OpenAI's app terms now cover ChatGPT calling your app on its own

Stani Mihov
Founder & CEO
·

TL;DR
Vendor: OpenAI
Document: App Developer Terms (the agreement for ChatGPT apps, connectors, plugins, and custom GPT actions)
Date: September 28, 2026
Key change: OpenAI's access to a developer's app now expressly includes "ongoing or proactive interactions," such as subscribing to updates or requesting information for suggestions and personalization. App Requests no longer have to be sent on behalf of a user, and App Responses now cover anything the app's API provides in connection with the app.
The update is dated one day before DevDay, where OpenAI announced plugins that start automations when something happens in a connected app. For a SaaS company with a ChatGPT app, it means calls to its API that no one typed in a chat, and a wider set of API output under the license OpenAI already had.
The change
On September 28, 2026, OpenAI updated its App Developer Terms, the agreement that applies to anyone who builds a ChatGPT app, connector, plugin, or custom GPT action. The previous version was dated July 9, 2026.
The next day, at DevDay 2026, OpenAI announced support for the proposed MCP Events specification, so that plugins can "start automations when something happens in a connected app," according to the DevDay recap. The terms update is short: one new sentence and two rewritten definitions. Together they cover ChatGPT using an app when nobody is asking it to in that moment.
What changed
Proactive access. Section 1.1 already let OpenAI access a developer's API and let users work with the app through ChatGPT. A new sentence adds: "For clarity, such access and use may include ongoing or proactive interactions, such as subscribing to updates to help carry out a user's ongoing tasks, or requesting information to provide relevant suggestions or personalize a user's experience."
App Requests. The old text said ChatGPT "may send a request to your API ("App Request") on behalf of a User." The new text says it "may send requests to your API ("App Requests") to enable or operate your App within the Services, including on behalf of a User."
App Responses. An App Response used to be what the app sent back "When your API receives an App Request." It is now any "information or content" the API provides "in connection with your App, including in response to App Requests."
What proactive access looks like
The new sentence gives two examples. The first is subscribing to updates to carry out a user's ongoing task. OpenAI's own DevDay example fits it: a user asks ChatGPT to watch a project board, and when a new task comes in, ChatGPT reads the linked documents and drafts a plan while the user is away. The MCP Events developer guide describes how a plugin exposes those events.
The second example is requesting information to provide suggestions or personalize a user's experience. That is a call to the app's API whose purpose is to help ChatGPT decide what to show or suggest, rather than to answer a question the user just typed.
OpenAI frames the sentence as a clarification, starting with "For clarity," of the access right Section 1.1 already granted. The DevDay recap also says users choose which plugins to use and approve the access each one receives. What the terms now say in writing is that, once that access exists, it is not limited to moments when the user is actively prompting.
More of your API's output falls under OpenAI's license
Section 1.3 already gave OpenAI a worldwide, nonexclusive, royalty-free license to "use, store, copy, translate, display, modify, and distribute the App Responses." That license did not change. What changed is what counts as an App Response. Before, it was the reply to a request. Now it is anything the API provides in connection with the app, which includes data sent through a subscription or returned for a suggestion.
Two sentences in the same section also stayed the same. OpenAI's use of App Requests and App Responses inside a user's conversations is governed by OpenAI's terms with that user, "which may include use of such content to provide, maintain, develop, and improve our Services." And if a developer removes an app, OpenAI "may continue to use prior App Responses" under those user terms. With a wider definition of App Responses, both sentences now reach more of what an app sends.
What did not change
Developers still may not use App Requests to develop models that compete with OpenAI.
The privacy section still requires developers to process personal data "as authorized by the User" and under a privacy notice presented to the user before processing.
OpenAI's total liability under these terms is still capped at $100.
Material changes still take effect 15 days after OpenAI posts them, and "Your continued availability of your App will constitute acceptance of the updated terms."
