Privacy · Effective 9 August 2026

Queries, not conversations.

This policy describes the first public Open Queries release. The product is intentionally engineered around a small data contract.

What can be stored locally

The extension stores observed queries, platform, source kind, capture time, language, adapter version and generated estimates. Local history is automatically limited to 30 days and 2,000 events and can be deleted at any time.

What happens when privacy is accepted

Privacy starts unaccepted. After it is accepted during onboarding or later in Settings, every observed query is automatically sent with a random pseudonymous installation tag, whether or not its fan-outs are requested. For Google Search, the typed search query is included as the clearly disclosed exception. Until privacy is accepted, the Current and History views show no query data. Privacy acceptance can be switched off and server-side query data can be deleted at any time.

What is never part of the contract

  • Chat messages or prompts on ChatGPT and Claude.
  • Conversation titles, chat URLs or conversation identifiers.
  • Account names, email addresses or provider cookies.
  • Browser history outside supported pages.
  • Estimated fan-outs represented as observed demand.

How provider pages are read

Open Queries extracts only explicit search-tool fields. ChatGPT and Claude expose supported queries in structured provider transport metadata; Google exposes the Search seed and, when present, explicit AI Overview query expansions. Ordinary message fields are ignored and never enter extension storage or an Open Queries request.

Processing and retention

While privacy is accepted, every observed search query is sent to Open Queries. A requested fan-out generation sends the selected query to the corresponding model provider for provider-native estimation. Open Queries never sends one provider's candidates to a universal GPT ranker.

Raw query events expire after 13 months. Cloudflare provides hosting and D1 storage; OpenAI, Anthropic and Google process fan-out requests for their respective roles.

Your controls

Settings provides separate controls to clear local history, stop future transfer and delete server-side events linked to the current installation. Server deletion rotates the installation's pseudonymous identifier. Estimated fan-outs are not stored as observed queries.

Contact and changes

Open Queries Contributors operates this first public release. Privacy questions and deletion failures can be sent to privacy@openqueries.org. Material policy changes will receive a new effective date and a release note.