Privacy
The ChatGPT plugins of Agent Tools, such as Company Jobs Finder, Startup Name Check, Package Health Check, Recall Check, Citation Checker, Business Days and Holidays, Tariff Code Finder, EU Business Check, Rules Lookup, Site Check, Travel Check, Food Facts, Car Check, Document Tools, Tax Numbers, Dev Facts Check, Paper Finder, CVE Risk Check, Domain Mail Check, Country Stats Facts, SEO Audit, AI Text Check, Market Indicators, Transcript Kit, Live Card, Hire or Automate, Post Kit, Ad Angle Map, Taste Profile, Trade Chart, Buyer Signals, Tarot Reader, Dream Analyzer, Feng Shui and Dream Soulmate, keep nothing about you. Apart from the exceptions described below, such as feedback an agent chooses to submit and the style profiles of Taste Profile, the only thing stored is a count of calls per tool per day (and, for the optional SEO Audit judgement, the local AI-readiness check, the optional Hire or Automate model tie-break and Buyer Signals lookups, daily limit counters described below, and for Live Card the HTML of a render until it finishes and the files for 24 hours).
What a plugin receives
When you use a plugin in ChatGPT, ChatGPT decides to call one of its tools and sends only that tool's arguments. For Company Jobs Finder those are the company names or careers page links you asked about and any filters (keyword, location, remote, department, posting date, posted salary). The profile keyword check takes the profile text you paste (for example a headline and About section) and either up to three target job titles or one company and job title. It never reads LinkedIn or any profile page; it only sees the text you send, and that text is checked in memory for the answer to that one call and is never stored, cached, logged or counted. The result lists role words, not your text. Send only text you are comfortable sharing with ChatGPT, and leave out contact details. The two job-fit tools also take a short work profile that you or ChatGPT write: target and recent job titles, years of experience, level, skills, places and whether you are open to remote work. The profile is used in memory only to rank the jobs in that one answer; it is never stored, cached, logged or counted, and the only record of the call is the existing daily call count. Send a short summary, never a full resume, and no names, contact details or employers you do not want to share. For Startup Name Check they are the business names or domains you asked about and the domain endings you chose. For Package Health Check they are the public npm or Python package names and versions you asked about, or the text of a package.json you shared. A package.json is read only for the names and versions in its dependency lists; the rest of the file is ignored, and the file and its dependency list are not stored or cached. Package names and versions are sent to the public sources named below, so do not use private package names. For Citation Checker they are the references you asked about, as text: authors, year, title, journal and DOI. Send it bibliographic details only. For Business Days and Holidays they are a country code, an optional region, the dates or the number of days you asked about, an optional weekend, and a year. For Tariff Code Finder they are the description of a product or a tariff code, a country (UK or US) and an optional country of origin. Describe the product only: never include names, addresses or other personal details. For EU Business Check they are a VAT number and its country, a company name or Legal Entity Identifier, a registry country (France or Norway) and, only if you choose to get a consultation number, your own VAT number. Send the names of companies only: never send the name of a private person. For Rules Lookup they are the CFR title and section you ask about, or the words, document type and dates you search for. Do not put personal details or a description of your own legal situation in a search. For Site Check they are the public web address of a page, a product page or a bare domain of a site you ask about. Send public sites only: addresses with a password or token in them are refused, and so are private and local addresses. For SEO Audit they are the public site or page address you ask about, a number of pages (up to 25) and whether you want the optional judgement. The local AI-readiness check, the AI instructions check and the llms.txt draft take that same kind of address. They do not take a question to send to an AI engine. The draft is built from the site's public pages and is not published to the site. For Travel Check they are a country name, up to five country names to compare, or an airport code. Travel Check never asks for your name, passport, nationality, travel dates or itinerary. For Food Facts they are a product barcode, the words of a product search with an optional country, and the allergens you want a product checked against. Food Facts never asks for your name or any health details, so do not include them. For Car Check they are a vehicle identification number (VIN) you ask to decode, or a vehicle year, make and model. Car Check never asks for your name, address, licence plate or mileage. A VIN identifies one vehicle, so send it only if you are comfortable with that. For Recall Check they are the vehicle year, make and model, a vehicle identification number (VIN) you ask to decode, or the product or food name you ask about, plus a number of days. Recall Check never asks for your name, address or licence plate. For Tax Numbers they are a tax year, a filing status, a date and, for an estimate, the income amounts you give; round figures are enough, so never send names, tax identification numbers or account details. For Shop Duty Desk they are order lines (a goods description, an optional tariff code, the country of origin, a quantity and a unit value; lines with a customer name, address or any other customer field are refused), the text of a Shopify Inventory or product CSV you shared, product titles, and a tariff code with amounts. For Catalog QA Desk they are the text of a Shopify product CSV you shared, or the address of a store whose public product feed you ask it to read. Send goods data only: a CSV export of products and inventory holds no customer data, and you should not send order exports. For Dev Facts Check they are a software product and version, a license name, a web feature name, or an RFC number or title words. For Paper Finder they are topic words and an optional year, category or open-access filter, or one DOI, PubMed id or arXiv