ChatMila Privacy Policy
Effective date: September 25, 2026
Applies to: ChatMila
Purpose and scope
ChatMila is an independent browser extension for exporting selected ChatGPT
conversations and available attachments to a folder chosen by the user. It is
not an OpenAI product and is not affiliated with or endorsed by OpenAI. This
policy describes the extension itself. ChatGPT, the browser and any file or
cloud-storage services you use have their own privacy practices.
Information the extension accesses
When you open the side panel, the extension checks the active tab and loads
your available ChatGPT conversation list using your existing signed-in session.
It may refresh that list when the active tab changes while the panel is open,
or when you use the list controls. List information includes titles, identifiers,
timestamps, archive status and project/Work grouping information.
For chats selected for export, the extension reads conversation history and
file metadata, and downloads available attachments if Files is enabled. Backend
responses may contain message roles and metadata beyond the user/assistant
text included in the exported transcript. Strong file references in those
responses may be inspected to locate attachments.
The extension reads the current ChatGPT session, including an access token and
available account/profile fields. It uses the token to authenticate requests
to ChatGPT, account/project identifiers for the relevant backend context, and
your available display name or email prefix to name the export folder. It does
not ask you to enter your ChatGPT password into the extension.
The extension reads the active tab's URL and title to identify ChatGPT. The
current package declares the tabs permission, which technically permits access
to those properties on other tabs too; the implementation queries the active
tab and does not build or retain a browsing-history database.
How information is used
Data is used to display the conversation list, apply your selections, retrieve
selected content, create TXT and optional DOCX exports, download and associate
files, generate integrity/error reports, and remember the export folder when
that option is enabled. It is not used for advertising, profiling, model
training, credit decisions or sale to data brokers.
Network requests and recipients
The extension communicates with ChatGPT and follows file-download addresses
provided by its responses to retrieve available attachments. These requests
may reach the file-hosting services used to serve those attachments. Such
services receive the network information needed to handle the request, such as
your IP address and the requested URL, which may include a temporary access
signature. ChatGPT requests use the current authenticated session. The code
does not attach the ChatGPT Authorization header or browser credentials to
cross-origin file-download requests.
The extension contains no developer-operated collection endpoint, analytics
service, advertising SDK or automatic crash-report uploader. It does not send
exported conversations or attachments to the developer. It does not execute
remote JavaScript or WebAssembly; retrieved files are treated as export data.
An attachment may itself contain source code, but the extension does not run it.
Local storage and retention
Selected conversations, files and reports are written to the folder you choose.
These exports are ordinary TXT, DOCX, JSON and attachment files; the extension
does not encrypt them. Other users or programs with access to that folder may
read them. If you choose a cloud-synced folder, its storage software may upload
them according to your settings. The extension does not control that software.
Exported files remain until you delete or move them yourself.
The remember-folder preference is stored in extension-local browser storage.
When you allow the folder to be remembered, its directory handle is stored in
IndexedDB for chatgpt.com. Compatibility code may also retain previously
confirmed Work container identifiers in chatgpt.com local storage. These
website-scoped records can remain after the extension is uninstalled.
The session token and retrieved content are held in page/extension memory as
needed for the current session. The token is not deliberately written to
extension settings or export metadata. Reloading/closing the ChatGPT tab clears
the injected engine's in-memory state. Runtime file-cache reuse is scoped to a
batch export. No automatic expiry is set for saved folder/settings records.
Diagnostics
This build retains local developer-console diagnostics. They can include chat
titles, file names, identifiers, backend error details and temporary download
URLs. Some error details are also written to local export reports. Diagnostics
are not automatically sent to the developer. Review and redact logs, reports,
exports and screenshots before sharing them; temporary URLs can grant file
access while valid. Content you choose to export may itself contain sensitive
information or credentials you previously included in a conversation.
Your controls
Use Export, DOCX, Files and Standalone to choose what is written. Selecting
Standalone gives a chat its own file copies; disabling it uses a shared _files
folder within the batch export. Use Forget folder to remove the remembered
directory handle without deleting your exports. Turning off Remember the
export base folder prevents reuse for that export; use Forget folder to remove
an already saved handle.
Close the side panel to stop its list-refresh interface. If an export is already
running in the page, closing only the panel does not necessarily stop it; close
or reload the ChatGPT tab to interrupt it. An interrupted export may leave
partial files. Remove those manually if unwanted. Uninstalling the extension
removes extension-local settings, but not downloaded exports or chatgpt.com
site data. Browser site-data controls can remove the latter; clearing ChatGPT
site data may also sign you out and remove other ChatGPT settings.
Sharing and support
ChatMila does not automatically share your exported folder. Anyone to whom
you give the files can read them. Share only the material you intend to disclose.
The developer has no remote copy of your exports to retrieve or delete. For
questions about this policy, use the developer/support contact supplied with
your copy of the extension or shown on its Chrome Web Store listing when
published. No support request is sent by the extension automatically.
Changes
A future release may update this policy to reflect changed behavior. The policy
included with that release will state its effective date and applicable version.