Chaos OS Privacy Policy

Effective Date: July 30, 2026

Operator: Chaos OS is operated by Chaos Intelligence LLC, a Texas limited liability company ("Chaos OS," "we," "us," or "our").

Contact: support@chaosintelligenceinc.com

Platform scope: Chaos Intelligence LLC operates Chaos OS, a platform that includes sub-applications such as Vectle. References to the "Service," "we," "us," and "our" in this document refer to Chaos Intelligence LLC and Chaos OS, including the sub-application you use.

This Privacy Policy explains how Chaos OS collects, uses, discloses, and otherwise processes personal information in connection with Chaos OS's websites, applications, APIs, developer tools, marketplace/payment features, collaboration features, public pages, and related services (the "Service").

This Policy applies to information we process as a business, controller, or similar role under applicable privacy laws. In some circumstances, Chaos OS may process information on behalf of a customer, organization, application developer, profile owner, hive owner, or other user under separate terms or data processing terms. Those parties may have their own privacy obligations to you.

If you do not agree to this Privacy Policy, do not use the Service.

Privacy at a Glance

This summary is not the whole Policy. Please read the full Policy below.

TopicSummary
Accounts and authenticationChaos OS uses Clerk for account creation, login, sessions, account identifiers, emails, phone numbers, verified emails/domains, reverification, step-up authentication, and Clerk account deletion workflows.
Profiles and personasA single account may create or control multiple profiles or personas, including real-ID, pseudonymous, and anonymous profiles. Profile data may include display names, handles, avatars, profile type, publicness settings, intros, links, demographics, date of birth, language, addresses, and location data.
User contentChaos OS processes collections, templates, artifacts, revisions, blocks, responses, uploaded files, images, videos, audio, metadata, provenance, comments, messages, and public Pages/Portals.
Public sharingInformation you publish, make public, share, grant, or route through applications, hives, organizations, collections, Pages/Portals, webhooks, or APIs may be visible to others or sent outside Chaos OS. Avatars and Portal hero images are stored in a public images bucket and may be accessible by URL.
Private mediaPrivate files, videos, and audio are protected through app-layer authorization and signed URLs, but anyone with a valid signed URL may be able to access the file until the URL expires.
PaymentsStripe processes card/payment method data, Know Your Customer (KYC), tax, bank, fraud/risk, invoices, subscriptions, refunds, disputes, and payouts. Chaos OS stores payment and accounting records such as Stripe customer IDs, Connect account IDs, subscription, ledger, revenue, withdrawal, refund, dispute, and accounting state.
AI featuresChaos OS currently uses Google Gemini to generate embeddings that support artifact search. Content submitted for embedding may be transmitted to Google for that processing. Additional AI features or providers, if introduced, will be disclosed before or when they are made available.
Analytics and measurementChaos OS currently uses essential authentication/session technologies and error monitoring where configured. It does not currently use advertising, cross-context behavioral advertising, or third-party product analytics such as Google Analytics.
Logs and securityChaos OS processes IP addresses, device and request metadata, rate-limit records, security logs, application request/response logs, product and audit events, webhook delivery records, Stripe event audit metadata, and Sentry error/performance data, with scrubbing where configured.
Retention and deletionAccount deletion is generally a mix of soft deletion, deidentification, and an external Clerk hard-delete attempt. We retain information where needed for security, fraud prevention, audit, payment disputes, tax/accounting, legal compliance, provenance, backups, user-directed sharing, and public content.
Your rightsDepending on where you live, you may have rights to access, correct, delete, port, opt out of sale/sharing/targeted advertising, limit certain sensitive information uses, object, restrict, or appeal. See the rights sections below.

1. Scope, Related Terms, and Roles

This Privacy Policy is incorporated into and forms part of our Terms of Service: https://chaosos.com/terms. Your use of Chaos OS may also be governed by our Cookie Policy or similar notice at https://chaosos.com/cookies, product-specific terms, payment terms, developer terms, marketplace terms, community rules, and third-party provider terms that apply to particular features.

Chaos OS operates a U.S.-based software platform where users can create accounts, profiles, personas, collections, templates, artifacts, responses, applications, APIs, public Pages/Portals, and payment-enabled experiences.

