Privacy
The ChatGPT plugins of Agent Tools, such as Company Jobs Finder, Startup Name Check, Package Health Check, Recall Check, Citation Checker, Business Days and Holidays, Tariff Code Finder, EU Business Check, Rules Lookup, Site Check, Travel Check, Food Facts, Car Check, Document Tools and Tax Numbers, keep nothing about you. The only thing stored is a count of calls per tool per day.
What a plugin receives
When you use a plugin in ChatGPT, ChatGPT decides to call one of its tools and sends only that tool's arguments. For Company Jobs Finder those are the company names or careers page links you asked about and any filters (keyword, location, remote, department, posting date, posted salary). For Startup Name Check they are the business names or domains you asked about and the domain endings you chose. For Package Health Check they are the public npm or Python package names and versions you asked about, or the text of a package.json you shared. A package.json is read only for the names and versions in its dependency lists; the rest of the file is ignored, and the file and its dependency list are not stored or cached. Package names and versions are sent to the public sources named below, so do not use private package names. For Citation Checker they are the references you asked about, as text: authors, year, title, journal and DOI. Send it bibliographic details only. For Business Days and Holidays they are a country code, an optional region, the dates or the number of days you asked about, an optional weekend, and a year. For Tariff Code Finder they are the description of a product or a tariff code, a country (UK or US) and an optional country of origin. Describe the product only: never include names, addresses or other personal details. For EU Business Check they are a VAT number and its country, a company name or Legal Entity Identifier, a registry country (France or Norway) and, only if you choose to get a consultation number, your own VAT number. Send the names of companies only: never send the name of a private person. For Rules Lookup they are the CFR title and section you ask about, or the words, document type and dates you search for. Do not put personal details or a description of your own legal situation in a search. For Site Check they are the public web address (or bare domain) of a site you ask about. Send public sites only: addresses with a password or token in them are refused, and so are private and local addresses. For Travel Check they are a country name, up to five country names to compare, or an airport code. Travel Check never asks for your name, passport, nationality, travel dates or itinerary. For Food Facts they are a product barcode, the words of a product search with an optional country, and the allergens you want a product checked against. Food Facts never asks for your name or any health details, so do not include them. For Car Check they are a vehicle identification number (VIN) you ask to decode, or a vehicle year, make and model. Car Check never asks for your name, address, licence plate or mileage. A VIN identifies one vehicle, so send it only if you are comfortable with that. For Recall Check they are the vehicle year, make and model, a vehicle identification number (VIN) you ask to decode, or the product or food name you ask about, plus a number of days. Recall Check never asks for your name, address or licence plate. For Tax Numbers they are a tax year, a filing status, a date and, for an estimate, the income amounts you give; round figures are enough, so never send names, tax identification numbers or account details. For Shop Duty Desk they are order lines (a goods description, an optional tariff code, the country of origin, a quantity and a unit value; lines with a customer name, address or any other customer field are refused), the text of a Shopify Inventory or product CSV you shared, product titles, and a tariff code with amounts. For Catalog QA Desk they are the text of a Shopify product CSV you shared, or the address of a store whose public product feed you ask it to read. Send goods data only: a CSV export of products and inventory holds no customer data, and you should not send order exports. The plugin does not receive your ChatGPT conversation, your name, your email address or your OpenAI account details.
Like any website, the server also sees the network address the request comes from. For plugin calls that is usually an OpenAI server rather than your own device.
What it does with it
- Answers the question. The arguments are used to read the matching public job boards on Greenhouse, Lever, Ashby, Workable and SmartRecruiters, and the answer is sent back to ChatGPT.
- Looks up domains. For Startup Name Check, the domain names built from your arguments (for example acme.com) are sent to the public registration lookup (RDAP) service of each domain's registry, found through the IANA directory. Only the domain name is sent. Only registration status and dates come back into the answer; no owner or contact details are kept or returned.
- Looks up recalls. For Recall Check, the vehicle or VIN you ask about is sent to the public NHTSA recall and VIN services, and a product or food name is sent to the public recall services of the CPSC or the FDA. Nothing else from your conversation is sent.
- Looks up packages. For Package Health Check, the package names and versions are sent to OSV.dev, the npm registry, the PyPI JSON API, deps.dev and the npm downloads API, and the public facts that come back (advisories, license, release dates, dependents) go into the answer.
- Looks up references. For Citation Checker, the reference text is used to look the paper up in Crossref, the DOI system (doi.org) and OpenAlex, which are public scholarly indexes, so those services receive the reference text and the network address of our servers, not yours. Only bibliographic details come back into the answer.
