Since we have an option to use any OpenAI-compatible AI provider, I think we should (or not?) add a paragraph to privacy notice like this:
JabRef supports connections to AI providers with OpenAI-compatible APIs, but it does not control or guarantee their behavior or privacy practices. If this option is used, the privacy policy of the selected provider should be manually reviewed to understand how data is handled.