Privacy Policy
Last updated: August 20, 2026
Notice of changes: We review this policy whenever our data-handling practices, features, or legal obligations change. The date above reflects the most recent revision. For material changes (such as new data categories, new third-party processors, or changes to your rights), we will make reasonable efforts to notify you through the extension or by email at least 14 days in advance.
At AI Toolbox (formerly ChatGPT Toolbox) ("we", "us", "our"), operated by Infi Developments, we are committed to protecting your privacy. This Privacy Policy comprehensively explains what data we collect, how we collect it, how we handle, store, and share it, and your rights, in plain language.
Looking for the Gemini or Claude module? AI Toolbox now bundles ChatGPT, Gemini, Claude, and Grok in one browser install. Module-specific privacy details are available for the Gemini module and the Claude module.
1. Data Controller
Infi Developments is the data controller responsible for your personal data. For any privacy-related inquiries, contact us at [email protected].
2. What Data We Collect
We collect only the minimum data needed to provide our service. Below is a complete list of every category of data we handle:
2.1 Account information
To authenticate you with the extension and verify your subscription, we collect your email address. Your email is derived from your existing ChatGPT session token (see Section 3 for details) and is used solely for authentication and subscription verification. We do not collect your name, password, physical address, or any other personal identifiers.
Email matching: To recognize your subscription, the email you use at checkout must match the email on your ChatGPT account. If they differ, contact us at [email protected] and we will reconcile your entitlement.
2.2 Data stored locally in your browser (never sent to our servers)
The following data is stored entirely on your device and is never transmitted to our servers:
- Your ChatGPT conversation content and message text
- Extension settings and preferences
- Local search history and recent searches within the extension
- Conversation cache (stored in your browser's IndexedDB for faster search)
- Smart tag computation results (tag matching is performed entirely in your browser, so conversation content is never sent to our servers for tagging)
Your session token: transmitted for authentication, never stored
An earlier version of this policy listed your ChatGPT session token among the data never transmitted to us. That was inaccurate, and we have corrected it rather than leave it standing. The accurate description is below.
Your session token is stored on your device. It is also sent to our server, over HTTPS, as the authorization header on each request, because it is how the extension authenticates: our server verifies the token's cryptographic signature against OpenAI's public signing keys and reads a single field from it, your email address, which is what your folders and prompts are keyed to. The token itself is never written to a database, never written to a log, and is discarded when the request ends. We hold no copy of it, which is also why there is no token on our side for us to revoke if you ask us to.
We never receive, request, or have any mechanism to accept your ChatGPT password, your Apple ID password, a two-factor or one-time code, or any other credential.
2.3 Data stored on our servers (encrypted at rest)
The following data is transmitted over HTTPS and stored in encrypted form on our servers, so that it is available to you on every device and browser where you sign in. This includes the content of the prompts you save, not only their names.
What our encryption does and does not mean. This data is encrypted at rest with keys held by our infrastructure. That protects it if our database is ever copied or accessed without authorization. It is not end-to-end or zero-knowledge encryption: our servers hold the key and decrypt this data in order to serve it back to your extension, so it is technically readable by our systems. We do not read it, and we never sell it, share it, or use it for anything other than providing the feature it belongs to. We state this plainly rather than claiming an encryption model we do not implement.
Your Prompt Library can be kept entirely on your device. Under Settings, Prompts, you can switch your saved prompts and prompt chains to device-only storage, which keeps them on your own machine and makes syncing across devices something you turn on rather than a condition of using the library. Folders, labels, and tags are still stored on our servers today; if you would prefer those to stay on your device as well, tell us at [email protected]. You can also delete any folder, prompt, or chain at any time, which removes it from our servers.