Different privacy roles may apply:

  • Chaos OS as controller/business. We decide how to process account, platform, security, payment, analytics, support, legal, and operational information.
  • Chaos OS as processor/service provider. We may process user content or organization/customer data on behalf of users, organizations, hive owners, application developers, or other customers under applicable terms.
  • Users and organizations as controllers or independent recipients. If you publish content, grant access, invite others, configure an application, subscribe to a webhook, or direct Chaos OS to disclose information, the recipient may process that information independently.
  • Stripe, Clerk, AI providers, analytics providers, and other vendors. Some third parties process information under their own terms and privacy notices as well as under contracts with us.

This Policy does not apply to third-party websites, applications, payment interfaces, AI model services, webhook endpoints, or other services that we do not control.

2. Information We Collect

2.1 Account, Authentication, and Clerk Data

We use Clerk for authentication and account management. We may collect, receive, or process:

  • Account identifiers and Clerk user IDs.
  • Email addresses, phone numbers, verified email addresses, and verified domains.
  • Account preferences and account status.
  • Session cookies, authentication tokens, login events, reverification, and step-up authentication information.
  • Security, account recovery, and account deletion data.
  • Legal consent records, currently including account ID, document kind, accepted revision ID or number, and timestamp. We do not currently store IP address or user agent in legal consent records unless the product changes.

Clerk may process additional information under Clerk's own terms and privacy notice.

2.2 Profiles, Personas, Identity, and Location Data

Chaos OS supports multiple profiles or personas under one account, including real-ID, pseudonymous, and anonymous profiles. Depending on your use of the Service, we may collect:

  • Display name, handle, avatar, short intro, profile links, profile type, profile status, and publicness settings.
  • Real-ID, pseudonymous, or anonymous profile indicators.
  • Demographic information you provide or that is associated with profile setup, such as first name, last name, date of birth, language, and similar profile attributes.
  • Addresses and place information.
  • Latitude, longitude, city, state, country, neighborhood, and public geographic visibility settings.
  • Payout eligibility signals, including whether a profile is eligible for payment or payout flows.
  • Profile ownership, permissions, access grants, memberships, blocks, invitations, and related lifecycle metadata.

If you use a pseudonymous or anonymous profile, Chaos OS may still be able to associate that profile with your underlying account for platform operations, security, legal compliance, payment eligibility, abuse prevention, support, and account lifecycle purposes. Public viewers may or may not be able to make that association depending on your settings and what you choose to disclose.

2.3 User Content and Collaboration Data

We collect and process content that you or others create, upload, submit, generate, publish, or share through the Service, including:

  • Collections, templates, artifacts, revisions, blocks, responses, placements, and associations.
  • Uploaded files, images, videos, audio, attachments, and previews.
  • Metadata, provenance, authorship, revision history, status, timestamps, access grants, permissions, and lifecycle records.
  • Comments, messages, notes, review data, requests, responses, and other communications if enabled.
  • Public Pages/Portals, Portal sections, Portal items, Portal hero images, public handles, public teaser surfaces, and public profile information.
  • Application/API inputs and outputs that contain or reference user content.

You are responsible for the personal information you choose to upload, submit, publish, share, or route through the Service, including information about other people.

2.4 Public Images, Private Files, and Media

All avatars and Portal hero images are stored in a public images bucket and may be publicly accessible by URL. Do not upload an avatar or Portal hero image unless you are comfortable with it being publicly accessible.

Private files, videos, and audio are protected through app-layer authorization and signed URLs. Signed URLs can allow temporary access to the covered file. If you share a signed URL or if someone else obtains it, that person may be able to access the file until the URL expires.

2.5 Payments, Subscriptions, Marketplace, and Stripe Data

Chaos OS uses Stripe for payment processing and payout infrastructure, including Stripe Connect where applicable. We may collect, receive, or store:

  • Stripe customer IDs, Stripe Connect account IDs, payment account status, and payout eligibility or onboarding status.
  • Subscription, paywall, ledger, revenue, withdrawal, refund, dispute, chargeback, invoice, and accounting records.
  • Product, plan, price, fee, tax, payout, revenue hold, response payout, and transaction metadata.
  • Stripe event audit metadata and operational records.
  • Billing contact details or tax-related business information where required for invoicing, compliance, or accounting.

Stripe, not Chaos OS, processes card numbers, payment method details, bank account details, KYC identity information, tax information, fraud/risk checks, invoices, subscriptions, refunds, disputes, chargebacks, and payouts. Stripe may process this information under Stripe's own terms and privacy notice.

