Agent Tools

Privacy

The ChatGPT plugins of Agent Tools, such as Company Jobs Finder, Startup Name Check, Package Health Check, Recall Check, Citation Checker, Business Days and Holidays, Tariff Code Finder, EU Business Check, Rules Lookup, Site Check, Travel Check, Food Facts, Car Check, Document Tools, Tax Numbers, Dev Facts Check, Paper Finder, CVE Risk Check, Domain Mail Check, Country Stats Facts, SEO Audit, AI Text Check, Market Indicators, Transcript Kit, Live Card, Hire or Automate, Post Kit, Ad Angle Map, Taste Profile, Trade Chart, Buyer Signals, Tarot Reader, Dream Analyzer, Feng Shui and Dream Soulmate, keep nothing about you. Apart from the exceptions described below, such as feedback an agent chooses to submit and the style profiles of Taste Profile, the only thing stored is a count of calls per tool per day (and, for the optional SEO Audit judgement, the local AI-readiness check, the optional Hire or Automate model tie-break and Buyer Signals lookups, daily limit counters described below, and for Live Card the HTML of a render until it finishes and the files for 24 hours).

Last updated 2026-11-01. Applies to the plugins served from openkrill.app hostnames (for example jobs.openkrill.app, names.openkrill.app, packages.openkrill.app, recalls.openkrill.app, citations.openkrill.app, stores.openkrill.app, businessdays.openkrill.app, tariffs.openkrill.app, eubusiness.openkrill.app, rules.openkrill.app, sitecheck.openkrill.app, travel.openkrill.app, food.openkrill.app, cars.openkrill.app, docs.openkrill.app, tax.openkrill.app, shopduty.openkrill.app, catalogqa.openkrill.app, devfacts.openkrill.app, papers.openkrill.app, cve.openkrill.app, mailcheck.openkrill.app, countrystats.openkrill.app and seoaudit.openkrill.app, aitext.openkrill.app, indicators.openkrill.app, pulse.openkrill.app, transcript.openkrill.app, livecard.openkrill.app, lpcheck.openkrill.app, hire.openkrill.app, postkit.openkrill.app and adangle.openkrill.app, signals.openkrill.app and taste.openkrill.app and chart.openkrill.app, tarot.openkrill.app, dream.openkrill.app, fengshui.openkrill.app, soulmate.openkrill.app) and to the API at api.openkrill.app and the OAuth connection service at connect.openkrill.app.