- Folder names, folder structure, and folder color preferences
- Saved prompts and prompt chain definitions
- Conversation IDs (for pinned chats and folder assignments)
- Message IDs (for bookmarked messages)
- Message labels (label text, color, and associated conversation/message IDs)
- Smart tag rules (custom tag names, matching patterns, and colors, not conversation content)
- Usage tracker data: message counts, input/output character counts, ChatGPT model used, session counts, session durations, and hourly activity patterns. This data is synced automatically every 30 minutes
- Achievement data: your daily streak length, the dates you were active, which milestone badges you have unlocked, and your streak freeze balance. This is synced so that your streak and badges follow you across your devices
2.4 Conversation content processed temporarily (not stored)
Three features send the content of a conversation to our servers. Each one runs only when you explicitly trigger it, never in the background, and only for the single conversation you selected. In every case the data is processed in real time and immediately discarded: it is never written to a database, a file, or a log, and it is never used for any other purpose.
- Context Mentions (@@): if the conversation you mention is long (roughly 15,000 characters or more), its messages and title are sent to our server to be summarized. Shorter conversations are inserted into your prompt box entirely on your device and are never sent to us.
- Carry this chat forward (context handoff): the messages and title of the chat you choose are sent to our server to be summarized, so the summary can start your next chat.
- PDF export: the conversation is sent to our server, which renders the PDF and returns the file. Exports to TXT, Markdown, and JSON are generated entirely on your device and are never sent to us.
Summaries are generated using the OpenAI API. For the two summarization features above, our server passes the conversation text to OpenAI's API to produce the summary and returns it to your browser. This applies on every platform, so if you use these features on Claude, Gemini, or Grok, that conversation is processed by OpenAI for that request. Under OpenAI's API terms, data submitted through the API is not used to train their models. If you would rather this never happen, do not use these two features; every other part of the extension continues to work, because nothing else sends conversation content to us.
2.5 Payment data
All current plans (Premium Monthly, Premium Annual, and Premium Lifetime across the ChatGPT, Gemini, Claude, and Grok modules, the All Access Lifetime plan, and Teams plans) are processed by Polar. Some legacy subscriptions are still billed through LemonSqueezy. We do not store your credit card details. To process your transaction, your email address and payment information are shared with the relevant processor (Polar or LemonSqueezy), who then provides us with your email address and payment status so we can verify your subscription. The privacy policy of the relevant processor governs how they handle your payment information.
2.6 Install and uninstall information
When you install the extension, a welcome page is opened in your browser. When you uninstall the extension, a feedback page may be opened that includes an authentication token so we can process any associated account deletion requests. No additional data is collected during install or uninstall beyond what is described in this policy.
2.7 Analytics
We use Google Analytics for our website and Chrome Web Store listing. No third-party analytics run inside the extension: it never contacts Google Analytics or any other analytics provider.
The extension does report anonymous feature counters to our own server, so we can see which features are used and which are not. The entire content of that request is the name of a feature, for example "bulk_export". It carries no account identifier, no email address, and no authentication, and it increments a single global total. There is no per-user analytics profile, because we do not build one.
2.8 Cookies
We do not use cookies on our website or within the extension.
2.9 Your status handle and the leaderboard
Your extension gives you a randomly generated handle (for example, "SwiftFalcon42") as your status name. It is generated for you - you cannot type your own, so it never contains your name, your email address, or any other personal detail. By default it is shown only to you, and you can replace it with another random handle at any time.
The leaderboard is optional and off by default. If you turn it on in the extension's Settings, your handle and your streak length become visible to other AI Toolbox users. If you never turn it on, you never appear to anyone else.
Your handle and streak length are the only data we store unencrypted, because a leaderboard has to be able to sort by them. Your underlying achievement data stays encrypted as described in 2.3. Your name, email address, conversations, subscription, and every other piece of your data are never on the leaderboard.
Turning the leaderboard off removes you from it and deletes your leaderboard entry. Your handle stays as your private status name, and you can rejoin at any time.
