Toolbox for ChatGPT

Privacy policy

This policy explains what Toolbox Password Remover receives, how it processes files, and how long it keeps temporary output.

Effective date: October 4, 2026

Who operates this service

Maulik Sompura operates Toolbox Password Remover as an individual publisher. The hosted service runs on Netlify. Auth0 handles sign-in. ChatGPT connects to the service when you choose to use the plugin.

Files and passwords you submit

When you call the tool, ChatGPT sends the selected file attachment and the password you provide to the hosted Toolbox service. The request can also include the file name, file type, and an attachment identifier. The password is sensitive data. Submit only files you are allowed to process and passwords you already know.

The service downloads the attachment to temporary working storage, passes the password to Toolbox’s native processor, and removes the working files after the request finishes. The service does not write file contents, passwords, bearer tokens, or attachment URLs to its application logs. Memory erasure is best effort. A sudden runtime failure can interrupt cleanup.

Toolbox creates a separate unlocked copy. It stores that output in Netlify Blobs and returns a private download link. The link expires after ten minutes. Anyone who has the link can download the output before it expires. The service rejects expired links and runs cleanup every five minutes. A storage or cleanup failure can delay deletion. Netlify’s handling of deleted data in backups or other provider systems follows Netlify’s terms and retention practices, which Toolbox does not control.

Sign-in information

Auth0 authenticates your ChatGPT connection. Toolbox receives an access token and verifies it against Auth0’s public signing keys. Toolbox does not receive your Auth0 password and does not send your access token to Auth0 for verification. Auth0 may process account, sign-in, security, and log data under its own policies. Auth0 log retention depends on the tenant’s plan.

Service and request data

Netlify hosts the public pages, serverless functions, and temporary output storage. Netlify may process request and device metadata to deliver, secure, and operate the service. Its documentation says function activity logs are retained for at least 24 hours. Netlify may retain logs longer under some plans. Toolbox does not control Netlify’s provider logs, backups, or infrastructure retention.

Toolbox does not use advertising trackers or product analytics. It does not sell uploaded files or passwords. It does not use them to train AI models.

Where providers may process data

Netlify, Auth0, and OpenAI operate services in multiple regions. Each provider may process data in the regions described in its own terms and privacy information. Toolbox does not set a user-selected processing region for this plugin.

ChatGPT and other providers

OpenAI processes your conversation and plugin interaction under its own terms, privacy policy, and account settings. How OpenAI handles data in ChatGPT can depend on your plan and settings. When you use this plugin, the selected file and the password you enter are sent to Toolbox’s hosted service. Read OpenAI’s Privacy Policy and its connected-app data information.

Read the provider information for Netlify and Auth0, an Okta service. Netlify documents function log retention. Auth0 says log retention depends on the tenant’s plan in its log documentation.

Support messages

The support page links to public GitHub issues. Anything you post there can be read by anyone. GitHub handles that information under its own terms and privacy statement. Do not include files, passwords, access tokens, or private account details.

Payments

Toolbox does not charge for the plugin or password-removal feature. OpenAI, Netlify, or Auth0 may apply their own account limits and terms.

Questions and requests

For support or privacy questions, use the Toolbox support page. GitHub issues are public. Do not post files, passwords, access tokens, or private account details there.