id. For CVE Risk Check they are the CVE ids you ask about, or a number of days and a product word for the list of recently exploited vulnerabilities. Send public CVE ids only. For Domain Mail Check they are the domain names you ask about and, optionally, DKIM selector names and DNS record types. Send public domain names only. For Country Stats Facts they are the country names or codes you ask about, an indicator name and optionally a year. For Market Indicators they are the indicator names and settings, up to 250 candles of prices you chose to send, or a currency pair and interval. No personal data is involved. For AI Text Check it is the text you ask it to check, up to 12,000 characters; do not send text with personal details you do not want processed. For Live Card they are the HTML of a cover and of an animation, a size, a duration and a frame rate. The HTML is kept only until the render finishes, then deleted. Do not put personal or sensitive information in that HTML. For LP Pool Check they are a pool id, a chain name, token symbols or token contract addresses, and, if you ask for the fee-versus-impermanent-loss estimate, a price range, a holding period and optional amounts for position size, gas and exit cost. Those amounts are used only to compute that answer. Send public pool and token identifiers only. For Hire or Automate they are a job title or an O*NET-SOC code, and optionally a job description. Send the role, not a person: no names, email addresses, phone numbers or identification numbers. The description is used in memory to match an occupation and is not stored, cached or logged. If the title is not in the occupation tables, a short excerpt may be sent to Cloudflare Workers AI to pick a code from a short list; that step is limited per day and per network, and only the day's call count and an estimated neuron total are stored. For Post Kit they are the topic, tone, platform names, the post text and the target market you write for the drafts and adaptations, or the address of your own product page for a launch clip. Do not include personal data, passwords or other people's private messages in a post; Post Kit does not need them. For Ad Angle Map they are up to three store addresses whose public product feeds you ask it to read, ads you paste in, and short phrases for a public-discussion check. Ads you paste in are analysed in memory and dropped. For Trade Chart they are a public ticker, currency pair or crypto pair, a timeframe and up to four indicator names. No account, order or personal data is involved. For Tarot Reader, Dream Analyzer, Feng Shui and Dream Soulmate, the words you ask about (a question, a dream, a room description, or answers about what you value) are used in memory for that one answer. They are not stored, cached or logged. A reading is sent to a model through our own relay and the answer comes back to you. A question about self-harm, a crisis or a medical issue is not sent for a reading. Dream Soulmate takes words only: do not send a photo. The plugin does not receive your ChatGPT conversation, your name, your email address or your OpenAI account details.
Like any website, the server also sees the network address the request comes from. For plugin calls that is usually an OpenAI server rather than your own device.
What it does with it
The ChatGPT plugins of Agent Tools, such as Company Jobs Finder, Startup Name Check, Package Health Check, Recall Check, Citation Checker, Business Days and Holidays, Tariff Code Finder, EU Business Check, Rules Lookup, Site Check, Travel Check, Food Facts, Car Check, Document Tools, Tax Numbers, Dev Facts Check, Paper Finder, CVE Risk Check, Domain Mail Check, Country Stats Facts, SEO Audit, AI Text Check, Market Indicators, Transcript Kit and Buyer Signals, keep nothing about you. Apart from the exceptions described below, such as feedback an agent chooses to submit, the only thing stored is a count of calls per tool per day (and, for the optional SEO Audit judgement, the local AI-readiness check and for Buyer Signals lookups, daily limit counters described below).
What a plugin receives
When you use a plugin in ChatGPT, ChatGPT decides to call one of its tools and sends only that tool's arguments. For Company Jobs Finder those are the company names or careers page links you asked about and any filters (keyword, location, remote, department, posting date, posted salary). The profile keyword check takes the profile text you paste (for example a headline and About section) and either up to three target job titles or one company and job title. It never reads LinkedIn or any profile page; it only sees the text you send, and that text is checked in memory for the answer to that one call and is never stored, cached, logged or counted. The result lists role words, not your text. Send only text you are comfortable sharing with ChatGPT, and leave out contact details. The two job-fit tools also take a short work profile that you or ChatGPT write: target and recent job titles, years of experience, level, skills, places and whether you are open to remote work. The profile is used in memory only to rank the jobs in that one answer; it is never stored, cached, logged or counted, and the only record of the call is the existing daily call count. Send a short summary, never a full resume, and no names, contact details or employers you do not want to share. For Startup Name Check they are the business names or domains you asked about and the domain endings you chose. For Package Health Check they are the public npm or Python package names and versions you asked about, or the text of a package.json you shared. A package.json is read only for the names and versions in its dependency lists; the rest of the file is ignored, and the file and its dependency list are not stored or cached. Package names and versions are sent to the public sources named below, so do not use private package names. For Citation Checker they are the references you asked about, as text: authors, year, title, journal and DOI. Send it bibliographic details only. For Business Days and Holidays they are a country code, an optional region, the dates or the number of days you asked about, an optional weekend, and a year. For Tariff Code Finder they are the description of a product or a tariff code, a country (UK or US) and an optional country of origin. Describe the product only: never include names, addresses or other personal details. For EU Business Check they are a VAT number and its country, a company name or Legal Entity Identifier, a