- Reads and records public store data. For Store Price Tracker, the store address you name is used to read the store's public product feed (/products.json), after its robots.txt, with a User-Agent that names StorePriceTracker and a contact address. A store you ask about is added to a daily snapshot list, and each day the plugin stores that store's public product data (titles, prices, variants, availability and the changes between days) so that price history can be read back. This is data about products and stores, not about you: the stored record is found by the store's address and holds nothing about who asked. A store owner can ask for a store to be removed through the support page or disallow StorePriceTracker in robots.txt.
- Looks up holidays. For Business Days and Holidays, the country code, region and year are sent to the public Nager.Date public holiday service and, for school holidays, to the public OpenHolidays service. The dates you asked about are used only inside our servers to count days and are not sent to them. Only holiday names and dates come back into the answer.
- Looks up tariffs. For Tariff Code Finder, the product description or tariff code and, when you give one, the country of origin are sent to the public UK Trade Tariff service or the public US Harmonized Tariff Schedule search service. Only the schedule's codes, descriptions and duty rates come back into the answer.
- Looks up businesses. For EU Business Check, the VAT number (and your own VAT number, if you ask for a consultation number) is sent to the European Commission's VIES service, a company name or LEI to the GLEIF Global LEI Index, and a company name or registration number to the French company search (api.gouv.fr) or the Norwegian Brønnøysund Register Centre. Only public register data about legal entities comes back into the answer; names that could belong to a private person, and sole proprietors, are left out.
- Looks up regulations. For Rules Lookup, the title and section or the search words are sent to the Electronic Code of Federal Regulations (ecfr.gov) or the Federal Register (federalregister.gov), both run by the Office of the Federal Register. Only public regulatory text and notices come back.
- Looks at a public site. For Site Check, our server requests the address you gave, the robots.txt of that site and any redirect it points to, and reads only the response headers and the head of the page. Nothing is sent from you or your conversation to that site; the site sees an ordinary request from the Site Check user agent, which names this service and a support page.
- Looks up travel advice. For Travel Check, the country you ask about is matched against the public UK travel advice index on GOV.UK and the US State Department advisory list, and the UK advice page for that country is read from GOV.UK. An airport code you ask about is sent to the FAA airport status service (US airports) and the NOAA Aviation Weather Center. Nothing else from your conversation is sent.
- Looks up food. For Food Facts, the barcode or search words you ask about, and the country if you give one, are sent to the public Open Food Facts service (world.openfoodfacts.org and search.openfoodfacts.org) with a user agent that names this service. The allergens you want to avoid are not sent: they are compared with the product entry here. Nothing else from your conversation is sent.
- Looks up vehicles. For Car Check, the VIN or the year, make and model you ask about are sent to the public NHTSA services (vpic.nhtsa.dot.gov and api.nhtsa.gov) and, for fuel economy, to the US EPA's fueleconomy.gov, with a user agent that names this service. Only counts and component names from NHTSA's complaint records come back into the answer: no complaint text and no VIN fragments. Nothing else from your conversation is sent.
- Counts text and makes files. For Document Tools, the text you ask it to count is used only to work out the counts and is never stored. A calendar or CSV file you ask it to make is written to our storage under a random 128-bit name, and the link only works for 24 hours. The files are not listed anywhere, so only someone with the link can open one. After 24 hours the link stops working and the file is deleted: a cleanup deletes expired files every 30 minutes, and a storage rule removes anything left after two days. The file contents are also returned to you in the answer, so you do not need the link. Do not put personal or sensitive information in a file you ask it to make.
- Looks up tax figures. For Tax Numbers, the figures come from a table of US federal tax data built into the service, each row naming the IRS document it was read from, so nothing from your request is sent to any other service. The income amounts you give for an estimate are used only for that calculation and are never stored or cached.
- Checks customs data. For Shop Duty Desk, a CSV you share is read in memory by a Worker object that keeps no state, and only counts and the rows with problems come back. The EUR 3 duty and the VAT table are calculated inside the service. Product titles and tariff codes are sent to the public UK Trade Tariff and US Harmonized Tariff Schedule services to find candidate codes and duty rates. Nothing from the order lines or the CSV is stored.
- Checks product catalogs. For Catalog QA Desk, a CSV you share is read in memory by a Worker object that keeps no state, and only counts and the rows with problems come back. If you give a store address instead, the plugin reads that store's public product feed (/products.json) once, after its robots.txt, with a User-Agent that names CatalogQADesk and a contact address, up to five pages of 250 products. The feed is analysed and dropped: it is not stored, not cached and not added to any index of stores, and the answer is not found by who asked. A store owner can disallow CatalogQADesk in robots.txt. Catalog QA Desk reads product data only, never customer or order data, and never changes a store.
