Your data in Avenlo
Updated October 3, 2026 · Sandbox beta
Avenlo connects your ChatGPT identity to the SAP Business One company you configure. This notice describes the current beta. Each account has its own SAP connection, usage records, and draft proposals.
Information we use
- Sign-in: ChatGPT supplies a site-specific identifier and may provide your name and email to the sign-in layer. Avenlo uses the identifier to associate requests with your workspace.
- Your connection: the workspace name, SAP endpoint, company database, SAP username, and encrypted SAP password that you enter.
- Your activity: requested SAP results, quotation proposals, operation types, timestamps, outcomes, and connection or permission changes.
- Billing: Stripe customer and subscription references, plan status, and billing periods. Payment details are entered with Stripe and are not stored in Avenlo’s application database.
Why we use it
This information lets Avenlo authenticate you, connect to your company, return requested records, enforce usage allowances and permissions, prevent duplicate operations, and manage subscriptions. Avenlo does not maintain a complete copy of your SAP database.
Where information goes
OpenAI provides ChatGPT sign-in and the Sites platform; Cloudflare provides the hosted application and database infrastructure; Stripe provides sandbox checkout and subscription management. Your configured SAP server receives the requests you authorize. Infrastructure providers may process network and security information needed to operate their services.
When you use Avenlo tools in ChatGPT, the requested SAP results are returned to ChatGPT. Their subsequent handling follows your ChatGPT account’s applicable settings and terms. Use only company data that you are authorized to share with these services. Avenlo’s application does not include advertising trackers or sell records through its features.
Credentials and retention
SAP passwords, retry-cache results, and prepared proposal contents are encrypted in Avenlo’s database. The encryption key is held separately in the hosted application configuration. Passwords are not returned in query results or sent to ChatGPT.
- Connection credentials remain until you replace them or disconnect SAP.
- Successful query results can be reused for duplicate-request protection for 15 minutes. Older cached results are cleared when you next load your workspace.
- Proposals expire for confirmation after 10 minutes. Stored proposals older than 30 days, and operation and audit records older than 100 days, are removed on workspace access.
- These cleanup periods are applied when the workspace is accessed, not by a continuous background deletion job. Account and billing references remain while the account is retained. Hosting backups and provider records follow their respective retention arrangements.
Your controls
You can update connection details, disable writes, and disconnect SAP in your workspace. Disconnecting removes the saved credentials and cancels pending proposals; it does not delete your account, past activity, or records already created in SAP. Account-wide export and deletion are not yet self-service features of this beta.
You can manage or cancel a test subscription in Usage & billing. Disconnecting SAP does not cancel a subscription.
Browser storage and tracking preferences
Your light or dark appearance preference is saved in browser storage. Authentication uses the sign-in platform’s session mechanisms. Avenlo does not currently implement advertising or cross-site behavioral tracking, and does not change its application behavior in response to Do Not Track signals. Linked services have their own privacy practices.
Updates to this notice
Changes to these practices will be reflected on this page with a revised update date. Read the current notice before connecting a company or using a new capability.