Why this matters
For a SaaS company with a ChatGPT app, the API used to see traffic that followed a user's prompt. Under the new wording, it can also see subscriptions to updates, event notifications sent while the user is away, and calls whose purpose is personalization. That affects rate limits and infrastructure costs, what shows up in logs, and whether the company's privacy notice describes data leaving its systems when the user is not in the conversation.
It is the same direction we have seen across AI vendors this month, as when HubSpot made customers answer for what its AI agents do, and it follows OpenAI's own September privacy update, which let it use data from advertisers for more than ads. Agents are moving from answering questions to acting in the background, and the contracts are being rewritten to match, as they were when Meta rewrote its privacy policy around agentic AI. Tracking which AI platforms touch company data, and under which terms, is part of monitoring AI subprocessors.
Potential impact
For a company that has published an app, plugin, connector, or GPT action for ChatGPT, the update raises five practical questions:
Can your API tell the difference between calls that follow a user's prompt and background calls from ChatGPT, and do rate limits and costs account for both?
If you support MCP Events, which events do you expose, and what data does each one send?
What does your API return when ChatGPT asks for information to make suggestions, and are you comfortable with all of it falling under OpenAI's App Response license?
Does your privacy notice cover data sent to ChatGPT through subscriptions or background requests, as the privacy section requires?
Who in your company reads OpenAI's developer terms when they change, given that keeping the app available counts as acceptance?
Terms that apply by staying on a platform, rather than by signing, are one of the hidden risks of vendor legal changes.
How Venpo detected it
Venpo monitors OpenAI's legal documents as part of continuous vendor risk monitoring. It flagged the new App Developer Terms and marked the inserted and deleted text in Sections 1.1, 1.2, and 1.3, and every quote in this article was checked against the redline and the live page. The full redline is on the OpenAI change page, and every monitored OpenAI document is listed on the OpenAI vendor profile.
Business outcome
If OpenAI treats the update as material, it takes effect 15 days after posting, on October 13, 2026. Teams that track OpenAI got the exact wording in time to check how their app handles background calls, review what their API returns for suggestions, and update the privacy notice before then. The alternative is noticing a new pattern of calls in the API logs and only then finding the sentence that allows it.
Key takeaway
OpenAI's September 28 update puts proactive, ongoing access to developer apps in writing and widens what counts as an App Response under the license OpenAI already had. It arrived one day before OpenAI launched event-driven plugins, which is why the reliable way to keep up with platform terms is to track them every time they change.
The change
On September 28, 2026, OpenAI updated its App Developer Terms, the agreement that applies to anyone who builds a ChatGPT app, connector, plugin, or custom GPT action. The previous version was dated July 9, 2026.
The next day, at DevDay 2026, OpenAI announced support for the proposed MCP Events specification, so that plugins can "start automations when something happens in a connected app," according to the DevDay recap. The terms update is short: one new sentence and two rewritten definitions. Together they cover ChatGPT using an app when nobody is asking it to in that moment.
What changed
Proactive access. Section 1.1 already let OpenAI access a developer's API and let users work with the app through ChatGPT. A new sentence adds: "For clarity, such access and use may include ongoing or proactive interactions, such as subscribing to updates to help carry out a user's ongoing tasks, or requesting information to provide relevant suggestions or personalize a user's experience."
App Requests. The old text said ChatGPT "may send a request to your API ("App Request") on behalf of a User." The new text says it "may send requests to your API ("App Requests") to enable or operate your App within the Services, including on behalf of a User."
App Responses. An App Response used to be what the app sent back "When your API receives an App Request." It is now any "information or content" the API provides "in connection with your App, including in response to App Requests."
What proactive access looks like
The new sentence gives two examples. The first is subscribing to updates to carry out a user's ongoing task. OpenAI's own DevDay example fits it: a user asks ChatGPT to watch a project board, and when a new task comes in, ChatGPT reads the linked documents and drafts a plan while the user is away. The MCP Events developer guide describes how a plugin exposes those events.
