1. Overview
Odoo AI Companion is a client-side browser extension. Its single purpose is to provide an AI-powered assistant for searching, analyzing, and navigating data in the Odoo ERP session chosen by the user. The project does not operate an intermediary server that receives your Odoo records or AI requests.
2. Information the extension handles
Depending on the features you use and the records you request, the extension may handle the following information locally or transmit permitted portions to your selected AI endpoint:
| Category | Examples and purpose |
|---|---|
| Odoo context | Odoo host, database, version, current app, model, view, action, record IDs, user ID, company ID, and related page context used to ground requests and navigation. |
| Website and ERP content | Records, fields, counts, aggregates, activities, chatter messages, and other Odoo content the signed-in user asks the extension to process. |
| Personal information | Names, usernames, email addresses, phone numbers, customer or employee identifiers, and other personal fields that may exist in requested Odoo records. |
| Financial information | Invoices, sales, totals, payment status, accounting data, and related business records requested by the user. The extension does not collect payment-card information for its own billing. |
| Communications | Accessible Odoo chatter messages, notes, and activity descriptions when the user invokes those features. |
| Authentication information | AI-provider API keys entered by the user and stored in local extension storage. Odoo requests reuse the browser's existing authenticated session; the extension does not ask for your Odoo password. |
| User input and settings | Prompts, custom commands, saved prompt templates, provider and model selections, privacy settings, safety controls, and appearance preferences. |
The extension does not intentionally collect a general browser history, precise location, keystroke logs, mouse movement, advertising identifiers, or information for credit scoring. It does not intentionally provide a health-data feature; users should not process regulated data unless authorized by their organization and applicable law.
3. How information is used
Information is handled only to provide the extension's user-facing purpose, including:
- detecting the active Odoo context;
- turning natural-language requests into Odoo searches and operations;
- showing, formatting, exporting, and navigating requested results;
- running bounded agent workflows and displaying their progress;
- enforcing privacy modes, step limits, permissions, and approval controls;
- connecting to the AI model or endpoint selected by the user; and
- remembering local preferences and configuration.
Information is not used for advertising, user profiling, unrelated analytics, lending, or determining creditworthiness.
4. Privacy modes
IDs Only — default
Odoo record contents remain in browser memory. For agent tool results, the external model receives privacy-safe information such as model names, record IDs, counts, numeric aggregates where applicable, success status, and notices. Your original prompt and necessary Odoo context may still be sent to the selected model.
Anonymized
The extension attempts to mask common identifying values, including email addresses, phone numbers, names, and relational display labels, before sending tool results to an external model. Automated redaction may not detect every sensitive value.
Full Data
Unredacted Odoo record content may be sent to the selected external provider. This mode requires the user to select it and affirmatively accept the in-product warning and consent. Users are responsible for confirming they have authority to transmit the data.
Local providers
When configured to use Ollama, LM Studio, or LocalAI on localhost, AI processing is directed to that endpoint. Whether data remains on-device depends on how the user deploys and configures the endpoint.
6. Storage and retention
Provider configuration, API keys, privacy choices, prompt templates, quick commands, safety settings, theme, and related preferences are stored using Chrome local extension storage on the user's device. The active bound-tab identifier may be kept in session storage.
Retrieved record data and conversations are processed in extension memory for the active session and are not intentionally uploaded to a developer-operated server. Locally stored extension settings remain until the user changes them, clears extension data, or uninstalls the extension. External AI providers and Odoo hosts may retain requests according to their own policies and the user's account configuration.
7. Security
The extension packages its executable JavaScript with the extension and does not intentionally execute remotely hosted code. External cloud services should be accessed over HTTPS. Local HTTP endpoints are supported for localhost development and self-hosted environments; users are responsible for the security of those endpoints and networks.
API keys are stored in Chrome local extension storage and are used only to authenticate requests to the provider selected by the user. No security method is perfect, so users should restrict provider keys, protect their browser profile, follow organizational security policy, and revoke credentials they believe may be compromised.
8. Your choices and controls
- Choose IDs Only, Anonymized, or consent-gated Full Data mode.
- Use a compatible local provider instead of an external cloud model.
- Disable Agent Mode or keep modifying actions disabled.
- Approve or reject each modifying action when writes are enabled.
- Change or remove API keys and saved preferences from extension settings.
- Clear the extension's site data through Chrome or uninstall the extension.
- Revoke an API key through the relevant provider account.
Access to Odoo data is also controlled by the signed-in user's Odoo permissions and record rules. For requests concerning data retained by an AI provider or Odoo host, contact that service directly.
9. Children's privacy
Odoo AI Companion is intended for business and organizational use and is not directed to children. The developer does not knowingly use the extension to collect personal information from children.
10. Changes to this policy
This policy may be updated when extension functionality, providers, permissions, or legal requirements change. The effective date at the top of this page will be revised. Material changes to data practices will be disclosed through an appropriate product or store notice before the new practice begins where required.
11. Contact
For privacy questions, deletion guidance, or security reports, open a private-safe request through the project's GitHub issue tracker. Do not include API keys, passwords, confidential Odoo records, or other sensitive information in a public issue.
12. Chrome Web Store Limited Use disclosure
The use of information received through Chrome extension APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Odoo AI Companion uses user data only to provide or improve its single purpose; does not sell user data; does not transfer data for personalized advertising; does not use data for creditworthiness or lending; and does not permit humans to read user data except with explicit consent for specific support, for security, to comply with law, or where data is aggregated and anonymized for lawful internal operations.