Product-Specific Privacy Notice
AgentReady GEO Auditor
Effective Date: June 14, 2026 | Last Updated: June 19, 2026
This notice supplements the main ReForge Extensions privacy policy and applies specifically to the browser extension AgentReady GEO Auditor.
Plain-Language Summary
- AgentReady GEO Auditor audits the current webpage for GEO, schema, AI-crawler visibility, AI citation readiness, and agent-readiness signals.
- When you run an audit, the extension reads data from the active tab, including the page URL, page title, meta tags, headings, links, structured data, robots directives, and relevant visible page text needed to create the audit report.
- The extension stores settings, cached audit results, local report history, and any optional user-provided OpenAI API key in your browser using Chrome extension storage so the tool can remember your preferences and show previous results.
- If you enable AI-assisted recommendations and enter your own OpenAI API key, the extension collects that user-provided API key, token, or password-like secret in the extension settings. The key is used only to authenticate OpenAI API requests that you initiate from the extension.
- When AI-assisted recommendations are enabled, the extension may send selected audit context, prompts, page metadata, page text snippets, structured data findings, and model responses between your browser and OpenAI's API over HTTPS. ReForge does not receive your OpenAI API key by default.
- By default, non-AI audit processing is designed to run locally in your browser. We do not send page content, audit reports, or browsing history to ReForge servers for this product unless you intentionally share that information with us, for example by emailing support.
- When the extension requests website files such as robots.txt, sitemap.xml, or llms.txt for the site you are auditing, those requests are sent from your browser to that website or its infrastructure providers as part of the audit you initiated.
- We do not sell, trade, rent, or transfer user data to data brokers, ad networks, or information resellers. We do not use extension data for credit-worthiness, lending, personalized advertising, retargeting, or interest-based advertising.
Limited Use statement: AgentReady GEO Auditor uses user data, including any optional user-provided OpenAI API key or password-like secret, only to provide or improve its single purpose: auditing the current webpage for GEO, schema, AI crawler visibility, AI citation readiness, and agent-readiness. We do not use or transfer user data for personalized advertising, retargeting, interest-based advertising, data brokerage, or credit-worthiness decisions.
Important password/API key clarification: AgentReady GEO Auditor does not intentionally collect passwords from websites you audit, login forms, password managers, or unrelated pages. The only password-like credential the extension may collect is an OpenAI API key, API token, or similar secret that you choose to type or paste into the extension's own settings to enable optional AI-assisted analysis. Some browser or store review systems may classify that masked API-key field as a password field; this notice expressly covers that credential.
1. Scope
This product-specific privacy notice applies to AgentReady GEO Auditor, its extension UI, the local audit reports it creates, and support requests related to this extension. The main ReForge Extensions privacy policy at /privacy.html still applies unless this product-specific notice is more specific.
Special Disclosure: Passwords, API Keys, Tokens, and Secrets
Chrome Web Store may classify AgentReady GEO Auditor as collecting user passwords because the extension includes an optional masked credential field where a user can enter an OpenAI API key, API token, project key, or similar secret. This is not a website login password. It is a user-provided API credential used only to call OpenAI's API for optional AI-assisted audit features.
- What we collect: the OpenAI API key/token/secret that you voluntarily type or paste into the extension settings.
- How we collect it: directly from the extension's API-key or password-style settings field when you choose to provide it.
- How we use it: only to authenticate OpenAI API requests that you initiate for AI-assisted GEO audit summaries, recommendations, explanations, or report wording.
- Where it is stored: in Chrome extension storage on your device if you choose to save it.
- Who receives it: OpenAI receives the key/token when your browser sends an API request to OpenAI. ReForge does not receive the key by default.
- What we do not collect: login passwords from audited websites, password-manager entries, payment-card numbers, or unrelated private form-field values.
If AI-assisted features are enabled, selected page content and audit context may be sent to OpenAI with the API request. Do not use the AI feature on pages that contain secrets, private credentials, or confidential content unless you want that content processed by OpenAI under the API account associated with your key.
