Ir al contenido principal

Seguridad, privacidad y datos

Cómo se tratan tus datos.

Vera y Clara siguen una misma política. Las funciones de los plugins se ejecutan dentro de Codex; los servicios alojados por Mparanza constituyen un límite de tratamiento separado.

Open the function register

Vera + Clara · Vídeo

Cómo tratan los datos Vera y Clara.

Descubre qué puede permanecer en tu ordenador, qué puede entrar en una llamada a un modelo de lenguaje a través de Codex y cuándo Mparanza se convierte en un límite de tratamiento separado.

Ver en YouTube

Cuando Vera y Clara trabajan dentro de Codex.

Vera y Clara no anonimizan los datos automáticamente. Pueden usar Python en local para filtrar o agregar información cuando resulte útil. Los datos facilitados al modelo se tratan mediante el plan de ChatGPT que ya usa el usuario. Los flujos dentro de Codex no envían a Mparanza archivos de clientes, prompts ni contenido del contexto del modelo.

Tu ordenador Archivos locales · Python local · resultados locales
Tu plan de ChatGPT actual Contexto del modelo · condiciones del plan · controles de datos

Los flujos dentro de Codex no envían contenido de clientes ni del trabajo a Mparanza.

Public function register

Check the boundary of each function.

Choose a Vera or Clara function to see what the selected model may read, which additional destinations can be used, and whether a Mparanza-hosted service is part of the function.

36 entries shown

Purposes and information classes below reproduce the reviewed technical record in English. Interface explanations are localized.

Vera

20
Vera · Riordino archivio Selected model account No Mparanza-hosted service specific to this function is declared.

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real case data needed for the work may enter the model context of the firm’s selected Codex or Cowork account.

Information the model may use

Purpose. Understand each selected client document and propose an evidence-backed studio archive category, practice, date, name, anomaly status, or probable-duplicate relationship

Information. One registered client and engagement identity; local client-relative paths or bound Google Drive root, file and parent IDs; file names, MIME types, hashes or available Drive checksums, sizes, timestamps and versions; selected readable local content or transiently downloaded/exported Drive evidence; proposed category, document type, date, subject, reference, practice, confidence, reasons, anomaly observations, and probable-duplicate relationships

Purpose. Prepare a dry-run filing plan, collect professional decisions, and execute only a separately approved mechanically safe path plan

Information. Versioned studio policy; storage mode; current and proposed client-relative paths; exact-duplicate checksum groups; Drive file, parent and folder IDs where applicable; collisions and blocked reasons; review payload; reviewer alias, actions, notes and edited paths; approved plan; pre-apply local hash or Drive version-state checks; apply and rollback journal state; artifact receipts and execution limitations

03

Mparanza-hosted services

No Mparanza-hosted service specific to this function is declared.

04

Other external destinations

Optional route

The user's explicitly authorized Google Workspace account through Google Drive API v3, limited operationally to one client folder bound by stable Drive folder ID

Purpose. Snapshot, transiently read, and after separate approval reorganize one My Drive or Shared Drive client archive while preserving Drive file identities

Information. Restricted-scope OAuth authorization; exact root folder, Shared Drive, file and parent IDs; names, relative paths, MIME types, sizes, modified times, versions, capabilities and available binary checksums; transient supported binary downloads or Google-native exports used for semantic classification; reviewed target folder paths and filenames; API-created folder IDs; move responses; original and applied parent, name and version state; journal and rollback outcomes

Audit Reconciliation Selected model account No Mparanza-hosted service specific to this function is declared.

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real case data needed for the work may enter the model context of the firm’s selected Codex or Cowork account.

Information the model may use

Purpose. Map sources, review reconciliations, and explain exceptions

Information. User instructions; the selected Studio Archive customer-folder run context, including stable opaque client, engagement, workflow and run identifiers; exact imported-input or upstream-artifact receipts and run-local execution copies; accounting files or extracted records; mappings; reconciliation results; exception evidence; workpapers, artifact purposes and audiences, lifecycle state, and review decisions

03

Mparanza-hosted services

No Mparanza-hosted service specific to this function is declared.

04

Other external destinations

No additional external destination is declared for this function.

Bandi e agevolazioni Selected model account No Mparanza-hosted service specific to this function is declared.

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real case data needed for the work may enter the model context of the firm’s selected Codex or Cowork account.

Information the model may use

Purpose. Discover and match source-backed opportunities, then prepare a reviewable grant-application dossier after selection

Information. Opaque client references, receipted profile-evidence references and dated revisionable opportunity-profile facets; professionally reviewed priority-source registry metadata for territory, category, official surface and act families; model-led query-scoped source selections with exact provider provenance, one professionally reviewed covered-or-gap claim for every requested territory and category, selected source IDs and rationales; scan windows, immutable source-check snapshots, explicit coverage gaps and optional last-seen publication cursors; opportunity lifecycle and amendment history; client/opportunity matches, gaps, contradictions, economic assumptions and reviewed recommendations; selected-client self-verifiable opportunity handoffs; call, formal amendments, annexes, official FAQs, forms and instructions; applicant identity and corporate, financial, quotation, declaration and project evidence when professionally relevant; bounded intelligence packets; extracted requirements, exact stored excerpts and facts; eligibility, exclusion and cost assessments; document checklist; form and narrative drafts; issues, recorded model suggestions and professional-review decisions

03

Mparanza-hosted services

No Mparanza-hosted service specific to this function is declared.

04

Other external destinations

Optional route

Direct official national, regional, local, chamber, EU, sectoral, issuing-authority, official-gazette, act-repository, funding-program and FAQ sources selected for an opportunity radar or call; general semantic web search only after priority-source attempts

Purpose. Discover and monitor opportunities source-first across an explicit temporal window, including relevant DGR, DDR, BUR, annex and amendment publications, while recording registry coverage and provenance without disclosing client data

Information. Generic territory, activity, investment topic, call identifier, authority, act family, program and temporal-window query; public document metadata, lifecycle observations, last-seen public publication cursor and official URLs; no client identifiers, opaque client references, financial data, project narrative, quotations, declarations, credentials, or portal-session material

Bilancio intelligente Selected model account No Mparanza-hosted service specific to this function is declared.

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real case data needed for the work may enter the model context of the firm’s selected Codex or Cowork account.

Information the model may use

Purpose. Review accounting meaning, mapping candidates, missing disclosures, schedule evidence, narrative drafts, validation issues, and professional decisions for an Italian OIC annual-accounts case

Information. User instructions; entity profile and tax identifier; CSV/XLSX and readable/scanned PDF trial balances and account descriptions; bounded PDF extraction candidates, page/table/cell geometry, OCR text and confidence, proposed headers, professional corrections and exclusions; prior accounts and XBRL, including explicit and typed dimensional contexts and context-fact groups; fixed-asset, receivable, payable, loan, equity, tax, payroll, provision, related-party, guarantee, post-closing-event, and going-concern evidence; source anchors and checksums; mapping candidates and accepted decisions; reviewed schedule-cell taxonomy dispositions and derived facts; the selected OIC professional-review checklist and structured disclosure answers; narrative drafts; validation issues; approval and export metadata

Purpose. Provide workflow guidance, mapping proposals, question prioritization, narrative drafts, prior-year comparisons, and issue explanations inside the existing bilancio process

Information. Task-specific context packets containing only the selected account rows, accepted facts and answers, active questions, prior text suggestions, bounded pending-PDF headers, sample rows, geometry, OCR confidence and extraction issues, bounded statutory-presentation gaps and arithmetic issues, or validation issues needed for the requested semantic task; direct entity identity and the out-of-band case routing identifier are excluded where the task does not require them; model output remains non-authoritative and evidence-linked and cannot accept, correct, exclude, or promote PDF extraction rows

03

Mparanza-hosted services

No Mparanza-hosted service specific to this function is declared.

