Chatmoe

Chatmoe Privacy Notice

Version: v3.1 Effective date: 2026-09-21 Last updated: 2026-09-21

This notice explains what personal data Chatmoe processes, why we process it, who we share it with, how long we keep it, and the rights you can exercise. It is written to meet the transparency requirements of the EU and UK General Data Protection Regulation (Articles 13 and 14).

Authoritative version

This English version is the authoritative version of this notice. If a translated version ever conflicts with it, this one prevails.

Chatmoe is operated by an individual developer. We deliberately do not publish a postal address: the operator is a single person, and publishing a home address would create a data protection risk of its own. Everything in this notice reaches us at privacy@chatmoe.cn, and if you need a postal address to serve a formal notice, ask us and we will provide one.

1. Who we are

Chatmoe (the "Service") is an AI assistant application operated by an individual developer ("Chatmoe", "we", "us"). For the purposes of the GDPR and the UK GDPR, we are the data controller for the personal data described in this notice.

Controller Chatmoe, an AI assistant service operated by an individual developer
Contact through privacy@chatmoe.cn
Privacy contact privacy@chatmoe.cn
EU / UK representative We are not established in the European Union or the United Kingdom, and we have not designated a representative under Article 27 of the GDPR. We consider our processing to fall within the exemption in Article 27(2), and we review that assessment as the Service grows: if it stops applying, we will designate a representative and name it here. Until then, data subjects in the EU and the UK reach us directly at privacy@chatmoe.cn, and we answer within the timescales in section 12.
Data Protection Officer We have not appointed a statutory DPO, because our processing does not meet the thresholds in Article 37. Privacy enquiries reach the operator at privacy@chatmoe.cn.

This notice covers the web application at app.chatmoe.cn, the website at chatmoe.cn, the Chatmoe API, and the emails we send you. It does not cover third-party services you reach through the Service, which have their own privacy policies.

2. In short

  • We collect what is needed to answer your messages, run your account, keep the Service secure and bill paid features. We do not collect more than that.
  • We do not sell your personal data, and we do not run advertising or cross-site tracking cookies.
  • We do not use your conversations to train AI models unless you give separate, explicit consent, and you can withdraw that consent at any time.
  • You can use the Service without an account, in which case your conversations stay in your own browser.
  • You can access, correct, export, or delete your data, and you can complain to a supervisory authority.

3. What we collect

We follow the principle of data minimisation: we collect personal data only where it is necessary to provide the Service, to keep it secure, or to comply with the law.

3.1 Data you give us

  • Account data: if you sign in, we process your email address and authentication data. Sign-in uses a one-time code sent to that address; we do not store a password.
  • Conversation content: the messages you send, the prompts you write, and the responses generated for you. If you are signed in, conversation history is stored so you can reopen it later.
  • Uploaded files: images, documents, PDFs, audio, and similar files you attach to a message, plus their extracted text where the feature needs it.
  • Support and feedback: the content of feedback, reports, or support requests you submit, together with your email address if you include it.
  • Order data: if you buy a paid plan, we process the order identifier, plan type, duration, amount, and payment status. Card and bank details are entered with, and processed by, the payment provider; we do not receive them.

3.2 Data collected automatically

  • Device and technical data: device type, operating system, browser type and version, screen size, and language settings.
  • Network data: IP address and the network used to reach us.
  • Usage and diagnostic data: request timestamps, features invoked, error and crash records, and performance metrics.
  • Security signals: rate-limit counters and abuse-prevention identifiers used to keep the Service available and to detect automated misuse.
  • Stored preferences: your interface language and similar display settings.

3.3 Device permissions

Some features need a browser permission. We request it only when you trigger that feature, and you can revoke it at any time in your browser or system settings:

  • notifications, for reply and status alerts;
  • clipboard, when you paste or copy content;
  • microphone and camera, for voice input and image capture;
  • storage, for local conversation and file management.

3.4 What we do not collect

  • precise location data;
  • your contacts, address book, or calendar;
  • biometric identifiers such as fingerprints or facial templates;
  • advertising identifiers, or data bought from data brokers.
Special category data

We do not ask for special category data (Article 9) and the Service is not built to process it. Please avoid putting health, biometric, political, religious, or similar details into your messages. If you do, you are choosing to share that content with us and with the model providers listed in section 6 so that the Service can answer you.

