Privacy Policy

Data Protection & Privacy Practices

Last Updated: March 26, 2026 | Version 3.0

Encrypted

TLS 1.3 + AES-256

No Selling

We never sell your data

Your Control

Export, delete anytime

Compliant

GDPR, CCPA, SOC 2

1. Overview & Scope

1.1 Introduction

ChaozCode Inc. ("ChaozCode," "we," "us," or "our") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard your data when you access or use our AI-powered development platform and related services.

1.2 Scope of This Policy

This Privacy Policy applies to:

  • Our website at chaozcode.com and all subdomains
  • ChaozCode platform, including Natural Language Coding (NLC) and Memory Spine
  • Our APIs, SDKs, and developer tools
  • Mobile applications (if applicable)
  • Customer support and communications

This Privacy Policy is incorporated into and subject to our Terms of Service. Terms not defined here have the meanings given in the Terms of Service.

1.3 Data Controller

ChaozCode Inc. is the data controller responsible for your personal data. For questions about this policy or your data rights, contact our Data Protection Officer at dpo@chaozcode.com.

Our Promise: We collect only what we need, protect what we collect, and give you control over your data. We never sell your personal information to third parties.

2. Information We Collect

2.1 Information You Provide Directly

Category Data Elements Purpose
Account Data Name, email, password (hashed), username Account creation, authentication
Payment Data Card details (via Stripe), billing address Process subscriptions, invoicing
Profile Data Preferences, settings, avatar, timezone Personalize your experience
Content Data Code, prompts, projects, files you create Provide platform services
Communication Data Support tickets, feedback, survey responses Customer support, product improvement

2.2 Information Collected Automatically

Category Data Elements Purpose
Device Data Browser type, OS, device identifiers Optimize experience, security
Usage Data Features used, session duration, actions Improve services, analytics
Log Data IP address, timestamps, error logs Security, troubleshooting
Location Data Country, region (from IP) Compliance, localization

2.3 Information from Third Parties

  • OAuth Providers: GitHub, Google (profile info you authorize)
  • Payment Processors: Stripe (transaction status, not full card numbers)
  • Analytics Partners: Aggregated usage patterns

3. How We Use Your Data

3.1 Primary Purposes

  • Service Delivery: Operate the platform, process your code, manage your account
  • AI Processing: Power NLC, Memory Spine, and agent orchestration features
  • Communication: Send service updates, security alerts, and support responses
  • Billing: Process payments, manage subscriptions, send invoices

3.2 Secondary Purposes

  • Product Improvement: Analyze usage patterns to enhance features
  • Security: Detect fraud, prevent abuse, protect our systems
  • Compliance: Meet legal obligations, respond to lawful requests
  • Marketing: Send product updates (with consent, easily opt-out)

3.3 AI Training

Important: We do NOT use your code or content to train our AI models without explicit opt-in consent. Your intellectual property remains yours. General usage patterns (not content) may be used to improve service performance.

5. Information Sharing

5.1 We Share Data With

  • Service Providers: Cloud hosting (AWS), payment processing (Stripe), email delivery (SendGrid), analytics (privacy-focused)
  • Professional Advisors: Lawyers, accountants, auditors (under confidentiality)
  • Business Transfers: In connection with merger, acquisition, or sale of assets
  • Legal Requirements: When required by law, court order, or to protect rights

5.2 We Never

  • Sell your personal data to data brokers or advertisers
  • Share your code or content with third parties without consent
  • Allow advertising networks to track you on our platform

5.3 Data Processing Agreements

All third-party service providers are bound by data processing agreements that require them to protect your data and use it only for specified purposes. A current list of Subprocessors is available upon request by emailing privacy@chaozcode.com. We will notify Enterprise customers at least 30 days before engaging new Subprocessors that process personal data.

6. Data Security

6.1 Technical Measures

  • Encryption in Transit: TLS 1.3 for all connections
  • Encryption at Rest: AES-256 for stored data
  • Password Security: Bcrypt hashing with per-user salts
  • Access Control: Role-based access, principle of least privilege
  • Infrastructure: SOC 2 Type II certified cloud providers

6.2 Organizational Measures

  • Employee security training and background checks
  • Incident response procedures and dedicated security team
  • Regular security audits and penetration testing
  • Vendor security assessments

6.3 Data Breach Notification

In the event of a data breach affecting your personal data, we will:

  • Notify affected users without undue delay and no later than 72 hours after becoming aware of the breach, as required by GDPR Article 33
  • Provide details of the nature of the breach, categories of data affected, and approximate number of records involved
  • Describe the measures taken or proposed to address the breach and mitigate potential adverse effects
  • Report to relevant supervisory authorities where legally required
  • Maintain an internal breach register documenting all incidents regardless of severity

6.4 Your Responsibilities

You are responsible for maintaining the security of your account credentials, using strong passwords, and enabling two-factor authentication when available.

7. Data Retention

7.1 Retention Periods

Data Category Retention Period Reason
Account Data Duration of account + 30 days Allow data recovery
Content/Code Duration of account + 30 days Service provision, export window
Billing Records 7 years after transaction Tax and legal compliance
Support Tickets 3 years after resolution Service quality, legal protection
Security Logs 90 days Security investigation
Analytics Data 26 months (aggregated) Trend analysis

7.2 Deletion

When you delete your account or request deletion, we permanently erase your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention).

8. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal data:

Access

Request a copy of your personal data

Rectification

Correct inaccurate or incomplete data

Erasure

Request deletion of your data

Portability

Export data in JSON or CSV format

Restriction

Limit how we process your data

Objection

Object to certain processing activities

Withdraw Consent

Revoke consent at any time without affecting prior processing

8.1 How to Exercise Your Rights

  • Self-Service: Access account settings to update, export, or delete data
  • Email: Contact privacy@chaozcode.com with your request
  • General Support: support@chaozcode.com for account-related inquiries
  • Acknowledgment: We acknowledge all privacy requests within 5 business days
  • Completion: Data subject requests are fulfilled within 30 days (extended to 45 days for complex requests with prior notice)
  • Verification: We may verify your identity before processing requests

8.2 Regional Rights

  • GDPR (EU/EEA): Full data subject rights, right to lodge complaint with supervisory authority
  • CCPA (California): Right to know, delete, opt-out of sale (we don't sell)
  • LGPD (Brazil): Similar rights to GDPR, including data portability

8.3 California Residents — "Do Not Sell or Share"

Under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), California residents have the right to opt out of the "sale" or "sharing" of personal information. ChaozCode does not sell your personal information and does not share it for cross-context behavioral advertising. If this practice ever changes, we will provide a clear "Do Not Sell or Share My Personal Information" link and notify you in advance. To submit a CCPA request, email privacy@chaozcode.com with the subject line "CCPA Request."

9. Cookies & Tracking

9.1 Types of Cookies We Use

Type Purpose Duration
Essential Authentication, security, basic functionality Session / 1 year
Functional Remember preferences, settings 1 year
Analytics Understand usage patterns (privacy-focused) 26 months

9.2 What We Don't Use

  • Third-party advertising cookies
  • Cross-site tracking pixels
  • Social media trackers

9.3 Managing Cookies

You can control cookies through your browser settings. Blocking essential cookies may affect platform functionality. For more details, see our Cookie Policy.

10. AI & Automated Processing

10.1 How We Use AI

  • Code Generation: NLC processes your prompts to generate code
  • Memory Spine: Stores and retrieves context for improved assistance
  • Agent Orchestration: Coordinates AI agents to complete tasks
  • Recommendations: Suggest features, tools, or content based on usage

10.2 Automated Decision-Making

We use automated processing for:

  • Fraud detection and security screening
  • Usage limit enforcement
  • Content moderation (flagging potentially harmful outputs)

These decisions may be appealed by contacting support. No solely automated decisions significantly affect your legal rights without human review.

10.3 Your AI Data Rights

Opt-Out: You can request that your content not be used for AI improvement. Contact privacy@chaozcode.com to opt out. This does not affect core service functionality.

11. Children's Privacy

ChaozCode services are not directed to children under 13 years of age. We do not knowingly collect personal data from children under 13 in compliance with COPPA (Children's Online Privacy Protection Act). Users must be at least 18 years of age (or the age of majority in their jurisdiction) to create an account, as specified in our Terms of Service.

11.1 Parental Notice

If you believe we have inadvertently collected data from a child under 13, please contact us immediately at privacy@chaozcode.com. We will promptly delete such information.

11.2 Educational Use

Educational institutions using ChaozCode for students under 18 must obtain appropriate parental/guardian consent. For students under 13, institutions must ensure compliance with COPPA and FERPA. We support school-managed accounts where the institution acts as the consenting party on behalf of the student.

12. International Data Transfers

12.1 Data Location

Your data may be processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards are in place:

  • EU-US Data Privacy Framework: Certified for transatlantic transfers
  • Standard Contractual Clauses: EU-approved contracts with processors
  • Adequacy Decisions: Transfers to countries with adequate protection

12.2 Data Residency

Enterprise customers may request data residency in specific regions (EU, US). Contact sales@chaozcode.com for options.

12.3 Data Processing Agreement (DPA)

Enterprise customers and organizations subject to GDPR or other data protection regulations may request a Data Processing Agreement (DPA) by contacting legal@chaozcode.com. Our standard DPA includes Standard Contractual Clauses (SCCs) for international data transfers and addresses data security, breach notification, subprocessor management, and data subject rights.

13. Policy Updates

13.1 How We Notify You

  • Material changes: Email notification at least 30 days before effective date
  • Minor changes: Updated "Last Updated" date on this page
  • Significant changes: In-app notification banner

13.2 Review History

Previous versions of this policy are available upon request. Contact privacy@chaozcode.com for historical versions.

13.3 Your Options

If you disagree with changes, you may close your account before the new policy takes effect. Continued use after the effective date constitutes acceptance.

14. Contact & DPO

14.1 Privacy Inquiries

For questions about this policy or to exercise your privacy rights:

  • Privacy: privacy@chaozcode.com
  • Data Protection Officer: dpo@chaozcode.com
  • Legal: legal@chaozcode.com
  • General Support: support@chaozcode.com

14.2 Supervisory Authority

If you are in the EU/EEA and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection authority.

14.3 Response Commitment

We acknowledge all privacy inquiries within 5 business days. Data subject access requests are completed within 30 days. Complex requests may be extended by an additional 15 days with prior notice.

14.4 Healthcare Disclaimer

ChaozCode is not a HIPAA covered entity and does not offer Business Associate Agreements (BAAs). Our Services are not designed for processing, storing, or transmitting Protected Health Information (PHI) as defined by HIPAA. If you are subject to HIPAA, you should not use our Services to process PHI.

Questions About Your Privacy?

Our privacy team is here to help with any data protection inquiries.