2.10 Approximate location (country)
We store an approximate location as a two-letter country code (for example, "US" or "IN"). It is derived on our server from the IP address of your extension's requests using an offline database; your IP address is not stored and is never sent to any third party for this purpose. We use this country code only to offer region-appropriate discounts by email (sent only to users who have consented to marketing email) and for aggregate regional reporting. Our lawful basis for deriving and storing the country code is our legitimate interest in offering fair, region-appropriate pricing. You can ask us to delete it at any time by contacting us at [email protected].
3. How We Collect Your Data
We collect data through the following methods:
- Session authentication: The extension reads the authorization header from your existing ChatGPT browser session (via the browser's webRequest API) to authenticate you. This is how we derive your email address and enable the extension to interact with ChatGPT on your behalf. We do not intercept, read, or store the content of your ChatGPT messages through this mechanism.
- Activity detection: The extension monitors ChatGPT network requests (via the browser's webRequest API) to detect when you send a new message. This is used solely to trigger local usage tracking (counting messages and sessions). The extension does not read or store the content of these requests.
- Your actions in the extension: When you create folders, save prompts, bookmark messages, apply labels, or configure smart tag rules, these are stored on our servers as described in 2.3 so they reach your other devices.
- Automatic usage tracking: The extension locally records usage metrics (message counts, session times, model used) as you use ChatGPT, and sends them to our servers every 30 minutes.
4. How We Use Your Data
We use the data we collect for the following purposes only:
- Provide our service: Enable folder sync, prompt access, bookmarks, labels, smart tags, pinned chats, context mentions, and usage analytics across your devices.
- Authenticate your account: Verify your identity using your email address to provide personalized access to your synced data.
- Verify subscriptions: Check your payment status via Polar (for all current plans) or LemonSqueezy (for legacy subscriptions) to unlock Premium features.
- Generate conversation summaries and PDFs: When you use Context Mentions (@@) on a long chat, or Carry this chat forward, we process that conversation temporarily to generate a summary (using the OpenAI API) and then immediately discard it. PDF export is rendered on our servers the same way. See 2.4.
- Respond to support requests: If you contact us, we use your email to respond.
- Improve the extension: Aggregated, non-personal usage patterns help us understand which features are most valuable so we can improve the experience.
- Send marketing emails (only with your explicit consent): If, and only if, you tick the opt-in box on our website, we use your email address to send you our newsletter, product updates, tips, and subscriber-only offers.
Marketing emails (opt-in only)
We send marketing emails only to people who have given explicit, informed consent by actively ticking an opt-in checkbox on our website. The box is never pre-ticked. We do not add you to our marketing list from a purchase, an account sign-up, or installing the extension. Email addresses collected for billing or authentication are used for those purposes only, never for marketing, unless you separately opt in.
- Lawful basis: Consent (GDPR Article 6(1)(a)). We record the date, the placement where you opted in, and the exact wording of the consent you agreed to, so we can demonstrate your consent on request.
- How to withdraw: Every marketing email includes a one-click unsubscribe link. You can also email us at [email protected] to be removed. Withdrawing consent does not affect transactional emails such as receipts, renewal notices, and security alerts, which we may always send.
- Email delivery provider: When you opt in, we deliver these emails through a third-party email service provider that processes your email address on our behalf solely to send the messages. See section 6.
- Retention: We keep your address on the marketing list until you unsubscribe or ask us to delete it, after which we remove it promptly (we may retain a minimal suppression record so we do not email you again by mistake).
5. How We Store Your Data
Local storage (your browser)
The majority of extension data, including your conversation content, search history, settings, and session tokens, is stored locally on your device using your browser's built-in storage APIs (chrome.storage.local) and IndexedDB. Your conversations never leave your browser except in the three cases described in 2.4, each of which you trigger yourself.