4. Why we process it, and on what legal basis

Purposes and the GDPR Article 6 legal bases we rely on.
Purpose Data involved Legal basis
Providing the Service: answering messages, running conversations, processing uploads Conversation content, uploaded files, device and network data Performance of a contract, Article 6(1)(b)
Creating and maintaining your account, sending sign-in codes, syncing your conversations Account data, conversation content Performance of a contract, Article 6(1)(b)
Keeping the Service secure: rate limiting, abuse and fraud prevention, DDoS mitigation, log analysis Network data, device data, usage and security signals Legitimate interests, Article 6(1)(f): protecting the Service and its users
Diagnosing faults and improving reliability and performance Diagnostic data, aggregated usage statistics Legitimate interests, Article 6(1)(f), using aggregated or anonymised data where possible
Operating paid plans: order handling, entitlements, usage accounting, receipts and support Account data, order data, feature-usage records Performance of a contract, Article 6(1)(b)
Meeting legal obligations: tax, accounting, responding to lawful requests Order data, account data, disclosure records Legal obligation, Article 6(1)(c)
Optional research, surveys, and testing new features with you Account data, your responses Consent, Article 6(1)(a), requested separately and withdrawable at any time
Using your content to train or fine-tune models Conversation content, uploaded files Consent, Article 6(1)(a). Not performed unless you opt in through a separate agreement

Where we rely on legitimate interests, we have carried out a balancing assessment and applied safeguards, including data minimisation, retention limits, and access controls. You can object to processing based on legitimate interests at any time (see section 12).

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before you withdrew.

We do not use your conversations for advertising, and we do not build advertising profiles about you.

5. Cookies and local storage

We use cookies and comparable browser storage for a small set of purposes:

Type What it does Examples
Strictly necessary Keeps you signed in, protects against cross-site request forgery, and lets the Service route requests correctly. Cannot be switched off without breaking sign-in. Session cookie, CSRF token
Preferences Remembers the choices you make, such as interface language and display settings. __locale cookie, local storage entries
Security Helps us recognise abnormal traffic and keep rate limits effective. Short-lived rate-limit markers
Offline cache A service worker caches application files on your device so the app loads quickly and can reopen cached conversations. Cache Storage buckets

We set no advertising cookies and no cross-site tracking cookies, so there is no tracking to consent to. If we ever add analytics or marketing cookies, we will ask for your consent first and update this notice.

You can clear or block cookies and site data in your browser settings. Blocking strictly necessary storage will prevent sign-in and conversation history from working.

6. Who we share it with

We do not sell your personal data. We share it only with the service providers we need to run the Service, and only as much as each purpose requires. Each provider acts under a data processing agreement that limits it to our instructions.

Processors and the data each one handles.
Provider Purpose Data involved
Cloudflare Hosting and edge delivery, DDoS protection, object storage for uploads, database hosting, and transactional email delivery IP address, request metadata, uploaded files, stored records, email address
AI model providers, including Cloudflare, Z.ai, DeepSeek, and Google Generating replies, embeddings, and image generation The content of the message being answered, the relevant conversation context, and attachments needed for that request
Tavily Web search, only when a search tool is used for your message The search query derived from your message
MDN (Mozilla) Developer documentation lookups, only when that tool is used The technical query derived from your message
Alipay Payment processing for paid plans Order identifier, amount, order status, and the payment details you enter with them

We may also disclose personal data when:

  • you ask us to, or give separate consent for a specific sharing;
  • we must comply with a lawful request from a court, regulator, or law enforcement authority, in which case we check the request's validity and disclose only what it requires;
  • it is necessary to protect someone's vital interests, for example in an emergency;
  • it is necessary to establish, exercise, or defend legal claims;
  • a reorganisation, merger, or transfer of the Service takes place, in which case the recipient remains bound by this notice, and we will tell you before your data is transferred.

We publish aggregate statistics about usage. Those figures cannot reasonably be used to identify you.