2.6 Applications, APIs, Webhooks, and Developer Data

Chaos OS supports applications, agents, APIs, GraphQL operations, developer keys, and webhooks. We may process:

  • Application identity, agents, API keys or key metadata, permissions, scopes, versions, activations, and ownership data.
  • API and application request logs, including request and response metadata, operation names, status, timestamps, latency, IP address, user agent, payload shape, touched resource IDs, and related provenance.
  • Content-bearing JSON payloads, inputs, outputs, and responses where application/API calls contain user content or personal information.
  • Webhook subscriptions, event types, endpoint URLs, signing secret metadata, webhook outbox records, delivery attempts, delivery status, response codes, timestamps, and payload metadata.
  • Developer-controlled destination information and delivery diagnostics.

When you grant an application access, configure a webhook, or otherwise direct Chaos OS to send information to a developer endpoint, the developer or endpoint operator may receive and process that information outside Chaos OS.

2.7 Device, Usage, Security, and Log Data

We may automatically collect or process:

  • IP address, browser type, device type, operating system, language, referring/exit pages, URLs, pages viewed, timestamps, and request metadata.
  • Session, authentication, reverification, and step-up metadata.
  • Rate-limit records, abuse-prevention records, security logs, audit events, product events, and lifecycle events.
  • Sentry error and performance data, with scrubbing where configured.
  • Vercel, Supabase, Clerk, Stripe, and other infrastructure or provider logs.
  • Application request/response logs and webhook delivery logs as described above.

2.8 Geocoding Data

If you enter an address, place, or location string, we may send that address or place string to OpenStreetMap/Nominatim or similar geocoding providers to resolve location information such as latitude, longitude, city, state, country, or neighborhood.

2.9 AI Feature Data

When you use AI-powered features, we may process:

  • Prompts, instructions, files, text, images, audio, video, or other inputs.
  • User content, metadata, context, application data, and retrieved records needed to provide the AI feature.
  • Model outputs, generated content, embeddings, classifications, summaries, transformations, evaluations, and logs.
  • Provider routing metadata, latency, token usage, safety or moderation signals, and diagnostics.

We may transmit this information to third-party AI/model API providers for temporary inference, processing, moderation, safety, evaluation, or related service operations. Providers may change over time.

2.10 Communications and Support Data

We may collect contact information, messages, support requests, feedback, transactional email data, notification preferences, and related communications. If Resend or another email provider is enabled, we may use it to send transactional or service communications.

2.11 Information From Other Sources

We may receive information from:

  • Other users, hives, organizations, administrators, application developers, or profile owners.
  • Clerk, Stripe, Supabase, Vercel, Sentry, Resend, OpenStreetMap/Nominatim, analytics providers, AI/model providers, and other service providers.
  • Public sources, if you or others make information public.
  • Integrated applications, webhook endpoints, or developer services.
  • Legal, compliance, fraud-prevention, payment, or security partners.

3. How We Use Information

We may use personal information for the following purposes:

  • Provide, operate, maintain, secure, and improve the Service.
  • Create and manage accounts, sessions, authentication, reverification, and account deletion workflows.
  • Create, display, manage, and operate profiles, personas, handles, avatars, publicness settings, hives, organizations, collections, templates, artifacts, responses, Pages/Portals, applications, APIs, and webhooks.
  • Process user content and files at your direction.
  • Enable sharing, publishing, access grants, permissions, memberships, application access, public teaser surfaces, and developer integrations.
  • Process payments, subscriptions, refunds, disputes, chargebacks, invoices, taxes, payout eligibility, Connect onboarding, revenue holds, withdrawals, and accounting.
  • Provide AI-powered features, including routing data to AI/model providers for inference or processing.
  • Geocode user-entered address or place strings.
  • Send service, transactional, security, support, legal, and administrative communications.
  • Monitor usage, measure performance, debug, test, develop, and improve features.
  • Conduct analytics, product measurement, advertising measurement, attribution, and similar activities.
  • Detect, prevent, investigate, and respond to fraud, abuse, spam, security incidents, unauthorized access, policy violations, and legal violations.
  • Enforce our terms, policies, and rights.
  • Maintain audit, provenance, consent, compliance, tax, accounting, payment, dispute, and legal records.
  • Comply with applicable law, legal process, regulatory obligations, and lawful requests.
  • Evaluate or complete a merger, acquisition, financing, reorganization, bankruptcy, sale, transfer, or other corporate transaction.