registry country (France or Norway) and, only if you choose to get a consultation number, your own VAT number. Send the names of companies only: never send the name of a private person. For Rules Lookup they are the CFR title and section you ask about, or the words, document type and dates you search for. Do not put personal details or a description of your own legal situation in a search. For Site Check they are the public web address of a page, a product page or a bare domain of a site you ask about. Send public sites only: addresses with a password or token in them are refused, and so are private and local addresses. For SEO Audit they are the public site or page address you ask about, a number of pages (up to 25) and whether you want the optional judgement. The local AI-readiness check takes that same kind of address. For Buyer Signals they are an industry from a fixed list, an optional region, an optional job title such as bookkeeper, a number of days (1 to 60) and a number of results, or, for the tool-complaint lookup, a category such as monitoring and a number of days (30 to 365). Describe companies, roles and tool categories only: never include names of people, usernames, emails or phone numbers. It does not take a question to send to an AI engine. For Travel Check they are a country name, up to five country names to compare, or an airport code. Travel Check never asks for your name, passport, nationality, travel dates or itinerary. For Food Facts they are a product barcode, the words of a product search with an optional country, and the allergens you want a product checked against. Food Facts never asks for your name or any health details, so do not include them. For Car Check they are a vehicle identification number (VIN) you ask to decode, or a vehicle year, make and model. Car Check never asks for your name, address, licence plate or mileage. A VIN identifies one vehicle, so send it only if you are comfortable with that. For Recall Check they are the vehicle year, make and model, a vehicle identification number (VIN) you ask to decode, or the product or food name you ask about, plus a number of days. Recall Check never asks for your name, address or licence plate. For Tax Numbers they are a tax year, a filing status, a date and, for an estimate, the income amounts you give; round figures are enough, so never send names, tax identification numbers or account details. For Shop Duty Desk they are order lines (a goods description, an optional tariff code, the country of origin, a quantity and a unit value; lines with a customer name, address or any other customer field are refused), the text of a Shopify Inventory or product CSV you shared, product titles, and a tariff code with amounts. For Catalog QA Desk they are the text of a Shopify product CSV you shared, or the address of a store whose public product feed you ask it to read. Send goods data only: a CSV export of products and inventory holds no customer data, and you should not send order exports. For Dev Facts Check they are a software product and version, a license name, a web feature name, or an RFC number or title words. For Paper Finder they are topic words and an optional year, category or open-access filter, or one DOI, PubMed id or arXiv id. For CVE Risk Check they are the CVE ids you ask about, or a number of days and a product word for the list of recently exploited vulnerabilities. Send public CVE ids only. For Domain Mail Check they are the domain names you ask about and, optionally, DKIM selector names and DNS record types. Send public domain names only. For Country Stats Facts they are the country names or codes you ask about, an indicator name and optionally a year. For Market Indicators they are the indicator names and settings, up to 250 candles of prices you chose to send, or a currency pair and interval. No personal data is involved. For AI Text Check it is the text you ask it to check, up to 12,000 characters; do not send text with personal details you do not want processed. The plugin does not receive your ChatGPT conversation, your name, your email address or your OpenAI account details.
- Answers the question. The arguments are used to read the matching public job boards on Greenhouse, Lever, Ashby, Workable and SmartRecruiters, and the answer is sent back to ChatGPT.
- Looks up domains. For Startup Name Check, the domain names built from your arguments (for example acme.com) are sent to Cloudflare's Registrar domain-check API when that lookup is configured, and otherwise, or when that API does not cover the ending, to the public registration lookup (RDAP) service of each domain's registry, found through the IANA directory. Only the domain name is sent. Registration status, dates when the registry publishes them, and a registration cost when Cloudflare returns one come back into the answer; no owner or contact details are kept or returned. The lookup does not register, buy or reserve a domain.
- Looks up recalls. For Recall Check, the vehicle or VIN you ask about is sent to the public NHTSA recall and VIN services, and a product or food name is sent to the public recall services of the CPSC or the FDA. Nothing else from your conversation is sent.
- Looks up packages. For Package Health Check, the package names and versions are sent to OSV.dev, the npm registry, the PyPI JSON API, deps.dev and the npm downloads API, and the public facts that come back (advisories, license, release dates, dependents) go into the answer.
- Looks up references. For Citation Checker, the reference text is used to look the paper up in Crossref, the DOI system (doi.org) and OpenAlex, which are public scholarly indexes, so those services receive the reference text and the network address of our servers, not yours. Only bibliographic details come back into the answer.
- Reads and records public store data. For Store Price Tracker, the store address you name is used to read the store's public product feed (/products.json), after its robots.txt, with a User-Agent that names StorePriceTracker and a contact address. A store you ask about is added to a daily snapshot list, and each day the plugin stores that store's public product data (titles, prices, variants, availability and the changes between days) so that price history can be read back. This is data about products and stores, not about you: the stored record is found by the store's address and holds nothing about who asked. A store owner can ask for a store to be removed through the support page or disallow StorePriceTracker in robots.txt.
