ChatGPT app privacy & support

UK Shortlists ChatGPT apps: privacy and support

This page is the stable public privacy and support policy for UK Shortlists ChatGPT app experiences, including the UK Shortlists Buyer Guide and the review-safe UK Shortlists Agent Dock Action. These tools are designed to help route buying and operational questions safely, not to collect sensitive personal data or perform hidden actions.

Last updated: 9 June 2026. For the wider website policy, see the Privacy Policy. For support or data questions, use Editorial Contact. For a user-facing explanation of the Buyer Guide boundaries, see UK Shortlists Buyer Guide for ChatGPT.

Covered ChatGPT experiences

UK Shortlists Buyer Guide

Helps a reader turn a buying question into a safer UK Shortlists starting route, including relevant guide caveats, disclosure context, and checks before buying.

UK Shortlists Agent Dock

Helps Mark inspect local Agent Dock health, worker metadata, SOPs, routing decisions, queue state, and evidence handoffs through a review-safe Action surface.

What the Buyer Guide app does

The ChatGPT app helps a reader turn a buying question into a safer starting route on UK Shortlists. It can search eligible buying guides, recommend a starting route, compare safe route options, summarize caveats, explain checks before buying, and queue a custom shortlist request when a user explicitly provides an email, buying context, and confirmation.

The app recommends UK Shortlists pages. It does not return raw affiliate links, Amazon links, Awin links, direct merchant checkout links, live prices, stock, ratings, review counts, or deal claims.

Custom shortlist requests are optional. They create a private triage record first; they do not automatically create a public route, change rankings, change merchant links, subscribe a user to the newsletter, or trigger a purchase.

What the Agent Dock Action can and cannot do

The public Agent Dock Action is intentionally review-safe. It can inspect status and make route recommendations, but it is not an autonomous computer-control system inside ChatGPT.

Allowed public Action capabilities

  • Inspect Agent Dock health and configuration status.
  • List SOPs, authority tiers, and worker capability metadata.
  • Return no-execution routing decisions for a proposed task.
  • Inspect queue, run, artifact, and evidence handoff summaries.
  • Explain the private next command or approval needed.

Not exposed through the public Action

  • Running workers, shell commands, deployments, migrations, or browser automation.
  • Creating, enqueueing, retrying, cancelling, or recovering tasks.
  • Posting publicly, sending email, mutating accounts, making payments, or changing billing.
  • Merging pull requests, pushing code, changing files, or editing affiliate/sitemap controls.
  • Requesting passwords, API keys, tokens, cookies, MFA codes, payment data, or private account screenshots.

Information used by the apps

  • The buying question or route request a user gives inside ChatGPT.
  • The route slug or guide id when ChatGPT asks for a specific UK Shortlists guide summary.
  • Email address, buying context, must-have notes, avoid/dealbreaker notes, and optional source URL only if a user asks to queue a custom shortlist request and explicitly confirms the request.
  • Newsletter interest only if a user separately opts in to newsletter updates while making a custom shortlist request.
  • The operational request text Mark gives to Agent Dock when asking for a route decision or evidence summary.
  • Non-secret Agent Dock status, worker metadata, SOP metadata, queue summaries, run summaries, and evidence handoff summaries.
  • Basic operational request data handled by the hosting provider for security, reliability, and debugging.

UK Shortlists does not need a user login, exact location, payment details, contact list, government id, API key, account credential, or MFA code for these public app surfaces.

Restricted information

The app should not ask users to provide payment card details, passwords, API keys, government identification, protected health information, precise location, or other sensitive account credentials.

If a user asks for medical, legal, financial, insurance, or safety-critical advice, the app should keep the answer general, avoid product recommendations where unsafe, and suggest qualified professional or official sources where appropriate.

Prompt retention and analytics

The public Buyer Guide app does not need to store raw user prompts by default. Aggregate operational signals may be used to understand route-match quality, no-safe-match cases, tool errors, and reliability.

Default retention for Buyer Guide operational logs should be limited to up to 30 days where UK Shortlists controls the setting, unless a longer period is required for security investigation, abuse prevention, legal compliance, or resolving a support request. Repo evidence reports may be retained longer when they contain only test prompts, public route metadata, validation results, and no private user prompt text.

Custom shortlist queue records are retained for triage, source checking, requester follow-up, abuse prevention, and audit purposes until they are actioned, deleted, or no longer needed. Requesters can ask for deletion or correction using the support details below.

Agent Dock stores local task and run evidence for operational review on Mark-controlled infrastructure. Public Action responses should contain summaries and evidence references, not credentials or raw private account data. Local evidence is retained until Mark deletes the relevant Agent Dock data or reports.

If more detailed logging, analytics, or prompt retention is introduced later, this page and the wider privacy policy should be updated before that change is used for a public app.

Third-party services

ChatGPT app interactions are handled through OpenAI's ChatGPT platform. The UK Shortlists app endpoint may also be hosted by a cloud provider. Those providers process technical data needed to deliver the service under their own terms and policies.

The app itself should not send user prompt text to affiliate networks or merchants. Merchant and affiliate journeys remain on the UK Shortlists website, where route-level disclosure and external-link controls apply.

If a user explicitly opts in to newsletter updates during a custom shortlist request, the email address may be sent to the configured email provider to process that opt-in and maintain unsubscribe or suppression records. Without that separate opt-in, the email is used for the custom shortlist request only.

When Mark separately approves a private Agent Dock task, local workers may contact configured systems such as GitHub, Codex, OpenClaw, Jules, browser automation, or shell validation commands. That private execution layer is not exposed through the public review-safe Action schema.

Retention and updates

Operational logs should be kept only as long as needed for reliability, security, and app-quality review. UK Shortlists should avoid retaining sensitive prompt details unless a specific privacy-reviewed need is documented.

These notes should be reviewed before the app is submitted publicly, after any material app-behaviour change, and after any change to logging, analytics, hosting, or data retention.

Support and deletion requests

For app-support, privacy, correction, deletion, or safety questions, email editorial@ukshortlists.co.uk or use the Editorial Contact page.

Include the app name, the approximate time of the issue, the affected page or route if relevant, and a short summary. Do not include passwords, tokens, cookies, payment details, or MFA codes in support messages.

Contact

For privacy questions, corrections, or app-support queries, use Editorial Contact.