4. How We Disclose Information

We may disclose personal information to the following categories of recipients:

  • Service providers and processors. Providers that host, store, process, secure, monitor, analyze, support, or operate the Service, including Supabase, Vercel, Sentry, Resend if enabled, analytics providers, AI/model providers, and similar providers.
  • Clerk. For authentication, account management, sessions, verified emails/domains, reverification, step-up authentication, and account deletion workflows.
  • Stripe. For payment processing, Stripe Connect, subscriptions, invoices, refunds, disputes, fraud/risk, KYC, tax, bank information, and payouts.
  • OpenStreetMap/Nominatim and geocoding providers. For location resolution when you enter address or place strings.
  • Other users and Chaos OS participants. Other users, profile owners, hive members, organization admins, collection owners, template owners, application owners, and similar participants according to your settings, access grants, memberships, roles, sharing choices, publicness settings, and product actions.
  • Public viewers. Anyone who can access public profiles, public Pages/Portals, public handles, public teaser surfaces, public images, publicly shared content, or publicly accessible URLs.
  • Application developers and webhook endpoints. Developers, applications, agents, and destination endpoints where you or an authorized user grant access, configure integrations, subscribe to events, or direct Chaos OS to send information.
  • AI/model providers. Third-party AI/model API providers that process inputs, user content, metadata, and outputs for inference, processing, moderation, evaluation, or related service operations.
  • Analytics and measurement providers. Providers that help us understand usage, improve the Service, perform attribution, or measure advertising or product performance.
  • Professional, legal, compliance, security, and fraud-prevention recipients. Auditors, advisors, insurers, law firms, banks, payment networks, regulators, law enforcement, courts, and compliance partners.
  • Corporate transaction recipients. Parties involved in an actual or proposed merger, acquisition, financing, reorganization, bankruptcy, sale, or transfer of assets or business.
  • With consent or direction. Other recipients when you consent or direct us to disclose information.

We do not broker, rent, or sell user content to data brokers. However, analytics, advertising measurement, and similar technologies may be considered a "sale," "sharing," "targeted advertising," or "cross-context behavioral advertising" under some U.S. state privacy laws. See the U.S. State Privacy Notice below.

5. Public Sharing, Pages/Portals, and User-Directed Disclosures

Chaos OS includes public and shared surfaces. Depending on your settings and actions, the following may be visible to other users or the public:

  • Profile display names, handles, avatars, intros, links, publicness settings, profile type, and public geographic visibility.
  • Public Pages/Portals, Portal hero images, Portal sections, Portal items, and public handles.
  • Collections, templates, artifacts, responses, files, metadata, provenance, comments, messages, or other content you make public or share.
  • Membership, role, creator, owner, admin, application, or provenance indicators where shown by the Service.
  • Geographic information at the public level you select or that is required for a feature, such as city, state, country, neighborhood, or other location granularity.

Public information may be copied, saved, indexed by search engines if indexing is enabled, scraped, disclosed, or used by others outside Chaos OS. We cannot control what others do with information you or authorized users make public.

Avatars and Portal hero images are in a public images bucket and may be accessible by URL even if displayed in a limited context. Do not upload sensitive images to those fields.

6. Developer Applications, APIs, and Webhooks

Chaos OS allows users and authorized administrators to create applications, grant applications access, use APIs, and configure webhooks. These features are designed to move data at user or administrator direction.

Application/API request logs may include content-bearing JSON payloads and responses. We use these logs for operation, debugging, audit, security, abuse prevention, developer tooling, and platform integrity.

Webhook payloads may contain event data, identifiers, metadata, and information about the relevant resources. Webhook endpoints are controlled by the application developer or configured recipient, not by Chaos OS. Chaos OS may sign webhook deliveries, validate endpoint URLs, and maintain delivery/outbox logs, but we do not control how a receiving endpoint processes data after delivery.

If you grant an application access, install or activate an application, configure a webhook, or use developer tools, review the relevant developer, application, and destination privacy practices.

7. AI Processing

Chaos OS currently uses the Google Gemini API to generate embeddings that support artifact search. Depending on the content embedded, this may include text and other content or metadata submitted to the Service. We may introduce additional AI-powered features, such as generation, transformation, summarization, classification, search, analysis, extraction, moderation, evaluation, workflow automation, or agent behavior.

To provide these features, we may send user content, prompts, inputs, files, context, metadata, and outputs to third-party AI/model API providers. Providers may process data outside your state, province, or country. Providers may change, and different features may use different providers or model tiers.

