Open a public ChatGPT Site and the server sets a cookie named __Host-appgarden-visitor in its very first response, valid for 90 days, before a single script on the page has run. That order matters for the General Data Protection Regulation (GDPR), because OpenAI's terms for ChatGPT Sites make you, the Site owner, the data controller for the personal data your Site collects, cookies included. Publishing is one click. The privacy notice, the consent and the questions about that cookie are yours.

What this means for your Site

  • Under section 3.2.1 of the ChatGPT Sites Terms, the Site owner is the controller of personal data a published Site collects, and OpenAI hosts it as a processor under its Data Processing Addendum.
  • A public Site that collects personal data needs a privacy policy, and any non-essential cookie needs consent first, under the same terms and under the ePrivacy Directive.
  • On 9 October 2026, a public Site from OpenAI's own showcase set three cookies before any visitor action: a 90-day visitor cookie from the Sites server and two Cloudflare security cookies.
  • An app previewed in a ChatGPT code block is not published anywhere. It becomes yours to answer for when you copy it to a host or rebuild it as a Site.

The Sites Terms make you the controller

A ChatGPT Site is a website or lightweight app that ChatGPT builds from a prompt and OpenAI hosts at an address ending in chatgpt.site. OpenAI launched Sites in public beta on 9 July 2026, according to its ChatGPT release notes. You start one in ChatGPT Work or Codex by asking for a website, on a Plus, Pro or workspace plan, since Sites is not offered on Free or Go.

The ChatGPT Sites Terms, updated on 23 July 2026, settle the roles in two clauses. Section 3.2 says OpenAI hosts a published Site on your behalf and processes the Site's data under its Data Processing Addendum, or the one your organisation signed. Section 3.2.1 says you are "the data controller of any personal data which is collected by your ChatGPT Site", and names three ways that happens: visitors posting or uploading content, login features such as Sign in with ChatGPT, and cookies or similar technologies. That is the usual split between a controller and a processor: you decide why the data is collected, OpenAI stores and serves it.

In the European Economic Area (EEA) and Switzerland your contract is with OpenAI Ireland Ltd, and section 1.3 lets OpenAI add a line such as "powered by ChatGPT" to your Site's footer or toolbar.

What a public Site sets before anyone clicks

OpenAI's documentation lists what Sites stores for you, but not which cookies a visitor receives. So on 9 October 2026, a headless Chromium browser opened little-ritual.openai.chatgpt.site, a public Site from OpenAI's own showcase, and recorded every response. The server set __Host-appgarden-visitor with Max-Age=7776000, which is 90 days, marked HttpOnly, so scripts on the page cannot read it. A second run with JavaScript switched off received the same cookie. Cloudflare, which serves the Site, added its own two. Every request went to the Site's own address: no third-party scripts, fonts or trackers, and nothing in local storage.

The visitor cookie, taken apart

The Set-Cookie header a public ChatGPT Site sent in its first response on 9 October 2026, taken apart. Name: __Host-appgarden-visitor, where the __Host- prefix ties the cookie to this one host. Max-Age=7776000: the cookie is kept for 7,776,000 seconds, which is 90 days. HttpOnly: scripts on the page, a consent banner included, cannot read it. Secure: it is sent only over HTTPS. SameSite=Lax: it is left out of most requests coming from other sites. The name and the lifetime are highlighted because they decide the consent question.Set-Cookie, in the first response__Host-appgarden-visitor=…The name: __Host- ties it to this one hostMax-Age=7776000Kept for 7,776,000 seconds, which is 90 daysHttpOnlyScripts on the page, a banner included, cannot read itSecureSent only over HTTPSSameSite=LaxLeft out of most requests from other sites
As sent by a public Site from OpenAI's own showcase on 9 October 2026. The value is left out. The header arrives with the page itself, so the cookie is set even with JavaScript switched off.

The two Cloudflare cookies are documented. According to Cloudflare's cookie reference, __cf_bm supports its bot protection, is encrypted and expires after 30 minutes of inactivity, and cf_clearance stores proof that a visitor passed a challenge. Cloudflare describes its cookies as strictly necessary for the service its customers request, which is the exemption Article 5(3) of the ePrivacy Directive allows. They still belong in your cookie policy.

Your own code can add to this list. A Site you ask to include analytics, a map, a video or a chat widget loads whatever those services load, and a Site built from a different starter may behave differently from the showcase one.

One cookie a banner inside the Site cannot hold back

The visitor cookie is the open question: OpenAI's developer guide for Sites says that "Sites records traffic automatically" and shows each owner the unique visitors and page views of their Site, except for Sites owned by an Enterprise workspace. Neither the guide nor the help centre names __Host-appgarden-visitor or says what it does. Its name, its 90-day lifetime and a count of unique visitors fit together, but that link is an inference, not something OpenAI states.

It matters because of where the cookie comes from. The server sets it with the page, so a consent banner written into your Site's code runs after the cookie already exists and cannot hold it back. If it is an audience-measurement identifier, most EU regulators treat it as needing consent, and the CNIL in France exempts audience measurement only under strict conditions, such as data used solely by the site itself for anonymous statistics. Whether this cookie meets them is a question only OpenAI can answer.

Until it does, three things are in your hands. Ask OpenAI support what the cookie is for and whether it can be switched off for your Site. Describe it in your cookie policy with whatever answer you get, and with its name, lifetime and the fact that the platform sets it.

