ChiMate.aiyour AI assistant

Privacy Policy

Last updated: 24 August 2026

1. Who we are

chimate.ai is a SaaS platform for AI-powered image analysis (OCR and analytical processing). This Privacy Policy describes what personal data we collect, why, and with whom we share it. By using the service you agree to the terms below.

2. What data we collect

Account data: your name and email from your Google account (via OAuth), Google account identifier, email-verified flag.

Technical and registration-source data: IP address, country derived from IP, browser language, browser and operating-system family and major version, device type, UTM parameters, referring-site hostname, landing-page path and attribution timestamp. We do not store the full referrer URL or raw User-Agent for this purpose.

Device data: a hash of the device fingerprint, used to enforce the per-device limit on the free tier.

Usage data: pages visited, funnel events (pricing views, plan selection, purchases, downloads, client launches), session recordings with passwords and private fields masked.

Images and analysis results: screenshots you upload and the OCR/AI output we produce are stored on our servers for the retention period stated below.

Payment data: amounts, currencies, statuses and subscription metadata. We do not store card numbers — they are processed by our payment provider Lava.top.

3. Purposes of processing

Delivering the service (storing and analysing images, maintaining subscriptions and credits).

Account management and authentication.

Billing, invoicing, subscription confirmation and renewal.

Product analytics to improve the service.

Ad campaign attribution and optimisation.

Notifying you about important changes to the service (email).

4. Recipients of data

PostHog Inc. (EU Cloud, servers in Frankfurt) — product analytics and session replay.

Yandex LLC — Yandex.Metrika and Yandex.Direct (analytics and advertising in Russia).

Lava.top — payment processor.

OpenRouter Inc. — executing requests against AI models (Google Gemini, Anthropic Claude).

Google LLC — OAuth authentication.

We have entered into Data Processing Agreements (DPA) with each of these processors in line with applicable law including GDPR.

5. Retention

Account and subscriptions — while your account is active.

Registration attribution linked to your account — until the account is deleted. Before registration, the latest meaningful attribution touch is stored in your browser for up to 30 days.

Images and analyses — 30 days from creation, then deleted automatically.

Server logs — 90 days.

PostHog and Yandex.Metrika session recordings — 30 days.

After you delete your account, personally identifiable information is erased or anonymised; aggregated transactional records may be retained for accounting and tax compliance.

6. Your rights

If you are located in the EU, EEA, the United Kingdom or Switzerland, GDPR / UK GDPR / FADP grant you the following rights:

Right of access to your data.

Right to rectification of inaccurate data (via the Profile page).

Right to erasure — use the "Delete account" button on the Profile page or write to support@chimate.ai.

Right to restriction of processing.

Right to withdraw consent to optional browser analytics — select Decline whenever the consent banner is shown, or contact support to change a consent choice stored with your account.

Right to lodge a complaint with your local data protection authority.

To exercise any of these rights please email support@chimate.ai. We respond within 30 days.

7. Cookies and trackers

Authentication uses JWT tokens in Local Storage; analytics cookies are not required for sign-in or the core operation of the service.

Browser analytics (PostHog and Yandex.Metrika) follow the service's current consent policy: we may ask only in regions where consent is required, ask in every region, or enable analytics without a prompt for visitors who have not made a choice. An explicit previous decision always takes priority.

Local Storage is used to remember your consent decision, interface language, session JWT tokens, and the latest meaningful registration-source touch for up to 30 days.

Declining optional analytics prevents browser-based PostHog and Yandex.Metrika from loading. It does not disable server-side transactional events needed to operate and measure the service or first-party registration attribution.

8. Transfers outside the EU/EEA

Some processors may be located outside the EU/EEA. Transfers rely on the European Commission's Standard Contractual Clauses 2021/914.

9. Children

The service is not intended for individuals under 16. We do not knowingly collect data from children. If you are a parent or guardian and discover that your child has provided us with personal data, please contact us and we will delete it.

10. Changes to this policy

We may update this Policy from time to time. We will communicate material changes by email or via on-site notification. The last-updated date is shown at the top.

11. Contact

Email: support@chimate.ai