Privacy Policy
Effective date: [REVIEW: effective date]
Draft. This document is under review and is not final.
This policy explains what [REVIEW: legal entity / LLC name] collects when you use Rin Chat, why we collect it, and what choices you have.
The short version: the app is local-first. Your characters and chats are stored on your own device and encrypted at rest. We do not need a copy of them.
[REVIEW: confirm this draft with counsel, and confirm it matches what the app and the billing service actually do.]
1. Data stored on your device
Characters, chats, personas, settings and provider API keys are stored on your computer.
That data is encrypted at rest with AES-256-GCM. The encryption key is wrapped by your operating system keychain, and a recovery key lets you restore access.
We cannot read this data, and we cannot recover it for you.
2. Data we collect
We collect the following, and only for the purposes stated.
- Account data, if you create an account: email address and authentication data.
- Billing data, if you subscribe: handled by our payment processor. We receive a subscription status and a customer identifier, not your full card number.
- Usage metering, if you use the hosted AI proxy: request counts, token counts and the cost of each request, so that we can apply your credit allowance.
- Support messages that you send us.
- [REVIEW: confirm whether the website uses analytics or cookies. If it does, list the provider and add a cookie section.]
3. Prompt content
When you generate a reply, the prompt is sent to the AI provider that you selected so that it can produce the response.
If you use your own API key, the request goes from your device to that provider.
If you use the hosted proxy, the request passes through our service to the provider. [REVIEW: state exactly how long, if at all, prompt content is retained by the proxy — the honest answer must match the code.]
4. Why we process data
- To provide the app and the subscription service.
- To process payments and prevent fraud.
- To meter usage against your credit allowance.
- To answer support requests.
- To meet legal obligations.
5. Sharing
We share data only with the service providers we need in order to operate.
- The payment processor, for billing. [REVIEW: name it.]
- The AI provider, for requests made through the hosted proxy. [REVIEW: name it.]
- Hosting and infrastructure providers. [REVIEW: name them.]
- Authorities, where the law requires it.
6. Retention
We keep account and billing records for as long as your account is active, and afterwards for as long as the law requires.
[REVIEW: state concrete retention periods, for example account data 30 days after deletion, billing records 7 years, proxy logs 90 days.]
7. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to some processing.
To make a request, email [email protected]. We may need to verify your identity first.
[REVIEW: GDPR and CCPA specifics, and whether an EU or UK representative is required.]
8. Security
Local data is encrypted at rest on your device. Traffic to our service is encrypted in transit.
No system is perfectly secure. Protect your password and your recovery key.
9. Children
The service is not directed at children. [REVIEW: state the minimum age and keep it consistent with the Terms.]
10. International transfers
Our providers may process data in other countries. [REVIEW: list the transfer mechanism, for example standard contractual clauses.]
11. Changes
We will post any update to this policy here and change the effective date.
12. Contact
Questions about this document go to [email protected]. Postal address: [REVIEW: business mailing address].