The second example is requesting information to provide suggestions or personalize a user's experience. That is a call to the app's API whose purpose is to help ChatGPT decide what to show or suggest, rather than to answer a question the user just typed.
OpenAI frames the sentence as a clarification, starting with "For clarity," of the access right Section 1.1 already granted. The DevDay recap also says users choose which plugins to use and approve the access each one receives. What the terms now say in writing is that, once that access exists, it is not limited to moments when the user is actively prompting.
More of your API's output falls under OpenAI's license
Section 1.3 already gave OpenAI a worldwide, nonexclusive, royalty-free license to "use, store, copy, translate, display, modify, and distribute the App Responses." That license did not change. What changed is what counts as an App Response. Before, it was the reply to a request. Now it is anything the API provides in connection with the app, which includes data sent through a subscription or returned for a suggestion.
Two sentences in the same section also stayed the same. OpenAI's use of App Requests and App Responses inside a user's conversations is governed by OpenAI's terms with that user, "which may include use of such content to provide, maintain, develop, and improve our Services." And if a developer removes an app, OpenAI "may continue to use prior App Responses" under those user terms. With a wider definition of App Responses, both sentences now reach more of what an app sends.
What did not change
Developers still may not use App Requests to develop models that compete with OpenAI.
The privacy section still requires developers to process personal data "as authorized by the User" and under a privacy notice presented to the user before processing.
OpenAI's total liability under these terms is still capped at $100.
Material changes still take effect 15 days after OpenAI posts them, and "Your continued availability of your App will constitute acceptance of the updated terms."
Why this matters
For a SaaS company with a ChatGPT app, the API used to see traffic that followed a user's prompt. Under the new wording, it can also see subscriptions to updates, event notifications sent while the user is away, and calls whose purpose is personalization. That affects rate limits and infrastructure costs, what shows up in logs, and whether the company's privacy notice describes data leaving its systems when the user is not in the conversation.
It is the same direction we have seen across AI vendors this month, as when HubSpot made customers answer for what its AI agents do, and it follows OpenAI's own September privacy update, which let it use data from advertisers for more than ads. Agents are moving from answering questions to acting in the background, and the contracts are being rewritten to match, as they were when Meta rewrote its privacy policy around agentic AI. Tracking which AI platforms touch company data, and under which terms, is part of monitoring AI subprocessors.
Potential impact
For a company that has published an app, plugin, connector, or GPT action for ChatGPT, the update raises five practical questions:
Can your API tell the difference between calls that follow a user's prompt and background calls from ChatGPT, and do rate limits and costs account for both?
If you support MCP Events, which events do you expose, and what data does each one send?
What does your API return when ChatGPT asks for information to make suggestions, and are you comfortable with all of it falling under OpenAI's App Response license?
Does your privacy notice cover data sent to ChatGPT through subscriptions or background requests, as the privacy section requires?
Who in your company reads OpenAI's developer terms when they change, given that keeping the app available counts as acceptance?
Terms that apply by staying on a platform, rather than by signing, are one of the hidden risks of vendor legal changes.
How Venpo detected it
Venpo monitors OpenAI's legal documents as part of continuous vendor risk monitoring. It flagged the new App Developer Terms and marked the inserted and deleted text in Sections 1.1, 1.2, and 1.3, and every quote in this article was checked against the redline and the live page. The full redline is on the OpenAI change page, and every monitored OpenAI document is listed on the OpenAI vendor profile.
Business outcome
If OpenAI treats the update as material, it takes effect 15 days after posting, on October 13, 2026. Teams that track OpenAI got the exact wording in time to check how their app handles background calls, review what their API returns for suggestions, and update the privacy notice before then. The alternative is noticing a new pattern of calls in the API logs and only then finding the sentence that allows it.
Key takeaway
OpenAI's September 28 update puts proactive, ongoing access to developer apps in writing and widens what counts as an App Response under the license OpenAI already had. It arrived one day before OpenAI launched event-driven plugins, which is why the reliable way to keep up with platform terms is to track them every time they change.
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