What a plugin receives

When you use a plugin in ChatGPT, ChatGPT decides to call one of its tools and sends only that tool's arguments. For Company Jobs Finder those are the company names or careers page links you asked about and any filters (keyword, location, remote, department, posting date, posted salary). The profile keyword check takes the profile text you paste (for example a headline and About section) and either up to three target job titles or one company and job title. It never reads LinkedIn or any profile page; it only sees the text you send, and that text is checked in memory for the answer to that one call and is never stored, cached, logged or counted. The result lists role words, not your text. Send only text you are comfortable sharing with ChatGPT, and leave out contact details. The two job-fit tools also take a short work profile that you or ChatGPT write: target and recent job titles, years of experience, level, skills, places and whether you are open to remote work. The profile is used in memory only to rank the jobs in that one answer; it is never stored, cached, logged or counted, and the only record of the call is the existing daily call count. Send a short summary, never a full resume, and no names, contact details or employers you do not want to share. For Startup Name Check they are the business names or domains you asked about and the domain endings you chose. For Package Health Check they are the public npm or Python package names and versions you asked about, or the text of a package.json you shared. A package.json is read only for the names and versions in its dependency lists; the rest of the file is ignored, and the file and its dependency list are not stored or cached. Package names and versions are sent to the public sources named below, so do not use private package names. For Citation Checker they are the references you asked about, as text: authors, year, title, journal and DOI. Send it bibliographic details only. For Business Days and Holidays they are a country code, an optional region, the dates or the number of days you asked about, an optional weekend, and a year. For Tariff Code Finder they are the description of a product or a tariff code, a country (UK or US) and an optional country of origin. Describe the product only: never include names, addresses or other personal details. For EU Business Check they are a VAT number and its country, a company name or Legal Entity Identifier, a registry country (France or Norway) and, only if you choose to get a consultation number, your own VAT number. Send the names of companies only: never send the name of a private person. For Rules Lookup they are the CFR title and section you ask about, or the words, document type and dates you search for. Do not put personal details or a description of your own legal situation in a search. For Site Check they are the public web address of a page, a product page or a bare domain of a site you ask about. Send public sites only: addresses with a password or token in them are refused, and so are private and local addresses. For SEO Audit they are the public site or page address you ask about, a number of pages (up to 25) and whether you want the optional judgement. The local AI-readiness check, the AI instructions check and the llms.txt draft take that same kind of address. They do not take a question to send to an AI engine. The draft is built from the site's public pages and is not published to the site. For Travel Check they are a country name, up to five country names to compare, or an airport code. Travel Check never asks for your name, passport, nationality, travel dates or itinerary. For Food Facts they are a product barcode, the words of a product search with an optional country, and the allergens you want a product checked against. Food Facts never asks for your name or any health details, so do not include them. For Car Check they are a vehicle identification number (VIN) you ask to decode, or a vehicle year, make and model. Car Check never asks for your name, address, licence plate or mileage. A VIN identifies one vehicle, so send it only if you are comfortable with that. For Recall Check they are the vehicle year, make and model, a vehicle identification number (VIN) you ask to decode, or the product or food name you ask about, plus a number of days. Recall Check never asks for your name, address or licence plate. For Tax Numbers they are a tax year, a filing status, a date and, for an estimate, the income amounts you give; round figures are enough, so never send names, tax identification numbers or account details. For Shop Duty Desk they are order lines (a goods description, an optional tariff code, the country of origin, a quantity and a unit value; lines with a customer name, address or any other customer field are refused), the text of a Shopify Inventory or product CSV you shared, product titles, and a tariff code with amounts. For Catalog QA Desk they are the text of a Shopify product CSV you shared, or the address of a store whose public product feed you ask it to read. Send goods data only: a CSV export of products and inventory holds no customer data, and you should not send order exports. For Dev Facts Check they are a software product and version, a license name, a web feature name, or an RFC number or title words. For Paper Finder they are topic words and an optional year, category or open-access filter, or one DOI, PubMed id or arXiv id. For CVE Risk Check they are the CVE ids you ask about, or a number of days and a product word for the list of recently exploited vulnerabilities. Send public CVE ids only. For Domain Mail Check they are the domain names you ask about and, optionally, DKIM selector names and DNS record types. Send public domain names only. For Country Stats Facts they are the country names or codes you ask about, an indicator name and optionally a year. For Market Indicators they are the indicator names and settings, up to 250 candles of prices you chose to send, or a currency pair and interval. No personal data is involved. For AI Text Check it is the text you ask it to check, up to 12,000 characters; do not send text with personal details you do not want processed. For Live Card they are the HTML of a cover and of an animation, a size, a duration and a frame rate. The HTML is kept only until the render finishes, then deleted. Do not put personal or sensitive information in that HTML. For LP Pool Check they are a pool id, a chain name, token symbols or token contract addresses, and, if you ask for the fee-versus-impermanent-loss estimate, a price range, a holding period and optional amounts for position size, gas and exit cost. Those amounts are used only to compute that answer. Send public pool and token identifiers only. For Hire or Automate they are a job title or an O*NET-SOC code, and optionally a job description. Send the role, not a person: no names, email addresses, phone numbers or identification numbers. The description is used in memory to match an occupation and is not stored, cached or logged. If the title is not in the occupation tables, a short excerpt may be sent to Cloudflare Workers AI to pick a code from a short list; that step is limited per day and per network, and only the day's call count and an estimated neuron total are stored. For Post Kit they are the topic, tone, platform names, the post text and the target market you write for the drafts and adaptations, or the address of your own product page for a launch clip. Do not include personal data, passwords or other people's private messages in a post; Post Kit does not need them. For Ad Angle Map they are up to three store addresses whose public product feeds you ask it to read, ads you paste in, and short phrases for a public-discussion check. Ads you paste in are analysed in memory and dropped. For Trade Chart they are a public ticker, currency pair or crypto pair, a timeframe and up to four indicator names. No account, order or personal data is involved. For Tarot Reader, Dream Analyzer, Feng Shui and Dream Soulmate, the words you ask about (a question, a dream, a room description, or answers about what you value) are used in memory for that one answer. They are not stored, cached or logged. A reading is sent to a model through our own relay and the answer comes back to you. A question about self-harm, a crisis or a medical issue is not sent for a reading. Dream Soulmate takes words only: do not send a photo. The plugin does not receive your ChatGPT conversation, your name, your email address or your OpenAI account details.