2. What User Data the Extension Collects or Processes
The extension processes the following categories of user data only when needed for the user-facing audit features.
| Data category | Examples | How it is collected | Why it is used |
|---|---|---|---|
| Active tab and page metadata | Current page URL, page title, canonical URL, meta description, robots meta tags, Open Graph/Twitter metadata, language tags, hreflang tags. | Read from the active tab after you open or run the extension on that page. | To identify the page being audited and generate GEO, SEO, AI-readiness, and metadata findings. |
| Page structure and content signals | Headings, link URLs, image alt text, visible text snippets, content structure, internal/external link signals, semantic entities inferred from page content. | Read from the page DOM by the extension while the audit is running. | To evaluate whether the page is clear, crawlable, citeable, and understandable by search engines, AI systems, and agents. |
| Structured data and machine-readable files | JSON-LD, Microdata, RDFa, Schema.org types, robots.txt, sitemap.xml, llms.txt, ai.txt or similar machine-readable files if present. | Read from the current page or requested from the audited website by your browser as part of the audit. | To detect schema coverage, crawler rules, LLM-crawler visibility, and agent-readiness signals. |
| Audit results and local report data | Scores, issue lists, recommendations, timestamps, audited URL, cached findings, exported report contents. | Generated locally by the extension from the audit inputs. | To show results, let you revisit recent audits, export reports, and avoid repeating work unnecessarily. |
| Extension settings and preferences | Saved options, selected audit modules, UI preferences, local history settings, export preferences. | Entered or selected by you in the extension UI and stored in Chrome extension storage. | To remember your configuration and make the extension work consistently between sessions. |
| User-provided passwords, API keys, tokens, and authentication secrets | OpenAI API key, OpenAI project key, API token, or any value you enter into the extension's API-key, token, password, or secret field. | Collected only when you voluntarily type or paste the credential into AgentReady GEO Auditor's settings to enable optional AI-assisted recommendations. | To authenticate API requests from your browser to OpenAI for AI-assisted audit summaries, recommendations, or report improvements requested by you. We do not use this credential to access unrelated accounts or websites. |
| AI prompt, response, and analysis data sent to OpenAI when enabled | Prompts generated by the extension, selected page URL/title/metadata, relevant page text snippets, structured data findings, audit scores, issue lists, user instructions, and OpenAI model responses. | Generated from the audit and sent from your browser to OpenAI only when you enable or use the optional AI-assisted feature with your own OpenAI API key. | To produce AI-assisted recommendations, explanations, summaries, and report wording for the page you chose to audit. |
| Passwords from audited websites and login forms | Password field values, password-manager entries, login credentials, payment-card numbers, and private form-field values from unrelated websites. | Not intentionally collected. The extension does not need these values for GEO auditing and is intended to ignore password fields and unrelated credential inputs on audited pages. | Not used. If a secret is visibly published as ordinary page text on a page you choose to audit, it may be treated as page content, so you should avoid auditing pages that display secrets unless you want that content processed. |
| Support contact data | Email address, name or signature, message content, attachments, screenshots, audit exports, and troubleshooting details you choose to send. | Collected only if you contact us for support. | To respond to your request, investigate bugs, process privacy requests, or handle disputes. |
| Website request and security data for this privacy page | IP address, user agent, timestamp, requested URL, referrer, and security event data. | Processed by website hosting, DNS, CDN, or security providers when you visit reforgeextensions.com. | To deliver and protect the website and this privacy page. |
3. How We Collect User Data
- User-initiated active-tab auditing: The extension reads the current page when you open the extension or start an audit for that page.
- Content and metadata extraction: The extension reads page metadata, structured data, links, headings, and relevant visible text from the page DOM to generate the report.
- Website file checks: For crawler and agent-readiness checks, the extension may request public files from the audited website, such as robots.txt, sitemap.xml, or llms.txt, from your browser.
- User-entered OpenAI credential: If you choose to use optional AI-assisted recommendations, you may enter an OpenAI API key, token, or password-like secret in the extension settings. This credential is collected directly from the settings field you fill in.
- OpenAI API requests: When you use the AI-assisted feature, selected audit context and your OpenAI API key are sent from your browser to OpenAI's API endpoint over HTTPS so OpenAI can authenticate the request and return a model response.
- Local storage: The extension stores preferences, cached findings, local report history, and any saved OpenAI API key using Chrome extension storage on your device.
