Legal
Privacy Policy
Effective August 10, 2026
What we collect
We collect account details such as email address, authentication identifiers, plan status, and security-session records. If you pay, our payment processor handles card details and returns billing identifiers, invoices, and payment status to us. We collect service-operation data such as storage totals, entitlement check-ins, device labels you provide, support messages, and security logs.
Project content enters our systems when you use the hosted workspace, upload a project, or direct a copilot request through the service. Provider account credentials and API keys you add are treated as secrets and used only to make the requests you direct. The public marketing site does not use advertising trackers.
How we use data
We use data to authenticate you, provide and secure the Services, process subscriptions, enforce limits, deliver service email, troubleshoot requests, prevent abuse, and meet legal obligations. We do not sell personal information or use project content to train a public model.
Service providers
We share only the data needed with infrastructure, email, payment, identity, and AI providers that perform a service on our behalf or at your direction. If you choose Google or GitHub sign-in, that provider supplies the verified identity information you authorize. When you select an AI provider, the prompt and necessary project context are processed under that provider's terms, privacy policy, retention policy, and billing arrangement.
Retention
We retain account and billing records while your account is active and as needed for tax, fraud, dispute, and legal obligations. Session and security logs are kept for a limited operational period. Deleting hosted project content removes it from active systems; encrypted backups expire on their rotation schedule.
Your choices
You can review account data, revoke sessions and devices, remove provider connections, export project files, and request account deletion. Some transaction and security records must be retained where law or legitimate fraud-prevention needs require it. Contact privacy@chudware.com to make a privacy request.
Security and transfers
We use access controls, encrypted transport, password hashing, secret isolation, and operational monitoring designed to protect data. No system can guarantee absolute security. Service providers may process data in jurisdictions different from yours under their applicable safeguards.
Children and changes
The Services are not directed to children under 13. We will post material changes on this page and update the effective date. Questions may be sent to privacy@chudware.com.