Scope and controller
This policy applies to the MyChatExport Chrome extension, the mychatexport.com website, and the account, licence and quota services the extension uses. For privacy questions, access requests or deletion requests, contact support@mychatexport.com.
Information processed on your device
- The open conversation. When you start an export, MyChatExport requests the conversation currently open in your ChatGPT tab and reads its messages, ordering, code blocks, tables and quoted text in order to reproduce the transcript.
- Your ChatGPT session credential. To ask ChatGPT for that conversation, the request must be authenticated as you — the same way the page itself is authenticated. The extension reads the session credential already present in your browser and uses it only for that single request. It is not stored by us and not transmitted to us.
- The generated file. Markdown is written by your browser and downloaded by Chrome. PDF is produced through Chrome’s own print dialog. Neither file passes through a MyChatExport server.
- Settings and sign-in state. Extension settings, access tokens and a basic account cache are stored in Chrome extension-local storage so the extension can recognise the signed-in account.
Processing data locally still counts as handling user data. MyChatExport limits that processing to the export you request.
What MyChatExport never does
- It does not list, enumerate or bulk-download your conversation history. Only the conversation you have open is ever requested, and a guard in the extension makes an out-of-scope request fail rather than proceed.
- It does not send conversation text, message content or generated files to our service or to any third party.
- It does not read your ChatGPT password.
- It does not execute remotely hosted code. All executable code ships inside the extension package.
Information sent to MyChatExport services
Account, entitlement, quota, security and diagnostic requests are sent over HTTPS to the MyChatExport SDK/API service at ext.mychatexport.com and may include:
- basic Google account information returned through sign-in, such as a user identifier, email address and display information;
- authentication tokens, account or subscription identifiers, and export quota requests;
- an anonymous installation identifier, acquisition source and browser/device fingerprint used for abuse prevention and request integrity;
- extension ID, extension and SDK versions, language, event names and limited diagnostic properties;
- standard server logs, including IP address, user agent, request time and response status.
No part of your conversation is included in any of these requests.
Website analytics
Updated August 23, 2026. This website uses Google Analytics 4 to count visits and see which pages get read. It sets Google Analytics cookies in your browser and sends Google the standard page-view data: the page address, the page you arrived from, an approximate location derived from your IP address, and your device and browser type.
Three things it does not do. It is not part of the extension. It never sees any part of a conversation. And nothing measured here is joined to your account, your subscription, or anything the extension does — those live on a different system that this measurement cannot reach.
Blocking googletagmanager.com in any content blocker stops it, and the site works exactly the same without it. There is no advertising on this site.
Access to ChatGPT pages
MyChatExport requests access to ChatGPT pages because that is where the conversation you want to export lives, and to the MyChatExport API domain for account and licence checks. It does not request access to other websites, and it cannot read pages on other domains.
How information is used
MyChatExport uses information only to:
- perform the export you request and produce the Markdown or PDF file;
- authenticate accounts and apply remotely configured plans and quotas;
- prevent fraud, abuse and duplicate quota consumption;
- maintain security, reliability and compatibility with ChatGPT’s interface;
- measure aggregated product performance directly related to MyChatExport’s disclosed functionality;
- respond to support, privacy and legal requests.
Sharing and service providers
MyChatExport does not sell personal data. Information may be processed by service providers only when necessary to operate the extension, including Google for OAuth sign-in, hosting and infrastructure providers for the MyChatExport API, and the payment provider displayed at checkout. Complete payment-card details are not stored in the extension.
Information may also be disclosed when required by law, to protect users or the service from security threats, or as part of a merger, acquisition or asset transfer subject to applicable protections. We do not transfer user data for personalized, retargeted or interest-based advertising.
Chrome Web Store Limited Use disclosure
MyChatExport’s use and transfer of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
- Chrome API data is used only to provide or improve MyChatExport’s single purpose: exporting the ChatGPT conversation the user has open.
- Chrome API data is transferred only when necessary to provide or improve that feature, for security, to comply with law, or as part of a qualifying business transfer.
- Chrome API data is not used or transferred for personalized advertising, creditworthiness, lending or unrelated profiling.
- Humans do not read private conversation content. Conversation content does not reach our systems, so it cannot be read by our staff.
Security
MyChatExport uses HTTPS for data sent to its services. Authentication tokens are stored in Chrome extension-local storage and are not intentionally exposed to webpages. The extension packages its executable code locally and does not execute remotely hosted code. No security measure is absolute, but access is limited to the data and systems needed to operate the service.
Retention
- Exported files live wherever Chrome saved them. We hold no copy.
- Settings remain until you reset them or uninstall the extension.
- Local authentication data remains until logout, local deletion or uninstall.
- Account, entitlement and quota records are retained while needed to provide the account and to resolve security, billing or legal obligations. When you send a verified deletion request, account records and the Google sign-in mapping are deleted within 30 days.
- Raw operational and SDK diagnostic events do not all have an automatic deletion schedule. They are retained only for operation, reliability, security and aggregate measurement, and may be included in a verified deletion request where legally and technically applicable.
- Transaction records may be retained for the period required by tax, accounting, fraud-prevention or other applicable law.
Your controls and deletion requests
- Delete an exported file the way you delete any other file on your computer.
- Reset extension settings at any time.
- Sign out to remove the active extension session.
- Uninstall MyChatExport to remove extension-local data from Chrome.
- Request access to or deletion of server-side account data by emailing support@mychatexport.com from the account email. We verify the request and complete account deletion within 30 days. Limited records may be retained where required for security, billing or law.
Changes to this policy
Material changes will be dated on this page. If a change introduces a new collection or upload that requires consent, MyChatExport will provide an in-product disclosure before that processing begins.
Contact
Email support@mychatexport.com for privacy questions, account deletion, data access or support. Please do not email passwords, authentication tokens or conversation contents.