Legal
Privacy Policy
Last updated: March 21, 2026
1. Introduction
ChimAura (“we,” “us,” or “our”) operates the ChimAura web application and related services (the “Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use the Service.
ChimAura is designed for general wellness and relaxation. It is not a medical device, mental health platform, or substitute for professional care.
By accessing or using the Service, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use of the Service. This policy is incorporated into our Terms of Service.
2. Information We Collect
We collect information you provide directly, information generated by your use of the Service, and limited technical data required to operate the Service securely.
3. Account and Authentication Data
When you register, we collect:
- Email address and display name
- Hashed password (we never store your password in plaintext)
- Email and phone verification status
- Account creation date and session tokens
- Legal consent records: which version of our Terms and Privacy Policy you accepted, and when
4. Wellness, Meditation, Mood, and Journal Data
As you use the Service, we store:
- Mood selections and check-in notes you enter
- Meditation session type, duration, voice preference, and completion status
- Breathing exercise sessions and sleep wind-down sessions
- Journal entries (reflections, gratitude logs, free-form notes)
- Daily usage counts (meditations, speech generations, horoscope views)
- Session history, favorites, saved presets, and streak data
- Saved affirmations and prompts you bookmark
This data is used to personalize your experience and is not sold or shared with third parties for marketing purposes.
5. Horoscope, Zodiac, and Astrological Profile Data
If you choose to add astrological profile information, we store:
- Birthdate and calculated zodiac sign
- Birth time (optional)
- Birth location (city/country text)
- Latitude, longitude, and timezone derived from or provided with birth location
This data is used solely to personalize horoscope and cosmic reflection features within the Service. It is not shared with third-party astrology providers in identifiable form.
6. AI Processing and Generated Content
ChimAura uses third-party AI services (currently OpenAI) to generate meditation scripts, voice narrations, and related content. Your session inputs (mood, duration, type) are sent to these services to produce your personalized session. We do not send your journal entries, astrological data, or account details to AI providers unless explicitly required for a feature.
AI-generated content is for general wellness and relaxation only. It does not constitute medical advice, mental health treatment, or a substitute for professional care.
7. Payment and Subscription Data
Payment processing is handled entirely by Stripe, our third-party payment processor. We do not store full card numbers, CVVs, or raw bank details on our servers. We store:
- Your Stripe customer ID and subscription ID
- Subscription tier (free or premium), status, billing interval, and current period end
- Billing-related webhook event logs
Stripe's data practices are governed by the Stripe Privacy Policy.
8. Email Delivery and Account Communications
We send transactional emails for:
- Email address verification after signup
- Password reset requests
- Billing confirmations and payment failure notices (via Stripe)
- Material changes to our Terms or Privacy Policy
Email delivery is handled by a third-party email provider. We share your email address with this provider only as necessary to send these communications. You cannot opt out of strictly transactional emails (verification, password reset, billing).
9. Push Notifications and Device Data
If you enable push notifications, we store your browser push subscription endpoint, encryption keys, device label (if provided), and platform type. This data is used only to deliver notifications you have opted into. You can revoke push notification permission at any time through your browser settings or in the app notification preferences.
10. Logs, Rate Limiting, IP Hashing, and Security Monitoring
To operate the Service securely and detect abuse, we collect:
- Hashed IP addresses (we apply a one-way hash with a server-side salt; we do not store your raw IP address in most cases)
- User-agent strings (browser and OS type)
- API request logs (route, method, status code, timestamp)
- Rate limit counters associated with hashed identifiers
- Webhook event logs from payment processors
These logs are used for fraud prevention, abuse detection, debugging, and capacity planning. They are not used for behavioral advertising.
11. How We Use Information
We use the information we collect to:
- Provide, operate, maintain, and improve the Service;
- Personalize AI-generated meditation and wellness sessions to your mood and preferences;
- Process transactions and manage your subscription;
- Send transactional and account communications;
- Detect, prevent, and address technical issues, fraud, and abuse;
- Comply with applicable legal obligations;
- Enforce our Terms of Service.
12. How We Share Information
We do not sell your personal information. We may share your information with:
- AI content providers (e.g., OpenAI): Session inputs to generate your personalized meditation content. Governed by their applicable terms.
- Payment processors (Stripe): Billing and subscription management.
- Email delivery providers: To send transactional emails on our behalf.
- Cloud infrastructure providers: Hosting, database, and storage services required to operate the Service.
- Law enforcement or regulators: When required by law or valid legal process.
- Business transfers: In connection with a merger, acquisition, or sale of assets, user information may be transferred as a business asset.
All third-party service providers are contractually required to use your data only as directed by us and in accordance with their own privacy and security obligations.
13. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. Specific retention considerations:
- Account and session data: retained while your account is active
- Wellness session history and journal entries: retained while your account is active
- API request logs: retained for up to 90 days for security and debugging purposes
- Legal consent records: retained for the lifetime of the account for compliance purposes
- Billing records: retained as required by applicable tax and financial regulations
You may request deletion of your account and associated data at any time by contacting us at privacy@chimaura.com. We will fulfill deletion requests within 30 days, except where retention is required by law.
14. Your Choices and Data Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you;
- Request correction of inaccurate or incomplete data;
- Request deletion of your account and associated data;
- Object to or restrict our processing of your data;
- Receive a portable copy of certain data;
- Withdraw consent (where processing is consent-based);
- Lodge a complaint with a data protection supervisory authority.
To exercise any of these rights, or to request an export or deletion of your data, contact us at privacy@chimaura.com. We will respond within 30 days.
15. Children and Minors
The Service is not directed to individuals under the age of 13 (or 16 in the European Economic Area). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately at privacy@chimaura.com and we will promptly delete it.
16. Security
We implement industry-standard administrative, technical, and physical security measures to protect your personal information, including password hashing, encrypted sessions, hashed IP identifiers, and access controls. However, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security and encourage you to use a strong, unique password for your account.
17. International Users
The Service is operated from the United States. If you are accessing the Service from outside the United States, your information may be transferred to and processed in the United States or other countries where our service providers operate. By using the Service, you consent to such transfer. If you are located in the EEA or UK, we process your data under the legal bases of: performance of a contract, legitimate interests (security and fraud prevention), legal obligation, and consent where applicable.
18. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page, updating the “Last updated” date, and sending a notice via email or in-app notification. Your continued use of the Service after changes become effective constitutes your acceptance of the updated policy.
19. Contact
If you have questions about this Privacy Policy or your data, please contact us at: privacy@chimaura.com
See also our Terms of Service.