04

Other external destinations

Used when selected

Official Unioncamere, XBRL Italia, Normattiva, OIC, XBRL International, and Arelle public sources

Purpose. Verify effective rules, filing instructions, taxonomy packages, technical standards, processor releases, and licensing metadata

Information. Public legal, accounting, filing, taxonomy, and software-version queries; client names, tax identifiers, balances, and case documents are excluded from queries

Optional route

User-selected official TEBENI validation and visualization service

Purpose. Perform the official external validation and rendering check after local validation

Information. The approved XBRL instance selected by the user and the returned validation or rendering report

Optional route

Configured Python package indexes and PaddleOCR public model sources

Purpose. Install the optional persistent PaddleOCR runtime and recognition models needed for image-only trial-balance PDFs

Information. Public package names, versions, platform metadata, and OCR model identifiers only; client documents, extracted text, entity identifiers, balances, and case metadata are excluded

Check Entries Selected model account No Mparanza-hosted service specific to this function is declared.

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real case data needed for the work may enter the model context of the firm’s selected Codex or Cowork account.

Information the model may use

Purpose. Map selected entries and resolve accounting-support checks

Information. User instructions; stable Studio Archive client, engagement and run identifiers; exact same-engagement Journal Sampling normalized-population, diagnostics and sample artifact bindings; exact support input receipts and run-local execution copies; lifecycle and output paths; sampled journal entries and signed amounts; FatturaPA XML or connector exports; supporting PDFs; invoice numbers, dates, currencies, supplier or customer names and tax identifiers; source metadata; match results; evidence excerpts; artifact purposes and audiences; and reviewed party, relationship, currency and direction decisions

03

Mparanza-hosted services

No Mparanza-hosted service specific to this function is declared.

04

Other external destinations

Optional route

User-selected accounting-system provider

Purpose. Acquire an invoice ZIP or folder export when the user chooses connection instead of supplying local support

Information. Authorized read/export request for the selected client and period; the resulting export is stored and mechanically prepared locally, and relevant entries or evidence may enter the selected runtime's model context

New Client · File Preparation Selected model account No Mparanza-hosted service specific to this function is declared.

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real case data needed for the work may enter the model context of the firm’s selected Codex or Cowork account.

Information the model may use

Purpose. Classify the incoming file, interpret evidence, and prepare the studio intake

Information. Incoming client documents or extracted text; document names and evidence passages; structured fiscal fields; formal checks; extraction diagnostics; evidence locators; missing items; studio memo, client-email draft, review decisions, and package state

03

Mparanza-hosted services

No Mparanza-hosted service specific to this function is declared.

04

Other external destinations

Optional route

Python Package Index (PyPI) and PaddleOCR model-weight hosts

Purpose. Install and initialize the optional shared PaddleOCR runtime after the user approves the roughly 500 MB first-use download

Information. Declared OCR package names and version constraints from the published requirements-ocr.txt, requested OCR language and model files, plus ordinary package-host request metadata; no user files, document contents, prompts, client data, or extracted evidence are sent

Comunicazione professionale Selected model account No Mparanza-hosted service specific to this function is declared.

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real case data needed for the work may enter the model context of the firm’s selected Codex or Cowork account.

Information the model may use

Purpose. Assess whether a professional development warrants communication and prepare source-backed studio-formatted drafts and visual stories for review

Information. Explicitly selected current source documents and official-source snapshots; selected prior studio emails, circulars, website articles, newsletters, FAQs, alerts and social posts; studio name, logo, colors, contact lines, optional format brief and approved or proposed format profile with field-level evidence basis; intended audience and client-segment descriptions; answer contract, source-authority assessments, exact public source notes and registered public URLs, claim-assurance review, editorial-value judgment, atomic claims, temporal qualifications, uncertainty, professional judgment, master brief, channel drafts, visual story, versioned model-pass prompts and SHA-256 digests, operator-attested host session identifiers, editorial-assessor benchmark cases and result, optional creative-direction handoff and selected board-reference metadata, review decisions and packaged artifacts. Real professional names and contact details may enter the selected runtime model context when present in selected material. The workflow does not promise automatic anonymization, provider-authenticated model-call receipts or local-only processing.

03

Mparanza-hosted services

No Mparanza-hosted service specific to this function is declared.

04

Other external destinations

Optional route

Public official legal, tax, regulatory, social-security, corporate, accounting, grant and issuing-authority sources selected for the communication topic

Purpose. Locate current authoritative material using generic topic-level queries before a professional claim is proposed

Information. Generic norm, authority, measure, date, topic and document queries plus public source metadata and bytes; no client identity, case facts, recipient list, private prior communication, credentials, cookies or session material

Optional route

A callable connected account or already authenticated supported browser surface explicitly selected to read prior studio communications

Purpose. Retrieve only user-selected prior studio communications for a proposed voice and format profile

Information. Selected prior post, article, email, newsletter, FAQ, alert or circular content and its channel and date metadata; no credential, cookie, session token, one-time code or unrelated account history

Optional route

The Creative Production board in the exact OpenAI Codex workspace selected by the professional

Purpose. Compare four to six non-publishable art-direction references for a render story accepted by the independent editorial assessor before Vera creates exact final graphics

Information. The exact editorially accepted public slide copy, reader-use descriptions, public source notes, contribution and story digests, minimal Studio colors and social-format rules, and the selected logo snapshot path and hash when present. The handoff excludes source bytes, selected prior communications, client facts, recipient data, credentials, session material and internal source or claim IDs. Returned board metadata, reference images and the user-selected item are snapshotted only in the owner-controlled run for translation and review.

Optional route

The exact recipient set, email account, website destination or social account selected by the professional

Purpose. Send, upload or publish the exact accepted final communication package after visible destination verification

Information. Accepted communication copy and selected accepted attachments or graphics plus destination metadata; no credentials, cookies, session tokens, one-time codes or unaccepted drafts

Concordato Preventivo Review Selected model account No Mparanza-hosted service specific to this function is declared.

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real case data needed for the work may enter the model context of the firm’s selected Codex or Cowork account.

Information the model may use

Purpose. Identify the concordato preventivo procedure, governing framework, authoritative proposal, plan, attestation, court material, and document perimeter

Information. User instructions; debtor and procedure identifiers; court and filing details; plan, proposal, attestation, professional and court documents; extracted text; document versions, roles, evidence locators, and reviewer judgment bases

Purpose. Reconstruct and review the creditor perimeter, priority, classes, voting treatment, recoveries, timing, disputes, and liquidation comparator

Information. Creditor names and identifiers; claim amounts and status; secured, privileged, unsecured, subordinated, tax, and social-security information; classes; vote and treatment data; proposed and liquidation recoveries; payment timing; evidence locators; professional assessments and follow-up

Purpose. Review sources and uses, liquidity, distributions, milestones, assumptions, consistency, and feasibility evidence

Information. Business-plan and accounting data; assets and disposals; financing and external contributions; procedure costs; cash flows and liquidity; distributions; milestones; assumptions; recalculations; inconsistencies; missing evidence; and reviewer findings

Purpose. Record review questions, issues, evidence requests, reviewer decisions, and professional handoff material

Information. Semantic case-model decisions; judgment bases; open and resolved issues; severity and ownership; requested documents; reviewer notes and actions; generated workpapers, summaries, and review memos

03

Mparanza-hosted services

No Mparanza-hosted service specific to this function is declared.