Unless a separate agreement, feature-specific notice, or provider-specific disclosure says otherwise:

  • We do not guarantee that every AI provider has the same retention, deletion, confidentiality, security, or model-training terms.
  • We do not promise that AI providers never retain, review, or train on submitted data.
  • We may use AI outputs, metadata, and logs to operate, debug, evaluate, secure, and improve the Service, subject to applicable law and contractual commitments.
  • AI outputs may be inaccurate, incomplete, or inappropriate, and you are responsible for reviewing outputs before relying on them.

Do not submit sensitive or regulated information to AI features unless you have the right to do so and the feature is appropriate for that information.

8. Payments, Stripe, and Marketplace Features

Chaos OS uses Stripe for payment processing, subscriptions, Stripe Connect, invoices, refunds, disputes, fraud/risk review, tax, bank information, and payouts. Stripe may collect information directly from you, including card or payment method data, billing information, bank account data, identity verification/KYC information, tax information, risk signals, and payout information. Stripe's own terms and privacy notice apply to Stripe's processing.

Chaos OS may store or process Stripe customer IDs, Connect account IDs, subscription records, ledger entries, revenue records, withdrawal records, refund records, dispute records, payout eligibility, accounting status, and related metadata. We use this information to operate subscriptions, paywalls, response payments, marketplace features, payout flows, fraud prevention, tax/accounting, support, audit, compliance, and dispute handling.

Payment and accounting records may be retained for longer periods than account content because of tax, accounting, fraud prevention, chargeback, dispute, legal, audit, and compliance obligations.

Current product lifecycle facts include a subscription revenue hold period of approximately 7 days and a response payout hold period of approximately 48 hours. These are payment operation holds, not privacy deletion periods, and may change.

9. Cookies, Analytics, and Similar Technologies

Chaos OS and Clerk use cookies, local storage, and similar technologies needed for authentication, sessions, security, preferences, and core Service functionality. Sentry may be used for error monitoring where configured. Chaos OS does not currently use advertising technologies or third-party product analytics such as Google Analytics.

Categories may include:

  • Strictly necessary technologies. Required for login, authentication, sessions, security, fraud prevention, load balancing, preferences, and core Service functionality. Clerk authentication and security cookies are included in this category.
  • Monitoring and error tooling. Used for error logging, performance monitoring, diagnostics, debugging, and reliability, including Sentry where configured.
  • Future analytics and product measurement. If we introduce non-essential analytics or product-measurement technologies, we will update this disclosure and provide any required notice or choice mechanism before or when they are enabled.
  • Future advertising and measurement. Chaos OS does not currently use advertising, attribution, or cross-context behavioral advertising technologies. If that changes, we will update this disclosure and provide required controls before or when they are enabled.
  • Similar technologies. Other storage or measurement technologies used for security, preferences, integrations, or feature operation.

You may be able to control cookies through your browser settings, device settings, cookie notice, consent management platform, or privacy preferences we provide. Disabling certain cookies may prevent the Service from working correctly.

If we introduce non-essential cookies, analytics, advertising measurement, or similar technologies, we will provide any consent or opt-out controls required by applicable law before or when they are enabled. See the U.S. State Privacy Notice below.

Global Privacy Control and Opt-Out Preference Signals

Chaos OS does not currently engage in sale, sharing, targeted advertising, or cross-context behavioral advertising that requires a Global Privacy Control opt-out mechanism, and it does not currently operate a GPC signal handler. If that changes, we will update this Policy and implement required opt-out preference-signal handling before or when the relevant activity is enabled. You may submit privacy questions to support@chaosintelligenceinc.com.

10. Security

We use administrative, technical, and organizational measures designed to protect personal information. These measures may include access controls, authentication, authorization checks, signed URLs for private files, logging, monitoring, rate limiting, encryption or secret-management practices, provider security controls, and incident response processes.

No method of transmission or storage is completely secure. We cannot guarantee absolute security.

11. Retention, Deletion, and Account Closure

We retain personal information for as long as reasonably necessary for the purposes described in this Policy, including to provide the Service, comply with legal obligations, resolve disputes, enforce agreements, maintain security, prevent fraud and abuse, preserve audit and provenance records, administer payments, support accounting and tax requirements, and maintain backups.

Account deletion is generally a mix of soft deletion, deidentification, product-level deletion or suppression, and an external Clerk hard-delete attempt. We may retain information as needed for:

  • Security, fraud prevention, abuse prevention, and rate limiting.
  • Audit logs, product events, legal consent records, and provenance.
  • Payment disputes, refunds, chargebacks, subscriptions, ledgers, withdrawals, accounting, tax, and compliance.
  • Legal obligations, litigation holds, regulatory requests, and enforcement of terms.
  • User-directed, shared, public, or collaborative content that other users, hives, organizations, applications, public viewers, or developers may have access to.
  • Backups, disaster recovery, debugging, and business continuity.
  • Records that have been deidentified, aggregated, or otherwise processed so they are no longer personal information under applicable law.