- Looks up holidays. For Business Days and Holidays, the country code, region and year are sent to the public Nager.Date public holiday service and, for school holidays, to the public OpenHolidays service. The dates you asked about are used only inside our servers to count days and are not sent to them. Only holiday names and dates come back into the answer.
- Looks up tariffs. For Tariff Code Finder, the product description or tariff code and, when you give one, the country of origin are sent to the public UK Trade Tariff service or the public US Harmonized Tariff Schedule search service. Only the schedule's codes, descriptions and duty rates come back into the answer.
- Looks up businesses. For EU Business Check, the VAT number (and your own VAT number, if you ask for a consultation number) is sent to the European Commission's VIES service, a company name or LEI to the GLEIF Global LEI Index, and a company name or registration number to the French company search (api.gouv.fr) or the Norwegian Brønnøysund Register Centre. Only public register data about legal entities comes back into the answer; names that could belong to a private person, and sole proprietors, are left out.
- Looks up regulations. For Rules Lookup, the title and section or the search words are sent to the Electronic Code of Federal Regulations (ecfr.gov) or the Federal Register (federalregister.gov), both run by the Office of the Federal Register. Only public regulatory text and notices come back.
- Looks at a public site. For Site Check, our server requests the address you gave, the robots.txt of that site and any redirect it points to, and reads only the response headers and the head of the page. The three store checks go a little further: product page SEO reads one product page, including its structured data (JSON-LD), but not reviews or reviewer names; AI readiness requests the site's llms.txt, agents.md, /.well-known/ucp file and sitemap; and the link sample requests up to 40 addresses from the site's sitemap with HEAD requests, which return status codes and no page content. The landing page check reads one page of HTML and returns only its main headline, the short labels of its buttons and a count of what it found (forms and fields, trust markup, contact links); it does not return review text, email addresses or phone numbers, and it requests up to five of the page's own link targets with HEAD requests. These checks read robots.txt first and do not request anything it disallows for Agent Tools. Nothing is sent from you or your conversation to that site; the site sees an ordinary request from the Site Check user agent, which names this service and a support page.
- Looks up travel advice. For Travel Check, the country you ask about is matched against the public UK travel advice index on GOV.UK and the US State Department advisory list, and the UK advice page for that country is read from GOV.UK. An airport code you ask about is sent to the FAA airport status service (US airports) and the NOAA Aviation Weather Center. Nothing else from your conversation is sent.
- Looks up food. For Food Facts, the barcode or search words you ask about, and the country if you give one, are sent to the public Open Food Facts service (world.openfoodfacts.org and search.openfoodfacts.org) with a user agent that names this service. The allergens you want to avoid are not sent: they are compared with the product entry here. Nothing else from your conversation is sent.
- Looks up vehicles. For Car Check, the VIN or the year, make and model you ask about are sent to the public NHTSA services (vpic.nhtsa.dot.gov and api.nhtsa.gov) and, for fuel economy, to the US EPA's fueleconomy.gov, with a user agent that names this service. Only counts and component names from NHTSA's complaint records come back into the answer: no complaint text and no VIN fragments. Nothing else from your conversation is sent.
- Renders a card. For Live Card, the HTML you supply is stored under a random id until the render finishes (or for two hours if it never does), then deleted. The JPEG, MOV, MP4 and GIF are stored under another random id. The links work for 24 hours and are not listed, so only someone with a link can open a file. After 24 hours the links stop working and the files are deleted: a cleanup deletes expired files every 30 minutes, and a storage rule removes anything left after two days. The render runs on our own server. Remote addresses in the HTML are refused, so the renderer does not fetch them. A coarse day-scoped hash of the network address is counted so one network cannot use the whole daily render allowance. That hash cannot be turned back into an address, and the count is deleted after a few days. No name, account or address is stored.
- Counts text and makes files. For Document Tools, the text you ask it to count is used only to work out the counts and is never stored. A calendar or CSV file you ask it to make is written to our storage under a random 128-bit name, and the link only works for 24 hours. The files are not listed anywhere, so only someone with the link can open one. After 24 hours the link stops working and the file is deleted: a cleanup deletes expired files every 30 minutes, and a storage rule removes anything left after two days. The file contents are also returned to you in the answer, so you do not need the link. Do not put personal or sensitive information in a file you ask it to make.
- Looks up tax figures. For Tax Numbers, the figures come from a table of US federal tax data built into the service, each row naming the IRS document it was read from, so nothing from your request is sent to any other service. The income amounts you give for an estimate are used only for that calculation and are never stored or cached.
- Checks customs data. For Shop Duty Desk, a CSV you share is read in memory by a Worker object that keeps no state, and only counts and the rows with problems come back. The EUR 3 duty and the VAT table are calculated inside the service. Product titles and tariff codes are sent to the public UK Trade Tariff and US Harmonized Tariff Schedule services to find candidate codes and duty rates. Nothing from the order lines or the CSV is stored.