04

Other external destinations

No additional external destination is declared for this function.

Answer Validator Selected model account No Mparanza-hosted service specific to this function is declared.

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real case data needed for the work may enter the model context of the firm’s selected Codex or Cowork account.

Information the model may use

Purpose. Assess answer-contract conformance, claim coverage, source identity, semantic support, reasoning quality, professional-judgment boundaries, and proposed corrections

Information. Generated or supplied answer, including a Deep Research report, memo, or one-page letter; answer contract; claims and surrounding text; citations; normalized captured text from fetched public pages or local source files; source-identity, semantic-support, reasoning, issue-treatment, disposition, and professional-judgment assessments; diagnostics; proposed corrections and review decisions

03

Mparanza-hosted services

No Mparanza-hosted service specific to this function is declared.

04

Other external destinations

Used when selected

Public hosts named by URLs cited in the answer

Purpose. Retrieve cited source pages for claim-support review

Information. Each complete cited HTTP or HTTPS URL, request metadata, and the resulting public page response

Financial Analysis Selected model account No Mparanza-hosted service specific to this function is declared.

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real case data needed for the work may enter the model context of the firm’s selected Codex or Cowork account.

Information the model may use

Purpose. Establish the accounting meaning, perimeter, mappings, relationships, reconciliation posture, and review status needed to prepare financial-analysis and financial due-diligence evidence

Information. User instructions; trial balances, general ledgers, P&L tables, receivables, payables, inventory, revenue and customer files; management adjustments; cash, debt, lease, factoring, fixed-asset and Capex records; working-capital targets; contingent-liability evidence; transaction definitions; EBITDA-to-cash and Enterprise-to-Equity bridge inputs; financial issues and deal-decision references; source identities and hashes; dataset and relationship contracts; reviewed crosswalks and decisions; calculation parameters; metric receipts; reconciliation results; prepared tables; replay evidence; limitations and review status

03

Mparanza-hosted services

No Mparanza-hosted service specific to this function is declared.

04

Other external destinations

No additional external destination is declared for this function.

Journal-Bank Reconciliation Selected model account No Mparanza-hosted service specific to this function is declared.

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real case data needed for the work may enter the model context of the firm’s selected Codex or Cowork account.

Information the model may use

Purpose. Resolve mappings and review matched, unmatched, or ambiguous transactions

Information. User instructions; bank statements; journals or ledgers; normalized rows; controls; matches; exceptions; supporting evidence and review decisions

Purpose. Classify, identify, or suggest eligible relationships for unresolved bank movements under the user's selected certainty threshold

Information. A bounded packet of unmatched bank rows, hard-compatible journal candidates, normalized dates and amounts, descriptions, beneficiary or counterparty details, references, movement numbers, account and perimeter fields, plus the reviewed matching policy

03

Mparanza-hosted services

No Mparanza-hosted service specific to this function is declared.

04

Other external destinations

No additional external destination is declared for this function.

Journal Sampling Selected model account No Mparanza-hosted service specific to this function is declared.

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real case data needed for the work may enter the model context of the firm’s selected Codex or Cowork account.

Information the model may use

Purpose. Resolve journal mappings and explain the sampling design and selected sample

Information. User instructions; the stable Studio Archive client, engagement and run identifiers; the exact journal input receipt and run-local execution copy; the customer-folder output root and lifecycle state; journal data or normalized rows; mappings; population statistics; sampling parameters; selected rows; diagnostics, artifact purposes and audiences, and review decisions

03

Mparanza-hosted services

No Mparanza-hosted service specific to this function is declared.

04

Other external destinations

No additional external destination is declared for this function.

New Client Selected model account No Mparanza-hosted service specific to this function is declared.

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real case data needed for the work may enter the model context of the firm’s selected Codex or Cowork account.

Information the model may use

Purpose. Prepare identity, engagement, privacy, AI-applicability, AML, document, and monitoring proposals for professional review

Information. Byte-verified file-preparation outputs or registered standalone evidence; identity, representative and beneficial-owner facts; engagement terms; privacy and AML records; source, template, chronology, and evidence passages; calculations; temporal-horizon state; gaps; proposals, review decisions, and package state

03

Mparanza-hosted services

No Mparanza-hosted service specific to this function is declared.

04

Other external destinations

Used when selected

Current primary and professional public sources selected for the case

Purpose. Verify the current source basis for legal and professional proposals

Information. Legal or professional research topics, public-source queries and selected source URLs; direct client identifiers are not used in the public research route

Presenza digitale dello studio Selected model account No Mparanza-hosted service specific to this function is declared.

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real case data needed for the work may enter the model context of the firm’s selected Codex or Cowork account.

Information the model may use

Purpose. Assess or create a professional studio website, propose its information architecture, copy and visual system, implement a responsive site, and prepare exact preview and release packages for review

Information. Selected captures of an existing public website; selected source code, screenshots, studio documents, approved communications, logo, photographs, contact details, team and professional biography, verified services and qualifications, supplied legal text, intended audiences, proposed sitemap, page copy, studio-profile fields with observed, user-supplied or Vera-default basis, design tokens, implementation files, browser screenshots, model-led quality assessments, deterministic validation findings, review decisions, package hashes and visible preview or publication receipts. Professional names, portraits, contact details and other real studio information may enter the selected runtime model context when supplied or selected for the website. The workflow does not promise automatic anonymization or local-only model processing.

03

Mparanza-hosted services

No Mparanza-hosted service specific to this function is declared.

04

Other external destinations

Optional route

The exact existing public website and directly referenced public assets selected by the professional

Purpose. Observe the current website's content, structure, rendered behavior and public assets before proposing a refresh

Information. The selected public URL, ordinary page and asset requests, and captured public HTML, text, metadata and screenshots; no private studio files, client facts, credentials, cookies, tokens or unrelated browsing history

Optional route

A callable connected Drive, document store or supported authenticated browser surface explicitly selected by the professional

Purpose. Read only selected studio identity, copy, logo, photography, service, qualification or legal-text material for the website

Information. The exact selected studio files and their metadata; no credentials, cookies, one-time codes, unrelated account contents or client-case archive

Optional route

The exact Creative Production board or image-generation service selected by the professional in the active runtime

Purpose. Explore or produce a bounded website visual direction or image when selected studio assets are insufficient

Information. The approved public-use studio identity context, exact requested visual purpose and non-sensitive selected reference assets; no client-case files, credentials, private correspondence, unpublished professional claims or unrelated source material

Optional route

The exact tokenized preview host or platform selected by the professional

Purpose. Publish the exact validated website package at a hard-to-guess review URL

Information. The exact preview website files, approved public-use studio facts and assets, noindex directives, destination metadata and visible preview URL; no credentials, cookies, tokens, unselected source files or unrelated run artifacts

Optional route

The exact production website platform, repository, account or domain selected by the professional

Purpose. Publish the exact accepted release package after professional and destination review

Information. The exact accepted website files and public assets plus destination metadata and visible production URL or provider receipt; no credentials, cookies, tokens, unaccepted drafts or unrelated run files

Previdenza INPS Selected model account No Mparanza-hosted service specific to this function is declared.