Server storage (our infrastructure)
The data listed in 2.3 (folders, prompt names and content, bookmarks, labels, smart tag rules, pinned chat IDs, and usage metrics) is stored on our servers hosted with DigitalOcean in Frankfurt, Germany. Our database runs on that same server rather than on a separate managed service, so this data is processed and stored in Germany. It is encrypted at rest with keys held by our infrastructure, and decrypted server side when your extension requests it. As stated in 2.3, this protects your data against unauthorized access to our database but is not zero-knowledge encryption. Data in transit is protected with HTTPS/TLS encryption.
Temporary processing
Conversation data sent for summarization (Context Mentions, Carry this chat forward) or PDF rendering is processed in server memory only and is never written to disk, databases, or logs. It is discarded immediately after the summary or PDF is generated.
6. Data Sharing and Third Parties
We do not sell, rent, or trade your personal data. We share data only with the following parties, and only as described:
- Our backend servers (api.infi-dev.com): Your email address (for authentication), the data listed in 2.3 (folders, prompt names and content, bookmarks, labels, smart tag rules, pinned chat IDs, usage metrics), stored encrypted at rest as described in 2.3, and the temporarily processed conversation content described in 2.4 (summaries and PDF rendering), which is discarded immediately.
- Polar (payment processor for all current plans): Payment processing and subscription management for Premium Monthly, Premium Annual, Premium Lifetime, All Access Lifetime, and Teams plans across the ChatGPT, Gemini, Claude, and Grok modules. They receive your email and payment details directly. We only receive your email and payment status from them.
- LemonSqueezy (payment processor for legacy subscriptions): Payment processing and subscription management for legacy subscriptions purchased before our migration to Polar. They receive your email and payment details directly. We only receive your email and payment status from them.
- Email service provider (only if you opt in to marketing emails): If you tick the marketing opt-in box, we use a third-party email service provider to deliver our newsletter and product emails. They process your email address on our behalf, solely to send these messages, and every email includes an unsubscribe link. We do not share the addresses of people who have not opted in.
- OpenAI / ChatGPT (chatgpt.com): The extension communicates with ChatGPT's existing APIs using your active browser session to provide its features (e.g., fetching conversations for search, exporting chats). This is the same data ChatGPT already has access to.
- OpenAI API (summarization sub-processor): When you use Context Mentions on a long chat or Carry this chat forward, our server sends that conversation's text to OpenAI's API to generate the summary, and returns the result to you. This happens on every platform we support, so a chat from Claude, Gemini, or Grok is processed by OpenAI when you use one of these two features on it. Under OpenAI's API terms, data submitted through the API is not used to train their models. No other feature sends your conversations to OpenAI.
- Google Analytics: Anonymous, aggregated usage data for our website and Chrome Web Store listing. The extension itself never contacts Google Analytics. See 2.7 for the anonymous feature counters the extension reports to our own server.
- DigitalOcean (hosting sub-processor): Our servers and database run on DigitalOcean infrastructure in Frankfurt, Germany. DigitalOcean hosts the data described in 2.3 on our behalf and does not access it.
- Resend (email sub-processor): Receives your email address in order to deliver purchase receipts and, only if you explicitly opted in on our website, marketing email. Resend never receives conversation content.
- Other AI Toolbox users (only if you turn on the leaderboard): The leaderboard is off by default. If you turn it on in Settings, your randomly generated handle and your streak length become visible to other AI Toolbox users. Nothing is shared until you turn it on, your name and email address are never shown, and turning it off removes you and deletes your entry. See 2.9.
- Legal obligations: We may disclose data if required by law or in response to a valid legal request from a government authority.
We do not share your data with any other third parties, advertisers, data brokers, or AI model training services.
7. Legal Basis for Processing (GDPR)
We process your data based on the following legal grounds under GDPR Article 6:
- Contract performance: Processing necessary to provide the services you signed up for (e.g., syncing folders across devices, authenticating your account, verifying your subscription).
- Legitimate interest: Processing necessary for the operation and improvement of our services (e.g., aggregated usage analytics to improve features), provided it does not override your rights.
