Privacy Policy

Effective 7 September 2026. Last updated 10 September 2026.

This Privacy Policy describes how Generative Chaos LLC, 5900 Balcones Drive #33409, Austin, TX 78731, United States ("Chui", "we", "us" or "our") collects, uses, discloses and otherwise processes information in connection with the Chui mobile applications, desktop applications and the website at chui.io (together, the "Service").

By creating an account or otherwise using the Service, you acknowledge that you have read this Policy. This Policy forms part of, and is incorporated by reference into, our Terms of Use.

1. Definitions

"User Content" means audio recordings, transcripts, summaries, notes, titles, speaker labels and any other content that you create, upload, import or generate through the Service, together with any content derived from it by the Service.

"Usage Data" means technical and operational information generated by your use of the Service, including device, application, performance, diagnostic and event data.

"Support Communications" means a fault report or other message you send us from within the Service or by email, together with any file you attach to it.

"Service Data" means User Content, Usage Data and Support Communications, collectively.

"Provider" means a third party engaged by us to process Service Data on our behalf and on our instructions.

2. Information we collect

We collect the following categories of information:

2.1 Account information. The identifier issued to us by the sign-in provider you use, your email address where you elect to share it, and your name where the provider supplies it and you allow it. We do not request your postal address or telephone number.

2.2 User Content. Audio recordings made or imported through the Service, and the transcripts, summaries, titles, speaker labels and notes generated from or alongside them.

2.3 Usage Data. Information including but not limited to recording duration, file size, coverage against elapsed time, battery level at the start and end of a recording, application version and build, device model, operating system, the surface used, feature interactions, session events, error and crash reports, and diagnostic messages returned by the operating system or by a Provider, together with your IP address and the approximate location — typically city, region and country — derived from it.

2.4 Support communications. Information you provide when you contact us, including the content of your message and any material you attach to it. Where you report a fault from within the application, we also receive the application version and build, the surface you were using, the name of the screen you were on, the identifier of the meeting that was open at the time if there was one, and a short list of the actions the application had most recently performed. The application does not capture an image of your screen at any time. Where a report carries an image, it is a file you selected yourself, and it may contain User Content — a screenshot of a meeting, for example. Images are re-encoded on your device before they are sent, which removes any camera, timestamp or location information the original file carried.

2.5 Calendar information. Where you connect a calendar account: which provider it is, the email address that identifies that account, the identifier that provider issues for it, the permissions you granted, and the times at which the connection was made and last read. We also hold the long-lived credential that account's provider issues to us, and a short-term copy of the meetings in your next day and a half. Section 5 describes both — what is read, what it is used for, where it is kept and for how long.

2.6 Questions you ask through an assistant. Where you connect an assistant — Claude, ChatGPT or another client — through our MCP interface, every request it makes on your behalf carries one sentence saying what you are trying to find out, in your own words. We ask for it because search quality is what this feature is: by the time a question reaches our index only the words searched for remain, and nothing anywhere records what you hoped to learn. The distance between those two is how we find out that a search failed somebody, and it cannot be recovered afterwards. It is read by the people who build the Service.

We ask the assistant for one sentence and for nothing else — not your chat history, not the messages surrounding your question, not a transcript of your exchange with the assistant, and no other contextual field: our interface offers nowhere to put them. What arrives is limited to 500 characters and truncated there. We ask an assistant for a sentence; we cannot inspect what it chooses to put in one, which is a reason to prefer assistants you trust and the reason we hold whatever arrives to the protections in this paragraph. Because your question is usually about a meeting you are reading, that sentence can quote or paraphrase the meeting: «where did Ivan say the release was slipping». We say so plainly rather than imply otherwise. What it can quote is your own recording, which we already hold, and it is stored in the same database and under the same protections as the recording it concerns. It never changes the answer you get back — the same request with the same parameters and a different sentence returns exactly the same result — and the interface says so to the assistant in those words. We never send the sentence itself to our analytics provider. What that provider receives about such a request is its shape and no part of its content: which tool was called, which of our two addresses it arrived on, the name the assistant registered itself under, whether it succeeded, how long it took, how many results came back, whether a sentence was supplied at all and how many characters it ran to — together with the internal identifier of your account, as section 9 describes.

It is retained until you delete your account, and section 9 describes one consequence worth knowing in advance: deleting a meeting does not delete a sentence that happened to quote it.

