1. Information We Collect
Account and contact information
We collect information you provide when creating or managing an account or contacting us.
- Name, email address, username, account identifiers, country or region, language, timezone, communication preferences, and support communications.
Billing and transaction information
We receive records needed to provide paid features and administer credits.
- Billing address, transaction and customer identifiers, payment status, purchased or consumed credits, tax information, refunds, chargebacks, disputes, affiliate activity, and related records.
- Payment-card details are generally entered directly into Stripe-hosted fields and are not available to ChanTan.
User Content
User Content includes material you submit, generate, store, transmit, or process through the Services.
- Prompts, chats, instructions, source and generated code, project files, documents, images, screenshots, audio and voice recordings, generated media, project configurations, databases, logs, browser-automation data, websites, applications, and other project material.
- As between you and ChanTan, and subject to applicable law and third-party rights, you retain the rights you have in your User Content and generated outputs. You are responsible for reviewing, using, publishing, licensing, and ensuring the legality of that material.
- You are responsible for having the rights and lawful basis needed to provide User Content, including information about other people.
Connected services, credentials, domains, and publishing
If you connect or use another service, we process the information needed to perform your instructions.
- GitHub account and repository details, installation identifiers, permissions, and encrypted access credentials.
- Supabase project details, database configuration, encrypted keys or personal access tokens, user-provided API secrets, deployment configuration, and service status.
- Domain searches and orders, registration and DNS information, registrar references, billing status, and any required registrant contact details.
- Published project files, hostnames, public URLs, and deployment metadata. Content you publish is available to the public.
Technical, monitoring, and usage information
We automatically collect IP address, approximate location derived from IP, browser, device, operating system, language, referring page, session and login activity, feature interactions, request metadata, network information, resource use, cookies, local or session storage, errors, and performance data.
- On production services, New Relic monitoring starts when the application loads. It may use cookies and a pseudonymous internal user ID after sign-in.
- Session Replay is enabled for approximately 5% of normal sessions and 100% of sessions in which an error occurs. Replays may capture page interactions needed to diagnose an issue.
- Form inputs and identified sensitive elements are masked or blocked. Passwords, API keys, access or refresh tokens, database credentials and connection strings, revealed secrets and environment values, payment-card fields, and domain authorization codes are intended to be excluded from replay capture. No masking system can eliminate every risk, so do not enter unnecessary sensitive information.
Security, fraud, and support information
We collect information needed to secure, support, and troubleshoot the Services.
- Authentication events, suspicious login information, fraud and abuse signals, rate-limit events, malware or network indicators, account associations, reports, enforcement history, support messages, diagnostic logs, screenshots, files, and incident information.
- Authorized personnel and contractors may access relevant information when needed for support, reliability, security, fraud prevention, legal compliance, or service operation.
2. How We Use Information
We use information where necessary to provide the Services, comply with law, pursue legitimate business and security interests, and obtain consent when required.
- Create and administer accounts; execute instructions; process and route AI requests; generate code, applications, content, and media; host and publish projects; and operate databases, storage, voice, domains, and connected services.
- Process transactions, credits, refunds, affiliate rewards, and account communications.
- Provide support; diagnose failures; monitor performance; improve reliability, functionality, safety, accessibility, and usability.
- Prevent fraud, abuse, prohibited activity, and security incidents; enforce agreements; protect legal rights; comply with lawful requests; maintain records; and establish or defend claims.
3. AI Routing and Third-Party Models
ChanTan orchestrates AI services. A request may be divided into tasks and processed sequentially or simultaneously by different models, inference providers, tools, and infrastructure providers. Different parts of one project may therefore be processed by different providers and in different locations.
Models and providers may be added, removed, replaced, or changed as technology and availability evolve. We disclose prompts, User Content, and related context only as reasonably necessary to perform your request, secure or support the Services, or as otherwise described in this Policy. AI output may be inaccurate, and you should review it before use.
4. Model Training and Service Improvement
ChanTan does not use private User Content to train ChanTan-owned general-purpose foundation models. We may use aggregated, statistical, operational, security, performance, or de-identified information, and feedback you voluntarily submit, to operate and improve the Services.
Third-party model providers process content under the applicable agreements, account settings, and privacy terms governing those services. Their retention and use practices can differ, and ChanTan does not control independent third-party practices. We may review specific User Content where reasonably necessary for support, debugging, security, abuse prevention, legal compliance, or enforcement.
5. Service Providers and Other Recipients
We disclose information to vendors and recipients that help operate the Services. Current examples may include the following, depending on the feature you use. Our architecture changes, so providers may be added, removed, or replaced.
- Cloudflare for network, hosting, security, bot protection, storage, and AI gateway services.
- Supabase for authentication, databases, storage, backups, and managed project infrastructure.
- Stripe for payments, refunds, disputes, fraud prevention, and transaction records.
- New Relic for browser monitoring, diagnostics, error reporting, and Session Replay.
- GitHub for optional repository connection, import, and export features; Resend for service emails; and domain registrars for domain searches, purchases, registration, DNS, and transfers.
- AI and model providers, including providers such as OpenAI, Anthropic, and Google, when their models or services are selected or routed to perform a request.
- Professional advisers, auditors, insurers, support providers, authorities, and other recipients where necessary for the purposes in this Policy.
6. We Do Not Sell Personal Information
ChanTan does not sell personal information for money and does not use it for third-party cross-context behavioral advertising. We do disclose information to service providers and other recipients for the business, operational, security, and legal purposes described in this Policy.
