Privacy Policy

Cupboard App LLC operates The Cupboard. This policy explains how we collect, use, and protect information when you use our app and services. This policy also covers the Cupboard plugin in ChatGPT and Codex.

Information We Collect

In the Cupboard app, we collect email addresses, display names, and profile pictures from users who authenticate using email and password or Google. The public ChatGPT plugin does not require a Cupboard account; its photo-processing practices are described below.

How We Use Your Information

Your email address is used solely for authentication purposes and to keep you updated about our services. Your account-linked app data is stored in a private database. The plugin uses separate, short-lived photo processing described below.

Data Protection

We implement appropriate security measures to protect your information from unauthorized access. Account information and photos may identify you. The plugin shares information with the recipients described below to provide its features.

Cupboard in ChatGPT

The Cupboard plugin lets you browse the cup catalog and identify cups from a photo without signing in to a Cupboard account. The plugin processes the catalog requests you send, selected photos or attachment references, random session and photo access identifiers, and the image-derived features, previews, and identification results it creates. OpenAI sends selected photo bytes or an attachment reference; when it sends a reference, our server downloads the photo from its HTTPS storage host.

We use catalog requests to return relevant catalog information. For photo identification, we prepare the image and compare image-derived features with our catalog on our server. Matching runs locally and does not send the photo to an external inference API. Photos can include personal information, including people or details in the background. Send a photo focused on the cup and leave out sensitive information.

The plugin uses random session and photo access identifiers to keep photo access within the session. These do not link the session to a Cupboard account. Using the plugin without a Cupboard account does not make requests anonymous to OpenAI, our hosting provider, or the networks involved.

Plugin Recipients and Hosting

OVHcloud hosts the Cupboard plugin server in Oregon, United States, where photo processing takes place. Cupboard returns identification candidates, image-derived results, a small photo preview, and public catalog thumbnails to OpenAI's ChatGPT or Codex host and the plugin interface so you can review the match. OpenAI handles information in its services under its own privacy policy.

Cloudflare R2 serves public catalog images. The plugin's photo identification flow does not upload your submitted photos to R2.

Plugin Retention and Controls

While a photo request waits for processing, photo bytes or a signed image URL may be held in server memory for up to 30 seconds. Original and prepared photo files use bounded, memory-backed temporary storage with swapping disabled. Cleanup is attempted after processing and retried once if it fails. If both attempts fail, the service invalidates retained photo state, rejects further photo work, and initiates shutdown so container supervision can replace the temporary storage. Recovery timing depends on process scheduling and host operation; this is not a promise of secure physical memory erasure.

The matching worker releases its request and result references after each request. The application's cached image-derived features, small preview, and candidate shortlist have a fixed 15-minute expiry after a successful match. Clearing the photo, ending the server session, expiration, or restarting the process removes that cached photo state.

Use the plugin's Clear control to remove cached photo state before it expires. Clearing this state does not delete copies or results already sent to ChatGPT or Codex. Manage those through OpenAI's controls. This 15-minute period applies to the plugin's photo cache, not to Cupboard account data, session metadata, OpenAI conversation history, or infrastructure logs and backups.

The plugin keeps random session and request identifiers, rate-limit counters, and connection state in server memory to manage requests and photo access. A session expires after 15 minutes without a successful response; successful responses refresh that period. Expired sessions are closed once pending work finishes. Session deletion or a server restart removes session state sooner. Active sessions have no fixed total-lifetime limit. Expired photo-reference identifiers may remain in an active session until a later photo operation or session close, but cannot access an expired photo.

Operational Logs and Backups

We keep operational logs to diagnose service, proxy, and TLS failures, and security logs to investigate blocked connections and security events. These can contain timestamps, service and process identifiers, diagnostic messages, error details, connection IP addresses, and other network connection details. System security logs can also contain login usernames. The hosted plugin does not deliberately write tool arguments, photos, or identification matches to a request log. It is designed not to log session access capabilities or input photo URLs, and the proxy has no routine request access log configured. Operational and security logs can still contain connection information.

Container diagnostic logs rotate across up to three 10 MiB files, with no configured maximum age. Entries can remain for the container's lifetime if rotation does not replace them. System journals have no configured maximum age and are managed by storage capacity. Forwarded system log files retain an active file and four weekly rotated archives. This does not guarantee deletion at an exact age, and journal copies can remain longer. Clearing a photo does not clear these logs.

The application does not create a persistent photo volume or an application backup of photo or query data. Disk-based operational and security logs may be included in OVHcloud's system backups. Our VPS is configured for Standard daily backups. OVHcloud describes this service as one daily backup on a 24-hour rotation, excluding additional disks; see its backup documentation. At our latest check, the backup table showed no available result, so a scheduled backup is not a promise of a completed backup. The documentation does not establish that every copy of volatile memory is excluded or erased on that schedule. Photo-cache expiry and Clear do not erase disk logs, provider backups, or OpenAI records.

User Data Management

We reserve the right to edit or delete any user-submitted data if it is deemed inappropriate, intentionally destructive, or outside the bounds of reasonable behavior. This includes, but is not limited to, inappropriate usernames or unrealistic pricing data.

Changes to This Policy

We may update this privacy policy from time to time. Any changes will be posted on this page. We encourage users to review the policy periodically.

Contact Us

For questions about this policy or requests about your information, email [email protected] or visit our support page.