The buyer-advocate trust protocol
ValueRoom is built so a buyer can trust the room they're in. This page explains exactly how we handle what you do and say here — enforced in our system and checked by automated tests, not just promised.
Read the full protocol
The protocol at a glance
Thirteen guarantees. Each one is a fact about how the room behaves, and each links to its full wording below.
- Your questions to the assistant are privateAnswered in the moment and discarded. Never shown to the vendor's team.
- The assistant can't see the seller's internal viewIt has no access to the vendor's scoring, risk reads, or account strategy.
- You can connect your own AI, and it stays yoursRead-only, created and withdrawn by you, and it records nothing back.
- Room activity is shared — both waysWhat you open and download is visible to both sides, and never feeds a hidden score.
- Reactions are explicit, named, and sharedA reaction carries your name and shows identically to both sides. Off means off.
- A decision you record is an explicit, named actYour click, your name, shown the same to both sides, changeable any time.
- Messages you post are shared, and read by the assistantA recorded, shared channel. Unlike your private questions to the assistant.
- Meeting recordings appear only as shared artifactsOne recording and transcript both sides see; recording starts only after your side confirms.
- What we record, and what we don'tRoom activity, yes. Your questions to the assistant, no.
- Confirmations carry a recorded identity gradeEach confirmation records how you were authenticated; a one-time code is available as a step-up.
- AI processingAnswers come from a third-party AI provider (Anthropic). Your question is not stored by ValueRoom.
- What happens to data over timeRaw text expires on the vendor's schedule, a person can be erased, a departing organization is exported then deleted.
- Published documents are quoted, never improvisedEvery quote is checked word for word against the source, and the source is always shown.
The guarantee about the guarantees.
Enforced, not just promised. Each guarantee above is enforced in our code and checked by automated tests. We do not yet hold a third-party certification such as SOC 2 — when we do, we'll say so here, and not before.
Enforced in code
Each guarantee above is a rule the system applies itself — a wall, a gate, a firewall — not a policy someone has to remember.
Checked before every release
Automated tests exercise the real code against each guarantee. A change that breaks one cannot ship.
Quoted, never paraphrased
Our disclosure documents quote this page word for word, and a check fails the build if the two ever drift apart.
The full protocol
The exact wording. It is the same text our disclosure documents quote, word for word.
Your questions to the assistant are private
When you ask the in-room AI assistant a free-form question, it's answered in the moment and then discarded — no question text is stored, and your questions are never shown to the vendor's team. The only thing recorded is an anonymous, organization-level tally of AI usage for billing; it can't be tied to you, your room, or what you asked. Alongside that tally, standard short-lived anti-abuse counters exist (rate limits); they contain no question text and no identity, and expire within minutes. Only an outcome you deliberately submit is shared.
The assistant can't see the seller's internal view
The buyer-side assistant is your advocate in the room. It is walled off from the vendor's internal scoring, risk assessments, and account strategy — it cannot reveal them even if you ask, because they are never within its reach. People in the room appear by name and role only, never with a seller's internal label.
You can connect your own AI, and it stays yours
If you'd rather read the record with your own AI assistant than through this room, you can. You create that access yourself and you can withdraw it at any time; the vendor can never create it, see it, or hold it on your behalf. It is read-only by construction — it can never confirm a milestone, withdraw one, leave a note, upload anything, or act in the room as you. It sees exactly what you can see and nothing the vendor keeps to itself. And it records nothing: your assistant's reading produces no notification, no activity entry, and no log of what it looked at.
Reactions are explicit, named, and shared
Rooms include the reaction control unless your vendor turns it off. A reaction you tap is recorded with your name and shown identically to both sides in the room's activity view. It is never a hidden rating and never an input to any score. Off means off: no reaction control, nothing of the kind recorded.
A decision you record is an explicit, named act
If your vendor adds a decision to a room, choosing an option is your click — it's recorded with your name and shown identically to both sides, so you both see the same result. You can change or clear your choice any time. It is never a hidden rating and never an input to any score.
What we record, and what we don't
So the room works and both sides stay in sync, we do record room activity — when you open the room, time spent on content, files you open or download, how far through videos you watch (quarter milestones only — never second-by-second), the links and buttons you click, and shares — tied to your identity. We also keep an anonymous, organization-level tally of AI usage for billing, and standard short-lived anti-abuse counters (rate limits) — no question text, no identity, expiring within minutes. We do not record your questions to the assistant. “Records nothing” applies to those questions specifically, not to the room as a whole; we'd rather be precise than sweeping.
Confirmations carry a recorded identity grade
When you confirm a milestone or an outcome, the confirmation records how it was authenticated. Your team can also require a one-time code emailed to your address before a confirmation counts — an available step-up, off by default.
AI processing
The assistant's answers are generated by a third-party AI provider (Anthropic). Your question is sent to produce the answer and is not stored by ValueRoom.
What happens to data over time
The vendor controls how long raw conversation text pulled from their connected tools is kept — once a retention window is set, older raw text is permanently removed on a nightly schedule (confirmed milestones and extracted signals stay). A person can be erased on request through the vendor's team: their name, email, and profile are permanently scrubbed, while anything they co-signed stays on record attributed to an erased person — so the shared history can't be quietly rewritten. And when an organization leaves ValueRoom, its data doesn't linger: a machine-readable export is offered, and after a grace period (30 days by default) everything is permanently deleted — all that survives is a minimal record that the deletion happened.
Published documents are quoted, never improvised
A vendor can publish reference documents for you — a security overview, data-processing agreement, product FAQ. When the assistant answers from them, every quote is checked word-for-word against the published document before you see it, and the source is always shown. If the documents don't answer your question — or it's a judgment call — the assistant says so and points you to your account team instead of guessing. Your questions about these documents are private, like all your questions here.