7. International transfers

The Service runs on a global edge network. Your personal data may be processed outside your country, including in the United States, Singapore, and the European Union, because Cloudflare serves requests from the location closest to the user and AI model inference happens where the provider operates.

For transfers out of the EEA, the UK, and Switzerland, we rely on:

  • the European Commission's Standard Contractual Clauses (Decision 2021/914), incorporated into our agreements with processors;
  • the UK International Data Transfer Addendum, where the UK GDPR applies;
  • an adequacy decision, where the destination country benefits from one.

We also apply transfer safeguards: encryption in transit, minimal caching of sensitive content, restrictions on what each provider may access, and access controls on our side. You can request a copy of the safeguards we rely on at privacy@chatmoe.cn.

8. How long we keep it

Data Where it lives Retention How it ends
Conversation content (server side) Cloudflare edge data stores While your account is active, then up to 30 days after you delete a conversation or close your account Deletion by you in the app, or automatic purge after account closure
Conversation content (local) Your own device Until you delete it Clearing the conversation or your browser storage
Uploaded and generated files Cloudflare R2 object storage While your account is active, then removed when you close your account Deletion by you, or removal as part of closing your account
Images handed to a model provider The provider's own file storage Up to 30 days from upload — the lifetime is set when the file is uploaded Removed together with the file it belongs to when you close your account, or automatically when that lifetime ends
Account record Cloudflare D1 database Life of the account, then up to 30 days Account closure
Sign-in sessions Cloudflare D1 database Up to 30 days from sign-in, or until you end that session Signing out, signing out all devices, changing your account email, or automatic expiry
IP address and access logs Cloudflare log pipeline Up to 30 days, for security and abuse investigation Automatic expiry
Order and payment records Cloudflare D1 database For as long as applicable tax and accounting law requires Automatic purge once the statutory period ends
Aggregated statistics Analytics storage Up to 24 months Periodic purge

If you use the app without an account

You can use the Service as a guest. Your conversations and any files you upload or generate are then tied to a random identifier stored in your browser instead of to an account. If you sign in later from that same browser, we move that data into your account so it carries over. If you never sign in, we delete guest conversations, deployed sites, and uploaded or generated files after 90 days without activity, so that data does not accumulate without an owner.

When you close your account

Closing your account removes your conversations and their messages, the sites you deployed, the files you uploaded and the images generated for you, the devices signed in to your account, and your usage records. Where an image had to be handed to a model provider for it to be read, we delete the provider's copy at the same time; if the provider cannot be reached at that moment, that copy expires on its own within 30 days. We complete this removal before the account itself is deleted, so a failure leaves the account intact for you to retry rather than leaving data behind with no way to reach it. Order and payment records are the one exception, for the reason given above.

If law requires us to keep something longer, or if we need it to establish, exercise or defend legal claims, we keep it for that period only and then delete it.

9. How we protect it

  • Encryption in transit: the Service is served over HTTPS only.
  • Encryption at rest: sensitive fields are stored encrypted, and storage is protected at the platform level.
  • Session control: every sign-in creates its own session, recorded server-side. Settings lists the devices signed in to your account with the last activity of each, lets you end any single session, and lets you sign out of all devices at once. Ending a session stops it from working immediately rather than when it would have expired.
  • Access control: role-based, least-privilege access for the people who operate the Service, with credentials managed as secrets rather than in code.
  • Verification: code review and periodic security testing of the application and its dependencies.
  • People: team members are bound by confidentiality obligations.

If something goes wrong

If a personal data breach occurs, we assess it without delay and, where it is likely to result in a risk to your rights and freedoms, notify the competent supervisory authority within 72 hours of becoming aware of it (Article 33). If the breach is likely to result in a high risk to you, we also tell you without undue delay, describing what happened and what we are doing about it (Article 34).

10. Automated processing and AI

  • No decisions made solely by a machine. We do not take decisions that produce legal effects for you, or similarly significantly affect you, on a solely automated basis. If we ever introduce such a process, we will tell you and provide the safeguards Articles 22 and 13(2) (f) require.
  • AI output is not professional advice. Model responses can be wrong, incomplete, or biased. They are not legal, medical, financial, or psychological advice. Do not rely on them for decisions that need a qualified professional.
  • Human review. If a safety or abuse decision restricts your account and you believe it was wrong, write to support@chatmoe.cn and a person will review it.
  • Model training. We do not train or fine-tune models on your conversations unless you agree through a separate opt-in. You can withdraw that consent at any time, after which your content is excluded from future training runs.
  • Transparency. We aim for a transparent, non-discriminatory service. If you spot behaviour that looks biased or unsafe, please report it.