- Support email: We collect support data only when you choose to email us or send attachments.
4. How We Use User Data
- To scan the page you chose and generate GEO, schema, AI crawler visibility, AI citation readiness, and agent-readiness findings.
- To use your optional OpenAI API key, token, or password-like secret to authenticate OpenAI API requests that you initiate from the extension.
- To send selected audit context to OpenAI and receive AI-assisted summaries, recommendations, explanations, or report wording when you enable that feature.
- To show recommendations, scores, issue lists, and exportable audit reports.
- To remember extension settings, saved OpenAI credential state, and local report history.
- To troubleshoot bugs, respond to support requests, and improve the reliability of the extension.
- To protect the website and respond to abuse, security, or legal issues.
We do not use extension data to create advertising profiles, serve personalized ads, sell data, determine credit-worthiness, or provide data to data brokers or information resellers.
5. Storage Location and Retention
5.1 Data stored locally in your browser
- Storage location: Chrome extension storage on your device, such as chrome.storage.local.
- Data involved: Settings, local audit cache, local report history, export preferences, and any optional OpenAI API key, token, or password-like secret you choose to save.
- Retention: Until you delete the data in the extension, clear browser/extension storage, reset the extension, or uninstall the extension. OpenAI credentials saved in browser storage are retained on your device until you remove them or uninstall/reset the extension.
- Security note: A saved OpenAI API key is stored in browser extension storage for convenience. ReForge does not receive it by default, but anyone with access to your unlocked browser profile or device may be able to use the extension. You can choose not to save the key and can revoke it in your OpenAI account dashboard.
5.2 Temporary page data processed during an audit
- Storage location: Browser memory while the audit is running.
- Data involved: Page DOM signals, metadata, structured data, visible text snippets, and related crawlability signals.
- Retention: Temporary inputs are intended to be discarded after the audit unless the resulting findings are saved in local report history or exported by you.
5.3 Support communications
- Storage location: Our email routing and mailbox providers.
- Data involved: Sender email address, message content, attachments, and routing metadata.
- Retention: Up to 24 months after the last support interaction, unless a longer period is required by law, security investigation, or dispute resolution.
5.4 Website request and security logs
- Storage location: Website hosting, CDN, DNS, or security providers such as Cloudflare.
- Retention: Up to 30 days unless a longer period is reasonably necessary to investigate abuse, resolve incidents, or comply with law.
5.5 OpenAI API processing when optional AI features are enabled
- Storage location: OpenAI systems, under the OpenAI account associated with the API key you provide.
- Data involved: Your OpenAI API key for authentication, request metadata, prompts, selected audit context, page snippets, and model responses.
- Retention: ReForge does not control OpenAI's retention. OpenAI states in its API data controls that API data is not used to train models by default unless the account opts in, and that abuse monitoring logs may be retained for up to 30 days unless a different retention setting or legal requirement applies. Please review OpenAI's current API data controls for your account.
6. Sharing and Transfers of User Data
This section lists the related parties with whom user data may be shared and why.
| Related party | Data shared or processed | Purpose |
|---|---|---|
| Audited website and its infrastructure providers | When the extension requests public files such as robots.txt, sitemap.xml, or llms.txt, the audited website may receive normal request metadata from your browser, such as IP address, user agent, requested URL, and timestamp. | To retrieve public crawlability or agent-readiness files from the site you chose to audit. |
| Your browser and Chrome extension storage | Settings, local audit cache, local report history, extension preferences, and any optional OpenAI API key/token/password-like secret saved on your device. | To provide local extension functionality, remember your preferences, and keep your optional OpenAI credential available for AI-assisted features. |
| OpenAI, L.L.C. or the OpenAI API provider associated with your API key | Your OpenAI API key/token for authentication, API request metadata, prompts, selected page metadata, selected page text snippets, structured data findings, audit results, and AI model responses when you use the optional AI-assisted feature. | To authenticate your API request and generate AI-assisted audit recommendations, explanations, summaries, or report wording requested by you. |
| ReForge Extensions support mailbox and email providers | Support email address, message content, attachments, screenshots, or exported audit data you choose to send. | To respond to support, bug, privacy, refund, or security requests. |
| Website hosting, CDN, DNS, and security providers | Request metadata for visits to reforgeextensions.com, including this privacy page. | To deliver the website, cache content, provide TLS, and protect against abuse. |
| Legal, safety, security, or business-transfer recipients | Only the information reasonably necessary for the specific legal, safety, security, merger, acquisition, financing, or asset-transfer purpose. | To comply with law, protect rights and security, investigate abuse, or complete a merger/acquisition/sale of assets. |
We do not share page content, audit reports, browsing history, or extension settings with data brokers, information resellers, ad networks, or unrelated third parties. By default, AgentReady GEO Auditor is designed so non-AI page audit processing happens locally in your browser and is not sent to ReForge servers. Optional AI-assisted processing is shared with OpenAI only when you enable or use that feature with your own API key.