Known operational lifecycle windows include:

  • Webhook outbox records may be retained for approximately 7 days after dispatch.
  • Delivered webhook delivery rows may be retained for approximately 30 days.
  • Failed or abandoned webhook deliveries may be retained for approximately 60 days.
  • Previous webhook signing secrets may remain available for approximately 24 hours during rotation.
  • Logger event partitions are retained for approximately 13 months by default.
  • Rate-limit rows may be swept after approximately 1 hour.
  • Application request-log deletion tooling is designed around an approximately 30-day window, but actual retention may vary based on operational scheduling, legal needs, security needs, backup handling, and the other retention reasons described in this Policy.

These windows are current engineering or operational defaults and may change. They do not override legal, security, tax, accounting, fraud-prevention, dispute, backup, or compliance retention needs.

12. Your Choices

Depending on the feature and applicable law, you may have choices to:

  • Update account or profile information.
  • Change profile publicness, public geographic visibility, sharing, membership, and access settings.
  • Remove or edit certain content, subject to retention, provenance, shared-content, public-content, payment, audit, and legal limits.
  • Disconnect or revoke certain access grants, applications, memberships, or integrations.
  • Manage cookie preferences or opt out of certain analytics, sale, sharing, targeted advertising, or advertising measurement where required.
  • Use browser privacy controls and any Chaos OS privacy controls made available when they are enabled.
  • Close or request deletion of your account, subject to the retention limits described in this Policy.

At this time, privacy requests should be submitted by email as described below unless we make additional privacy controls available in the Service.

13. U.S. State Privacy Notice

This section provides additional information for residents of U.S. states with consumer privacy laws, including California. The rights and disclosures in this section apply only where the relevant law applies to Chaos OS and to the relevant information.

13.1 Categories of Personal Information

The table below describes categories of personal information we may collect, sources, purposes, and categories of recipients. The categories are broad because Chaos OS is a flexible user-content and developer platform.

CategoryExamplesSourcesPurposesCategories of recipients
IdentifiersName, display name, handle, email, phone, account ID, Clerk ID, Stripe IDs, IP address, device identifiers, public profile URLsYou, Clerk, Stripe, device/browser, other users, service providersAccounts, authentication, profiles, payments, security, support, communications, complianceService providers, Clerk, Stripe, other users by direction, public viewers where public, applications/webhooks by direction, legal/compliance recipients
Customer recordsAccount contact information, billing contact information, payment account records, support recordsYou, Clerk, Stripe, service providersAccount administration, payments, support, legal/complianceService providers, Clerk, Stripe, legal/compliance recipients
Protected classification characteristicsAge/date of birth, demographic information you provide, language, location-related demographic signals where applicableYou, profile settings, service providersProfile features, payout eligibility, compliance, personalization where enabledService providers, other users/public viewers if you make public, legal/compliance recipients
Commercial informationSubscriptions, purchases, paywalls, ledger records, revenue, withdrawals, refunds, disputes, invoices, payout eligibilityYou, Stripe, Chaos OS systemsPayments, subscriptions, accounting, fraud prevention, tax/compliance, supportStripe, service providers, professional advisors, legal/compliance recipients
Internet or network activityIP address, device/request metadata, logs, pages/actions, API activity, application request/response logs, webhook delivery logs, cookie dataDevice/browser, Chaos OS systems, service providersService operation, security, analytics, debugging, rate limiting, abuse prevention, API/webhook operationService providers, analytics providers, Sentry, Vercel, Supabase, applications/webhooks by direction, legal/compliance recipients
GeolocationAddress/place strings, latitude/longitude, city, state, country, neighborhood, public geographic visibilityYou, OpenStreetMap/Nominatim or similar providersProfiles, hives, location features, payout eligibility, public geographic visibility, geocodingService providers, OpenStreetMap/Nominatim, other users/public viewers if you make public, legal/compliance recipients
Audio, visual, and similar informationAvatars, Portal hero images, uploaded images, videos, audio, files, generated mediaYou, other users, applicationsUser content, profiles, Pages/Portals, artifacts, responses, AI features, sharingService providers, public viewers where public, other users by direction, AI providers where used, applications/webhooks by direction
Professional or employment-related informationOrganization affiliation, role, admin status, developer role, business profile information, billing email, organization metadataYou, organizations, other users, StripeOrganizations, hives, roles, access, payments, support, complianceService providers, Stripe, other users by direction, public viewers where public
Education informationEducation-related content only if you or others upload or provide itYou, other users, applicationsUser-directed content and Service operationService providers, other users by direction, public viewers where public, AI providers where used
InferencesPreferences, eligibility, abuse/risk signals, product analytics, profile or usage-derived signalsChaos OS systems, service providers, analytics providersSecurity, eligibility, personalization where enabled, analytics, product improvementService providers, analytics providers, legal/compliance recipients
Sensitive personal informationAccount login credentials or tokens handled through Clerk, precise geolocation if provided, date of birth, payment/payout identity and financial data handled primarily by Stripe, tax/KYC data handled primarily by Stripe, contents of communications or user content where legally sensitiveYou, Clerk, Stripe, device/browser, service providersAuthentication, security, payments, payout eligibility, legal/compliance, service operation, user-directed content processingClerk, Stripe, service providers, public viewers if you make public, other users/applications/webhooks by direction, legal/compliance recipients
User content and communicationsCollections, templates, artifacts, revisions, blocks, responses, files, metadata, provenance, comments, messages, prompts, AI inputs/outputsYou, other users, applications, AI providersService operation, sharing, publishing, AI features, support, security, provenance, legal/complianceService providers, AI providers, other users by direction, public viewers where public, applications/webhooks by direction, legal/compliance recipients