- Consent: Where applicable, we process data based on your explicit consent (e.g., using Context Mentions or Carry this chat forward, appearing on the leaderboard, or opting in to marketing emails). You may withdraw consent at any time by disabling the relevant feature, unsubscribing from marketing emails, or contacting us. Appearing on the leaderboard is always off until you turn it on, and turning it off deletes your leaderboard entry.
8. Data Security
We take the security of your data seriously and implement multiple layers of protection:
- Encryption at rest: All data stored on our servers is encrypted at rest, including your folders, prompts, bookmarks, labels, usage data, and achievement and streak data. As explained in 2.3, the keys are held by our infrastructure, so this is protection against unauthorized access to our database rather than zero-knowledge encryption. The only data stored unencrypted is the leaderboard handle and streak number described in 2.9, which have to be readable so the leaderboard can be sorted. Your handle is shown only to you until you turn the leaderboard on.
- Encryption in transit: All communication between the extension and our servers uses HTTPS/TLS encryption.
- Minimal data collection: We follow the principle of data minimization. We only collect what is necessary to provide our service.
- Local-first architecture: The majority of your data (including all conversation content) never leaves your browser, reducing exposure risk.
- Secure infrastructure: Our servers are hosted with DigitalOcean in Frankfurt, Germany, with regular security updates.
- No plaintext logging: We do not log synced data content on our servers.
9. Your Rights
Under GDPR and applicable data protection laws, you have the following rights. To exercise any of these rights, contact us at [email protected]:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate data.
- Right to erasure: Request deletion of your personal data from our servers.
- Right to data portability: Request your data in a structured, machine-readable format.
- Right to restrict processing: Request that we limit how we use your data.
- Right to object: Object to processing based on legitimate interest.
- Right to withdraw consent: You can stop using the features described in 2.4 at any time, delete any folder, prompt, or chain (which removes it from our servers), request deletion of all your server-side data by contacting us, and unsubscribe from marketing emails using the link in any email.
- Right to lodge a complaint: You have the right to file a complaint with your local data protection authority.
We will respond to all data rights requests within 30 days.
10. Data Retention
We retain the data listed in 2.3 (folders, prompt names and content, conversation IDs, message IDs, labels, smart tag rules, usage statistics) for as long as your account is active.
- Local data: Usage events older than 7 days are automatically pruned from your browser. Daily summaries are retained locally for up to 365 days.
- Server data: Synced data is retained until you request deletion or your account is removed.
- Temporary data: The conversation content described in 2.4 (summaries and PDF rendering) is discarded immediately after processing. It is never retained.
If you wish to have your server-side data deleted, contact us at [email protected] and we will remove all associated data from our servers within 30 days.
Uninstalling the extension removes all locally stored data from your browser immediately. Server-side data requires a separate deletion request.
11. International Data Transfers
Our services are available worldwide, and our servers are located in Frankfurt, Germany, so the data described in 2.3 is stored and processed inside the European Economic Area regardless of where you live. Some of our sub-processors listed in Section 6 (for example OpenAI and Google) operate outside the EEA, so using the features that involve them means data reaching those countries. Where data is transferred outside the EEA we rely on the appropriate safeguards required by GDPR.
12. Children's Privacy
Our free extension does not have age restrictions. However, purchasing a paid plan requires a valid payment method (credit card or Apple Pay), which is limited to individuals of legal age in their jurisdiction. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us at [email protected] and we will promptly delete it.
13. Teams Data Handling
For Teams plans, the organization admin can view aggregated usage statistics (e.g., total messages, sessions, active members). Individual conversation content is never accessible to admins or our servers. Each team member's data remains encrypted and private, consistent with the same privacy protections applied to all AI Toolbox users on the ChatGPT module.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. For significant changes, we will make reasonable efforts to notify you via the extension or email.
15. Contact Us
If you have any questions about this Privacy Policy, your data, or your rights, contact us at: [email protected]