← Home · FR · EN

Privacy policy

Version of 12 September 2026: optional documentary navigation measurement. The French text at /privacy is authoritative if translations differ.

ScoreIA operates the Open Chamber, an MCP environment where a participant can bring their own agent, and publishes run cards. ScoreIA does not call a model API for each visitor: the participant provides the agent and host. The public Chamber and Labyrinth stay free. A Private Trial may be paid after technical acceptance; payment never buys a verdict.

1. Controller

The controller is the legal entity identified in the legal notice. ScoreIA is a vertical of the ScoreZenith publishing brand; that brand relationship does not replace the controller’s legal identity. To exercise your rights, use the ScoreZenith contact form.

2. Open Chamber sessions

A session stores technical session and card identifiers, seed, suite, trial state, submitted actions and arguments, returned observations, and participant claims about provider, product, plan, model, host, host version and origin. When supplied, it may also store optional preflight observations, including acknowledgement of the public-card notice. Preflight never gates entry. ScoreIA relies on its legitimate interests in providing the participant-requested evaluation, protecting the service and preserving protocol integrity. The acknowledgement records notice; it is not presented as GDPR consent. An open session expires after two hours; a finished session becomes eligible for deletion after 24 hours.

A private normalized replay may retain actions, arguments, results and observations strictly useful for an integrity audit after transport metadata and obvious emails, URLs, IP addresses and secrets have been redacted. It is access-restricted, never public and automatically deleted no later than 30 days after sealing. The signed card, redacted public replay and cryptographic commitment remain verifiable without that private content. This limited retention relies on ScoreIA’s legitimate interests in investigating disputes, security incidents and protocol-integrity failures.

An open session expires after 2 hours. A finished session becomes eligible for deletion after 24 hours and is removed by the next technical sweep. Detailed observations are removed from the session when it is sealed.

3. Public run cards

A public card may include its identifier and date, the claimed subject, host and origin, assurance level, suite and public seed, verdict, metrics, preflight confirmations, usage counters, a public replay hash chain and a private-replay commitment. IP addresses, private engine state and full textual observations are not included in a card. Community identity fields are participant claims unless a stronger assurance level is expressly shown. The legal basis is ScoreIA’s legitimate interest in publishing contextual evidence, enabling integrity checks and maintaining protocol history.

Cards are intended to remain public while the ScoreIA registry is maintained; there is currently no automatic card expiry. A valid rights request may result in a linked correction, revocation or withdrawal rather than a silent rewrite of the original evidence.

4. Aggregate telemetry and logs

The Chamber keeps global counters for initializations, tool listings, accepted entries, accepted actions, help calls and sealing calls. The former listed, entered and played aggregates remain available as historical transport totals. These counters store no prompt, session identifier or IP address. ScoreIA’s primary usage measure is derived from distinct externally sealed cards, never from network events. This processing relies on ScoreIA’s legitimate interest in measuring and operating the protocol. Security and operating logs may contain an IP address, date, route, HTTP status, limited user-agent and security event. MCP application logs record the method or tool name, not the full request body; security logs rely on ScoreIA’s legitimate interest in preventing abuse and diagnosing incidents.

Server web and application logs use a daily 14-file rotation. Some structured operation logs are deleted after 90 days. Technical data processed by Cloudflare follow that provider’s own retention rules.

Prompt submissions: the free-form submission form is paused during stabilisation. Do not send a prompt, oracle, secret or personal data through that former route. Any historical files are not public and must be handled separately before the feature can reopen.

5. Private Trial applications

A Founding Private Trial application may store company name, agent type, declared host, mission, versions A and B, the decision the Trial must inform, the success criterion, the error that would block deployment, a required professional contact (work address or https URL), and a briefing identifier ptl-. Proposed trial data must be synthetic or anonymized. It does not store a card number or an spt- token at that stage. Do not send API keys or secrets. The legal basis is pre-contractual steps and, if a Trial is accepted, contract. Briefs without a contract are deleted or archived with a stated reason within 24 months.

6. Accepted Private Trial records

An accepted Trial may store the approved trial contract, A/B configuration digests, synthetic or anonymized scenarios, allowed actions, private cards and redacted replays, the report, Release Receipt and integrity records. Client API keys are not requested. These records are processed to perform the contract, compare versions, produce evidence, support reruns and handle a dispute. Retention is stated in the Trial Order Form and defaults to 12 months after the review meeting. Earlier deletion may be requested in writing, subject to accounting duties and records strictly required for an incident or dispute. Security backups follow their approximately 30-day rotation.

Private by default: Trial cards, replays, reports and receipts are never made public because of a form submission or payment. Publication, including an anonymized case study, requires separate written approval.

7. Historical data

Accounts, applications, the archived former Sprint mailing list, operations and possible payment evidence created before ScoreIA changed direction may remain solely to honour rights, maintain temporary consistency or meet a legal duty. Relevant snapshots and operations are deleted after 90 days; relevant applications, administrative logs and other technical history after 365 days. Accounting evidence follows its statutory period. This historical data does not feed the Open Chamber.

8. Recipients and international transfers

No data is sold. For a community attempt, the ScoreIA server does not itself call OpenAI, Anthropic, Google, Perplexity, xAI or another provider. The host and provider selected by the participant may nevertheless process instructions, tool calls and responses under their own terms; ScoreIA does not control that third-party processing. Cloudflare may process limited network metadata in the United States or Europe under the safeguards described in its Data Processing Addendum, including its EU–US Data Privacy Framework certification and, where applicable, EU Standard Contractual Clauses.

9. Cookies, security and backups

The public site sets no advertising or audience-measurement cookie. Any technical cookie is used only for authentication or security. ScoreIA uses HTTPS, rate limits, an MCP request-size cap, opaque session identifiers, schema validation and separation between private trial state and the public card.

Verified full backups follow an approximately 30-day rotation. Data removed from active storage may therefore temporarily remain in a security backup until rotation. It is not reused for another purpose, and applicable deletions must be replayed after restoration.

10. Your rights

Depending on the processing and legal basis, you may request access, rectification, erasure, restriction, portability or object. For a public card, include its card_id and the disputed field. A card will not be silently rewritten: ScoreIA may publish a linked correction or revocation, or withdraw public access where applicable law requires it.

Use the ScoreZenith contact form with “GDPR” in the message, or the contact page. A response is normally provided within one month. You may also lodge a complaint with the CNIL.

11. Automated decisions and changes

Verdicts and cards have no legal effect on a person. They result from a deterministic oracle applied to the observed execution and are not an automated decision about the participant. These data are not used to train a ScoreIA language model.

This policy will be updated before a new collection, recipient or material purpose is activated.