- Checks writing. For AI Text Check, the text is matched against fixed pattern rules inside the Worker, in memory, with no AI model and no outside service. It is never stored, cached or logged, and only the daily call count is kept. The answer repeats short excerpts of your text (up to 120 characters each) back to you.
- Draws a price chart. For Trade Chart, the ticker or pair you name is sent to Yahoo Finance's public chart endpoint, and only if that has no candles, to Coinbase's public candle endpoint for a crypto pair or to Frankfurter for an ECB reference rate. The symbol, timeframe and indicator names are used to build the chart and are not stored. The chart page on chart.openkrill.app reads the same public sources and keeps no record of who opened it, only the daily call count.
- Checks product catalogs. For Catalog QA Desk, a CSV you share is read in memory by a Worker object that keeps no state, and only counts and the rows with problems come back. If you give a store address instead, the plugin reads that store's public product feed (/products.json) once, after its robots.txt, with a User-Agent that names CatalogQADesk and a contact address, up to five pages of 250 products. The feed is analysed and dropped: it is not stored, not cached and not added to any index of stores, and the answer is not found by who asked. A store owner can disallow CatalogQADesk in robots.txt. Catalog QA Desk reads product data only, never customer or order data, and never changes a store.
- Looks up developer facts. For Dev Facts Check, the software product and version, license name, web feature name or RFC number or title words you ask about are sent to the public services that hold that data: endoflife.date, the SPDX License List at spdx.org, webstatus.dev, the RFC Editor and the IETF Datatracker, with a user agent that names this service. Nothing else from your conversation is sent.
- Looks up papers. For Paper Finder, the topic words, filters or DOI, PubMed id or arXiv id you ask about are sent to Europe PMC, Crossref and arXiv, with a user agent that names this service and our support address (Crossref uses it to route polite callers). Nothing else from your conversation is sent.
- Looks up vulnerabilities. For CVE Risk Check, the CVE ids you ask about are sent to the National Vulnerability Database (services.nvd.nist.gov) and, for exploit scores, to FIRST (api.first.org), with a user agent that names this service. The list of recent exploited vulnerabilities sends only a date range. Nothing else from your conversation is sent.
- Looks up a domain. For Domain Mail Check, the domain name (and any selector name such as the part before ._domainkey) is sent as a DNS query to Cloudflare (cloudflare-dns.com) and, if that fails, to Google Public DNS (dns.google). A registration lookup sends the domain to IANA's RDAP directory (data.iana.org) and to the registry of its ending (for example rdap.verisign.com for .com), with a user agent that names this service. Registrant and contact details in a registry answer are never read or returned. Nothing else from your conversation is sent.
- Looks up country statistics. For Country Stats Facts, the country codes, the indicator and the year are sent to the World Bank (api.worldbank.org), and an IMF forecast request reads the public tables of the IMF DataMapper (imf.org), with a user agent that names this service. Nothing else from your conversation is sent.
- Audits a public site. For SEO Audit, our server requests the robots.txt and sitemap of the site you named and up to 25 of its pages, at most three at a time, only on that site and only where its robots.txt allows this tool, with a User-Agent that names this service and a support page. The pages are read in memory, turned into a list of findings and dropped; no page content is stored. If you ask for the optional judgement, short extracts of the page text (the title, description, main heading and up to about 6,000 characters of text) of the homepage and of pages with overlapping titles are sent to the TypeSafe Jev service (api.typesafe.ai), which returns only answers about what a page is for. Do not use it on pages with personal or confidential content. Judgement is limited per day overall and per network; for that, the day's totals of judgement requests and their estimated cost are stored, plus a count per day for a coarse bucket of a salted hash of the network address that changes every day and is deleted after a few days. The local AI-readiness check reads the same pages and does not call Gemini, OpenAI, Anthropic, Perplexity or any directory or review site. Its daily limits store only a day total of checks and a count per day for that same kind of coarse network bucket, deleted after a few days. No page content is stored for it either. The AI instructions check reads robots.txt, /llms.txt, /llms-full.txt and a small sample of the site's pages. The draft is made from those pages in memory. Neither calls an AI engine. The draft is not written back to the site. Email addresses and phone numbers are removed from the draft text before it is returned. Like other SEO Audit answers, the result may be cached for ten minutes and then dropped. No page content is stored beyond that cache.
- Reads exchange rates. For Market Indicators, a currency pair you ask about is turned into a request for its daily rates to Frankfurter (frankfurter.dev), which serves the European Central Bank's euro reference rates, with a user agent that names this service and our support address. The pair and the date range are all that is sent. The prices you send to compute_indicators are used in memory for that one answer and are never sent anywhere, stored, cached or logged. Nothing else from your conversation is sent.
