Odoo AI Companion
FeaturesGetting StartedPrivacyGet the extension →
Clear, accountable data practices

Privacy Policy

This policy explains how the Odoo AI Companion browser extension handles information when you use its Odoo search, analysis, navigation, and controlled agent features.

Effective date: September 13, 2026  ·  Last updated: September 13, 2026

On this page OverviewData handledHow data is usedPrivacy modesSharingStorage and retentionSecurityYour choicesChildrenChangesContactLimited Use

1. Overview

Odoo AI Companion is a client-side browser extension. Its single purpose is to provide an AI-powered assistant for searching, analyzing, and navigating data in the Odoo ERP session chosen by the user. The project does not operate an intermediary server that receives your Odoo records or AI requests.

Important: The extension communicates directly with the Odoo instance open in your browser and, when you submit an AI request, with the AI service or local endpoint you configure.

2. Information the extension handles

Depending on the features you use and the records you request, the extension may handle the following information locally or transmit permitted portions to your selected AI endpoint:

CategoryExamples and purpose
Odoo contextOdoo host, database, version, current app, model, view, action, record IDs, user ID, company ID, and related page context used to ground requests and navigation.
Website and ERP contentRecords, fields, counts, aggregates, activities, chatter messages, and other Odoo content the signed-in user asks the extension to process.
Personal informationNames, usernames, email addresses, phone numbers, customer or employee identifiers, and other personal fields that may exist in requested Odoo records.
Financial informationInvoices, sales, totals, payment status, accounting data, and related business records requested by the user. The extension does not collect payment-card information for its own billing.
CommunicationsAccessible Odoo chatter messages, notes, and activity descriptions when the user invokes those features.
Authentication informationAI-provider API keys entered by the user and stored in local extension storage. Odoo requests reuse the browser's existing authenticated session; the extension does not ask for your Odoo password.
User input and settingsPrompts, custom commands, saved prompt templates, provider and model selections, privacy settings, safety controls, and appearance preferences.

The extension does not intentionally collect a general browser history, precise location, keystroke logs, mouse movement, advertising identifiers, or information for credit scoring. It does not intentionally provide a health-data feature; users should not process regulated data unless authorized by their organization and applicable law.

3. How information is used

Information is handled only to provide the extension's user-facing purpose, including:

  • detecting the active Odoo context;
  • turning natural-language requests into Odoo searches and operations;
  • showing, formatting, exporting, and navigating requested results;
  • running bounded agent workflows and displaying their progress;
  • enforcing privacy modes, step limits, permissions, and approval controls;
  • connecting to the AI model or endpoint selected by the user; and
  • remembering local preferences and configuration.

Information is not used for advertising, user profiling, unrelated analytics, lending, or determining creditworthiness.

4. Privacy modes

IDs Only — default

Odoo record contents remain in browser memory. For agent tool results, the external model receives privacy-safe information such as model names, record IDs, counts, numeric aggregates where applicable, success status, and notices. Your original prompt and necessary Odoo context may still be sent to the selected model.

Anonymized

The extension attempts to mask common identifying values, including email addresses, phone numbers, names, and relational display labels, before sending tool results to an external model. Automated redaction may not detect every sensitive value.

Full Data

Unredacted Odoo record content may be sent to the selected external provider. This mode requires the user to select it and affirmatively accept the in-product warning and consent. Users are responsible for confirming they have authority to transmit the data.

Local providers

When configured to use Ollama, LM Studio, or LocalAI on localhost, AI processing is directed to that endpoint. Whether data remains on-device depends on how the user deploys and configures the endpoint.

5. Data sharing and third parties

The project developer does not sell user data. The extension transfers data only when necessary to provide its disclosed purpose, including:

  • to the Odoo instance selected by the user, to retrieve or operate on requested records;
  • to the AI provider or compatible endpoint explicitly configured by the user, to generate answers or agent decisions;
  • when required by applicable law; or
  • when necessary to protect users, security, or legal rights.

Supported provider types include Anthropic, OpenAI, Google Gemini, Ollama Cloud, Ollama, LM Studio, and LocalAI. Each external service processes transmitted information under its own terms and privacy policy. Odoo deployments are operated by Odoo S.A., the user's organization, or another hosting provider—not by this project.

6. Storage and retention

Provider configuration, API keys, privacy choices, prompt templates, quick commands, safety settings, theme, and related preferences are stored using Chrome local extension storage on the user's device. The active bound-tab identifier may be kept in session storage.

Retrieved record data and conversations are processed in extension memory for the active session and are not intentionally uploaded to a developer-operated server. Locally stored extension settings remain until the user changes them, clears extension data, or uninstalls the extension. External AI providers and Odoo hosts may retain requests according to their own policies and the user's account configuration.

7. Security

The extension packages its executable JavaScript with the extension and does not intentionally execute remotely hosted code. External cloud services should be accessed over HTTPS. Local HTTP endpoints are supported for localhost development and self-hosted environments; users are responsible for the security of those endpoints and networks.

API keys are stored in Chrome local extension storage and are used only to authenticate requests to the provider selected by the user. No security method is perfect, so users should restrict provider keys, protect their browser profile, follow organizational security policy, and revoke credentials they believe may be compromised.

8. Your choices and controls

  • Choose IDs Only, Anonymized, or consent-gated Full Data mode.
  • Use a compatible local provider instead of an external cloud model.
  • Disable Agent Mode or keep modifying actions disabled.
  • Approve or reject each modifying action when writes are enabled.
  • Change or remove API keys and saved preferences from extension settings.
  • Clear the extension's site data through Chrome or uninstall the extension.
  • Revoke an API key through the relevant provider account.

Access to Odoo data is also controlled by the signed-in user's Odoo permissions and record rules. For requests concerning data retained by an AI provider or Odoo host, contact that service directly.

9. Children's privacy

Odoo AI Companion is intended for business and organizational use and is not directed to children. The developer does not knowingly use the extension to collect personal information from children.

10. Changes to this policy

This policy may be updated when extension functionality, providers, permissions, or legal requirements change. The effective date at the top of this page will be revised. Material changes to data practices will be disclosed through an appropriate product or store notice before the new practice begins where required.

11. Contact

For privacy questions, deletion guidance, or security reports, open a private-safe request through the project's GitHub issue tracker. Do not include API keys, passwords, confidential Odoo records, or other sensitive information in a public issue.

12. Chrome Web Store Limited Use disclosure

The use of information received through Chrome extension APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Odoo AI Companion uses user data only to provide or improve its single purpose; does not sell user data; does not transfer data for personalized advertising; does not use data for creditworthiness or lending; and does not permit humans to read user data except with explicit consent for specific support, for security, to comply with law, or where data is aggregated and anonymized for lawful internal operations.

Odoo AI Companion
HomeGetting StartedGitHubSupport
Privacy policy · September 13, 2026