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real case data needed for the work may enter the model context of the firm’s selected Codex or Cowork account.

Information the model may use

Purpose. Structure facts, resolve evidence conflicts, and apply supported sources to the case

Information. INPS records and exports or captured page evidence; contracts, F24s, emails and scans; extracted text; page quotes; facts; timelines; official sources; calculation basis; draft findings and review decisions

03

Mparanza-hosted services

No Mparanza-hosted service specific to this function is declared.

04

Other external destinations

Used when selected

Current official public legal and INPS sources

Purpose. Research the confirmed framework and verify material claims

Information. Contribution issue, period, legal-research query and selected public source URLs; public queries exclude personal identifiers

Optional route

One already-open, human-authenticated INPS tab through a loopback browser endpoint

Purpose. Capture a read-only current-view snapshot when an official export is not used

Information. Visible page text and screenshot received into the private local run folder; source URL and title are stored only as hashes

Optional route

Configured PaddleOCR model-weight host

Purpose. Download missing OCR model weights before local recognition

Information. Pinned Hugging Face model repository and revision requests plus ordinary connection metadata; no case documents, extracted case content, or approval identifier are sent

Answer Planner Selected model account No Mparanza-hosted service specific to this function is declared.

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real case data needed for the work may enter the model context of the firm’s selected Codex or Cowork account.

Information the model may use

Purpose. Understand the professional question, define the answer and validation contract, write route-specific generation instructions, and review their semantic conformance

Information. The question and facts typed or attached by the user, including names or other personal facts when material; inferred legal, tax, or compliance framing; answer contract including document type, validation scope, correction policy, and professional-judgment policy; generation route and instructions; model-led prompt-to-question and prompt-to-contract conformance assessments; source-domain sidecars; diagnostics and review decisions

03

Mparanza-hosted services

No Mparanza-hosted service specific to this function is declared.

04

Other external destinations

Used when selected

Public official and reliable-source websites

Purpose. Curate qualified source domains for the confirmed legal framework and issue

Information. Legal or tax issue research terms and public-source URLs; queries can reflect case facts when the selected model runtime uses them

Registro Imprese e SARI Selected model account No Mparanza-hosted service specific to this function is declared.

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real case data needed for the work may enter the model context of the firm’s selected Codex or Cowork account.

Information the model may use

Purpose. Frame the case, apply current official guidance, and draft the professional-review practice plan

Information. Case facts and local evidence; DIRE or SARI screenshots and OCR; dates and chamber; official-source passages and provenance; proposed classifications, recipient positions, filing steps, questions and review decisions

03

Mparanza-hosted services

No Mparanza-hosted service specific to this function is declared.

04

Other external destinations

Used when selected

Public SARI, Registro Imprese, DIRE, chamber, INPS, INAIL, SUAP, and IVASS sources relevant to the case

Purpose. Select current official guidance and record its provenance

Information. Competent chamber and generic topical query, selected public content ID, public page metadata and official-source URLs; no client identifiers or case narrative

Optional route

Exact public SARI host and selected chamber tenant

Purpose. Search public metadata and fetch one human-selected SARI card through the conditional connector

Information. Generic topical query or selected card ID, tenant and expected chamber; public metadata and card response

Optional route

Configured PaddleOCR model-weight host

Purpose. Download missing OCR model weights before local recognition

Information. Pinned Hugging Face model repository and revision requests plus ordinary connection metadata; no case screenshots, extracted case content, or approval identifier are sent

Report Builder Selected model account No Mparanza-hosted service specific to this function is declared.

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real case data needed for the work may enter the model context of the firm’s selected Codex or Cowork account.

Information the model may use

Purpose. Map source tables, write the report narrative, and review the generated report

Information. User instructions; spreadsheets, CSV files or extracted PDF text; table inventories and rows; mappings; calculations; diagnostics; draft narrative; report artifacts and review decisions

03

Mparanza-hosted services

No Mparanza-hosted service specific to this function is declared.

04

Other external destinations

No additional external destination is declared for this function.

Plan Selected model account No Mparanza-hosted service specific to this function is declared.

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real case data needed for the work may enter the model context of the firm’s selected Codex or Cowork account.

Information the model may use

Purpose. Interpret and review commercial and FX assumptions, then prepare a forward-looking sales Plan from reviewed Actuals

Information. User instructions; monthly Actual sales rows, including sparse observed grains; product, customer, country, channel or other reviewed dimensions; units, prices, gross sales, discounts, COGS, transaction and reporting currencies, and FX rates; Actual-to-Plan period mappings; reviewed assumptions, scopes, priorities, same-driver overlap behavior, discount and COGS assumption bases, and rationale; source identities and hashes; Plan scenario rows; assumption ledger; scenario summary; reconciliation results; replay evidence; limitations and review status

03

Mparanza-hosted services

No Mparanza-hosted service specific to this function is declared.

04

Other external destinations

No additional external destination is declared for this function.

Vera · Archivio dello Studio Selected model account No Mparanza-hosted service specific to this function is declared.

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real case data needed for the work may enter the model context of the firm’s selected Codex or Cowork account.

Information the model may use

Purpose. Find and interpret prior studio documents within an explicit archive scope

Information. User questions; the selected connected-file or configured archive scope; relative document paths; search snippets or opened source passages; file, page, paragraph, sheet-row, message-line, or text-line locators; source hashes when available; extraction and coverage limitations; and Vera's source-backed synthesis

Purpose. Bind Vera workflows to one stable registered client and current Studio Archive folder without copying the private identity registry

Information. The stable opaque client ID; current opaque folder scope ID; absolute archive and client-folder paths; archive-relative scope path and display name; and a deterministic content digest. The binding contains no email address, legal name, tax identifier, document content, Gmail content, or authentication material

Purpose. Create or resume any registered client-bound Vera workflow across separate Codex chats

Information. The selected customer-folder manifest and current local or Google Drive folder binding; explicit engagement, workflow and run IDs; source, journal, support, local-folder snapshot, Google Drive snapshot, or upstream-artifact roles; canonical input-receipt and run execution-copy paths; original filenames, bounded client-relative snapshot paths, Drive file and parent IDs, MIME types, versions, capabilities and available checksums, excluded links, shortcuts or special entries, byte counts, SHA-256 receipts and timestamps; transiently opened Drive text and citations; run labels, purposes and lifecycle state; portable run contexts and input and artifact manifests; exact workflow output paths; artifact purposes, audiences and media types; and recovery or retention inventories. Email addresses, legal-name aliases, tax identifiers and OAuth token contents remain in private local state except when the user supplies non-token identity facts in the current chat

Purpose. Find and interpret Gmail correspondence for one explicitly selected studio client

Information. Client name or identifier and full email or PEC addresses supplied or confirmed in the current task; an optional private local archive scope and identity profile only when the selected runtime supports them; bounded discovery and exact-address Gmail queries; connected account profile; candidate and matching message or thread identifiers; returned sender and recipient fields; subjects, timestamps, snippets and labels; selected message or thread bodies; selected attachment metadata or content when the connector supports them; exact-address routing evidence; ambiguity findings; search coverage; and Vera's source-backed synthesis

Purpose. Inspect and interpret visible messages in one verified local WhatsApp Desktop chat for an explicitly selected studio client

Information. The selected client name or identifier and complete international phone supplied or confirmed in the current task; sanitized guarded-search status and a fresh target result index; verified one-to-one chat identity; the exact target ChatMessagesTableView subtree only after phone verification; visible sender or profile name; visible message text or captions, timestamps and on-screen locators; unreadable media, read-state, history and coverage limitations; focus or identity failures; and Vera's source-backed synthesis. Raw pre-verification accessibility snapshots remain inside the local Computer Use JavaScript call so unrelated sidebar previews are not returned to model context

03

Mparanza-hosted services

No Mparanza-hosted service specific to this function is declared.

