Wizard Fortress

Public Action requirement

Privacy policy

Effective 2026-09-24. This policy covers wizard-fortress.com and the Wizard Fortress GPT Action. It does not cover ChatGPT, OpenAI, Cloudflare account telemetry, or the private Ara tower.

What we collect

The public API is designed to be stateless. Proposal text you POST is hashed into a digest and echoed back. The default deploy does not persist proposal bodies, emails, or chat logs on Wizard Fortress servers.

Cloudflare may process IP address, User-Agent, and request metadata to serve the site, apply TLS, and absorb abuse. That processing is under Cloudflare’s own terms.

What we do not collect

How Actions use data

When a GPT calls the Action, OpenAI sends the model-chosen fields to https://www.wizard-fortress.com. We treat that payload as untrusted prompt text. It is not a permission. It cannot authorize file writes or command execution.

Retention

Default: no application-level retention. If a later approved stage binds Cloudflare KV, retention will be stated here before that binding is enabled. Until then, treat proposals as ephemeral edge memory.

Sharing

We do not sell data. We do not send Action payloads to model providers. Local Ara, if used later, stays on hardware you control and is not this website.

Children

This service is not directed at children under 13.

Contact

Privacy and abuse: security@wizard-fortress.com once mail is live. Until MX exists, use the GitHub issue path the operator publishes.

Changes

Material changes get a new effective date on this page. Public Actions must keep this URL valid.