Privacy Policy

Data Protection & Privacy Practices

🔒 Last Updated: January 30, 2026 | Version 2.0
🔐

Encrypted

TLS 1.3 + AES-256

🚫

No Selling

We never sell your data

🎛️

Your Control

Export, delete anytime

Compliant

GDPR, CCPA, SOC 2

1. Overview & Scope

1.1 Introduction

ChaozCode Inc. ("ChaozCode," "we," "us," or "our") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard your data when you access or use our AI-powered development platform and related services.

1.2 Scope of This Policy

This Privacy Policy applies to:

  • Our website at chaozcode.com and all subdomains
  • ChaozCode platform, including Natural Language Coding (NLC) and Memory Spine
  • Our APIs, SDKs, and developer tools
  • Mobile applications (if applicable)
  • Customer support and communications

1.3 Data Controller

ChaozCode Inc. is the data controller responsible for your personal data. For questions about this policy or your data rights, contact our Data Protection Officer at dpo@chaozcode.com.

Our Promise: We collect only what we need, protect what we collect, and give you control over your data. We never sell your personal information to third parties.

2. Information We Collect

2.1 Information You Provide Directly

Category Data Elements Purpose
Account Data Name, email, password (hashed), username Account creation, authentication
Payment Data Card details (via Stripe), billing address Process subscriptions, invoicing
Profile Data Preferences, settings, avatar, timezone Personalize your experience
Content Data Code, prompts, projects, files you create Provide platform services
Communication Data Support tickets, feedback, survey responses Customer support, product improvement

2.2 Information Collected Automatically

Category Data Elements Purpose
Device Data Browser type, OS, device identifiers Optimize experience, security
Usage Data Features used, session duration, actions Improve services, analytics
Log Data IP address, timestamps, error logs Security, troubleshooting
Location Data Country, region (from IP) Compliance, localization

2.3 Information from Third Parties

  • OAuth Providers: GitHub, Google (profile info you authorize)
  • Payment Processors: Stripe (transaction status, not full card numbers)
  • Analytics Partners: Aggregated usage patterns

3. How We Use Your Data

3.1 Primary Purposes

  • Service Delivery: Operate the platform, process your code, manage your account
  • AI Processing: Power NLC, Memory Spine, and agent orchestration features
  • Communication: Send service updates, security alerts, and support responses
  • Billing: Process payments, manage subscriptions, send invoices

3.2 Secondary Purposes

  • Product Improvement: Analyze usage patterns to enhance features
  • Security: Detect fraud, prevent abuse, protect our systems
  • Compliance: Meet legal obligations, respond to lawful requests
  • Marketing: Send product updates (with consent, easily opt-out)

3.3 AI Training

Important: We do NOT use your code or content to train our AI models without explicit opt-in consent. Your intellectual property remains yours. General usage patterns (not content) may be used to improve service performance.

5. Information Sharing

5.1 We Share Data With

  • Service Providers: Cloud hosting (AWS), payment processing (Stripe), email delivery (SendGrid), analytics (privacy-focused)
  • Professional Advisors: Lawyers, accountants, auditors (under confidentiality)
  • Business Transfers: In connection with merger, acquisition, or sale of assets
  • Legal Requirements: When required by law, court order, or to protect rights

5.2 We Never

  • Sell your personal data to data brokers or advertisers
  • Share your code or content with third parties without consent
  • Allow advertising networks to track you on our platform

5.3 Data Processing Agreements

All third-party service providers are bound by data processing agreements that require them to protect your data and use it only for specified purposes.

6. Data Security

6.1 Technical Measures

  • Encryption in Transit: TLS 1.3 for all connections
  • Encryption at Rest: AES-256 for stored data
  • Password Security: Bcrypt hashing with per-user salts
  • Access Control: Role-based access, principle of least privilege
  • Infrastructure: SOC 2 Type II certified cloud providers

6.2 Organizational Measures

  • Employee security training and background checks
  • Incident response procedures and breach notification
  • Regular security audits and penetration testing
  • Vendor security assessments

6.3 Your Responsibilities

You are responsible for maintaining the security of your account credentials, using strong passwords, and enabling two-factor authentication when available.

