Privacy and measurement choices
For how login tokens are stored and used, and how to revoke access, read account connection security. Storage encryption is server-side, not end-to-end encryption.
First-party business statistics
We count signed-out homepage visits and clicks on sign-in and demo controls on our own server. A secure 24-hour cookie groups repeated visits into one observed landing session. We store a keyed hash of its random identifier, the event type and time for up to 90 days. We do not store full URLs, referrers, IP addresses, email addresses or connected-account details in these traffic events, and do not link them to your identity. Do Not Track and Global Privacy Control disable this collection. Browser restrictions and automated traffic can affect these counts.
The owner-only business dashboard shows registration email, registration and last sign-in times, plan entitlement, linked-account count and supported campaign attribution. Checkout and verified payment records are stored privately for business reporting. Provider credentials and usage contents are never displayed there. These first-party records are separate from optional advertising measurement.
Separately from optional advertising measurement, supported Google and ChatGPT campaign links use a secure, signed 24-hour first-party cookie. For a new registration within that period, we store the campaign name and visit and signup times in private account metadata with our sign-in provider, Clerk. This first-party record is not sent to Google or OpenAI. It respects Do Not Track and Global Privacy Control and does not record ad click IDs, arbitrary URL values or returning users as new signups.
Advertising measurement is optional and off until you allow it. Declining does not change access, pricing, or your connected accounts. Use Ad privacy settings to change your choice. We honor Do Not Track and Global Privacy Control.
With permission, OpenAI receives visits to our public homepage, completed registrations, checkout starts, and confirmed purchases, including the purchase amount and currency. The browser measurement SDK can receive your page URL, browser/network information and use its first-party browser identifier. We send an ad click reference when available to attribute a conversion. These events are marked to opt out of future user-level personalization.
We do not send names, email addresses, phone numbers, connected-account credentials, usage readings or AI conversations with these events. We do not use automatic form matching. The browser SDK is not loaded on signed-in account screens; purchases are measured server-side after payment verification.
A secure first-party cookie identifies your browser for privacy settings for up to 30 days. The choice and optional click reference are stored privately in our database and associated with your account when you sign in. Permission expires after 30 days; expired permissions are not used for measurement, although the stored record may remain. Withdrawal stops future measurement once saved; events already delivered cannot be recalled by this setting. If saving fails, the settings panel shows a retry message.
After consent, the OpenAI browser SDK may set __oppref for 30 days and __obref for 365 days. These cookie lifetimes are separate from conversion attribution windows and OpenAI’s retention of events. Revoking consent tells the SDK to remove these cookies.
See OpenAI’s privacy policy for how OpenAI handles measurement information.