- Reads public news and public posts. Industry Pulse, on a schedule that has nothing to do with who asks, reads the RSS and Atom feeds that publishers offer (company blogs, GitHub release feeds, changelogs) and Hacker News stories through its public search API. It stores those public items, the events they are grouped into and short English summaries for 30 days. A Cloudflare Workers AI model scores, groups and summarizes that public text; nothing you type is sent to it. What you type is only the topic words of a search or a date, which are matched against the stored events and not kept, and, for product feedback, a product name, which is sent as a search phrase to the Hacker News search API and, for a few known tools, used to read the public GitHub issues and App Store reviews of that product. The counted result is kept for six hours and is found by the product name, not by who asked. Quotes in it are short excerpts of public posts with a link to the original and no author name. It does not read X, Reddit, WeChat or any page that needs a login.
- Transcribes recordings you own. For Transcript Kit, an audio or video file you upload or a direct link to one is read in memory, its audio is sent to Cloudflare Workers AI (Whisper) to be turned into text, and the file is dropped: the media itself is never stored. The transcript is kept for 24 hours so you can search it and ask for clips: the text with its times, a title, the language and the length, filed under a hashed form of the anonymous user id ChatGPT sends (or, when there is none, a random library id that the answer returns). A library holds the latest 10 transcripts, and expired ones are deleted by a scheduled job. A daily count of minutes transcribed is kept as a number, in total, per network and per user id, with no content. To translate captions, the text you send (or the text of a transcript you name) is sent to Cloudflare Workers AI (a translation model, and for a dub script a small language model) and the translation is returned to you; it is not stored. A daily count of characters translated is kept as a number, in total, per network and per user id, with no content. Links to video or social platform pages are refused and never fetched, and a link is only fetched after a check that it points at a public address.
- Splits a role. For Hire or Automate, the occupation tables are loaded from the O*NET 31.0 Database (U.S. Department of Labor, Employment and Training Administration, CC BY 4.0) and kept in our database. A title is matched here. The job description, if you send one, is used in memory for that call and is not stored. If the tables do not pick one occupation, a short excerpt of the title and description, plus a short list of candidate codes, may be sent to Cloudflare Workers AI (
@cf/meta/llama-3.2-1b-instruct), which returns a code. Do not include names or contact details. The tie-break is limited per day overall and per network; for that, the day's totals of tie-breaks and their estimated neuron cost are stored, plus a count per day for a coarse bucket of a salted hash of the network address that changes every day and is deleted after a few days. Nothing about the job text is stored. - Writes drafts with an AI model. For Post Kit, the topic, tone, platform names, post text, video script request and target market are sent to Cloudflare Workers AI, which runs the open Gemma 4 26B model (gemma-4-26b-a4b-it) inside Cloudflare's network, to write or adapt the text. Cloudflare does not use these inputs to train its models. Nothing is sent to any other AI provider, the text is not stored, cached or logged by us, and only a count of model calls per day is kept, to hold the shared free allowance. Whether a draft fits a platform, and whether a draft or script declares an AI-generated person or voice that a platform asks creators to label, is checked by fixed rules in the Worker, not by the model; the platforms' own policy pages are linked in the answer.
- Reads your product page. For Post Kit's launch clip, the page address you give is fetched once from the public web, after its robots.txt has been read and honoured, with a user agent that names this service. Only the page's title, description and headings are used, and only public addresses are fetched (private and internal addresses are refused). The page is not stored or cached, and nothing is posted anywhere: Post Kit never publishes, never connects to a social account and never reads statistics.
- Maps advertising angles. For Ad Angle Map, a store address you name is used to read that store's public product feed (/products.json) once, after its robots.txt, with a User-Agent that names AdAngleMap and a contact address, up to three pages of 250 products. The feed is analysed and dropped: it is not stored and not added to any index of stores. A store owner can disallow AdAngleMap in robots.txt. Ads you paste in are analysed in memory and not kept. The answer holds counts and product handles or ad ids, and says that an offer map is product-page copy and prices, not ads. A gap check sends a short phrase to Hacker News (Algolia) and, if you name one, a Stack Exchange site; only titles, links, scores and counts are read, never user names, and Reddit is not used. Nothing is stored, no personal data is read, and no ad is created or changed.