2.7 Billing information. There is no paid plan today and we collect nothing of this kind. Where a paid plan is offered and you take one at chui.io, the payment is taken by a payment processor, and your card number is given to that processor and never to us. What we receive and keep is the record of the subscription itself: which plan it is, when it began, when it renews or ended, the country we are required to determine in order to charge the right rate of tax and the evidence on which we determined it, the amount charged and the tax within it, and an identifier issued by the processor that lets us match the subscription to your account. Where you subscribe from within an application obtained from the Apple App Store, Apple takes the payment and tells us only that a subscription exists and when it ends; Apple gives us no payment details of yours.

We do not collect precise geolocation such as GPS coordinates, nor contacts, nor advertising identifiers, and we do not employ any technology intended to track you across other applications or websites.

3. How we use Service Data

We process Service Data for the following purposes, including but not limited to:

(a) providing, operating, maintaining and supporting the Service, including transcribing, diarising, summarising, indexing and making your recordings searchable and playable, and delivering notifications to your devices;

(b) authenticating you, administering your account, taking payment for a paid plan and issuing receipts for it, and enforcing account entitlements, usage limits and subscription terms;

(c) investigating, diagnosing and resolving faults, including through crash reports, error logs and diagnostic messages;

(d) measuring and analysing usage, performance, reliability and adoption, including through event analytics and aggregate reporting;

(e) maintaining the security and integrity of the Service, and detecting, preventing and investigating fraud, abuse and breaches of our Terms of Use;

(f) responding to your enquiries and support requests, including where you submit a specific recording to us for review;

(g) complying with applicable law and responding to lawful requests from competent authorities, and establishing, exercising or defending legal claims; and

(h) operating, developing, evaluating, testing and improving the Service and any current or future features, functionality, products and services, including by review and automated analysis of Service Data, User Content and any content generated by the Service or by users.

3.1 Your choice in respect of paragraph (h). You may opt out of the processing described in paragraph (h) at any time in Settings → Privacy within the application. Opting out does not affect processing carried out before we receive your instruction, nor the purposes in paragraphs (a) to (g).

3.2 No sale and no advertising. We do not sell Service Data and we do not share it for cross-context behavioural advertising. We do not use Service Data for advertising and we have no advertising partners.

4. Disclosure of Service Data

4.1 Categories of Provider. We disclose Service Data to Providers engaged to perform functions on our behalf. Each processes it under a written contract, solely on our instructions and for no purpose of its own.

CategoryWhat it receivesPurpose
Speech-to-text providersaudio recordingstranscription and speaker separation
Language-model providerstranscripts, notes and Support Communicationssummarisation, generated output and classifying reported faults
Cloud infrastructure providersService Datahosting, storage, processing and delivery
Product analytics providersUsage Data only; no User Contentmeasuring use, performance and reliability
Authentication providersaccount identifiers only; no User Contentsigning you in
Push notification providersdevice tokens, recording and meeting identifiers, and the text of the notificationdelivering notifications to your devices
Issue-tracking providersthe text of a fault report, and a link to any file attached to it; the file itself is not disclosedrecording and resolving reported faults
Payment processorsyour name, your email address and the payment details you give them directly; no User Contenttaking payment and determining the tax within the price

Some Providers are established outside the European Economic Area, including in the United States.

4.2 Which Providers, and changes to them. The Providers currently engaged in each category are listed at chui.io/subprocessors, and that list is also available on request. We may change or add a Provider within a category — for example, engaging a different speech-to-text engine — and where we do, we update that list. The categories and purposes set out above continue to describe what is disclosed and why.

4.3 No training by Providers. No Provider is permitted to use your User Content to train, fine-tune or otherwise develop its own models. We require this by contract or under the Provider's applicable terms, and it is a condition of engaging any Provider in the first two categories above.

4.4 Other disclosures. We may disclose Service Data where required by applicable law or legal process, to protect the rights, property or safety of Chui, our users or the public, and in connection with a merger, acquisition, financing or sale of assets, subject to equivalent protections.

4.5 A link you create yourself. The Service can, at your request and for one meeting at a time, publish that meeting at a web address on chui.io. This is a disclosure you make rather than one we make: no meeting has such an address unless you ask for one, and none is created by default. While the address exists, anybody holding it may read the meeting's title, the date and length of the meeting, the names you have given to the voices in it, and the summary.

