Chordize AI

Effective date: September 2, 2026 | Version: location-2026-09-02

Privacy Policy

How Chordize AI collects, uses, discloses, retains, and protects personal information for the website, wallet, AI features, and desktop application.

1. Scope and controller

This Privacy Policy explains how Chordize AI Inc., operating as Chordize AI (“Chordize AI”, “we”, “us”, or “our”), collects, uses, discloses, retains, and protects personal information when you use our website, account portal, AI services, wallet/top-up features, desktop application, communications, and support channels (the “Service”).

For privacy questions, contact support@chordize.com. Our mailing address is #1219, 39 Niagara street, Toronto ON M5V 0T6 Canada.. Where applicable, Chordize AI is the controller or business responsible for personal information collected through the Service. Certain providers, such as payment processors and AI providers, may act as our processors/service providers or as independent controllers/businesses depending on the context and their own terms.

2. Personal information we collect

CategoryExamples
Account and identity informationEmail address, username or display name, password hash, account ID, account settings, preferences, consent records, login status, and support identifiers.
Billing and wallet informationWallet balance, top-up amount, currency, transaction IDs, Stripe customer/session/payment identifiers, invoices, receipts, refunds, chargebacks, taxes, billing country, and limited card metadata such as brand, funding type, country, last four digits, and processor-provided card or payment fingerprints where provided by Stripe for fraud and dispute prevention. We do not store full card numbers.
AI usage and User ContentPrompts, selected text, pasted text, analysis requests, AI outputs, model selected, provider selected, Detect AI requests, token counts, word counts, estimated and actual cost, latency, safety flags, error logs, and usage history.
Device, technical, and security dataIP address, user agent, device and browser information, operating system, desktop app version, crash or diagnostic information, request IDs, authentication events, failed login information, cookies/local storage, and abuse-prevention logs.
CommunicationsSupport messages, feedback, emails, complaint details, refund requests, legal notices, and related metadata.
Approximate location and tax dataCountry, region/province/state, time zone, tax jurisdiction, IP-derived approximate location, and payment/billing location information used for fraud prevention, tax calculation, and compliance.
Optional account locationIf you turn on “Use my location,” the coordinates and accuracy supplied by your browser, your browser-reported time zone, capture and expiry times, coordinate precision, and a consent record. The stored coordinate payload is rounded and encrypted.

2.1 Optional account location

“Use my location” is off by default and requires a separate choice in your signed-in Account settings. When you turn it on, your browser asks for location permission and sends the resulting coordinates to Chordize over HTTPS. Browser coordinates can be precise when first supplied. Before database storage, Chordize rounds the coordinates to the configured approximate precision and encrypts the location payload. The website does not place the coordinates in cookies, local storage, or session storage, and the account-location status API does not return them to the browser.

When this setting and the corresponding service features are enabled, we may use the fresh approximate location to localize a request. For non-Gemini models, location is applied only when you choose Search Web. For Gemini, relevant location or place requests may use Google Maps grounding automatically. The approximate location may therefore be sent with the applicable request to Google or another selected AI or search provider. It is not used for advertising.

The encrypted location expires 30 days after capture and an expired location is not used for requests. You may refresh it to start a new 30-day period. Turning “Use my location” off deletes the saved location payload immediately. We retain a separate consent audit record containing the account ID, action, policy version, source, and time—but no coordinates—for compliance, security, and dispute records under our general retention practices.

3. Sensitive information and content warnings

Except for the optional browser-location flow described in Section 2.1, the Service is not designed to receive highly sensitive personal information, including government IDs, financial account credentials, payment card numbers, passwords, health information, biometric information, precise location, children’s information, special-category data, trade secrets, privileged legal material, or regulated business records. Do not place precise addresses or coordinates in prompts or selected text unless you have lawful authority, have assessed the risk, and accept that they may be processed by us and third-party providers to provide the Service.

If you submit personal information about another person, you are responsible for having a lawful basis, consent where required, and the authority to do so.

4. How we use personal information

We use personal information for the following purposes:

5. Legal bases for EEA/UK users

Where GDPR, UK GDPR, or similar laws apply, our legal bases may include: performance of a contract for account, AI, wallet, desktop, and support features; legitimate interests in security, fraud prevention, service improvement, billing integrity, and enforcement; compliance with legal obligations for tax, accounting, sanctions, consumer, and privacy laws; consent where required for optional communications, cookies, or certain processing; and, where applicable, establishment or defence of legal claims.

6. AI providers and third-party disclosures

We may disclose or make available personal information to:

Third-party providers may have their own terms and privacy policies. We do not control how independent third parties process personal information outside our instructions or agreements.

