Privacy Policy
Last updated: June 2026
What we collect
The information you provide when you create an account: your name, email, bio, and expertise. Beyond that, we collect the data you create and manage through the platform, including:
- CRM and pipeline data (contacts, companies, deals, notes)
- Outreach content (pitches, email sequences, target lists) and delivery telemetry (sent, opened, replied timestamps)
- Community content (posts, comments, course materials, membership data)
- Booking and scheduling data (calendar events, availability, attendee information)
- Social media content queued or published through connected accounts
- Call and SMS logs (phone numbers, call metadata, message content via Twilio)
- Wiki and knowledge base content
- Form and survey submissions
- Business Vault documents, credentials, and encrypted files
- Usage analytics and feature-interaction data
How we use it
To operate the platform you signed up for. This includes: managing your contacts and pipeline, sending outreach on your behalf, syncing your calendar, hosting your community, publishing social media posts, tracking calls and messages, generating AI-assisted content, running workflow automations, storing encrypted vault data, processing form responses, and surfacing analytics in your dashboard. We do not sell your data. We do not share it with advertisers.
Who we share it with
Our infrastructure subprocessors: Supabase (database + auth + file storage), Stripe (billing), Railway (hosting), Anthropic (AI features — prompts only, no training on API data), Resend (transactional email), Twilio (SMS and voice), Ayrshare (social media publishing), Google Calendar API (scheduling sync), and the SMTP provider you configure yourself. The full, current list with regions and DPAs lives at /legal/subprocessors. We give enterprise customers 30 days' notice before adding a new subprocessor.
Your rights (GDPR / CCPA)
- Access: download everything we have on you from Settings → Privacy & data → "Download my data".
- Erasure: delete your account + all associated data from the same card. This is permanent and immediate.
- Correction: edit your profile directly in the app.
- Portability: the export is a standard JSON file; import it anywhere.
- Marketing email opt-out: toggle under Settings → Email → Preferences (or unsubscribe from any email).
How we protect your data
We apply the following safeguards to all personal data, and specifically to sensitive data such as the Google account and calendar information you connect:
- Encryption in transit: all traffic between you, our servers, and every third-party API (including Google) is encrypted with TLS (HTTPS).
- Encryption at rest: your data is stored on infrastructure that encrypts disk contents at rest using AES-256 (Supabase / PostgreSQL).
- Tenant isolation: every record is protected by row-level security scoped to your account and workspace, so one customer cannot read another customer's data.
- OAuth credentials: access and refresh tokens for connected accounts (including Google) are stored server-side only, are never exposed to your browser or to other users, and are used solely by our backend to perform the actions you requested.
- Least privilege: we request the minimum Google scopes needed for scheduling (read-only availability and event write) and nothing more.
- Revocation and deletion: you can disconnect Google at any time from your Google Account permissions page or inside Chuhching, which deletes the stored tokens. Deleting your account permanently removes associated data, with backups rolling off within 30 days.
- Restricted personnel access: no one on our team accesses your calendar or connected-account data except when you request support, or where required by law.
Data retention
We keep your data for as long as your account is active. If you delete the account, we remove the underlying rows and auth record immediately. Backups roll off within 30 days.
Cookies
We use a single session cookie for login and a Stripe cookie during checkout. We also set a chuh_ref cookie (max 60 days) when you arrive via an affiliate referral link — this tracks which affiliate referred you so they receive proper credit. It contains only a referral code and is not used for advertising or cross-site tracking. We do not run third-party analytics or advertising cookies.
For business customers (GDPR Article 28)
If you process Personal Data through Chuhching on behalf of others, our standard Data Processing Agreement applies by default. It covers purpose, subprocessors, security measures, data-subject rights, and international transfers (SCCs / UK IDTA / Swiss addendum). Enterprise customers can request a countersigned PDF copy from privacy@chuhching.com.
Children
The Service is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal data, please contact us at privacy@chuhching.com and we will delete that data promptly, in compliance with the Children's Online Privacy Protection Act (COPPA).
California residents
If you are a California resident, the California Consumer Privacy Act (CCPA) grants you additional rights:
- Right to know: you can request a summary of the personal information we have collected about you, the categories of sources, the business purpose, and the categories of third parties with whom we share it.
- Right to delete: you can request deletion of your personal information, subject to exceptions under the CCPA.
- Right to opt-out of sale: we do not sell personal information as defined by the CCPA. If this changes, we will provide an opt-out mechanism.
- Non-discrimination: we will not discriminate against you for exercising any CCPA rights.
To exercise any of these rights, email privacy@chuhching.com or use the self-service controls in Settings → Privacy & data.
Google API data — Limited Use disclosure
Chuhching's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Chuhching accesses Google Calendar data (event titles, times, attendee lists, and free/busy status) solely to:
- Display your availability on your public booking page so guests can schedule with you
- Create calendar events when a booking is confirmed
- Send booking reminders based on upcoming event times
We do not use Google Calendar data for advertising, and we do not transfer it to third parties except as strictly necessary to provide the scheduling features described above (e.g., showing a guest your open time slots). No human at Chuhching reads your calendar data unless you explicitly ask us to debug a sync issue, or we are required to by law.
You can revoke Chuhching's access to your Google account at any time from your Google Account permissions page.
Contact
Privacy questions, deletion requests we couldn't handle automatically, or data-subject inquiries: email privacy@chuhching.com.