04

Other external destinations

Optional route

The user's explicitly authorized Google Workspace account through Google Drive API v3, operationally bounded to one exact client folder ID

Purpose. Bind and snapshot one My Drive or Shared Drive client folder and transiently open selected snapshotted evidence for Riordino archivio

Information. Restricted-scope OAuth authorization; exact client, engagement, snapshot input, root folder, Shared Drive, file and parent IDs; names, MIME types, sizes, modified times, versions, capabilities and available checksums; selected transient binary downloads or Google-native exports; bounded extracted text, locators, citations and limitations. The full OAuth token remains only in owner-only local state

Optional route

User-selected Gmail account through the separately installed and connected OpenAI Gmail connector used in Codex

Purpose. Search and read correspondence for one explicitly selected client when the user chooses Gmail evidence

Information. A discovery query derived from the selected client's supplied name or identifier may return at most ten candidate messages before address confirmation; after confirmation, bounded Gmail-native queries use full client email or PEC addresses plus the user's topic or date bounds. Gmail returns message metadata and snippets first, followed only by shortlisted bodies, necessary thread context, or supported attachment content that may enter Codex context

Optional route

The user's already-authenticated local WhatsApp Desktop application and selected WhatsApp account, controlled on demand through Computer Use from Codex Desktop

Purpose. Inspect visible messages in one verified one-to-one client chat when the user explicitly chooses WhatsApp evidence

Information. A complete client phone and optional topic or date bounds supplied or confirmed in the current task; sanitized guarded-search status and a fresh target result index; verified contact identity; and only the exact verified target ChatMessagesTableView subtree containing selected visible message text or captions, sender or profile name, timestamps and screen locators, unreadable-media and history limitations, and Vera's source-backed synthesis. Raw pre-verification accessibility snapshots remain inside the local Computer Use JavaScript call and are not returned because they can contain unrelated sidebar previews. Verified target evidence read by Codex may enter the user's selected Codex model context; no WhatsApp copy is sent to a Mparanza service

Optional route

User-selected Gmail account through a callable, read-only Anthropic Gmail connector in Cowork

Purpose. Search and read correspondence for one explicitly selected client when the Cowork user chooses Gmail evidence

Information. Connected mailbox identity; bounded searches built from complete client email or PEC addresses supplied or explicitly confirmed in the current task plus user-supplied topic or date bounds; returned participant metadata; the smallest useful message shortlist; message identifiers, sender, subject, timestamp and message content needed for source-backed findings; inclusion and exclusion decisions; and coverage limitations. Relevant returned evidence may enter the user's selected Anthropic Cowork model context

Clara

9
Retailer Signals Selected model account Mparanza Retail Data and Mapping Service

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real professional data needed for the work may enter the model context of the user’s selected ChatGPT or Codex account.

Information the model may use

Purpose. Map product attributes and compare retailer cohorts

Information. Retailer and category; structured product, variant, brand, description, price, promotion, ranking, cohort and taxonomy records; public image URLs and locally hydrated product images; package provenance and mapping history

Purpose. Resolve ambiguous taxonomy mappings and author and review a checked report

Information. Mapping tasks, decisions, evidence, local-image hashes, independent mapping reviews, computed tables, report model, claim ledger, caveats, selected examples, semantic review, browser QA, and correctness verdict

03

Mparanza-hosted services

This function can use a separately documented Mparanza service.

Mparanza Retail Data and Mapping Service

04

Other external destinations

Optional route

Public product-image hosts named by the evidence package

Purpose. Download product images for local mapping evidence and report review

Information. The package-supplied public image URL and ordinary network request metadata; downloaded image bytes remain local and are not sent back with the report

Brand Fit Selected model account Mparanza Retail Data and Mapping Service

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real professional data needed for the work may enter the model context of the user’s selected ChatGPT or Codex account.

Information the model may use

Purpose. Compare retailer signals with current retailer presence and the brand-owned catalogue

Information. Completed Retailer Signals report and verdict; retailer, category and brand names; current database snapshot, retailer-presence rows, owned-catalogue rows, accepted mappings, product attributes, candidate products, image URLs and locally hydrated images

Purpose. Interpret gaps and candidates and create and independently check the local report

Information. Scope metrics, deterministic claims, report model, selected products, rationales, caveats, semantic review, browser QA, correctness findings, and final HTML

03

Mparanza-hosted services

This function can use a separately documented Mparanza service.

Mparanza Retail Data and Mapping Service

04

Other external destinations

Optional route

Public product-image hosts named by the evidence package

Purpose. Download retailer and owned-catalogue product images for local evidence and report review

Information. Package-supplied public image URLs and ordinary network request metadata; image bytes remain local

Claim Basis Map Selected model account No Mparanza-hosted service specific to this function is declared.

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real professional data needed for the work may enter the model context of the user’s selected ChatGPT or Codex account.

Information the model may use

Purpose. Capture or audit the basis for claims in a presentation

Information. PPTX visible text and shape names; slide titles and claims; source titles, locators and URLs; calculation inputs and methods; reasoning inputs, assumptions, and cross-slide claim references

Purpose. Identify changed, missing, moved, untracked, or unsupported claims

Information. Generation-time claim snapshots, current-deck text, matched support, drift statuses, ungrounded items, and required semantic refresh decisions

03

Mparanza-hosted services

No Mparanza-hosted service specific to this function is declared.

04

Other external destinations

No additional external destination is declared for this function.

Clara Advisory Case Selected model account Mparanza Hosted Voice, Mparanza Plugin Feedback, Mparanza Plugin Update Check

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real professional data needed for the work may enter the model context of the user’s selected ChatGPT or Codex account.

Information the model may use

Purpose. Understand and organize an advisory engagement

Information. Client and project labels; objectives and audience; company, participant and stakeholder identities; source documents, decks, spreadsheets, notes, transcripts, recordings, dates, facts, financial or operating data, constraints, risks, and open questions

Purpose. Weigh evidence and prepare decision-ready advice

Information. Material summaries, evidence maps, source limitations, consultant and advisor judgement, Codex inferences, contradictions, hypotheses, options, recommendations, implementation conditions, pending inclusion decisions, case issues, and pseudonymous but linkable audit metadata such as exact source digests, byte counts, stable IDs, dates, counts, and cross-receipt hashes

Purpose. Draft and review workpapers, briefs, decks, memos, and decision packs

Information. Narrative, charts, claims, citations, speaker notes, review findings, approved content, and final deliverables

03

Mparanza-hosted services

This function can use a separately documented Mparanza service.