11. Children

The Service is designed for adults. It is not directed to children, and we do not knowingly collect personal data from them.

  • Under 14: the Service is not offered, and we do not knowingly process personal data of children under 14. If we learn we have, we delete it.
  • 14 to 17: the Service may be used only with the express consent and under the guidance of a parent or guardian.
  • EEA and UK: where local law sets a higher age of digital consent, we require verifiable parental consent below that age, and we do not process such data without it.
  • Parents and guardians: you may ask us to show, correct, or delete data relating to a child in your care, or to withdraw consent, by writing to privacy@chatmoe.cn.

12. Your rights

Subject to the conditions in the GDPR, you have the right to:

  1. Be informed about how your personal data is processed, which is what this notice is for.
  2. Access your personal data and obtain a copy of the data undergoing processing.
  3. Rectify inaccurate or incomplete personal data.
  4. Erase your personal data where the law provides for it, for example when it is no longer needed for the purpose it was collected for.
  5. Restrict processing while a question about accuracy or lawfulness is resolved.
  6. Data portability: receive the personal data you provided in a structured, commonly used, machine-readable format, and transmit it to another controller where technically feasible.
  7. Object to processing based on legitimate interests, and to object at any time to processing for direct marketing. We do not send marketing today; if we ever do, this right applies immediately.
  8. Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
  9. Not be subject to solely automated decisions that produce legal or similarly significant effects.
  10. Complain to a supervisory authority, as described in section 13.

How to exercise them

  • Self-service in the app: Settings lets you manage your account, export your data, and delete conversations or your account.
  • By email: write to privacy@chatmoe.cn, telling us who you are, how to reach you, and what you want. Write from the address associated with your account where possible.
  • We may ask for information needed to confirm your identity before acting, so that we do not hand your data to someone else. We do not use identity checks to collect more data than necessary.

We respond to rights requests within one month of receiving them. Where a request is complex or you have made several, we may extend that by up to two further months, and we will tell you why within the first month. Exercising your rights is free; we may charge a reasonable fee, or refuse, only for requests that are manifestly unfounded or excessive, and we will explain our reasons.

Other regions

If you are in a jurisdiction with its own data protection law, you also have the rights it grants you, including the right to know, delete, and correct under California law, the right to opt out of the sale or sharing of personal data (we do not sell or share personal data for advertising), and the rights granted by the Personal Information Protection Law of the People's Republic of China. Contact us at privacy@chatmoe.cn to exercise them, and we will not discriminate against you for doing so.

13. Complaints

If you believe we have handled your personal data unlawfully, please tell us first at privacy@chatmoe.cn so we can put it right. You always have the right to lodge a complaint with a supervisory authority, in particular in the country where you live or work, or where the alleged infringement took place. As we are not established in the EU or the UK and have not designated a representative, you can bring that complaint yourself to the authority for your country, and we will cooperate with it.

Severity, safety, and abuse reports can go to report@chatmoe.cn.

14. Changes to this notice

We update this notice when our processing changes, when the law changes, or when a regulator requires it. The current version and its effective date are always shown at the top of this page, and the version number increases with each revision.

For material changes, for example a new purpose, a new category of data, or a new international transfer, we give you clear notice in advance through the app or by email. If the change relies on consent, we ask for it separately rather than treating continued use as agreement.

If you do not agree with a change, you can stop using the Service, delete your account, and exercise your right to erasure. Earlier versions are available on request.

15. Contact us

Privacy and data rights privacy@chatmoe.cn
General support support@chatmoe.cn
Reports and complaints report@chatmoe.cn
Postal address Not published, for the reason given in section 1. Write to privacy@chatmoe.cn; if you need a postal address to serve a formal notice, ask us and we will provide one.

Write to us in English, Chinese, or Japanese. We answer in the language you wrote in, or in English.