Who can open the Site decides what you owe

A new Site is visible only to its owner and workspace admins until you change its access. OpenAI's help article on creating Sites lists the options in the Share panel:

  • the owner and workspace admins
  • selected users or groups, and named viewers outside the workspace
  • anyone in the workspace, where supported
  • anyone on the internet, only when public publishing is enabled

Every deployment goes live at once: OpenAI's guide says each Sites deployment URL is a production deployment, so save a version first if you want to review it. A Site shared with named colleagues still processes their data, but the public option is where strangers arrive, and with them the cookie, notice and consent questions above. In Enterprise workspaces, public publishing is off until an admin turns it on.

At the public beta launch on 9 July 2026, public publishing was not available in the EEA, Switzerland or the United Kingdom. The help article, updated in early October 2026, lists plans but no regional limit, so the Share panel is the reliable answer for your own account.

Sign in with ChatGPT passes you a name, an email and a photo

A public Site can offer Sign in with ChatGPT for saved progress or personal views. OpenAI's guidance on a privacy policy for Sites says that after a visitor approves the sign-in, OpenAI may share their name, email address and profile photo, if they have one, with the Site. The developer guide adds that the Site receives that identity in request headers, and the Sites Terms make the owner responsible for login features like this one.

So the sign-in belongs in your privacy policy: what the Site receives, why, the legal basis, how long you keep it, and how a visitor asks for it to be deleted. OpenAI's own guidance suggests linking the policy from every page, from your cookie banner and from any sign-up page.

The data sits where OpenAI hosts it

OpenAI says Sites does not support data residency or inference residency at launch. That covers the deployed Site, its code, its D1 database and R2 file storage, generated artifacts and logs. Responses come from Cloudflare, and D1 and R2 are the names of Cloudflare's database and storage products, so Cloudflare is part of the chain that serves your visitors.

For EU visitors, the transfer terms in OpenAI's Data Processing Addendum are the place to look before you store anything personal, and the help centre itself tells owners not to assume a hosting country. Some data is ruled out entirely: the Sites Terms forbid protected health information, payment card data except through a third-party payment processor, and Sites aimed at children under 13 or below the age of digital consent.

Code blocks keep an app inside the chat

Since OpenAI removed canvas from its GPT-5.5 models on 28 May 2026, small apps start life in code blocks: ChatGPT writes the code in the conversation and, since February 2026, can preview diagrams and mini apps right there. A preview in a code block runs inside chatgpt.com. It has no address of your own and no visitors of yours, so there is nothing published for the GDPR to attach to yet.

That changes the moment the app leaves the chat, and there are two ways out. Copy or download the code to your own hosting, and the checks in the GDPR checklist for apps built in ChatGPT Canvas apply: what the page loads from other companies, what it stores and what happens to form data. Or ask ChatGPT Work to rebuild it as a Site, and everything above applies. The same split runs through most AI app builders: the preview belongs to the builder, the published app to whoever publishes it.

Before you choose Anyone on the internet

  1. Open the Site in a private window, signed out, and list every cookie and storage entry in the browser's developer tools.
  2. Add a privacy policy page and link it from every page: who runs the Site, what it collects, why, the legal basis, who receives the data, OpenAI as host included, how long you keep it and how to exercise rights.
  3. Ask OpenAI what __Host-appgarden-visitor does, and record the answer in your cookie policy next to the two Cloudflare cookies.
  4. Put a consent banner in front of every non-essential cookie or script your own code adds, such as analytics, embedded media or a chat widget.
  5. Remove form fields you do not need, and say next to the form what happens to the answers.
  6. If the Site uses Sign in with ChatGPT, name the profile data it receives in the privacy policy.
  7. Check the Share panel one last time, then deploy. The new version is live for that audience the moment it deploys.

ChatGPT Sites and visitor data: quick answers

Does a ChatGPT Site need a cookie banner?

If the Site, or code you add to it, places non-essential cookies or similar technologies, section 3.2.2 of the ChatGPT Sites Terms and the ePrivacy Directive require consent first. A Site that sets only strictly necessary cookies needs them described in its cookie policy, not a banner.

Is OpenAI the controller or the processor for a ChatGPT Site?

For personal data the Site collects from visitors, the Site owner is the controller and OpenAI processes it under its Data Processing Addendum, according to the ChatGPT Sites Terms. For your own use of ChatGPT while building the Site, OpenAI's privacy policy or your organisation's agreement applies.

Can I publish a ChatGPT Site to the public from the EU?

At the public beta launch on 9 July 2026, public publishing was not available in the EEA, Switzerland or the United Kingdom. OpenAI's help article on creating Sites, updated in early October 2026, lists no regional limit, so the Share panel shows what your account can do.

Does a ChatGPT Site have built-in analytics?

Yes. OpenAI's developer guide says Sites records traffic automatically and shows unique visitors and page views, except for Sites owned by an Enterprise workspace. OpenAI does not say which cookie, if any, the count relies on.

Where is a ChatGPT Site's data stored?

OpenAI does not offer data residency or inference residency for Sites at launch, which covers the deployed Site, its code, its database and file storage, artifacts and logs. The Data Processing Addendum that applies to your account sets the transfer terms.

Scan your Site before you share the link

Before you switch a Site to anyone on the internet, run its address through the Cookie scanner. It opens the page the way a first-time visitor does and lists every cookie it finds, including HttpOnly cookies the server sets before your own code runs.