Mparanza Hosted Voice Mparanza Plugin Feedback Mparanza Plugin Update Check

04

Other external destinations

Optional route

Public or otherwise authorized external sources selected for the engagement

Purpose. Obtain current industry, market, governance, legal, or other external context relevant to the advisory question

Information. Research questions, search terms, selected URLs, retrieved public material, and concise source takeaways; queries may reflect engagement facts when Codex uses them

Optional route

Python Package Index (PyPI)

Purpose. Install Clara's exact declared Python dependencies into the user-scoped Cowork plugin data directory when the fingerprinted dependency cache is absent or invalid

Information. Declared package names and version constraints from Clara requirements files, plus ordinary package-index request metadata; no user files, prompts, case data, or advisory content are sent

Optional route

Python Package Index (PyPI)

Purpose. Install the optional shared PaddleOCR runtime after the user approves the roughly 500 MB first-use download

Information. Declared OCR package names and version constraints from Clara's published requirements-ocr.txt, plus ordinary package-index request metadata; no user files, document contents, prompts, case data, or advisory content are sent

Deck Correction Selected model account Mparanza Hosted Voice

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real professional data needed for the work may enter the model context of the user’s selected ChatGPT or Codex account.

Information the model may use

Purpose. Interpret requested changes against the correct deck and evidence

Information. Existing PPTX or HTML deck; slide text, images, notes and structure; spoken feedback, transcript, screen recording, review notes, partner comments, case evidence, style authority, and source materials

Purpose. Plan, apply, and verify only the understood changes

Information. Interpretation packets, requested changes, uncertainty, targets, success criteria, approval state, patches, corrected deck, rendered slides, verification findings, and final audience-facing review

03

Mparanza-hosted services

This function can use a separately documented Mparanza service.

Mparanza Hosted Voice

04

Other external destinations

No additional external destination is declared for this function.

HTML Deck Selected model account No Mparanza-hosted service specific to this function is declared.

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real professional data needed for the work may enter the model context of the user’s selected ChatGPT or Codex account.

Information the model may use

Purpose. Build a source-faithful presentation

Information. Word, PDF, Markdown, spreadsheet, case-workspace, sealed JSON or CSV evidence artifacts, or mixed source material, including names, facts, figures, qualifications, evidence gaps, and advisor judgement

Purpose. Plan, compose, revise, and review the presentation

Information. Storyline, claims, evidence references, evidence bundle and binding records, resolved values, slide titles and text, speaker notes, layout choices, content and evidence ledgers, HTML/CSS, screenshots, and QA findings

03

Mparanza-hosted services

No Mparanza-hosted service specific to this function is declared.

04

Other external destinations

No additional external destination is declared for this function.

Hosted Interview Selected model account Mparanza Hosted Interviews

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real professional data needed for the work may enter the model context of the user’s selected ChatGPT or Codex account.

Information the model may use

Purpose. Select or prepare an interview that addresses the engagement question

Information. Campaign definitions; case and project labels; participant name, role, language, introduction and identifier; purpose, background context, hypotheses, topics, questions, red flags, boundaries, and expiry

Purpose. Retrieve and interpret the completed interview

Information. Status, completion data, transcript events, participant answers, media metadata, generated review, uncertainties, contradictions, missed opportunities, and follow-up questions

03

Mparanza-hosted services

This function can use a separately documented Mparanza service.

Mparanza Hosted Interviews

04

Other external destinations

Optional route

A participant or mailing channel selected by the user

Purpose. Deliver the bearer interview link to its intended participant

Information. Participant URL and any invitation text

Reporting Engine Selected model account No Mparanza-hosted service specific to this function is declared.

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real professional data needed for the work may enter the model context of the user’s selected ChatGPT or Codex account.

Information the model may use

Purpose. Profile, interpret, validate, and visualize the user's business data

Information. CSV, XLSX, or Parquet fields and values; dataset identity; metrics, dimensions, periods, identifiers, members, source notes, and compatibility evidence

Purpose. Author reusable dataset semantics and choose a source-backed analysis

Information. Dataset profiles, intake receipts, semantic layers, evidence, reviewed Sales/Discount/COGS mapping states, role bindings, snapshot attachments, analysis policies, chart plans, exact input and output byte hashes, effective recipe records, rendered charts, validation results, and interpretations

03

Mparanza-hosted services

No Mparanza-hosted service specific to this function is declared.

04

Other external destinations

Optional route

Python Package Index (PyPI)

Purpose. Install Clara's exact declared Python dependencies into the user-scoped Cowork plugin data directory when the fingerprinted dependency cache is absent or invalid

Information. Declared package names and version constraints from Clara requirements files, plus ordinary package-index request metadata; no user files, prompts, case data, or report content are sent

Transcribe Selected model account Mparanza Hosted Voice

01

Local workspace

Source files, helper execution, and outputs can remain in the selected workspace. The technical register does not enumerate every local operation; the model and external boundaries are stated separately below.

02

Selected model account

Real professional data needed for the work may enter the model context of the user’s selected ChatGPT or Codex account.

Information the model may use

Purpose. Transcribe an advisor debrief, meeting, call, or existing recording in the correct project context

Information. Audio or screen-recording content; compact case brief; client and project facts; recording title, date, participants, interviewer, notes, language, and source metadata

Purpose. Attribute speakers, review evidence, and integrate the transcript

Information. Raw and reviewed transcripts, speaker identities or labels, timing and media metadata, uncertainty notes, transcription corrections, review findings, judgement proposals, questions, issues, and evidence-map updates

03

Mparanza-hosted services

This function can use a separately documented Mparanza service.

Mparanza Hosted Voice

04

Other external destinations

No additional external destination is declared for this function.

Mparanza processing boundary

What reaches Mparanza-hosted services.

These records describe service-level processing separately from ordinary work inside Codex. Expand a service to see what is sent and retained.

Vera Plugin improvement feedback Automatic route Shared Vera service

Shared Vera services are product-level routes and are not attributed to a single professional function.

01

Provider or recipients

Mparanza's fixed HTTPS change-request evidence endpoint · Mparanza's fixed HTTPS change-request intake · Mparanza's fixed HTTPS change-request status endpoint · Mparanza's hosted interview service and its OpenAI voice and transcription services

02

Information sent

When. Notify the user when a previously submitted problem or suggestion has been fixed or needs specific additional evidence

Information. Locally stored change-request IDs and their bearer status tokens, in batches of at most 100, plus ordinary connection metadata. The response may return an explicit disposition and bounded needs-information question. The submitted feedback text and client or case material are not resent.

When. Submit a concrete Vera problem report or improvement suggestion to the developer

Information. The exact JSON request file selected for submission, together with request kind, Vera name and version, an idempotent submission ID, submission timestamp, operating-system family, Python version, and fixed plugin-client identifier. Problem reports must include occurred time, runtime, operation, reproduction, and at least one bounded evidence string. Vera's workflow requires showing and sanitizing the request before consent. The client enforces mechanical shape but does not detect personal data, judge semantic sufficiency, or anonymize the file automatically.

When. Answer one specific developer needs-information question and return the request to active investigation

Information. Change-request identifier, locally stored bearer status token, idempotent evidence-update identifier, bounded summary, and one or more exact sanitized evidence strings. The original request and client or case material are not resent.

When. Capture one optional one-minute explanation of a Vera improvement suggestion

Information. The opportunity text supplied to the client, Vera name and version, language, submission ID, and—after the user opens the interview—the user's audio, transcript, and hosted interview responses. Vera's workflow supplies a generic client-free opportunity string, but the client accepts any 1–4,000-character value and does not detect personal data or anonymize it automatically.