You choose whether the transcript is published with it, and the choice starts at «summary only». A newly created address carries the summary and not the transcript; only a further request of yours, for that one meeting, adds the transcript to the page. Changing that setting applies to the address as it already stands, so it changes what everybody you have already given the address to can read, at once and in both directions. The recording is never published, at either setting: the page does not contain it and there is no setting on it that would add it. Nothing else about the meeting is published at either setting — not your own notes, not its processing status, not its diagnostics.

The address contains an unguessable value we generate; we do not publish, list or index it, and the page asks search engines not to index it either. You may withdraw the address at any time, after which it stops working permanently; a later request creates a different address, so that anybody still holding the old one does not regain access, and that new address again starts at the summary. We record that a meeting was given an address, when it was withdrawn and how many times the page has been opened; that record contains no part of the meeting, is deleted when the meeting is deleted, and is deleted with your account. Once a page has been read we cannot recall what the reader saw, and neither withdrawing an address nor narrowing what it publishes attempts to.

5. Third-party integrations

5.1 Generally. Where you connect a third-party account to the Service — a calendar, or an assistant or client connected through our MCP interface — we receive from that provider only what the connection requires. What an assistant sends us on your behalf, and what we keep of it, is described in paragraph 2.6. User Content transmitted to a provider you have selected is thereafter governed by that provider's terms and privacy policy. You may disconnect an integration at any time. Where a connection requires an access credential that we hold, it is retained only while the connection is active and is deleted when you revoke it; for calendar connections we hold such a credential on our servers, encrypted, as paragraph 5.4 describes.

5.2 Calendar connections, and what is read. The Service can connect to a Google account or to a Microsoft account so that a recording can be filed against the meeting it belongs to. Connecting a calendar is a separate step from signing in — it is requested separately and may be refused on its own — and it grants the Service read-only access to two things: the list of calendars on that account, and the events on those calendars. We request no other calendar permission, and the Service cannot create, alter, delete or move any calendar or any event; it never writes anything to your calendar. The calendar permissions requested are calendar.calendarlist.readonly and calendar.events.readonly from Google, and Calendars.Read from Microsoft.

The same authorisation request also asks for the sign-in permissions that tell us which account you have just connected — without them the application could show you only "Microsoft" and not which of your accounts it is: openid and email from Google, and openid, profile and email from Microsoft. From Microsoft we additionally request offline_access, and from Google access_type=offline: both are what allow the connection to be renewed without asking you to consent again, so that connecting once connects every device you sign in on.

5.3 What calendar data is used for. Events are read in order to show you the meetings taking place around you, so that you may start a recording against one, and to remind you shortly before a meeting begins. Where you record against an event, that event's title names the recording, the invitation body or agenda is supplied to the summariser as context for it, and the names of the people invited become the list of candidates the Service offers when a speaker is labelled — a set of suggestions, and never a record of who attended.

Calendar data is used for these purposes and for no other. It is not used for advertising; we do not sell it and do not share it for cross-context behavioural advertising; it is not used to profile, score or assess you or any person named in your calendar; and it is not used to train, fine-tune or otherwise develop any model, whether ours or a Provider's.

5.4 Where calendar data is held. The credential Google or Microsoft issues when you connect a calendar is held on our servers. It is stored encrypted, under a key held separately from the database, and it is never returned to any application, shown on any screen or included in any log. Connecting a calendar once therefore connects it for every device you sign in on, and lets the Service read your calendar when the application is not open — which is what allows a reminder before a meeting starts.

We also store the meetings in your next day and a half, so that the Service can offer to record one at the time it begins. For each such meeting we hold what the invitation itself contains — what it is called, when it begins and ends, where or by what means it is to be held, its body or agenda, who was invited, and whether you have accepted it. A meeting that has ended is deleted within twenty-four hours, and every stored meeting for a calendar account is deleted the moment that account is disconnected. Nothing older is retained, and this store is not used for any purpose other than the ones paragraph 5.3 describes.

Where a meeting is stored with a recording, that copy forms part of the recording, is subject to the recording's own retention and is deleted when the recording is deleted.

What we hold about the people invited to a meeting is what that invitation itself carries about them, and we hold it only for the purposes paragraph 5.3 describes. We keep no separate record of those people and build nothing about them: nobody is looked up, enriched, profiled or contacted because their name appeared on a meeting in your diary, they are not added to any list, and they are not counted as users of the Service. What an invitation says about them is part of the stored meeting and shares its life — deleted within twenty-four hours of the meeting ending, and at once when the calendar is disconnected. Section 6 addresses the other people a recording itself captures.

