1. Scope
This Privacy Policy explains how Anh Bui Developer ("we", "us") handles information when you use the ChatGPT Export Chrome extension, backend web pages, checkout, Pro restore, license validation, admin-supported license tools, and support contact flows.
Where UK or EU data-protection law applies, we process purchase, license, restore, and support information to perform a contract or take steps you request; optional measurement only with consent; and security, fraud prevention, and service reliability for our legitimate interests. We do not use special-category data as part of the service.
2. Conversation Content
Conversation export processing is designed to happen in the browser extension. The extension accesses ChatGPT page content only to provide the export action you request. The backend does not need your exported conversation content to create files, validate licenses, process checkout, or restore Pro access.
We do not sell, use for targeted advertising, or transfer conversation content for unrelated purposes. We do not allow people to read it unless you deliberately send relevant content to support or disclosure is required for security or law. You control the files you export, store, share, or delete from your own device.
3. Information We Collect
Depending on the feature used, the backend may store or process purchase email, plan ID, license state, Stripe customer or subscription identifiers, device identifiers, activation timestamps, subscription cancellation state, admin session data, restore tokens, support messages, optional uninstall feedback, and optional analytics events.
- Checkout requires an email address to create or restore a license.
- Pro activation uses device identifiers to enforce the 3-device limit.
- Admin tools may record license changes needed for support and fraud prevention.
4. Payments
Stripe processes payment details. ChatGPT Export stores Stripe identifiers, plan status, billing mode, subscription period information, and checkout metadata needed to provide Pro access. We do not store card numbers.
5. Email And Restore Messages
Restore links, login messages, and support-related messages may be sent through Microsoft Graph or SMTP when configured by the site operator. These messages use your email address and may include temporary restore or admin login links.
6. Analytics, Cookies, And Logs
Product measurement is off by default. Schema v2 requires fresh consent in Settings and uses a random resettable installation token, stored as a keyed hash by the server, to group repeat use on one installation. Fixed categories describe actions, format, scope, browser and version. It excludes conversation content, titles, raw URLs, full user agents, device fingerprints, license keys and emails. It does not match identities across devices or join product cohorts to billing identities. Turning it off stops collection and requests deletion; save again while online if deletion is pending.
Separately, the backend keeps daily operational counters for trusted service actions such as purchase intents, checkout sessions, verified payments and automatic activations. These counters are grouped by UTC day, plan and live/test payment mode; they do not store or receive a user, device, browser, IP address, URL, email, token or conversation content, and are retained for up to 365 days. They help operate checkout and licensing without behavioural tracking.
The website uses essential session cookies only for protected admin access. Hosting, email, Stripe, or storage providers may create security and delivery logs.
7. How We Use Information
Information is used to provide Pro access, validate licenses, restore purchases, manage trusted devices, process subscription cancellation, support users, prevent abuse, debug failures, improve reliability, and operate admin tools.
8. Sharing
Information may be shared only with service providers that operate the product: Stripe for payments; Microsoft Graph or the configured SMTP provider for messages; Vercel or another configured hosting provider for the backend; and Upstash Redis or another configured storage provider for license and session data. These providers process information to provide their services. We do not sell conversation content or license data.
These providers may process data outside your country. Where applicable law requires safeguards for an international transfer, we rely on the provider's applicable transfer mechanism or another lawful safeguard.
9. Retention
Local export history is capped by plan. PDF preview jobs expire after 24 hours, with at most ten retained for retry; cleanup runs when the extension is active. Pending upgrade exports use session storage and expire after 30 minutes. Settings can clear local export settings, recent history, and the saved Notion connection without removing a license or resetting the monthly allowance. Schema v2 measurement uses a 90-day window and a 50,000-event cap per environment; expired data is excluded and purged at the next measurement access or store expiry. Deletion markers prevent retry resurrection for 90 days. Operational counters retain up to 365 days. Legacy analytics remain excluded from the new dashboard. Legacy analytics retain up to 200 historical events, support messages up to 1,000 records, uninstall feedback up to 500 records, and Stripe event receipts up to 1,000 records. License and payment records remain while needed to provide Pro access, support purchases, enforce device limits, handle disputes, prevent abuse, meet legal requirements, and maintain backups.
10. Security
ChatGPT Export uses technical controls such as hashed or temporary tokens, trusted-device checks, payment-provider checkout, and admin sessions. No system is perfectly secure, so you should avoid exporting or sharing sensitive content unless you are comfortable managing that file yourself.
11. Your Choices
You can use Free features without checkout, clear local export settings/history/Notion connection, disable optional analytics, cancel subscriptions through supported flows, request license support, revoke old devices when supported, and delete exported files from your own device. For privacy questions or data requests, contact support from the email used for purchase when possible.
Depending on where you live and applicable law, you may have rights to request access, correction, deletion, restriction, portability, or to object to certain processing. You may withdraw analytics consent at any time. You may also have a right to complain to your local data-protection authority. We may need to verify your identity and may retain limited information where required to complete a transaction, prevent fraud, resolve a dispute, or comply with law.
12. Changes And Contact
This Privacy Policy may be updated when product behavior, providers, checkout, restore, admin tooling, or legal requirements change. The effective date above identifies the current version. For a material change, we will take reasonable steps to provide notice before it takes effect when required by applicable law.
Questions: support@anhbui.dev