- Caches the answer. The same question asked again within about two hours is answered from a cache instead of asking the job boards again (for Startup Name Check, within about five minutes; for Package Health Check, about an hour, for a single package only, never for a package.json; for Recall Check, 24 hours; for Citation Checker, six hours; for Business Days and Holidays, 24 hours; for Tariff Code Finder, six hours; for EU Business Check, an hour, except a VAT check that asks for a consultation number, which is never cached; for Rules Lookup, six hours for a section and an hour for a search; for Site Check, five minutes; for Travel Check, about three hours, and five minutes for an airport, with the two country lists kept for up to a day; for Food Facts, about twelve hours for a product and six hours for a search; for Car Check, 24 hours; for Dev Facts Check, six hours for end-of-life and browser support and 24 hours for licenses and RFCs; for Paper Finder, six hours for a search and 24 hours for a single paper; for CVE Risk Check, an hour, with each National Vulnerability Database record kept for up to three hours; for Domain Mail Check, two minutes for DNS answers and an hour for registration data; for Country Stats Facts, six hours; for SEO Audit, ten minutes; for Market Indicators, an hour for a currency pair's indicators, and never for prices you send; for Trade Chart, fifteen minutes for an intraday chart and an hour for a daily or weekly chart; for Hire or Automate, 24 hours for a title with no description, and never when a description was sent; Post Kit answers are never cached). A cached entry holds the public job listings, domain status, package facts, recall records, bibliographic records, holiday calendars, tariff schedule entries, company register records or regulation text, a site's published robots.txt rules and tags, travel advisories, airport conditions, food product entries, vehicle recalls, ratings, complaint counts, fuel economy figures, software release dates, license records, browser support data, RFC records or paper records, plus public vulnerability records and exploit scores,, plus public DNS records and registry dates,, plus public World Bank and IMF figures, plus exchange rates, store offer counts, product handles or discussion counts, plus public SEC filing facts, job postings and counted tool-complaint themes, and is found by a hash of the tool arguments; it holds nothing about who asked. Entries expire on their own.
- Limits abuse. The network address is used, in memory and for about a minute, to limit how many calls one network can make. It is not written to any database or log we keep, except for the optional SEO Audit judgement, the local AI-readiness daily limits and the optional Hire or Automate model tie-break and the daily count of Post Kit model calls, described under those plugins.
- Reads public pool figures. For LP Pool Check, the chain and token addresses or pool id you ask about are used to look up a shared index of public liquidity-pool rows from DefiLlama, and token addresses are sent to GoPlus and to DefiLlama's public price API when those sources cover the chain. The index holds public pool figures (volume, TVL, fee metadata, token addresses) and nothing about who asked. Amounts you pass for an estimate are not written to the database.
- Writes a short entertainment note. For Tarot Reader, Dream Analyzer, Feng Shui and Dream Soulmate, the words of that one call are sent through an outbound relay to a language model and the note is returned to you. The words are not stored. A daily count of readings is kept as a number, in total, per network and, when ChatGPT sends an anonymous user id, per user. The count has no content. A crisis or medical ask is answered on our server with a pointer to real help and is not sent to the model.
- Counts calls. Each call adds one to a counter for that plugin, tool and UTC day, plus one to an error counter when the call failed. Apart from the public store data, the 24-hour download files above, the Live Card files described above, the SEO Audit judgement limits and the local AI-readiness daily limits, the Hire or Automate model limits and the daily count of Post Kit model calls, and the reflection reading counters, these aggregate counts are the only thing stored. They contain no prompts, arguments, answers, addresses or identifiers.
Feedback from agents
@cf/google/gemma-4-26b-a4b-it), which writes a short description of its layout, type, colours, texture and hierarchy; a second Workers AI model (@cf/baai/bge-m3) turns that description, and any search text, into numbers used for matching. The image itself is never stored by us. What is stored, in our database, is that description (with text that looks like a link, email address or phone number removed), the image's file name or the last part of its link without any query string, the numbers used for search, and the style rules you save. They sit under a random profile key that the first call returns and that only you hold; we store only a one-way hash of the key, so a lost key cannot be recovered and nobody can list or read profiles without it. A profile is deleted 90 days after it was last used, or at once when you ask for it with delete_profile, which removes the descriptions, search numbers and saved rules. There are no accounts. Daily counters for the plugin hold only totals and a short one-way hash of the network and the key, rotating at UTC midnight.Feedback from agents
Every plugin and the API have two optional tools, submit_feedback and get_feedback_reply (also POST /v1/feedback and GET /v1/feedback/{ticket}), for an agent to say what it needs or what broke. This is the one place where we keep text an agent wrote. It is kept as follows:
- What is stored. The message (at most 1000 characters), its kind (need_tool, need_data, bug or other), the tool it names if any, which host it came through (for example tariffs, or api), the UTC day, a ticket id, and the reply once there is one. Links, email addresses and phone numbers are removed from the message before it is stored; the same is done to the reply.
- What is not stored. No network address, user agent, API key, token or conversation content is stored with the feedback.
- Limits. The network address is used in memory, for about a minute, to allow 5 submissions a minute. The daily cap per network uses the same kind of short one-way hash bucket as the API, which changes every day and is deleted after three days. A global daily total is also kept. Refused and accepted calls are counted in the aggregate call counters described above.
- Replies. A reply is written by an automated assistant, a language model reached through a proxy we run. It is given only the feedback text, quoted as data, and a list of our tools; it has no tools of its own and its reply is stored as text, never run. The feedback text is therefore sent to that model provider (xAI) to produce the reply. Do not put anything private in feedback.
- Retention. Feedback and its reply are deleted after 90 days. It is read by the operator to decide what to build, and appears, shortened, on a private operator page.
What it never does
- It stores no prompts, tool arguments, answers or conversation content beyond the short-lived cache, the 24-hour download files, the feedback an agent chooses to submit and the Taste Profile descriptions and saved rules (kept 90 days after last use), all described above.