5.5 Disconnecting a calendar, and revoking access. You may disconnect a calendar at any time in Settings within the application. Doing so revokes the credential at the provider where the provider offers a means to do so, deletes that credential from our servers, and deletes every stored meeting for that account together with the record described in paragraph 2.5. Signing out of your last remaining device does the same for every calendar on the account.

Google publishes a means of revocation and we use it. Microsoft publishes none that an application may use on your behalf, so for a Microsoft account we destroy the credential and the standing permission is removed by you at the provider. You may in any case revoke the Service's access at the provider itself — at myaccount.google.com/permissions for a Google account, and at account.live.com/consent/Manage for a personal Microsoft account or myapps.microsoft.com for a work or school account. Doing so does not depend on us and cannot be undone by us.

5.6 Google API Services User Data Policy. Chui's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5.7 Microsoft accounts. A Microsoft calendar connection is subject to the same limits throughout: read-only access under the Calendars.Read permission, the credential held on our servers and the meetings in your next day and a half stored, on the terms and for the retention paragraph 5.4 sets out, and no use of the data beyond the purposes set out in paragraph 5.3. Where your Microsoft account is issued by an employer or other organisation, your administrator may permit or refuse the connection and may revoke it at any time.

6. Other participants in a recording

A recording ordinarily captures more than one person, and only one of them holds an account with us. This section addresses the others.

6.1 No bot joins your meeting. The Service does not send a participant, agent or bot into any call. Recording is performed by the device in your possession.

6.2 Your responsibility. You are solely responsible for ensuring that you have a lawful basis and, where required, the consent of all participants before recording. Requirements differ between jurisdictions and some require the consent of every party. We have no means of determining who is present or whether they have agreed.

6.3 Requests from non-account holders. If you were recorded through the Service and wish to exercise rights in respect of that recording, contact privacy@chui.io. Recordings are indexed to the account that created them, and speakers within a recording are labelled speaker_0, speaker_1 and so on unless a name becomes known in one of the ways described in paragraph 6.4. Within a single account a named person is a record in their own right, and the meetings they appear in can be listed; that index exists only inside that one account. The voiceprints described in paragraph 6.4 reach one step further and no further: where the account belongs to an organisation, they are held by that organisation and are available to every account in it; where it belongs to none, they are held in that one account. Nothing spans organisations. We operate no directory of people and no index of voices that reaches beyond a single organisation, a voiceprint held by one organisation is never compared against a recording made by another, and we therefore cannot search the Service for you, whether by name or by voice. We will require sufficient particulars to identify the recording — ordinarily who recorded you and approximately when — and will verify your identity so far as is reasonably practicable. Where we locate a recording, we will respond in a manner that does not disclose the personal data of other participants.

6.4 Voiceprints. The Service separates the voices within a single recording and labels them speaker_0, speaker_1 and so on. A speaker acquires a name where a user types it, where the name is stated plainly in the conversation, or where the Service recognises the voice as described in this paragraph.

(a) What is created. Where a speaker has spoken for long enough for the measurement to be reliable — at present, approximately thirty seconds of sufficiently clear speech — the Service computes and stores a mathematical representation of that voice (a "voiceprint") within the account that made the recording and, where that account belonged to an organisation of more than one member when the recording was made, within that organisation. Where a name for that speaker is known, the voiceprint is held against that named person. Where none is, it is held against a person record carrying no name, so that the same voice can be recognised as the same voice if it is heard again.

(b) What it is used for. In later recordings made by the same account — and, where the account belongs to an organisation, in later recordings made by any account in that organisation — the Service compares each separated voice against the voiceprints held there; where one matches, it treats the two as the same person and proposes that person's name if a name is known. Where the recording is associated with a calendar event, the people that invitation names are preferred among the candidates. A proposed name is shown to the user and may be changed in a single action, and a name a user has entered is never overwritten by one the Service has inferred. We use voiceprints for no other purpose: they are not used to verify or authenticate identity, to grant access to anything, to profile, score or assess any person, or to infer emotion, health or any other characteristic.

(c) This is biometric data, and we treat it as such. A stored voice representation used to recognise a person is a special category of personal data within the meaning of Article 9 of the GDPR, and sensitive personal information under several United States state privacy laws. We retain it for one reason: so that the Service does not ask who each speaker is at every meeting held with the same people.