Like any website, the server also sees the network address the request comes from. For plugin calls that is usually an OpenAI server rather than your own device.

What it does with it

The ChatGPT plugins of Agent Tools, such as Company Jobs Finder, Startup Name Check, Package Health Check, Recall Check, Citation Checker, Business Days and Holidays, Tariff Code Finder, EU Business Check, Rules Lookup, Site Check, Travel Check, Food Facts, Car Check, Document Tools, Tax Numbers, Dev Facts Check, Paper Finder, CVE Risk Check, Domain Mail Check, Country Stats Facts, SEO Audit, AI Text Check, Market Indicators, Transcript Kit and Buyer Signals, keep nothing about you. Apart from the exceptions described below, such as feedback an agent chooses to submit, the only thing stored is a count of calls per tool per day (and, for the optional SEO Audit judgement, the local AI-readiness check and for Buyer Signals lookups, daily limit counters described below).

Last updated 2026-10-27. Applies to the plugins served from openkrill.app hostnames (for example jobs.openkrill.app, names.openkrill.app, packages.openkrill.app, recalls.openkrill.app, citations.openkrill.app, stores.openkrill.app, businessdays.openkrill.app, tariffs.openkrill.app, eubusiness.openkrill.app, rules.openkrill.app, sitecheck.openkrill.app, travel.openkrill.app, food.openkrill.app, cars.openkrill.app, docs.openkrill.app, tax.openkrill.app, shopduty.openkrill.app, catalogqa.openkrill.app, devfacts.openkrill.app, papers.openkrill.app, cve.openkrill.app, mailcheck.openkrill.app, countrystats.openkrill.app and seoaudit.openkrill.app, aitext.openkrill.app, indicators.openkrill.app, pulse.openkrill.app transcript.openkrill.app and signals.openkrill.app, tarot.openkrill.app, dream.openkrill.app, fengshui.openkrill.app, soulmate.openkrill.app) and to the API at api.openkrill.app and the OAuth connection service at connect.openkrill.app.