- It has no accounts, sign-ups, cookies, analytics or advertising trackers, and it sells or shares nothing.
- It never asks for, and you should never send it, personal or sensitive information. Questions about public job openings, domain names, public packages, the references in a paper, public holidays, tariff codes or company registers need none, and a package.json check needs only the dependency names and versions: never send source code, tokens or passwords. Tax Numbers needs no name, tax identification number or account detail, only a year, a filing status and amounts. Dev Facts Check needs only a product, license, web feature or RFC name. Paper Finder needs only topic words or a paper identifier: never send an unpublished manuscript or private notes. Market Indicators needs only prices, never account, portfolio or position details.
Service providers
The plugins run on Cloudflare Workers. Cloudflare processes requests on our behalf to deliver them and protect them from attacks, under its own privacy policy. The job boards that are read are public pages of the companies you ask about; the plugin sends them only the request for those public listings. Cloudflare Registrar, when that lookup is configured, and domain registries receive only the domain name being checked, and the package sources receive only the package names and versions being checked. Crossref, doi.org and OpenAlex receive the reference text you ask Citation Checker about, and operate under their own terms and privacy policies. The stores you ask Store Price Tracker about receive an ordinary request for their public product feed from our servers, not from your device. Nager.Date and OpenHolidays receive only the country code, region and year of the holiday calendar being read. The UK Trade Tariff and the US International Trade Commission receive only the product description or tariff code being looked up. The European Commission (VIES), GLEIF, the French government company search and the Brønnøysund Register Centre receive only the VAT number, company name, LEI or registration number being checked, and for a consultation number the requester's VAT number, under their own terms and privacy policies. The World Bank and the IMF receive only the country codes, indicator and year being looked up, under their own terms and privacy policies. Cloudflare, Google, IANA and the domain registries receive only the domain name being looked up (and for DKIM the selector name), under their own terms and privacy policies. The National Vulnerability Database and FIRST receive only the CVE ids being looked up, or for the exploited list a date range, under their own terms and privacy policies. The UK Trade Tariff and the US International Trade Commission receive the product titles and tariff codes you ask Shop Duty Desk about. A store you give Catalog QA Desk or Ad Angle Map receives an ordinary request for its public product feed from our servers, not from your device. endoflife.date, the SPDX project at spdx.org, webstatus.dev, the RFC Editor and the IETF Datatracker receive only the product and version, license, web feature or RFC number or title words being looked up, under their own terms and privacy policies. Europe PMC, Crossref and arXiv receive only the topic words, filters or paper identifier being looked up, under their own terms and privacy policies. Frankfurter and the European Central Bank, whose euro reference rates it serves, receive only the currency pair and date range being read, under their own terms and privacy policies. Hacker News (Algolia), GitHub and Apple receive only the product name or product identifier that Industry Pulse looks up, from our servers. The audio you give Transcript Kit goes to Cloudflare Workers AI, which runs the speech model, and the images you give Taste Profile and the search texts go to Cloudflare Workers AI too, under Cloudflare's own privacy policy; a link you give it receives an ordinary request for that file from our servers. DefiLlama receives the pool id or the chain and token addresses being looked up, and GoPlus receives the token addresses, under their own terms and privacy policies. Yahoo Finance and Coinbase receive only the ticker or pair being charted, under their own terms and privacy policies.
API customers
The API at api.openkrill.app works without a key. A call without a key adds to a shared monthly count of billable results, and to a daily count for a coarse bucket of the network address it came from: a short one-way hash of the address and the day, shared by many addresses, that changes every day and is deleted after three days. It is used only to cap how many calls one network can make a day, and the address itself is not stored. With a key, the API stores a hash of the key (never the key itself) and a monthly count of billable results per key. Request contents are handled as described above.
Connecting an agent (OAuth)
An AI agent or MCP client can connect at connect.openkrill.app and receive an access token. There is no account, email address, password or sign-in, and no person is asked anything. To connect, the client registers itself, so we store what it states about itself: its client name and its redirect addresses, which an agent client chooses and which may include a company or product name. Connecting also stores a record of the grant and the issued tokens. Access tokens, authorization codes and client secrets are kept only as hashes, the data attached to a grant is encrypted with a key only the token holder can unwrap, and a grant holds nothing but the client's identifier. We do not store prompts, tool arguments or answers for connected clients, and calls with a token are metered and rate limited under a number derived from the client's identifier, not under a name. A client that has not been used for 90 days is deleted, access tokens last one hour and refresh tokens at most 90 days, and a client can revoke its tokens at any time. The network address of a registration or sign-in attempt is used in memory, for about a minute, to limit repeated attempts, and is not stored. A short event line (the client name at registration, the granted scope, and any error code) is written to our operational logs; it contains no token, argument or address.
Public guides on this site
The install guides, role guides and glossary are static pages. Opening one does not create an account, and the pages do not store what you read. A tool call those pages describe is handled under the rules above for that plugin.
Questions and changes
Questions about this policy go through the support page. If what is processed or stored ever changes, this page changes first and its date above is updated.