Privacy Policy
Last updated: August 30, 2026
1. Introduction
ValueSignal ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our Service.
By using ValueSignal, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.0 Evidence vs. Personal Data
ValueSignal distinguishes between "Evidence" and "Personal Data" to provide transparent, reviewable skill signals while protecting your privacy:
- Evidence refers to anonymized, structured representations of skills derived from your conversations. Evidence includes:
- Skill scores and capability assessments (e.g., "Problem Solving: 85/100")
- Extracted evidence snippets that demonstrate skills (e.g., "Analyzed complex data structure and proposed optimization")
- Work type classifications and tags
- Aggregated patterns and trends
- Personal Data refers to information that directly identifies you or contains your full conversation content. Personal Data includes:
- Your complete prompts and AI responses
- Account information (email, name, profile details)
- Conversation metadata (timestamps, platform identifiers, message signatures)
- Any information that could be used to identify you personally
When you share your profile, you are sharing Evidence (skill signals and anonymized evidence snippets), not your Personal Data (full conversations or identifying information). You maintain full control over what Evidence is visible and can edit or delete any Evidence at any time.
2.1 Account Information
When you create an account, we collect:
- Email address
- Password (stored as a hashed value)
- Name (optional)
- Account type (user or recruiter)
2.2 Conversation Metadata
When you capture AI work through any ValueSignal surface — our browser extension, our web console, or an editor or agent integration you install and authenticate (for example our Cursor plugin, and comparable integrations we may add) — we collect:
- Conversation content (prompts and responses)
- AI platform and model information (e.g., ChatGPT, Claude, Gemini, Cursor)
- Timestamps and interaction metadata
- Work type classifications
- Message hashes for deduplication
How integrations authenticate: Our browser extension and web console use a browser session. Editor and agent integrations instead use a personal access token you generate in Account Settings. That token is scoped to submitting captures only — it cannot read your account, billing, or stored data — expires after 180 days, is stored by us only as a hash, and can be revoked by you at any time. Because a token outlives a browser session, an integration can submit captures while you are signed out of the website.
Message hashes: We compute hashes to deduplicate messages and improve system efficiency. In some jurisdictions (for example, under the GDPR), a hash derived from message or conversation content may be treated as pseudonymous personal data, not anonymous data. We protect message hashes with the same technical and organizational measures we apply to conversation content and related metadata (including encryption in transit, access controls, and retention aligned with your account).
Extension updates: We publish the ValueSignal extension through applicable browser extension marketplaces (for example, the Chrome Web Store today, and other supported channels if we add them). New versions may be delivered automatically by the browser or platform, replacing the previous version where the store supports it. We describe material changes to data practices in this Privacy Policy and in the relevant marketplace listing when required.
Talent vs. recruiter accounts in the extension: Today, conversation capture via the extension applies to talent (user) accounts using supported AI platforms as described above. If you use a recruiter account in the extension, you may see an informational screen only; we do not collect AI conversation content from the extension for recruiter accounts in that configuration. Recruiter-related data you submit through the web application (for example, job or workspace information) is handled under the applicable sections of this Policy and your account settings.
2.3 Profile Information
You may provide additional profile information:
- Headline and summary
- Skills and preferences
- Industry and job role preferences
- Location and work preferences
2.4 Usage Data
We automatically collect information about how you use the Service:
- Pages visited and features used
- Time spent on the Service
- Device and browser information
- IP address (for security and analytics)
3. How We Use Your Information
We use the collected information for the following purposes:
- Service Provision: To provide, maintain, and improve the Service
- Skill Analysis: To analyze your AI conversations and generate skill signals
- Profile Building: To create and maintain your talent profile
- Job Matching: To match your profile with relevant job opportunities (if applicable)
- Communication: To send you service-related notifications and updates
- Security: To detect and prevent fraud, abuse, and security threats
- Analytics: To understand usage patterns and improve our Service
4. Data Storage and Security
We implement industry-standard security measures to protect your data:
- Encrypted data transmission (HTTPS/TLS)
- Hashed passwords (never stored in plain text)
- Secure database storage
- Regular security audits and updates
- Access controls and authentication
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.