7. Cookies, local storage, and similar technologies

We may use cookies, local storage, session storage, and similar technologies to keep you signed in, remember settings, secure the Service, prevent abuse, measure performance, and support checkout flows. Where required by law, we will request consent for non-essential cookies. Browser settings may allow you to block or delete cookies, but some Service features may stop working.

We do not currently sell personal information or share personal information for cross-context behavioural advertising as those terms may be defined by certain U.S. state privacy laws. If that changes, we will update this policy and provide required choices.

8. International processing and transfers

We may process and store personal information in Canada, the United States, the European Economic Area, the United Kingdom, and other countries where we or our providers operate. These countries may have privacy laws that differ from those where you live. Where required, we use appropriate safeguards for international transfers, such as contractual protections, standard contractual clauses, adequacy decisions, provider data-processing terms, or other lawful transfer mechanisms.

9. Retention

We retain personal information only as long as reasonably necessary for the purposes described in this policy, unless a longer period is required or permitted by law. Typical retention periods include:

Record typeTypical retention
Account recordsFor the life of the account and a reasonable period after closure for security, backup, dispute, tax, and legal purposes.
Wallet, payment, receipt, tax, and refund recordsAs required for tax, accounting, financial, chargeback, fraud, audit, and legal obligations, often 7 years or longer where required.
AI usage logs, cost records, and request metadataAs needed to provide balances, investigate issues, enforce policies, improve reliability, and support billing audits, subject to minimization and deletion processes.
Prompt/output body logsDisabled by default unless needed for debugging, consented/authorized, or otherwise lawful; retained for a short period where enabled.
Optional account-location payloadUp to 30 days from capture unless you refresh it; deleted immediately when you turn the setting off, and expired payloads are excluded from request processing and removed by bounded cleanup.
Location consent auditContains no coordinates and is retained as reasonably needed to demonstrate consent or withdrawal and meet security, dispute, and legal obligations.
Security and abuse logsAs long as needed to protect the Service, investigate misuse, comply with provider/legal obligations, and prevent repeat abuse.
Support communicationsAs long as needed to resolve the issue and maintain business/legal records.

10. Security

We use administrative, technical, and organizational safeguards designed to protect personal information, such as access controls, password hashing, transport encryption, encryption of stored account-location payloads, logging designed to redact location fields, monitoring, limited access, and provider security controls. No internet service, AI system, payment system, or storage system is completely secure. You are responsible for protecting your devices, passwords, sessions, and account credentials.

11. Your privacy choices and rights

Depending on where you live, you may have rights to access, correct, delete, export, restrict, object to, or withdraw consent for certain processing of your personal information. You may also have rights to complain to a privacy regulator, appeal a denied request, use an authorized agent, opt out of certain processing, or avoid discrimination for exercising rights.

Canadian users may contact us about access, correction, consent, safeguards, and complaints. EEA/UK users may have GDPR/UK GDPR rights. California and certain U.S. state residents may have rights to know/access, delete, correct, opt out of sale/share or targeted advertising, limit sensitive personal information, and non-discrimination where applicable.

You can withdraw optional account-location consent at any time by turning off “Use my location” in Account settings. This deletes the stored location payload without affecting your account or your ability to use non-location features.

To exercise rights, contact support@chordize.com. We may verify your identity before responding. Some information may be exempt from deletion or access where needed for legal, tax, security, fraud-prevention, billing, dispute, backup, or legitimate business purposes.

12. Automated processing and human review

The Service may use automated systems for AI responses, moderation, rate limits, billing calculations, wallet debits, fraud detection, security alerts, and policy enforcement. We do not intend to make solely automated decisions that produce legal or similarly significant effects about you. If an automated safety or billing action affects your access, you may contact us to request review.

13. Children and minors

The Service is not directed to children or minors and may only be used by adults who can form a binding contract. We do not knowingly collect personal information from children under 13, or under a higher age where applicable law requires parental consent. If you believe a child has provided personal information, contact us so we can investigate and delete it where required.

14. Breach notification

If we determine that a security incident involving personal information requires notice under applicable law, we will notify affected individuals, regulators, providers, or other parties as required. We may also keep records of security incidents as required or permitted by law.

15. Changes to this policy

We may update this Privacy Policy from time to time. The updated version will be posted with a new effective date. For material changes, we may provide additional notice through the Service, email, checkout flow, or another reasonable method.

16. Contact

Privacy contact: support@chordize.com
Legal entity: Chordize AI Inc.
Mailing address: #1219, 39 Niagara street, Toronto ON M5V 0T6 Canada.