EFFECTIVE AUGUST 9, 2026
Privacy policy
This policy covers the Never86'd Marketplace Margin Audit website, operator-pilot form, plugin, and public MCP service.
Data you choose to provide
The plugin processes files and financial totals you intentionally supply through ChatGPT or Codex. Supported server-side files include redacted CSV/TSV marketplace exports, redacted Toast OrderDetails CSV exports, and redacted native-text PDQ Z-report PDFs or text exports. For other marketplace PDFs, screenshots, and spreadsheets, ChatGPT or Codex extracts structured totals before calling the calculation tools; those raw files are not sent to the plugin's calculation server.
Supplied data can include restaurant or location labels, statement dates, food sales, marketplace fees, promotions, credits, payout totals, POS sales and order evidence, business-day configuration, and redacted bank-deposit amounts. The PDQ PDF tool extracts native text only and does not run image OCR.
Do not provide bank or card account numbers, card first-six or last-four, approval or network references, routing numbers, tax or government identifiers, credentials, API keys, guest or consumer identifiers, loyalty IDs, guest contact information, delivery addresses or ZIP codes, receipt barcodes, or other information that is unnecessary for a marketplace audit. Do not upload a whole DoorDash report ZIP or Red Card transaction export; extract only the required redacted financial CSV.
How we use data
We use supplied data only to inspect POS evidence; calculate and display the requested statement audit, payout reconciliation, period trend, or channel comparison; prevent abuse; maintain service reliability; and respond to support requests.
Website and pilot requests
If you request the operator pilot, we collect the contact and business information entered in the form: name, work email, restaurant or group, role, location range, marketplace, stated priority, and redaction acknowledgement. The form does not accept statement uploads.
The website records a limited event when a visitor selects the ChatGPT audit or pilot link. That event can include the button location, page path, campaign tags supplied in the URL, and the referring website's hostname. These values are used to understand which outreach produces pilot interest. We do not set advertising cookies or collect the referring page's full URL for this measurement.
Human-reviewed improvement
Restaurant files are not automatically used to train a model or to rewrite a parser. When an operator explicitly chooses to help improve an adapter, Never86'd can create a separate redacted review record containing a source fingerprint, generic scope alias, normalized claim, human decision, reason code, and evidence reference. Raw statement rows, guest data, credentials, and account numbers do not belong in that record.
An approved correction can become a redacted regression test only after review. Model-generated criticism is advisory; it cannot approve financial ground truth, waive privacy controls, promote an adapter, or deploy a change.
Storage and retention
File contents, extracted PDF text, and supplied audit figures are processed in memory and are not intentionally stored by the application after the tool request completes. The application does not create a restaurant profile or retain audit history in this release.
Service diagnostics may retain an error category, service version, and timing for up to 30 days. They are designed not to include raw statement rows, tool inputs, account numbers, or guest data. Hosting and network providers may process standard request metadata to deliver and secure the service.
Pilot requests are delivered to Never86'd by email for lead follow-up and service operation. Limited website events may appear in hosting logs for campaign measurement and service reliability. They are retained only while reasonably needed for those purposes or until deletion is requested, subject to legal and security requirements.
Recipients and processors
Data is processed by Never86'd and infrastructure providers needed to host and secure the service, including Vercel for the website and request handling, Resend for pilot-request email delivery, and the separate provider hosting the plugin during marketplace review. ChatGPT or Codex and OpenAI handle information under the terms and privacy choices applicable to your OpenAI account. We do not sell restaurant statement data or use it for third-party advertising.
Your controls
You control what you submit. Redact unnecessary information before use. For a privacy question, access request, correction, or deletion request concerning data you believe you sent to the service, email myke@n86.app. Because statement content is not intentionally retained after the request, it may no longer exist when a request is received.
Changes
Material changes will be posted on this page with a new effective date. New data connections or persistent account features will require an updated policy before launch.