7. International Processing
ChanTan operates globally using distributed providers. Information may be stored, transmitted, accessed, or processed in the United States and other countries where ChanTan or its providers operate. Those countries may have different privacy laws. Where required, we use legally recognized safeguards for international transfers.
8. Retention and Deletion
We retain information for as long as reasonably necessary for the purposes described in this Policy. The period depends on the information, the feature, account and project status, provider backup cycles, security needs, disputes, and legal or accounting obligations.
- Account and User Content may remain while your account, project, hosted service, or workspace is active.
- After a valid deletion request or product deletion action, we remove or de-identify applicable information from active systems through our normal processes, subject to technical limitations and lawful exceptions.
- Copies may remain for a limited period in encrypted backups, disaster-recovery systems, logs, caches, fraud and security records, or records needed for tax, accounting, disputes, enforcement, or legal holds.
- Third-party services, connected accounts, public websites, domain registries, recipients, and repositories to which you exported or published content may retain their own copies under their policies. Deleting from ChanTan does not automatically delete those external copies.
- We may shorten retention when information is no longer needed or preserve relevant records for an investigation, legal request, incident, claim, or other lawful purpose.
9. Legal Requests, Safety, and Enforcement
We may preserve, access, review, or disclose information when reasonably necessary and legally permitted.
- To comply with law, subpoenas, warrants, court orders, or binding requests from authorities.
- To investigate fraud, cybersecurity incidents, abuse, illegal activity, or violations of our agreements.
- To protect the rights, property, systems, personnel, users, or safety of ChanTan and others; respond to emergencies; or establish, exercise, and defend legal claims.
- We may preserve information after a lawful preservation request. Where permitted and appropriate, we may notify affected users, but may withhold notice when prohibited or when notice could create risk or interfere with an investigation.
10. Corporate Transactions
If ChanTan is involved in a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, investment, or change of control, information may be disclosed or transferred as part of that transaction, subject to applicable law and appropriate confidentiality protections.
12. Your Privacy Rights
Depending on your location, you may have the following rights, subject to legal limitations and exceptions.
- Request information about processing, access, correction, deletion, or a portable copy of applicable personal information.
- Object to or restrict certain processing, withdraw consent where processing relies on consent, appeal certain decisions, request disclosure information, and complain to an applicable regulator.
- Use an authorized agent where the law permits and receive equal service without unlawful discrimination for exercising protected rights.
- Submit a request to [email protected] . We may request information reasonably necessary to verify identity, authority, and the scope of the request.
13. Sensitive and Regulated Information
Unless expressly authorized by a separate written agreement, do not use general-access Services for information subject to specialized regulation or heightened protection.
- Protected health information, payment-card authentication data, government-classified information, highly sensitive government identifiers, third-party passwords, biometric identification databases, children's information, unlawfully obtained information, or data requiring specialized contractual or security obligations.
- Enterprise customers requiring specific compliance commitments, data-processing terms, or service levels must enter an appropriate written agreement with ChanTan.
14. Security and General-Access Service Limitations
ChanTan uses administrative, organizational, and technical measures designed to protect information, including access restrictions and encryption for designated credentials and secrets. No online service, network, database, AI system, transmission method, or safeguard can guarantee absolute security.
You are responsible for protecting account credentials, API credentials, secrets, authentication tokens, projects, and devices. Maintain independent backups of important information and do not use ChanTan as the sole repository for irreplaceable data. Contact [email protected] if you believe your account or information has been compromised.
General-access service limitations
General-access Services and AI outputs may be experimental, inaccurate, incomplete, interrupted, changed, or unavailable, and information may be lost or corrupted. They are not designed to be the sole foundation for mission-critical, safety-critical, regulated, or enterprise operations. You must independently review outputs, test projects, maintain backups, and use appropriate professional oversight before relying on them.
Organizations requiring guaranteed availability, support response times, retention, recovery, security, compliance, or other service commitments must contact ChanTan and enter a separate written Enterprise or Service Level Agreement. No service level commitment applies to general access unless ChanTan expressly agrees to it in writing.
15. Children
The general-access Services are intended only for people aged 18 or older. We do not knowingly offer general-access accounts to children. If we learn that a person under 18 is using such an account contrary to this requirement, we may suspend it and delete associated information, subject to lawful retention.
Schools or organizations seeking to provide ChanTan to younger users must contact us and enter an appropriate written agreement before doing so.
16. Third-Party Services and Customer Applications
Third-party services
Projects may interact with third-party websites, APIs, applications, models, app stores, payment systems, databases, or other services. Those parties may independently process information under their own terms and privacy policies. ChanTan is not responsible for parties it does not control.
Applications you build
If you use ChanTan to build, host, or publish an application that collects information from your own visitors or users, you determine the purpose and means of that collection. You are responsible for an accurate privacy notice, required consent, lawful processing, user requests, security, and compliance for your application. Where ChanTan processes that information only to provide the service to you, ChanTan acts as your service provider or processor as applicable.
17. Changes to This Privacy Policy
We may update this Policy as our Services, providers, technology, practices, or legal requirements change. The Last Updated date identifies the current version. When appropriate or legally required, we may provide additional notice of material changes through the Services, by email, or by another reasonable method.
18. Contact Us
ChanTan Studio, Inc. 2810 North Church Street, Suite 89423 Wilmington, Delaware 19802, United States
For privacy inquiries, rights requests, legal inquiries, or general support, contact [email protected]