4.1 Data Minimization
ValueSignal follows a "Private by Default" principle and practices data minimization:
- We only collect data that is necessary to provide the Service and generate your skill signals
- We do not collect data without your explicit action — data capture only occurs when you explicitly activate the capture feature
- We minimize the scope of data collection — we capture conversation content only when you choose to capture it, not continuously or in the background
- We store only what is needed — full conversation data is stored only for generating skill signals; we do not retain unnecessary metadata or browsing history
- We anonymize where possible — when generating evidence and skill signals, we extract structured, anonymized representations rather than storing full conversation context
- We apply automated filtering patterns — to detect and redact sensitive patterns before your capture is stored. Today this covers two groups. Personal identifiers: email addresses, phone numbers, validated payment card sequences, and government ID–like number formats. Credentials: private key blocks, vendor API keys, JSON Web Tokens, authorization headers, database connection strings containing passwords, and values assigned to secret-named variables. Patterns and coverage may evolve, the filtering is not exhaustive — it matches known shapes, not meaning — and you remain responsible for reviewing and editing what you capture before sharing
- Credentials are removed before transmission — in our editor and agent integrations, the credential patterns above are applied on your own machine, before the capture is sent. A detected secret is replaced locally and never reaches our servers. We record only that a redaction occurred and how many, never the removed value
You have full control over what data is captured, stored, and shared. You can delete any captured data at any time, and deleted data is permanently removed from our systems.
4.1.1 Evidence, conversation-derived content, and encryption
Evidence (skill signals, evidence snippets, and related structured fields) and the underlying conversation-derived content you choose to capture are transmitted to our servers using TLS (HTTPS) and stored in our production environment under two layers of encryption at rest. Prompts and responses are individually encrypted by ValueSignal using AES-256-GCM before they are written to the database, so the stored value is unreadable without a key held separately from the data; our production service refuses to start if that key is missing or malformed. That sits on top of the disk and database encryption provided by our hosting infrastructure, together with access controls and authentication as described in Section 4.2. We do not intend for Evidence to include direct identifiers when shown to third parties; it is still associated with your account in our systems until you delete it or close your account, subject to legal retention.
Where we produce aggregated or analytics datasets, we apply industry-standard de-identification techniques so that such data cannot reasonably be linked back to an individual user, consistent with the limitations described in our Terms of Service. No method eliminates all theoretical re-identification risk.
4.2 Access Control
ValueSignal implements strict access controls to ensure your data remains private by default:
- User-controlled access — only you can access your full conversation data and personal information through your authenticated account
- Role-based access controls — ValueSignal employees and contractors have access only to data necessary for their role (e.g., technical support, system maintenance), and access is logged and audited
- No default sharing — your data is never shared with third parties (including recruiters) without your explicit consent
- Granular sharing controls — when you choose to share your profile, you control what information is visible (evidence and skill signals, not full conversations)
- Encrypted storage — all personal data is encrypted at rest and in transit
- Regular access reviews — we regularly review and audit who has access to user data and remove access when no longer needed
If you believe your account has been accessed without authorization, please contact us immediately at privacy@valuesignal.ai.
5. Data Sharing and Disclosure
We do not sell your personal information. We may share your data only in the following circumstances:
- With Your Consent: When you explicitly authorize sharing (e.g., sharing your profile with a recruiter)
- Service Providers: With trusted third-party services that help us operate the Service (e.g., hosting, analytics)
- Legal Requirements: When required by law, court order, or government regulation
- Business Transfers: In connection with a merger, acquisition, or sale of assets (with notice to users)
- Protection of Rights: To protect our rights, property, or safety, or that of our users
5.1 Proof of Work certifications
If you choose to mint a Proof of Work certification, you are creating a deliberately public artifact. This is the one feature that publishes information outside your account by design, so it is worth understanding before you use it.
A certification contains summary Evidence only — a proof type and overall signal score, counts of sessions and signals, your top domains and skills, and the categories of source your evidence came from. It does not contain your prompts, the AI's responses, your email, or your account details.