03

Retention and deletion

The IDs and status tokens remain in local plugin state until that state is removed. State files are forced to mode 0600, while only the temporary fallback directories are forced to mode 0700. The corresponding change request remains in Mparanza's service record; the plugin does not enforce its deletion period. Mparanza stores the submitted change request and status receipt as a service record. The plugin does not promise an automatic deletion period. Mparanza appends the evidence update to the existing change-request service record. The plugin stores only the update identifier and payload hash for retry deduplication; it does not promise an automatic service-record deletion period. Mparanza retains the resulting change-request and interview record until service-level deletion; link expiry is not a deletion guarantee. OpenAI-side handling follows the hosted service's configured account and terms, which the Vera plugin cannot inspect or enforce.

Vera Plugin update check Automatic route Shared Vera service

Shared Vera services are product-level routes and are not attributed to a single professional function.

01

Provider or recipients

Mparanza's fixed HTTPS plugin-version manifest

02

Information sent

When. Check whether a newer published Vera version is available

Information. An HTTP GET with ordinary connection metadata and a generic update-check User-Agent. No client, case, prompt, plugin version, or locally stored file content is placed in the URL or request body.

03

Retention and deletion

When Codex supplies a plugin-data directory, Vera stores the downloaded public manifest and check time locally and reuses them for up to 24 hours. Without that directory, the hook performs a new check at each startup or resume. Any Mparanza access-log retention is a hosted-service setting outside the plugin's control.

Clara Mparanza Hosted Interviews Used when selected Used by · interview

01

Provider or recipients

Mparanza Hosted Interviews · OpenAI realtime, transcription, and review services configured by Mparanza

02

Information sent

When. When the preparer authenticates or requests a magic link

Information. Authorized email address and redirect path for magic-link requests, or a Mparanza session cookie or consumed magic link

When. When creating a participant link from a registered campaign

Information. Exact campaign identifier, non-sensitive case identifier, participant name, language, participant role, and requested expiry

When. When creating a one-off interview

Information. Campaign and case identifiers; case, project, participant and interview labels; role and language; purpose, participant introduction, background context, hypotheses, topics, questions, red flags, boundaries, and expiry

When. When the participant opens the bearer link and completes the interview

Information. Participant microphone audio and answers, conversation events, and service-generated transcript and review material

Information returned

When. After interview preparation

Information. Bearer participant URL, expiry, campaign identifier, and preparation receipt

When. When checking a known participant link

Information. Minimal status plus case name and interview title exposed by the unauthenticated status route

When. After authenticated retrieval of a completed interview

Information. Prepared record, completion data, current-run events, transcript material, media metadata, and generated quality review; the documented JSON bundle contains no raw audio or video bytes

03

Retention and deletion

The hosted interview record remains stored until manual or administrative deletion. Participant-link expiry, revocation, or archiving is not deletion.

Access arrangement

An authenticated preparer creates and retrieves interviews. The participant uses an expiring bearer link without login. A known bearer token can read minimal public status, including case name and interview title; bundle and review retrieval use the authenticated helper. Mparanza and OpenAI process audio, answers, and transcript to conduct, transcribe, and review the interview.

Clara Mparanza Hosted Voice Used when selected Used by · clara, deck-correction, transcribe

01

Provider or recipients

Mparanza Hosted Voice · The realtime or transcription provider configured by Mparanza; Clara's main skill currently identifies an OpenAI Realtime session for live voice

02

Information sent

When. When requesting or consuming a magic link or reusing a Mparanza session, then opening a user-bound launch token

Information. Authorized email and redirect path, magic-link token or session cookie, short-lived launch token used alongside the authenticated session, and ordinary connection metadata

When. When the default context-bearing launch or authenticated upload path is used

Information. A bounded excerpt of the local case brief, which can include client, project, participant, fact, judgement, question, and other professional context; when selected, it is used to guide transcription of names and professional terms

When. During live consultant debrief or deck-feedback capture

Information. Microphone audio, selected language, launch token, and realtime transcription-session metadata. Screen video, active-slide timeline, and visual capture metadata remain in the browser and local downloaded bundle and are not uploaded to Mparanza.

When. When an existing audio recording is uploaded

Information. Audio bytes, language, title, source type, interview date, participants, interviewer, notes, and upload/job metadata

Information returned

When. After launch or upload creation

Information. Launch token or browser URL, upload job identifier, status, and service messages

When. When capture or transcription completes

Information. The server returns transcript payload, timed events, source metadata, transcription metadata, and job status. The browser combines those results with locally recorded audio, screen video, and slide-timeline provenance when it builds the downloadable ZIP.

03

Retention and deletion

Live screen video remains in the browser and is not uploaded. Context-bearing launch metadata is bound to the authenticated user behind an opaque token; token access expires after eight hours, and expired metadata is removed by startup or periodic cleanup rather than at a guaranteed exact instant. Hosted audio, upload chunks, and transcription work files must be deleted before a completed package is available. On terminal package retrieval, transcript and job state are scrubbed before the response; a scrub failure blocks retrieval. Cleanup also removes stale chunks, terminal jobs, and abandoned processing state. Ordinary technical logs follow the separate service logging arrangements.

Access arrangement

Launch and upload require a Mparanza user session established directly or by consuming a magic link. The short-lived, user-bound launch token is an additional session control, not standalone authentication. The browser uses the token alongside the authenticated session to access the hosted capture surface; the plugin downloads or receives the completed bundle into the local workspace. The plugin source does not establish internal operator access.

Clara Mparanza Plugin Feedback Automatic route Used by · clara

01

Provider or recipients

Mparanza plugin change-request service

02

Information sent

When. After explicit consent to transmit one sanitized problem or suggestion

Information. Schema version, problem or capability kind, plugin name and version, idempotency identifier, and the selected JSON request. Problem reports must include occurred time, runtime, operation, reproduction, and at least one bounded diagnostic evidence string. The helper enforces that mechanical shape but does not detect personal data, judge semantic sufficiency, or anonymize the file. Clara's host-specific instructions require the assistant to show, sanitize, and obtain consent for the exact request.

When. With an approved text problem or suggestion submission

Information. Submission timestamp, operating-system family, Python version, and the fixed plugin-change-request client identifier. The helper does not collect a username, path, environment value, document, account identifier, or stable device identifier.

When. After status polling returns a specific needs-information question and the user approves the exact sanitized answer

Information. Change-request identifier, locally held opaque status token, idempotent evidence-update identifier, bounded summary, and one or more sanitized evidence strings. The original request and client or case material are not resent.

When. After the user separately chooses the short hosted voice route for a general improvement suggestion

Information. Plugin name and version, generic client-free opportunity text, language, and submission identifier; the participant's later hosted explanation is outside the text-submission payload

When. On SessionStart after a prior request has returned a pending receipt

Information. Change-request identifier and opaque status token for each locally pending request; no original case or request text is resent by this poll

Information returned

When. After a successful problem or suggestion submission

Information. Change-request identifier, opaque status token, legacy open or fixed release status, explicit disposition, needs-information question when applicable, fixed version when available, and validated install URL

When. After creating the optional one-minute suggestion interview

Information. Mparanza interview URL and associated durable receipt fields

When. During automatic polling of previously submitted requests

Information. Whether each request exists, its legacy release status, explicit disposition, needs-information question when applicable, fixed version, and install URL

03

Retention and deletion

Submitted feedback remains a Mparanza support record until administrative deletion. The plugin also stores local pending payloads, receipts, and status tokens for retry and status notification until local plugin state is removed.

