and error codes, diagnostic messages, and upstream API error details. Error details may repeat submitted values or source-record information. Routine results are not a guarantee that every field has been de-identified.
Operational and security records: our service may record the acting user or API-key identifier, organization and workspace, requested action and resource, timestamps, outcome, query text or other action metadata, request IP address, and user-agent information. App audit records are separate from the website analytics system described below. A query can leave an audit record or a short-lived result cache even when it does not change ERP records; asynchronous analysis creates job records.
How app information is used and shared
We use app information to authenticate users, enforce workspace and environment access, retrieve and analyze authorized data, run requested jobs and governed workflows, create and display artifacts, support the service, diagnose failures, and maintain security and auditability. The app is intended for business workflows. Do not put passwords, authentication secrets, full payment-card details, health records, or other unrelated sensitive information into queries or briefing content.
Tool responses, including their nested contents and error details, are returned to the AI platform you use: OpenAI for ChatGPT, or the provider of another connected MCP client. That platform can use these results to produce your answer and may retain them in conversation history under its own terms, privacy policy, and account settings. A request for a summary can still return structured source data to the platform. Disconnecting the app does not erase data already present in that platform’s conversations.
Vertical Bar and CrossCheck services process the request using our hosted infrastructure, including Amazon Web Services for compute, storage, identity, and operational logging. Authorized NetSuite queries and governed test or deployment actions communicate with the customer’s connected NetSuite environment. Optional integrations and AI features may involve OpenAI, Anthropic, GitHub, or support providers as described in our Data Processing Agreement. Customer administrators and other authorized workspace users may access shared artifacts and associated activity according to their permissions. Service providers may process information in the United States.
We do not sell customer personal data provided under the Data Processing Agreement. The website analytics and newsletter services described below have their own purposes; they are separate from the app’s business-data workflows.
App retention and deletion
Connected business data, snapshots, jobs, tests, workflow histories, and published artifacts are retained to provide the customer’s ongoing service and instructed workflows. A completed tool call does not automatically delete these records. Published briefings, their supplied prompts and provenance, and persistent audit histories do not have an automatic expiry for each call. Applicable customer deletion instructions and service-agreement requirements govern their removal, subject to legally required retention.
Short-lived caches and infrastructure records have separate lifetimes. Live-query result caching defaults to 30 seconds and can vary with service configuration. Our standard production infrastructure configuration retains application and MCP runtime logs for three months, selected authentication-helper logs for one month, and rolling database backups for 7 to 14 days, depending on the database. These periods do not apply to persistent business or audit records stored in the service database, and retained recovery copies are separate from live records.
To request access, correction, export, or deletion of personal information held by Vertical Bar, contact hello@vertical.bar. Identify the account and workspace involved without sending passwords or tokens. For information held on an organization’s behalf, we coordinate with its authorized administrator. Customer deletion and return requests are handled under the applicable service agreement, Data Processing Agreement, and law; we may need to verify identity and authority before acting.
You can disconnect the app in your AI platform and revoke the relevant authorization to stop future app access. Disconnecting does not itself delete CrossCheck or Vertical Bar business records, published artifacts, audit history, source NetSuite records, or copies held by the AI platform. Use the relevant service’s deletion controls or contact the provider for those copies.