13.2 Sale, Sharing, Targeted Advertising, and Data Brokers

Chaos OS does not broker, rent, or sell user content to data brokers.

Chaos OS does not currently use advertising, attribution, or third-party product-analytics technologies that sell or share personal information or constitute targeted advertising. If we introduce such technology, we will update this notice and provide any required opt-out controls before or when it is enabled.

If Chaos OS later engages in sale, sharing, targeted advertising, or similar activity, you may use the controls identified in the updated notice or contact support@chaosintelligenceinc.com to exercise applicable rights.

We do not knowingly sell or share personal information of consumers under 16.

13.3 Sensitive Personal Information

We use sensitive personal information for purposes such as authentication, security, fraud prevention, payment and payout processing, tax/accounting, legal compliance, profile/location features, user-directed content processing, and Service operation. Where applicable law gives you a right to limit certain uses or disclosures of sensitive personal information, you may submit a request by contacting support@chaosintelligenceinc.com or using any privacy controls made available in the Service.

13.4 Your U.S. State Privacy Rights

Depending on your state and subject to applicable exceptions, you may have the right to:

  • Know or access the personal information we collect, use, disclose, sell, or share.
  • Receive a portable copy of certain personal information.
  • Correct inaccurate personal information.
  • Delete personal information.
  • Opt out of sale, sharing, targeted advertising, profiling, or automated decision-making where applicable.
  • Limit certain uses or disclosures of sensitive personal information.
  • Appeal a denied request where applicable.
  • Not be discriminated against for exercising privacy rights.

13.5 How to Submit Requests

Submit privacy requests to:

We may need to verify your identity or authority before completing a request. Verification may require account login, confirmation through Clerk, email verification, or other information reasonably necessary to match you to the relevant account or profile. Authorized agents may submit requests where permitted by law, but we may require proof of authorization and may ask you to verify your identity directly.

We may deny or limit requests where allowed by law, including where we cannot verify the request, the request is excessive or fraudulent, the information is publicly available or exempt, or retention is needed for security, fraud prevention, legal compliance, payment disputes, tax/accounting, audit, provenance, user-directed sharing, or other permitted reasons.

13.6 California Shine the Light

California Civil Code Section 1798.83 may allow California residents to request certain information about disclosures of personal information to third parties for their direct marketing purposes. Submit requests to support@chaosintelligenceinc.com with "California Shine the Light" in the subject line.

14. GDPR, UK GDPR, and International Privacy Module

This section applies if Chaos OS processes personal data subject to the GDPR, UK GDPR, or similar laws.

14.1 Controller and Processor Roles

Chaos Intelligence LLC is generally the controller for account, authentication, billing, payment operations, security, analytics, support, legal, product, and platform operations data.

Chaos OS may act as a processor for user content, organization data, application data, or customer-controlled workflows when we process data on behalf of a customer, organization, developer, or user under applicable terms. In those cases, the relevant customer or user may be the controller and may be responsible for providing privacy notices and responding to rights requests.