7. Third-Party Services
- Audited websites: The extension may request public machine-readable files from the website you choose to audit.
- Chrome browser and extension APIs: Used to run the extension, access the active tab for the user-initiated audit, and store local settings, reports, and optional OpenAI credential settings.
- OpenAI API: Used only if you choose to enable AI-assisted recommendations with your own OpenAI API key. Your browser sends the API key and selected audit context to OpenAI over HTTPS, and OpenAI returns a model response. OpenAI's handling of that data is governed by its API terms, privacy policy, and data controls for the account that owns the API key.
- Cloudflare or similar website infrastructure providers: Used only for delivery, DNS, TLS, caching, and security for reforgeextensions.com.
- Email routing and mailbox providers: Used only to receive and respond to support messages you send.
This product-specific notice does not describe use of Google Analytics, Firebase Analytics, Stripe, Sentry, PostHog, Mixpanel, advertising SDKs, data brokers, or analytics SDKs in AgentReady GEO Auditor because we do not currently use those services for this extension. Current OpenAI API data information is available at OpenAI API data controls.
8. Data Security
- Local extension data is stored through Chrome extension storage on your device.
- Optional OpenAI API keys, tokens, or password-like secrets are stored locally in browser extension storage if you save them. They are not sent to ReForge servers by default.
- OpenAI API requests initiated by the AI-assisted feature are transmitted to OpenAI over HTTPS and include the API key for authentication.
- Any communication with websites, OpenAI, support systems, or reforgeextensions.com uses HTTPS/TLS where supported.
- We limit access to support communications to people or processors who need access to respond to requests or protect the service.
9. User Choices and Deletion
- You can stop collection by not running an audit on a page.
- You can delete local extension data by clearing the extension's local data, clearing browser extension storage, resetting the extension if the UI provides that option, or uninstalling the extension.
- You can remove or replace the saved OpenAI API key/token/password-like secret from the extension settings, or revoke/delete that key in your OpenAI account dashboard.
- You can avoid OpenAI processing by not entering an OpenAI API key and not using optional AI-assisted recommendations.
- You can export or copy reports only when you choose to do so. If you share an exported report with another party, that sharing is controlled by you.
- You can request deletion of support emails by contacting [email protected].
10. Limited Use Compliance
- Allowed use: We use user data only to provide and improve the extension's single purpose and user-facing features.
- Allowed transfer: We transfer user data only when necessary to provide or improve the extension, comply with law, protect security, respond to support you initiated, or complete a merger/acquisition/sale of assets.
- OpenAI transfer limitation: We transfer your OpenAI API key and selected audit context to OpenAI only when you enable or use the optional AI-assisted feature, and only to provide the AI recommendation functionality requested by you.
- No advertising use: We do not use or transfer user data for personalized ads, retargeting, interest-based advertising, or ad measurement.
- No unrelated human review: We do not allow humans to read page content or audit reports unless you intentionally send that information to support, it is required for security or legal reasons, or it is necessary for internal operations with appropriate access controls.
11. Children
AgentReady GEO Auditor is not directed to children under 13, and we do not knowingly collect personal information from children through this extension.
12. Changes
We may update this notice when the extension, our practices, or legal requirements change. We will update the effective date or last updated date when we make material changes.
13. Contact
Questions, privacy requests, or support requests can be sent to [email protected].
Static review URL: https://reforgeextensions.com/privacy/agentready-geo-auditor/