New — Sohay now answers WooCommerce product, policy & cart questions. See how →

What Sohay sends to OpenAI and Google

The complete list of what leaves your site, when, and to which service — including the part that always goes to OpenAI.

Sohay sends data to an AI provider to generate answers, and to OpenAI to index and search your Knowledge Base. This is the full list, so you can write an accurate privacy policy rather than a cautious one.

Which service receives what

The provider you select under Sohay → AI Settings receives your visitors’ chat messages. Knowledge Base indexing and search always go to OpenAI, whichever provider answers the chat.

So a site on Gemini with the Knowledge Base switched on shares data with both Google and OpenAI. That is worth stating in your privacy policy explicitly, because it is the part people get wrong.

When something is sent

When a visitor sends a chat message — the message text and recent conversation history go over HTTPS to your selected provider, and are processed by the model you configured.

When you publish or update a Knowledge Base article — its title and body are sent in the background to OpenAI’s Files and Vector Stores so the chat can retrieve them. Not while you wait on Save.

When the chatbot looks something up in your Knowledge Base — the visitor’s question goes to OpenAI’s vector search, and the matched article text is then sent on to whichever provider is writing the reply.

On a WooCommerce store, when a shopping tool runs — what it found goes back to the model so it can answer. Depending on the tool, that is product names, descriptions, prices, sale prices, stock status, categories, tags, option names and values, product page and image URLs; the text of your Terms, Privacy, and Refunds and Returns pages, plus Knowledge Base articles matched to a shipping, returns or refund question; and the contents of the shopper’s cart — items, quantities, options, and totals.

Only for the tools the chatbot actually calls, in that conversation.

What is not sent

No customer identity. The cart data describes the basket, not the shopper: no name, email address, postal address, phone number, or payment details.

No orders, refunds, or customer records. None of the shopping tools read them, so there is no path by which they could be sent.

Where it goes

All requests go over HTTPS to api.openai.com and, if you select Google, generativelanguage.googleapis.com.

Nothing else. No analytics, no telemetry, no third-party fonts, no CDN assets, no phone-home for updates. Updates come from WordPress.org.

Your responsibilities

Review the terms of the provider you select before activating — OpenAI’s Terms of Use and Privacy Policy, and for Gemini, Google’s Gemini API Additional Terms of Service and Privacy Policy. Google applies different data-handling terms to free-tier and paid API keys; read the ones for the tier you are actually on.

You are responsible for having an appropriate legal basis to share visitor messages with these services under GDPR, CCPA, and whatever else applies where you operate. On a store that basis needs to cover the shopping tools too — what a visitor has put in their cart is information about that visitor, even with no name attached.

If you would rather the cart never left your site, the shopping tools can be switched off individually. See Turning individual shopping tools off.

Where to go next

Where your API keys are stored, and Exporting and erasing visitor data.

Mithun B.
Mithun B.

More articles by Mithun B..

View all posts

Give your website an assistant that answers from your content

Grounded answers, a team inbox, and store-aware tools — free on WordPress.org.

Add Sohay — Free

Free plugin · You bring your OpenAI key · Works with any theme