(d) It does not leave the organisation that holds it. A voiceprint is stored within a single account or, where that account belongs to an organisation, within that one organisation. Where an organisation holds voiceprints, every account in it is compared against all of them — including against voices measured in recordings that were never shared with anyone — so a person recorded by one member of an organisation may be recognised in a meeting held by another member of it whom they have never met. A voiceprint measured before an organisation had a second member stays in the account that made it and is not pooled afterwards. We operate no global index of voices and none that spans organisations, and a voiceprint is never shared with an account outside the organisation that measured it. The only Provider it reaches is the cloud infrastructure that stores it on our behalf (paragraph 4.1); no Provider and no other third party receives it for any purpose of its own, and it is not used to train, fine-tune or otherwise develop any model, whether ours or a Provider's.

(e) Most of the people measured hold no account. A voiceprint may be created for any speaker in your recordings who speaks for long enough, whether or not you have named them, and it is retained in your account and, where your account belongs to an organisation, in that organisation. The responsibility described in paragraph 6.2 extends to it: you are responsible for having a lawful basis for that processing and, where required, that person's explicit consent, and where your account belongs to an organisation that organisation carries that responsibility with you under our Terms of Use.

6.5 Removing a voiceprint. Deleting a recording deletes the voiceprints measured from it, permanently and together with the audio, transcript, summary and notes. To have a voiceprint of your voice erased without deleting the recording it was measured from, to object to the measurement of your voice, or where you do not hold the account concerned, contact privacy@chui.io. Where we rely on your consent for this processing, you may withdraw it at any time; withdrawal does not affect processing carried out before we receive it. Section 10 sets out your rights and the time within which we respond.

7. Artificial intelligence and automated processing

7.1 How AI is used. The Service uses automatic speech recognition and generative language models to transcribe recordings, separate speakers, and produce titles, summaries, search results and related output from your User Content. Output is generated by machine and is not reviewed by a person before it is shown to you.

7.2 Accuracy. AI output contains errors, particularly where audio quality is poor, where participants speak concurrently, and where proper nouns, specialist terminology or more than one language are present. You should review AI output before relying on it. It is not a verbatim record.

7.3 No automated decisions with legal effect. The Service does not use automated processing to make decisions that produce legal or similarly significant effects concerning you. To the extent any processing were to constitute automated decision-making within the meaning of Article 22 of the GDPR, you have the right to obtain human intervention, to express your point of view and to contest the decision, and may exercise it by contacting privacy@chui.io.

7.4 Transparency. Where required by applicable law, including Regulation (EU) 2024/1689 (the EU Artificial Intelligence Act), we identify content generated by the Service as machine-generated.

7.5 Model training. Providers may not train on your User Content — see section 4.3. Our own use of Service Data to improve the Service is described in paragraph 3(h), and your choice in respect of it in section 3.1.

7.6 Automated review of fault reports. Where you report a fault from within the application, the text of your report is read by a generative language model, which produces a summary and a suggested classification for our engineering records. That processing falls within paragraphs 3(c) and 3(f) and is not affected by the choice in section 3.1. No decision concerning you is made by it, and where you attached an image, the image is not disclosed to that model.

8. Legal bases

Where the GDPR applies, we rely on: performance of a contract (paragraphs 3(a), (b) and (f)); our legitimate interests in operating, securing, measuring and improving the Service (paragraphs 3(c), (d), (e) and (h)); compliance with a legal obligation and the establishment or defence of legal claims (paragraph 3(g)); and your consent where separately requested.

9. Retention

We retain User Content until you delete it. Deletion from within the application is permanent and removes the audio, transcript, summary and notes; there is no recovery facility. Deleting a meeting does not delete a fault report you sent us about it, or any file you attached to that report; those are Support Communications and we retain them for as long as they remain necessary for the purposes in section 3, after which they are deleted. Where you delete your account, the account itself and every record of your meetings are destroyed the moment you ask — there is no grace period and no recovery facility, so retrieve anything you want to keep first — and the stored files behind them, together with routine backups, are removed within thirty days; a fault report you sent from within the application, and any file attached to it, is deleted with the account. Where the substance of such a report has already been written into an engineering record so that the fault can be fixed, that record is retained and identifies the report rather than you or your account. Deleting a meeting likewise does not delete a question you asked an assistant that happened to quote it (paragraph 2.6); those sentences are deleted with your account. Usage Data and diagnostic records are retained for as long as they remain useful for the purposes in section 3. They carry no name and no address: a usage event identifies an account only by an internal identifier, and a diagnostic record carries no account identifier at all. Once an account is deleted, nothing links those records to a person.

