Privacy Policy
Last Updated: December 2025
Chema (“we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy describes the data we collect, how we use it, and the choices available to you.
Chema is designed to provide leadership guidance, clarity, and conversation-based assistance. We do not sell your data, track you across apps or websites, or use your information for advertising.
1. Information We Collect
We collect only the data necessary for Chema to function:
A. Account Information
When you create an account, we collect:
- Email address
- Supabase User ID (generated automatically)
Stored securely in Supabase, our managed database provider.
B. Subscription & Payment Information
If you upgrade to a paid plan (Leader or Founder), Stripe collects:
- Payment method
- Subscription tier
- Transaction history
- Stripe Customer ID
We do not store your full payment details on our servers. All payment data is processed and stored by Stripe, a PCI-compliant payment processor.
A copy of your subscription tier (free, Leader, Founder) is stored in Supabase so Chema can enable the correct features.
C. Messages (App Functionality Only)
When you use Chema:
- Your input message is sent to our backend (Render)
- The backend forwards it to OpenAI to generate a response
- The response is returned to your device
Messages are not used for advertising, not shared, and not linked with third-party data.
We retain minimal logs in Supabase only for troubleshooting and app functionality.
D. Device Information (Basic Technical Logs)
Automatically through our hosting provider (Render):
- IP address
- Timestamp
- Basic device type (iPhone, iPad, etc.)
Used solely for security, diagnostics, and preventing abuse.
2. How We Use Your Information
We use your data only for:
1. App functionality
- Handling conversations
- Returning responses
- Ensuring features work properly
2. Account & authentication
- Logging in
- Keeping your session active
- Saving your subscription tier
3. Payment processing
- Managing subscriptions via Stripe
- Updating your plan in Supabase
4. Security & diagnostics
- Monitoring system health
- Detecting spam or abuse
We do not use your data for marketing, advertising, or selling to third parties.
3. Third-Party Services We Use
We work with trusted vendors to operate Chema:
- Supabase: Stores user accounts, subscription tier, and app logs.
- Stripe: Handles subscription payments securely.
- OpenAI: Processes your messages to generate responses.
- Render: Hosts our backend infrastructure.
Each provider only uses data as required to perform the service.
4. Data Retention
We retain:
- Account info — while your account is active
- Subscription info — per financial compliance
- Messages — minimal retention for app functionality and debugging; not used for marketing
You may request deletion anytime.
5. Data Security
We use industry-standard safeguards:
- Encrypted database storage
- Secure HTTPS communication
- Stripe PCI-compliant payment processing
- Access control for internal systems
No system is perfect, but we take your data protection seriously.
6. Children's Privacy
Chema is intended for users 17 years and older.
We do not knowingly collect data from children.
7. Your Rights
You may:
- Request deletion of your account
- Update your email
- Cancel your subscription
- Export your data (upon request)
To exercise these rights, contact: support@chema.ai
8. Changes to This Policy
We may update this Privacy Policy as Chema evolves.
We will update the “Last Updated” date when changes occur.
9. Contact Us
For questions about this policy: support@chema.ai