PRIVACY & SECURITY
A clear view of your data.
Effective July 28, 2026
What we collect
We collect waitlist email addresses. When you use the service, we process email addresses and names, subjects, message bodies, headers, timestamps, threading information, AI requests and responses, and technical or security logs. We store attachment names, types, and sizes. The current beta does not read attachment contents, although attachments still pass through our email provider.
How we use it
We use this information to receive and thread emails, understand the shared context, generate and deliver responses, control access, prevent abuse, troubleshoot failures, and operate Chime In. Current-information requests may use web search, and relevant parts of a request may be used to formulate searches.
Who processes it
Resend receives and sends email. Railway hosts the application and database. OpenAI processes thread content to generate answers and supported web searches. OpenAI states that API data is not used to train its models by default, although its standard abuse-monitoring retention may apply. We do not sell conversation content or personal information, and we do not use it for advertising.
Human access
Chime In is not end-to-end encrypted. A limited number of authorized Chime In operators may access stored conversation content when reasonably necessary to investigate a reported problem, troubleshoot an incorrect or failed response, prevent abuse or security incidents, respond to support requests, or comply with legal obligations. We do not routinely read conversations for advertising or unrelated purposes.
Retention and deletion
Conversation data is automatically deleted after 90 days by default. You may request earlier deletion by emailing [email protected] from the address associated with the data. We may ask you to verify control of that address. Limited records may remain where required for security, fraud prevention, legal compliance, or in provider backups subject to their retention schedules.
Security
We use safeguards including signed email webhooks, restricted administrative access, access logs, recipient and usage limits, and automated loop prevention. No internet service can guarantee absolute security, which is why Chime In is not intended for sensitive or regulated information.
Your choices
You may ask to access or delete your information, leave the waitlist, or stop using the service. Contact [email protected]. Questions about the product may be sent to [email protected].
Changes
We may update this notice as the beta develops. Material changes will be posted with a new effective date.