What a plugin receives

When you use a plugin in ChatGPT, ChatGPT decides to call one of its tools and sends only that tool's arguments. For Company Jobs Finder those are the company names or careers page links you asked about and any filters (keyword, location, remote, department, posting date, posted salary). The profile keyword check takes the profile text you paste (for example a headline and About section) and either up to three target job titles or one company and job title. It never reads LinkedIn or any profile page; it only sees the text you send, and that text is checked in memory for the answer to that one call and is never stored, cached, logged or counted. The result lists role words, not your text. Send only text you are comfortable sharing with ChatGPT, and leave out contact details. The two job-fit tools also take a short work profile that you or ChatGPT write: target and recent job titles, years of experience, level, skills, places and whether you are open to remote work. The profile is used in memory only to rank the jobs in that one answer; it is never stored, cached, logged or counted, and the only record of the call is the existing daily call count. Send a short summary, never a full resume, and no names, contact details or employers you do not want to share. For Startup Name Check they are the business names or domains you asked about and the domain endings you chose. For Package Health Check they are the public npm or Python package names and versions you asked about, or the text of a package.json you shared. A package.json is read only for the names and versions in its dependency lists; the rest of the file is ignored, and the file and its dependency list are not stored or cached. Package names and versions are sent to the public sources named below, so do not use private package names. For Citation Checker they are the references you asked about, as text: authors, year, title, journal and DOI. Send it bibliographic details only. For Business Days and Holidays they are a country code, an optional region, the dates or the number of days you asked about, an optional weekend, and a year. For Tariff Code Finder they are the description of a product or a tariff code, a country (UK or US) and an optional country of origin. Describe the product only: never include names, addresses or other personal details. For EU Business Check they are a VAT number and its country, a company name or Legal Entity Identifier, a registry country (France or Norway) and, only if you choose to get a consultation number, your own VAT number. Send the names of companies only: never send the name of a private person. For Rules Lookup they are the CFR title and section you ask about, or the words, document type and dates you search for. Do not put personal details or a description of your own legal situation in a search. For Site Check they are the public web address of a page, a product page or a bare domain of a site you ask about. Send public sites only: addresses with a password or token in them are refused, and so are private and local addresses. For SEO Audit they are the public site or page address you ask about, a number of pages (up to 25) and whether you want the optional judgement. The local AI-readiness check takes that same kind of address. For Buyer Signals they are an industry from a fixed list, an optional region, an optional job title such as bookkeeper, a number of days (1 to 60) and a number of results, or, for the tool-complaint lookup, a category such as monitoring and a number of days (30 to 365). Describe companies, roles and tool categories only: never include names of people, usernames, emails or phone numbers. It does not take a question to send to an AI engine. For Travel Check they are a country name, up to five country names to compare, or an airport code. Travel Check never asks for your name, passport, nationality, travel dates or itinerary. For Food Facts they are a product barcode, the words of a product search with an optional country, and the allergens you want a product checked against. Food Facts never asks for your name or any health details, so do not include them. For Car Check they are a vehicle identification number (VIN) you ask to decode, or a vehicle year, make and model. Car Check never asks for your name, address, licence plate or mileage. A VIN identifies one vehicle, so send it only if you are comfortable with that. For Recall Check they are the vehicle year, make and model, a vehicle identification number (VIN) you ask to decode, or the product or food name you ask about, plus a number of days. Recall Check never asks for your name, address or licence plate. For Tax Numbers they are a tax year, a filing status, a date and, for an estimate, the income amounts you give; round figures are enough, so never send names, tax identification numbers or account details. For Shop Duty Desk they are order lines (a goods description, an optional tariff code, the country of origin, a quantity and a unit value; lines with a customer name, address or any other customer field are refused), the text of a Shopify Inventory or product CSV you shared, product titles, and a tariff code with amounts. For Catalog QA Desk they are the text of a Shopify product CSV you shared, or the address of a store whose public product feed you ask it to read. Send goods data only: a CSV export of products and inventory holds no customer data, and you should not send order exports. For Dev Facts Check they are a software product and version, a license name, a web feature name, or an RFC number or title words. For Paper Finder they are topic words and an optional year, category or open-access filter, or one DOI, PubMed id or arXiv id. For CVE Risk Check they are the CVE ids you ask about, or a number of days and a product word for the list of recently exploited vulnerabilities. Send public CVE ids only. For Domain Mail Check they are the domain names you ask about and, optionally, DKIM selector names and DNS record types. Send public domain names only. For Country Stats Facts they are the country names or codes you ask about, an indicator name and optionally a year. For Market Indicators they are the indicator names and settings, up to 250 candles of prices you chose to send, or a currency pair and interval. No personal data is involved. For AI Text Check it is the text you ask it to check, up to 12,000 characters; do not send text with personal details you do not want processed. The plugin does not receive your ChatGPT conversation, your name, your email address or your OpenAI account details.