- It is public and unauthenticated. Anyone holding the verification link can check the certification without signing in — that is what makes it verifiable to a third party
- It expires, and you can revoke it at any time from your account, which invalidates the verification link
- Revocation cannot reach copies. A certification is designed to be committed into a code repository. If you have published those files somewhere, revoking the certification invalidates the link but does not remove the files you placed elsewhere. Only you can do that
- Closing your account invalidates your outstanding certifications
Minting a certification is always an action you take deliberately. We never create or publish one on your behalf.
6. Your Rights and Choices
You have the following rights regarding your personal information:
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your account and data
- Export: Export your data in a portable format
- Opt-Out: Unsubscribe from marketing communications
- Control: Control what data is captured and shared through your account settings
To exercise these rights, contact us at privacy@valuesignal.ai.
7. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to:
- Maintain your login session
- Remember your preferences
- Analyze Service usage
- Improve user experience
When you arrive at our site from a marketing campaign link (for example, a link containing UTM parameters), we store those campaign attribution values in your browser's local storage for up to 30 days so we can understand which campaigns bring visitors to the Service. This information identifies the campaign, not you personally, and expires automatically.
You can control cookies through your browser settings. However, disabling cookies may limit your ability to use certain features of the Service.
8. Third-Party Services
Our Service may contain links to third-party websites or integrate with third-party services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
8.1 Third-Party AI Services
This section covers two different relationships that are easy to confuse, so we state them separately.
AI services you use directly. ChatGPT, Claude, Gemini and Cursor are services you have your own relationship with. What you send them is governed by their terms and privacy policies, not ours. ValueSignal observes that conversation only on the surfaces you have installed and authenticated, and only as described in Section 2.2. We do not control those services, are not responsible for their data handling or retention, and cannot guarantee their availability.
AI providers we use to analyze your captures. This is different, and it is our responsibility rather than yours. To turn a capture into skill signals, ValueSignal sends the captured prompt and response to a large language model provider under our own commercial account. We currently use OpenAI and Anthropic for this. They act as our processors: they receive this content because we send it, for the sole purpose of producing your skill analysis.
- Content is transmitted over TLS and decrypted only in memory for the duration of the analysis
- The redaction described in Section 4.1 is applied before analysis, so identifiers and credentials we detect are already removed
- We instruct our providers not to use this content to train their models, and we select processing terms intended to prevent it
- We will update this section if we change providers, and material changes are announced as described in Section 12
The remaining points concern the services in the first group — the ones you use directly:
- What you send to them directly is processed according to their terms and privacy policies, including their data retention, security practices, and any use of your data for training
- Third-party AI services may experience downtime, errors, or changes to their services that affect ValueSignal's functionality
- ValueSignal is not liable for any losses, damages, or data incidents resulting from third-party AI service failures, security breaches, or policy changes
We encourage you to review the privacy policies and terms of service of any third-party AI services you use. ValueSignal does not guarantee the availability, accuracy, or reliability of any third-party AI service.
9. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. When you delete your account, we will delete or permanently de-identify your personal data within 30 days, except where we are required to retain it for legal or regulatory purposes.
Plan limits affect what you can see, not what we keep. On our free plan, your logbook displays captures from the most recent 90 days. Older captures are retained, not deleted — they are hidden from that view and become visible again if you upgrade. If you want data removed rather than hidden, delete it directly; deletion is permanent and is the only action that removes it from our systems.
Aggregates and Evidence after closure: Anonymized Evidence or other information that has been irreversibly de-identified may remain in aggregated datasets used for analytics or service improvement; such data will no longer be linked to your identity or account. Where we rely on reversible pseudonymization only, we will delete or de-identify it consistent with the paragraph above and our Terms of Service.
10. Children's Privacy
ValueSignal is not intended for users under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child under 18, we will take steps to delete such information.
11. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country. By using the Service, you consent to the transfer of your information to these countries.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically.
13. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:
Email: privacy@valuesignal.ai
Website: valuesignal.ai