7. Data Retention

7.1 Retention Periods

Data Category Retention Period Reason
Account Data Duration of account + 30 days Allow data recovery
Content/Code Duration of account + 30 days Service provision, export window
Billing Records 7 years after transaction Tax and legal compliance
Support Tickets 3 years after resolution Service quality, legal protection
Security Logs 90 days Security investigation
Analytics Data 26 months (aggregated) Trend analysis

7.2 Deletion

When you delete your account or request deletion, we permanently erase your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention).

8. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal data:

👁️

Access

Request a copy of your personal data

✏️

Rectification

Correct inaccurate or incomplete data

🗑️

Erasure

Request deletion of your data

📦

Portability

Export data in machine-readable format

⏸️

Restriction

Limit how we process your data

🚫

Objection

Object to certain processing activities

8.1 How to Exercise Your Rights

  • Self-Service: Access account settings to update, export, or delete data
  • Email: Contact privacy@chaozcode.com with your request
  • Response Time: We respond within 30 days (45 for complex requests)
  • Verification: We may verify your identity before processing requests

8.2 Regional Rights

  • GDPR (EU/EEA): Full data subject rights, right to lodge complaint with supervisory authority
  • CCPA (California): Right to know, delete, opt-out of sale (we don't sell)
  • LGPD (Brazil): Similar rights to GDPR, including data portability

9. Cookies & Tracking

9.1 Types of Cookies We Use

Type Purpose Duration
Essential Authentication, security, basic functionality Session / 1 year
Functional Remember preferences, settings 1 year
Analytics Understand usage patterns (privacy-focused) 26 months

9.2 What We Don't Use

  • Third-party advertising cookies
  • Cross-site tracking pixels
  • Social media trackers

9.3 Managing Cookies

You can control cookies through your browser settings. Blocking essential cookies may affect platform functionality. We respect "Do Not Track" browser signals.

10. AI & Automated Processing

10.1 How We Use AI

  • Code Generation: NLC processes your prompts to generate code
  • Memory Spine: Stores and retrieves context for improved assistance
  • Agent Orchestration: Coordinates AI agents to complete tasks
  • Recommendations: Suggest features, tools, or content based on usage

10.2 Automated Decision-Making

We use automated processing for:

  • Fraud detection and security screening
  • Usage limit enforcement
  • Content moderation (flagging potentially harmful outputs)

These decisions may be appealed by contacting support. No solely automated decisions significantly affect your legal rights without human review.

10.3 Your AI Data Rights

Opt-Out: You can request that your content not be used for AI improvement. Contact privacy@chaozcode.com to opt out. This does not affect core service functionality.

11. Children's Privacy

ChaozCode services are not directed to individuals under 16 years of age (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal data from children.

11.1 Parental Notice

If you believe we have inadvertently collected data from a child, please contact us immediately at privacy@chaozcode.com. We will promptly delete such information.

11.2 Educational Use

Educational institutions using ChaozCode for students under 16 must obtain appropriate parental/guardian consent and are responsible for compliance with COPPA, FERPA, and similar laws.

12. International Data Transfers

12.1 Data Location

Your data may be processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards are in place:

  • EU-US Data Privacy Framework: Certified for transatlantic transfers
  • Standard Contractual Clauses: EU-approved contracts with processors
  • Adequacy Decisions: Transfers to countries with adequate protection

12.2 Data Residency

Enterprise customers may request data residency in specific regions (EU, US). Contact sales@chaozcode.com for options.

13. Policy Updates

13.1 How We Notify You

  • Material changes: Email notification at least 30 days before effective date
  • Minor changes: Updated "Last Updated" date on this page
  • Significant changes: In-app notification banner

13.2 Review History

Previous versions of this policy are available upon request. Contact privacy@chaozcode.com for historical versions.

13.3 Your Options

If you disagree with changes, you may close your account before the new policy takes effect. Continued use after the effective date constitutes acceptance.

14. Contact & DPO

14.1 Privacy Inquiries

For questions about this policy or to exercise your privacy rights:

  • Email: privacy@chaozcode.com
  • Data Protection Officer: dpo@chaozcode.com
  • Address: ChaozCode Inc., Privacy Team

14.2 Supervisory Authority

If you are in the EU/EEA and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection authority.

14.3 Response Commitment

We aim to respond to all privacy inquiries within 5 business days, and complete data requests within 30 days.