When an account or a subscription ends. Where we terminate an account for breach of the Terms, clause 9.4 of those Terms gives you not less than thirty days in which to ask us at privacy@chui.io for a copy of your User Content before the same destruction happens. The end of a subscription is not the end of an account: where a subscription lapses, is cancelled or is ended by us, the account continues on the free plan and no recording is deleted because payment stopped. Where a change to the free plan would put a recording beyond what that plan includes, clause 6.4 of the Terms says what becomes of it — it stops being available to open, and we do not delete it without notice and a period in which you can retrieve it.

We may retain Service Data for longer where required by law or where reasonably necessary to establish, exercise or defend legal claims.

10. Your rights

Where the GDPR applies, you have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing carried out on the basis of our legitimate interests.

Deletion of a recording and of your account are available within the application. For all other requests, contact privacy@chui.io; we will respond within one month. Where the GDPR applies to you, you may also lodge a complaint with the data protection supervisory authority of the country in which you live or work.

11. United States state privacy rights

Where you are a resident of a United States state with a comprehensive consumer privacy law — including Texas, California, Colorado, Connecticut, Virginia and others — you have the right to confirm whether we process your personal data and to access it, to correct it, to delete it, and to obtain a portable copy.

You also have the right to opt out of the sale of personal data, of sharing or processing for targeted advertising, and of profiling in furtherance of decisions producing legal or similarly significant effects. We do none of those things: we do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not carry out such profiling.

Appeals. If we decline a request, you may appeal by writing to privacy@chui.io with "Appeal" in the subject line. We will respond within forty-five days and, where an appeal is refused, will tell you how to complain to your state Attorney General.

Non-discrimination. We will not deny you the Service, charge a different price, or provide a different quality of service because you exercised a privacy right.

Authorised agents. An authorised agent may submit a request on your behalf with written authorisation. We may still ask you to verify your identity directly.

12. Marketing communications

We send messages necessary to operate the Service — sign-in, transactional, billing, security and service notices — and you cannot opt out of those while you hold an account.

Where we send promotional email, you may opt out at any time using the unsubscribe link in the message or by writing to privacy@chui.io. Opting out of promotional email does not affect the service messages described above.

13. Cookies and tracking

The Service uses no cookie to track you. It stores a session token and your preferences — the language and the appearance you chose — in your browser's local storage, or in the application's own storage on your device, which is necessary for the Service to function; the one cookie it sets, chui_consent, is written only on the page where you authorise a third-party application to reach your account, is confined to that page's path (/oauth), holds a random value that means nothing away from our servers, expires forty-five minutes after it is set, and exists solely so that such an application cannot obtain your authorisation in somebody else's name — it is strictly necessary to a service you have requested and accordingly requires no consent. Signing out clears the session token; your preferences remain on the device until you clear the browser's storage or remove the application.

We do not use advertising or tracking pixels, and we do not use any technology that follows you across other applications or websites. Because we do not carry out such tracking, we do not respond differently to browser "Do Not Track" signals.

14. Security

Service Data is encrypted in transit and at rest. Access to audio is granted through short-lived signed links rather than public addresses. Access to User Content within our systems is limited to the purposes set out in section 3.

Sign-in is provided through third-party identity providers and we do not hold your password to any of them. You are responsible for the security of the account you use to sign in, and for access to the devices on which the Service is installed.

No method of transmission or storage is entirely secure, and we do not warrant absolute security.

15. International transfers

Service Data is processed in the United States and in the European Union. Where personal data is transferred from the European Economic Area, the United Kingdom or Switzerland, that transfer is made on the basis of the European Commission's Standard Contractual Clauses or another lawful transfer mechanism.

16. Children

The Service is not directed to, and may not be used by, persons under sixteen years of age. We do not knowingly collect personal data from such persons.

17. Changes to this Policy

We may amend this Policy from time to time. Where an amendment materially affects how we process User Content, we will provide notice within the application before it takes effect. Continued use of the Service following the effective date constitutes acceptance of the amended Policy.

18. Contact

Generative Chaos LLC 5900 Balcones Drive #33409, Austin, TX 78731, United States privacy@chui.io