Access arrangement

The client submits to fixed Mparanza HTTPS endpoints and stores the returned opaque status token locally. In Claude Cowork that state is stored under CLAUDE_PLUGIN_DATA; in the OpenAI package it uses the plugin's existing private local state. Plugin source does not establish who inside Mparanza can access request content. Optional suggestion interviews exist only in the OpenAI package and use a returned Mparanza browser URL.

Clara Mparanza Plugin Update Check Automatic route Used by · clara

01

Provider or recipients

Mparanza public static-site infrastructure

02

Information sent

When. On SessionStart when no valid local manifest cache is available

Information. An HTTPS GET to the fixed public version-manifest URL with Accept: application/json and User-Agent: Mparanza-Plugin-Update-Check/1, plus ordinary connection metadata such as source IP and time; no client files, prompts, transcripts, or case content are included by the plugin

Information returned

When. After a successful manifest request

Information. Public manifest schema, Clara published version, and validated ChatGPT plugin install URL

03

Retention and deletion

The plugin caches the downloaded public manifest and check time locally. Current Mparanza web access logs use 14 daily rotations; other application logs, download records, caches, exports, and backups do not share one automatic deletion schedule.

Access arrangement

The version manifest is a public unauthenticated static resource. The plugin source does not establish infrastructure-log access.

Clara Mparanza Retail Data and Mapping Service Used when selected Used by · attribute-reporting, brand-fit

01

Provider or recipients

Mparanza Attribute Reporting service

02

Information sent

When. When requesting or consuming a magic link or using a persisted authenticated session

Information. Authorized email and redirect path, consumed magic link or Mparanza session cookie, and ordinary connection metadata

When. When requesting taxonomy, evidence packages, or mapping worksets

Information. Retailer, category, taxonomy version and hash, evidence job and mapping submission identifiers, mapping mode, and explicit correction reason when used

When. At the explicit authenticated server-write checkpoint

Information. Pinned mapping workset identity and hash, idempotency key, complete mapping tasks, Codex decisions, validated mappings, and independent mapping review

When. When creating a downstream Brand Fit package

Information. Actor-owned source evidence-job identifier, brand source retailer, brand name, source Retailer Signals report SHA-256 and verdict, and optional owned or retailer category aliases; the local report file is not sent

When. Only when an app_files development run explicitly requests a fresh scrape

Information. Structured locally captured retailer listing and product-detail records written to the server-backed database; this upload path is not available in the installed Clara plugin

Information returned

When. During Retailer Signals preparation and mapping

Information. Published category taxonomy, immutable public mapping worksets, task coverage, source identifiers, mapping acceptance receipts, and sanitization/provenance receipts

When. After actor-owned evidence jobs are ready

Information. Checksum-bound structured retail records, cohort comparisons, accepted mapping state, package provenance, and public image URLs; packages contain no server paths or image bytes

When. After an actor-owned Brand Fit job is ready

Information. Checksum-bound current retailer-presence rows, brand-owned catalogue rows, accepted mapping-state snapshot, scope metrics, candidate-product evidence, timestamps, and public image URLs

03

Retention and deletion

The bridge retains Retailer Signals and Brand Fit evidence jobs, mapping worksets, mapping submissions, central structured product records, taxonomy, accepted mappings, retailer-presence data, and owned-catalogue data as durable service data. The reviewed runtime has no age-based or event-triggered automatic deletion path for these artifacts. Count and byte limits reject new work without deleting retained artifacts.

Access arrangement

The installed bridge uses an authenticated Mparanza session. Artifacts and jobs are actor-owned and another authenticated user receives no information about whether an artifact exists. The plugin receives no database credentials. Development persistence uses the app_files runtime rather than the installed plugin.

This register describes reviewed technical boundaries. It is not a DPIA, legal advice, or proof of GDPR compliance.

El tratamiento local se usa cuando ayuda al trabajo.

Python en local puede ordenar, calcular, conciliar, filtrar, agregar y crear resultados sin trasladar antes los archivos fuente completos a un sistema separado de Mparanza.

Esto no es anonimización automática. Cuando la tarea profesional requiere nombres, documentos, el idioma original o hechos del caso, ese material puede entrar en el contexto del modelo.

Un mapeo por flujo de trabajo, no por prompt.

Cada flujo dentro de Codex se revisa cuando se añade o modifica. La revisión registra qué permanece normalmente en local y qué puede leer Codex. No crea un formulario, un paso de consentimiento ni un registro para cada prompt.

Nunca incluyas contraseñas, claves de API, cookies de autenticación, tokens de acceso ni datos de sesión en prompts o archivos que Codex pueda leer.

Gmail y WhatsApp Desktop tienen límites distintos.

Vera y Clara trabajan en ChatGPT con los materiales aportados en la conversación y con las aplicaciones conectadas disponibles. Después de producir un resultado útil, pueden recomendar Codex Desktop para acceder directamente a carpetas, conservar archivos del proyecto, usar herramientas locales y crear entregables duraderos. La instalación es opcional y el trabajo puede continuar en ChatGPT.

En ChatGPT o Codex, Vera busca en Gmail mediante el conector de Gmail de OpenAI, instalado y vinculado por separado. El correo permanece en Gmail; Vera no crea una copia del buzón ni conserva credenciales o mensajes.

WhatsApp se consulta únicamente desde Codex Desktop con Computer Use, en la aplicación WhatsApp Desktop ya abierta y autenticada por el profesional. Ningún servidor de Mparanza recibe ni conserva una copia de esos mensajes. El texto y las imágenes de pantalla que lee Codex pueden entrar en el contexto del modelo de la cuenta de ChatGPT/Codex del usuario; las condiciones de OpenAI, Gmail y WhatsApp se aplican por separado.

Los servicios alojados por Mparanza tienen un límite separado.

Cuando una función de Vera o Clara usa un servicio alojado por Mparanza, el contenido necesario para ese servicio llega a sistemas controlados por Mparanza. Las entrevistas alojadas, Hosted Voice y el puente de datos de retailers son ejemplos, no políticas separadas.

Cada servicio alojado se documenta una vez a nivel de servicio: qué se puede enviar, quién puede acceder y cuáles son las condiciones de conservación y eliminación. No hay documentación para cada prompt.

Las búsquedas públicas, conectores, portales o acciones de envío que elija el usuario se rigen por las condiciones de ese servicio externo. Se trata de un destino externo, no de una tercera categoría de tratamiento de Mparanza.

Los plugins también contactan con Mparanza para comprobar actualizaciones y el estado de comentarios enviados anteriormente. Esas solicitudes no contienen contenido de clientes ni del trabajo, aunque pueden registrarse los datos técnicos de conexión. El contenido de los comentarios solo se envía mediante el flujo de envío explícito.

Una política para Vera y Clara.

La distinción es arquitectónica, no profesional. Una conciliación de Vera y una presentación de Clara pertenecen a la primera categoría cuando se ejecutan dentro de Codex.

Cualquier servicio alojado por Mparanza que use cualquiera de los dos plugins pertenece a la segunda categoría y queda cubierto por su descripción a nivel de servicio.

Comprueba esta posición.

No tienes que confiar únicamente en esta afirmación.

Una política para Vera y Clara. Sin documentación para cada prompt.