OpenAPI Repair · ChatGPT plugin

Plugin privacy notice

This notice describes the OpenAPI Repair MCP plugin, provided by Masashi Nakadaira.

Effective date: the date this page is first publicly published.

What is sent to the service

When you ask ChatGPT to use the plugin, the tool call sends your complete JSON or YAML API definition and its format to the processing server. Preview and export calls also include the expected input hash and repair choice. Export additionally includes the approved candidate hash and the host’s assertion that you approved the displayed preview.

The service uses that data to diagnose selected issues or return a requested repair candidate. Definitions may contain internal URLs, names, examples, security configuration, or personal data. Remove anything unnecessary before you submit them.

Authentication and application storage

Access uses the existing Sites-managed ChatGPT connection. Application code checks a Site-scoped authenticated-user identifier and does not persist it. The application does not require your name, email address, AWS account, payment details, AWS credentials, or a model API key.

The current application processes definitions in memory. It has no definition database, file store, persistent cache, analytics collector, or request-body logger. It does not fetch external references, call AWS, or send definitions to a separate model API. Findings and candidates return to the requesting host.

Hosting, traffic data, and retention

OpenAI hosts the MCP service through Sites. Hosting may process authentication, traffic, and security metadata. Sites records traffic analytics automatically, even without an application analytics SDK, and does not provide data-residency controls. Do not assume processing or logs remain in your country.

The absence of application storage is not a zero-retention promise for ChatGPT or hosting records. A fixed retention period for this endpoint’s hosting logs has not been independently confirmed. ChatGPT conversations and any output files follow their own applicable policies and settings; chat-deletion timing is not a stated retention period for Sites logs.

Support email

If you email goldilocks.1208.bear@gmail.com, the publisher’s Gmail mailbox receives your address, message, and any attachments you choose to send. Your own email provider also handles the message. Send only the information needed for the question and use synthetic examples.

Support message bodies and attachments are kept only while needed to handle the inquiry. Unnecessary message bodies and attachments are manually deleted. There is no automatic deletion schedule or promised response deadline.

Contact the publisher with privacy questions or access/deletion requests, without resending the original definition. A request does not automatically delete ChatGPT, hosting-provider, or device records.

Information you should not submit

Do not submit passwords, API keys, access tokens, payment-card data, health records, or unnecessary personal/customer data. This utility is not designed for regulated health or payment-card processing.

The separate browser-local website

The web checker processes selected definitions on your device and does not upload their contents. Visiting its static pages still involves the website’s hosting provider. Its browser-local privacy notice applies to that mode; it does not describe MCP processing.

Support and privacy contact

Provided by Masashi Nakadaira, an individual publisherContact the publisher