← All pages

1. What the document is: OpenAI's Cookie Policy — a table of first- and third-party cookies and trackers (name, duration, purpose, domain). Outside this wiki's core focus on AI training and data licensing; included for completeness.

What this wiki found — complete, every page

AI trainingRoyalty-freeSublicensablePerpetual / irrevocableTransferableDerivative works

Presence facts, not verdicts — each flagged term links to its definition and the exact clause on this page. Absence of a badge means the term isn't currently flagged here, not that the page is risk-free.

ChatGPT – Trackers Policy

Dataset: GenGA (Generative AI Governance Archive) — 11 AI services, 2025–present

GenGA (Generative AI Governance Archive) is this wiki’s Generative-AI dataset: raw policy snapshots captured by the Open Terms Archive genai-eu project across 11 GenAI providers (ChatGPT, Claude.ai, DeepSeek, Google Generative AI Services, Le Chat, Llama API, Meta AI, Microsoft Copilot, Perplexity, Qwen Chat, xAI). Unlike PGAv2, GenGA has no pre-tagged risk scores — all risk scoring and keyword tagging on these pages is LLM-assigned by direct reading, spanning 2025–present.

Note: This page contains documented policy clauses. Risk assessment is qualitative and context-dependent. For analysis of patterns across platforms, see:

Source: sources/GenGA/ChatGPT/Trackers Policy/ (raw Markdown captures, Open Terms Archive genai-eu dataset — no pre-tagged JSONL exists for this source) Last updated: 2026-01-21

Note on methodology: No pre-computed risk_score/keyword fields exist for this source. Keyword tags on this page are LLM-assigned. Treat as first-pass analysis, not externally verified ground truth. This wiki’s risk-scoring system was retired project-wide on 2026-06-21 (see methodology.md §4) — no page, GenGA included, computes or displays a numeric risk score.


Overview

1. What the document is: OpenAI’s Cookie Policy — a table of first- and third-party cookies and trackers (name, duration, purpose, domain). Outside this wiki’s core focus on AI training and data licensing; included for completeness.

2. Input rights: Not addressed.

3. Output restrictions: Not addressed.

4. Non-explicit predatory clauses: None found — this is a disclosure document listing what’s tracked, not a rights-granting one. Notable mainly for how many trackers it discloses (190+ rows across necessary, functional, analytics, and marketing categories), including third-party trackers from Cloudflare and others.

5. Regulatory references: Implicitly shaped by GDPR and the ePrivacy Directive (cookie-consent categories, a dedicated “Cookie consent” purpose column for oai-allow-ne/analytics_consent/marketing_consent), but no regulation is named in the text itself.

6. Regional variation: Not stated explicitly, though cookie-consent banners like this one are typically built to satisfy the EU’s ePrivacy Directive/GDPR rules.

7. Key risk to users: Low for this wiki’s scope. The only mild concern is that the broad analytics/marketing cookie set is gated behind a “Cookie consent” purpose — meaning consent, not a strict default-off setting, is what limits those categories. No clause here claims AI-training rights.

No AI-training, data-licensing, or output-restriction clauses found — out of scope for this wiki’s core risk categories.

Regulatory & Research Context

Edwards et al. (2025) observe that generative-AI privacy materials often “requir[e] reading comprehension abilities at university level,” a complexity concern that applies by extension to this page’s 190+-row cookie inventory, where consent gating is split across oai-allow-ne/analytics_consent/marketing_consent categories without naming the underlying ePrivacy Directive or GDPR basis in the text itself. Pandit et al. (2026)‘s broader finding that GenAI terms “discard assurances” and create “significant imbalance of power” is less directly applicable here, since this is a disclosure-only tracker inventory rather than a rights-granting clause — illustrating, by contrast, how their unfairness framework targets substantive licensing terms rather than itemized cookie tables like this one.


Changes Summary

DateWhat changed
2025-11-11Baseline version (first capture in this dataset; “Last updated: November 4, 2025”).
2025-12-18Cookie-list churn: oai-did domain list expanded to include deploymentsafety.openai.com; two new sidebar-state cookies added (oai-sidebar-closed-applied, oai-sidebar-expanded); Cloudflare attribution link-formatting fixed (broken markdown syntax corrected). No change to document structure or purpose.
2026-01-21Cookie-list churn: oai-did domain list narrowed (dropped openai.com); several cookies’ domain lists trimmed (next-auth.csrf-token, next-auth.callback-url, oai_client_auth_info); Cloudflare cookie set reorganized. No change to document structure or purpose.

Version History

2025-11-11

No AI-training, data-licensing, or output-restriction clauses found in this document — it is a cookie/tracker inventory.


2025-12-18

No substantive change from 2025-11-11 — cookie-list additions only (see Changes Summary).


2026-01-21

No substantive change from 2025-12-18 — cookie-list domain-scope trims only (see Changes Summary).