14.2 Lawful Bases

We may rely on the following lawful bases:

  • Contract. To provide the Service, authenticate users, manage accounts and profiles, process user content, provide APIs/webhooks, administer subscriptions and payments, provide support, and enforce terms.
  • Legitimate interests. To secure, improve, debug, measure, and operate the Service; prevent fraud and abuse; maintain audit and provenance records; conduct analytics; develop features; and protect Chaos OS, users, and third parties, where those interests are not overridden by your rights and interests.
  • Consent. For certain cookies, analytics, marketing, optional profile fields, AI features, or other processing where consent is required. You may withdraw consent where applicable.
  • Legal obligation. To comply with tax, accounting, payment, legal, regulatory, sanctions, law enforcement, and compliance obligations.
  • Vital interests or public interest. Where required in rare circumstances to protect people or comply with public-interest obligations.

14.3 Special Category Data

Chaos OS is not designed for uploading special category data unless a feature or separate agreement specifically supports it. However, user content, demographics, location, messages, files, or AI inputs may include special category data if you or others provide it. You are responsible for ensuring you have a lawful basis and any required permissions before uploading or sharing special category data.

14.4 International Transfers

Chaos OS is based in the United States, and we may process personal data in the United States and other countries. These countries may have privacy laws that differ from those where you live.

Where required, we use appropriate transfer mechanisms, which may include Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, adequacy decisions, Data Privacy Framework certifications where applicable, provider transfer terms, or other lawful transfer mechanisms.

14.5 GDPR/UK Rights

Subject to applicable limits, you may have the right to:

  • Access your personal data.
  • Correct inaccurate or incomplete personal data.
  • Delete personal data.
  • Restrict processing.
  • Object to processing based on legitimate interests or direct marketing.
  • Port certain personal data.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with your local data protection authority.

To exercise rights, contact support@chaosintelligenceinc.com. If Chaos OS processes your data as a processor, we may refer your request to the relevant controller.

14.6 Cookies and Consent

Where required by EU, UK, or similar laws, we will seek consent before using non-essential cookies or similar technologies and provide a way to withdraw or adjust consent. Strictly necessary cookies may be used without consent where permitted.

14.7 Data Processing Addendum

Customers that need a Data Processing Addendum, Standard Contractual Clauses, UK Addendum, subprocessor list, or similar terms should contact support@chaosintelligenceinc.com.

15. Children and Minors

You may use the Service only if you are at least 18 years old, or the age of legal majority in your jurisdiction if higher. The Service is not intended for children under 13, and we do not knowingly collect personal information from children under 13 without legally required parental consent. If you believe a child under 13 has provided personal information to Chaos OS, contact us at support@chaosintelligenceinc.com.

Certain features, especially payments, payouts, public sharing, developer applications, or AI features, may require additional eligibility requirements.

We do not knowingly sell or share personal information of minors in a way that requires opt-in consent under applicable law.

16. Marketing and Communications

We may send transactional, administrative, legal, support, security, and service-related communications. These are part of the Service and you may not be able to opt out of them while maintaining an account.

If we send marketing communications, you may opt out using the unsubscribe link or instructions in the message or by contacting support@chaosintelligenceinc.com. We may still send non-marketing communications.

17. Third-Party Links and Services

The Service may link to, embed, integrate with, or route data to third-party services, including Clerk, Stripe, AI providers, analytics providers, developer applications, webhook endpoints, and public websites. We do not control third-party privacy practices. Review their privacy notices before using those services or directing Chaos OS to share information with them.

18. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We may provide notice by posting an updated Privacy Policy, updating the effective date, sending email, showing an in-product notice, requiring reacceptance, or using another reasonable method. Changes are effective when posted or as stated in the notice.

19. Contact

Questions or requests about this Privacy Policy may be sent to:

Chaos Intelligence LLC Texas, United States
support@chaosintelligenceinc.com

You may submit privacy, access, deletion, correction, portability, opt-out, cookie, sale/share, targeted advertising, sensitive information, and appeal requests by emailing support@chaosintelligenceinc.com. You may also use any privacy controls made available in the Service.

For EU/UK matters:

  • Privacy contact: support@chaosintelligenceinc.com
  • EU representative: not appointed unless separately identified in the Service or a supplemental notice.
  • UK representative: not appointed unless separately identified in the Service or a supplemental notice.
  • Data Protection Officer: not appointed unless separately identified in the Service or a supplemental notice.