Feedback from agents

  • Searches public filings and job boards. For Buyer Signals, our server reads the SEC EDGAR full-text search (efts.sec.gov) and the Form D filings it returns (www.sec.gov), then, only if you name a role, the public job-board feeds of up to six of the companies found (Greenhouse, Lever and Ashby), at most four requests at a time and about 35 requests in all, with a User-Agent that names this service and a support address. Only company facts are read from a filing (the company name, state, industry group, amount offered and the date); the people and addresses listed in a filing are ignored, and nothing is taken from LinkedIn, Google, Reddit or the Y Combinator directory. The tool-complaint lookup reads the public Algolia Hacker News search API and the Stack Exchange API, drops author names before anything is counted, and returns tool names, themes and source links only. Results hold companies, public links and counts only, with no emails, phone numbers, usernames or named people. Searches are limited to a set number per day for each network and across all users: the only things written for this are daily counters, one for all users and one per network keyed by a short one-way hash of the address that is mixed with the date, so it cannot be turned back into an address or followed from one day to the next, and rows older than three days are deleted. The question you asked is not stored.
  • Audits a public site. For SEO Audit, our server requests the robots.txt and sitemap of the site you named and up to 25 of its pages, at most three at a time, only on that site and only where its robots.txt allows this tool, with a User-Agent that names this service and a support page. The pages are read in memory, turned into a list of findings and dropped; no page content is stored. If you ask for the optional judgement, short extracts of the page text (the title, description, main heading and up to about 6,000 characters of text) of the homepage and of pages with overlapping titles are sent to the TypeSafe Jev service (api.typesafe.ai), which returns only answers about what a page is for. Do not use it on pages with personal or confidential content. Judgement is limited per day overall and per network; for that, the day's totals of judgement requests and their estimated cost are stored, plus a count per day for a coarse bucket of a salted hash of the network address that changes every day and is deleted after a few days.
  • Analyses your images and keeps style profiles. For Taste Profile, each image you add is sent by its link to Cloudflare Workers AI (the model @cf/google/gemma-4-26b-a4b-it), which writes a short description of its layout, type, colours, texture and hierarchy; a second Workers AI model (@cf/baai/bge-m3) turns that description, and any search text, into numbers used for matching. The image itself is never stored by us. What is stored, in our database, is that description (with text that looks like a link, email address or phone number removed), the image's file name or the last part of its link without any query string, the numbers used for search, and the style rules you save. They sit under a random profile key that the first call returns and that only you hold; we store only a one-way hash of the key, so a lost key cannot be recovered and nobody can list or read profiles without it. A profile is deleted 90 days after it was last used, or at once when you ask for it with delete_profile, which removes the descriptions, search numbers and saved rules. There are no accounts. Daily counters for the plugin hold only totals and a short one-way hash of the network and the key, rotating at UTC midnight.
  • Caches the answer. The same question asked again within about two hours is answered from a cache instead of asking the job boards again (for Startup Name Check, within about five minutes; for Package Health Check, about an hour, for a single package only, never for a package.json; for Recall Check, 24 hours; for Citation Checker, six hours; for Business Days and Holidays, 24 hours; for Tariff Code Finder, six hours; for EU Business Check, an hour, except a VAT check that asks for a consultation number, which is never cached; for Rules Lookup, six hours for a section and an hour for a search; for Site Check, five minutes; for Travel Check, about three hours, and five minutes for an airport, with the two country lists kept for up to a day; for Food Facts, about twelve hours for a product and six hours for a search; for Car Check, 24 hours; for Dev Facts Check, six hours for end-of-life and browser support and 24 hours for licenses and RFCs; for Paper Finder, six hours for a search and 24 hours for a single paper; for CVE Risk Check, an hour, with each National Vulnerability Database record kept for up to three hours; for Domain Mail Check, two minutes for DNS answers and an hour for registration data; for Country Stats Facts, six hours; for SEO Audit, ten minutes). A cached entry holds the public job listings, domain status, package facts, recall records, bibliographic records, holiday calendars, tariff schedule entries, company register records or regulation text, a site's published robots.txt rules and tags, travel advisories, airport conditions, food product entries, vehicle recalls, ratings, complaint counts, fuel economy figures, software release dates, license records, browser support data, RFC records or paper records, plus public vulnerability records and exploit scores,, plus public DNS records and registry dates,, plus public World Bank and IMF figures, and is found by a hash of the tool arguments; it holds nothing about who asked. Entries expire on their own.
  • Limits abuse. The network address is used, in memory and for about a minute, to limit how many calls one network can make. It is not written to any database or log we keep, except for the optional SEO Audit judgement, whose per-network daily limit is described under SEO Audit.
  • Counts calls. Each call adds one to a counter for that plugin, tool and UTC day, plus one to an error counter when the call failed. Apart from the public store data, the 24-hour download files above and the SEO Audit judgement limits, these aggregate counts are the only thing stored. They contain no prompts, arguments, answers, addresses or identifiers.
  • Feedback from agents

    Every plugin and the API have two optional tools, submit_feedback and get_feedback_reply (also POST /v1/feedback and GET /v1/feedback/{ticket}), for an agent to say what it needs or what broke. This is the one place where we keep text an agent wrote. It is kept as follows:

    What it never does

    Service providers

    The plugins run on Cloudflare Workers. Cloudflare processes requests on our behalf to deliver them and protect them from attacks, under its own privacy policy. The job boards that are read are public pages of the companies you ask about; the plugin sends them only the request for those public listings. Cloudflare Registrar, when that lookup is configured, and domain registries receive only the domain name being checked, and the package sources receive only the package names and versions being checked. Crossref, doi.org and OpenAlex receive the reference text you ask Citation Checker about, and operate under their own terms and privacy policies. The stores you ask Store Price Tracker about receive an ordinary request for their public product feed from our servers, not from your device. Nager.Date and OpenHolidays receive only the country code, region and year of the holiday calendar being read. The UK Trade Tariff and the US International Trade Commission receive only the product description or tariff code being looked up. The European Commission (VIES), GLEIF, the French government company search and the Brønnøysund Register Centre receive only the VAT number, company name, LEI or registration number being checked, and for a consultation number the requester's VAT number, under their own terms and privacy policies. The World Bank and the IMF receive only the country codes, indicator and year being looked up, under their own terms and privacy policies. Cloudflare, Google, IANA and the domain registries receive only the domain name being looked up (and for DKIM the selector name), under their own terms and privacy policies. The National Vulnerability Database and FIRST receive only the CVE ids being looked up, or for the exploited list a date range, under their own terms and privacy policies. The UK Trade Tariff and the US International Trade Commission receive the product titles and tariff codes you ask Shop Duty Desk about. A store you give Catalog QA Desk or Ad Angle Map receives an ordinary request for its public product feed from our servers, not from your device. endoflife.date, the SPDX project at spdx.org, webstatus.dev, the RFC Editor and the IETF Datatracker receive only the product and version, license, web feature or RFC number or title words being looked up, under their own terms and privacy policies. Europe PMC, Crossref and arXiv receive only the topic words, filters or paper identifier being looked up, under their own terms and privacy policies. Frankfurter and the European Central Bank, whose euro reference rates it serves, receive only the currency pair and date range being read, under their own terms and privacy policies. Hacker News (Algolia), GitHub and Apple receive only the product name or product identifier that Industry Pulse looks up, from our servers. The audio you give Transcript Kit goes to Cloudflare Workers AI, which runs the speech model, and the images you give Taste Profile and the search texts go to Cloudflare Workers AI too, under Cloudflare's own privacy policy; a link you give it receives an ordinary request for that file from our servers. DefiLlama receives the pool id or the chain and token addresses being looked up, and GoPlus receives the token addresses, under their own terms and privacy policies. Yahoo Finance and Coinbase receive only the ticker or pair being charted, under their own terms and privacy policies.

    API customers

    The API at api.openkrill.app works without a key. A call without a key adds to a shared monthly count of billable results, and to a daily count for a coarse bucket of the network address it came from: a short one-way hash of the address and the day, shared by many addresses, that changes every day and is deleted after three days. It is used only to cap how many calls one network can make a day, and the address itself is not stored. With a key, the API stores a hash of the key (never the key itself) and a monthly count of billable results per key. Request contents are handled as described above.

    Connecting an agent (OAuth)

    An AI agent or MCP client can connect at connect.openkrill.app and receive an access token. There is no account, email address, password or sign-in, and no person is asked anything. To connect, the client registers itself, so we store what it states about itself: its client name and its redirect addresses, which an agent client chooses and which may include a company or product name. Connecting also stores a record of the grant and the issued tokens. Access tokens, authorization codes and client secrets are kept only as hashes, the data attached to a grant is encrypted with a key only the token holder can unwrap, and a grant holds nothing but the client's identifier. We do not store prompts, tool arguments or answers for connected clients, and calls with a token are metered and rate limited under a number derived from the client's identifier, not under a name. A client that has not been used for 90 days is deleted, access tokens last one hour and refresh tokens at most 90 days, and a client can revoke its tokens at any time. The network address of a registration or sign-in attempt is used in memory, for about a minute, to limit repeated attempts, and is not stored. A short event line (the client name at registration, the granted scope, and any error code) is written to our operational logs; it contains no token, argument or address.

    Public guides on this site

    The install guides, role guides and glossary are static pages. Opening one does not create an account, and the pages do not store what you read. A tool call those pages describe is handled under the rules above for that plugin.

    Questions and changes

    Questions about this policy go through the support page. If what is processed or stored ever changes, this page changes first and its date above is updated.