- Caches the answer. The same question asked again within about two hours is answered from a cache instead of asking the job boards again (for Startup Name Check, within about five minutes; for Package Health Check, about an hour, for a single package only, never for a package.json; for Recall Check, 24 hours; for Citation Checker, six hours; for Business Days and Holidays, 24 hours; for Tariff Code Finder, six hours; for EU Business Check, an hour, except a VAT check that asks for a consultation number, which is never cached; for Rules Lookup, six hours for a section and an hour for a search; for Site Check, five minutes; for Travel Check, about three hours, and five minutes for an airport, with the two country lists kept for up to a day; for Food Facts, about twelve hours for a product and six hours for a search; for Car Check, 24 hours). A cached entry holds the public job listings, domain status, package facts, recall records, bibliographic records, holiday calendars, tariff schedule entries, company register records or regulation text, a site's published robots.txt rules and tags, travel advisories, airport conditions, food product entries, vehicle recalls, ratings, complaint counts or fuel economy figures and is found by a hash of the tool arguments; it holds nothing about who asked. Entries expire on their own.
- Limits abuse. The network address is used, in memory and for about a minute, to limit how many calls one network can make. It is not written to any database or log we keep.
- Counts calls. Each call adds one to a counter for that plugin, tool and UTC day, plus one to an error counter when the call failed. Apart from the public store data and the 24-hour download files above, these aggregate counts are the only thing stored. They contain no prompts, arguments, answers, addresses or identifiers.
What it never does
- It stores no prompts, tool arguments, answers or conversation content beyond the short-lived cache and the 24-hour download files above.
- It has no accounts, sign-ups, cookies, analytics or advertising trackers, and it sells or shares nothing.
- It never asks for, and you should never send it, personal or sensitive information. Questions about public job openings, domain names, public packages, the references in a paper, public holidays, tariff codes or company registers need none, and a package.json check needs only the dependency names and versions: never send source code, tokens or passwords. Tax Numbers needs no name, tax identification number or account detail, only a year, a filing status and amounts.
Service providers
The plugins run on Cloudflare Workers. Cloudflare processes requests on our behalf to deliver them and protect them from attacks, under its own privacy policy. The job boards that are read are public pages of the companies you ask about; the plugin sends them only the request for those public listings. Domain registries receive only the domain name being checked, and the package sources receive only the package names and versions being checked. Crossref, doi.org and OpenAlex receive the reference text you ask Citation Checker about, and operate under their own terms and privacy policies. The stores you ask Store Price Tracker about receive an ordinary request for their public product feed from our servers, not from your device. Nager.Date and OpenHolidays receive only the country code, region and year of the holiday calendar being read. The UK Trade Tariff and the US International Trade Commission receive only the product description or tariff code being looked up. The European Commission (VIES), GLEIF, the French government company search and the Brønnøysund Register Centre receive only the VAT number, company name, LEI or registration number being checked, and for a consultation number the requester's VAT number, under their own terms and privacy policies. The UK Trade Tariff and the US International Trade Commission receive the product titles and tariff codes you ask Shop Duty Desk about. A store you give Catalog QA Desk receives an ordinary request for its public product feed from our servers, not from your device.
API customers
The API at api.openkrill.app works without a key. A call without a key adds to a shared monthly count of billable results, and to a daily count for a coarse bucket of the network address it came from: a short one-way hash of the address and the day, shared by many addresses, that changes every day and is deleted after three days. It is used only to cap how many calls one network can make a day, and the address itself is not stored. With a key, the API stores a hash of the key (never the key itself) and a monthly count of billable results per key. Request contents are handled as described above.
Connecting an agent (OAuth)
An AI agent or MCP client can connect at connect.openkrill.app and receive an access token. There is no account, email address, password or sign-in, and no person is asked anything. To connect, the client registers itself, so we store what it states about itself: its client name and its redirect addresses, which an agent client chooses and which may include a company or product name. Connecting also stores a record of the grant and the issued tokens. Access tokens, authorization codes and client secrets are kept only as hashes, the data attached to a grant is encrypted with a key only the token holder can unwrap, and a grant holds nothing but the client's identifier. We do not store prompts, tool arguments or answers for connected clients, and calls with a token are metered and rate limited under a number derived from the client's identifier, not under a name. A client that has not been used for 90 days is deleted, access tokens last one hour and refresh tokens at most 90 days, and a client can revoke its tokens at any time. The network address of a registration or sign-in attempt is used in memory, for about a minute, to limit repeated attempts, and is not stored. A short event line (the client name at registration, the granted scope, and any error code) is written to our operational logs; it contains no token, argument or address.
Questions and changes
Questions about this policy go through the support page. If what is processed or stored ever changes, this page changes first and its date above is updated.