Chumi (“we,” “us,” or “our”) operates the Chumi web application at chumi.app (the “Service”). This Privacy Policy explains what information the Service collects, how it is used, and your rights regarding that information.
By using the Service you agree to the collection and use of information as described in this policy. If you do not agree, do not use the Service.
When you create an account, we collect your email address, display name, and authentication credentials (or, if you sign in through a third-party provider such as Google or Apple, the identity token that provider shares with us). We store this information on our servers to maintain your account.
During onboarding and assessments the Service asks you to provide personal information including your first name, birth date, birth time, birthplace, birth sex, birth order, family background, personality questionnaire responses, relationship information, dealbreakers, a personal story, body and health assessments, values, beliefs, and journal entries.
Depending on your account status and the features you use, this data may be stored on your device in your browser’s local storage, on our servers, or both. If you use the Service without creating an account, data is stored on your device only. If you create an account, your data may be synced to our servers to enable multi-device access, cloud backup, and social features.
Certain assessments ask about health-related topics including body symptoms, sleep patterns, medications, substance use, mental health history, and sexual health. We understand that the nature of personality and wellness assessments may lead you to share sensitive information. This data is subject to the same storage and transmission practices described in this policy. When you request AI-generated reports, sensitive data may be transmitted to third-party AI providers for processing unless you have opted out of profile sharing (see Section 5).
When you purchase a subscription or make a payment, your payment is processed by Stripe, Inc., a PCI-compliant third-party payment processor. We do not receive, store, or have access to your full credit card number, debit card number, or bank account number. Stripe provides us with a limited set of information associated with your transaction, including the last four digits of your card, card brand, expiration date, billing name, billing address, email address, and transaction history. This information is stored on our servers and associated with your account.
Payment processing is subject to Stripe’s privacy policy and terms of service.
When you use features that generate AI-powered analysis or reports, certain data is transmitted to third-party AI providers for processing. The specific data varies by feature:
If you use social features such as sharing reports, connecting with friends, or viewing shared content, we collect and store information about those interactions, including which users you are connected with and what content you have shared or received.
We may collect information about how you use the Service, including pages viewed, features used, session duration, device type, operating system, browser type, and general geographic location (country or region, not precise location). We may use cookies, local storage, or similar technologies for this purpose.
If you opt in to push notifications, we collect and store the notification subscription token provided by your browser or device. You can revoke this permission at any time through your browser or device settings.
We use the information we collect for the following purposes:
The Service uses OpenRouter to route requests to AI language model providers. When you request an AI-generated feature, data described in Section 1.5 is transmitted to OpenRouter and then to the underlying AI model provider.
Important: Once your data is transmitted to a third-party AI provider, it is subject to that provider’s own privacy policy and data practices. While we select providers that commit to not using input data for model training, we cannot guarantee how third parties handle data after transmission. We encourage you to review OpenRouter’s privacy policy.
We may change AI providers or add new providers at any time. We will update this policy to reflect material changes in our provider relationships.
We share information with third-party service providers who perform services on our behalf, including payment processing (Stripe), AI model providers (via OpenRouter), hosting and infrastructure providers, email delivery services, and analytics providers. These providers are contractually obligated to use your information only as necessary to provide their services to us.
We may share, sell, license, or otherwise disclose aggregated, de-identified, or anonymized data that cannot reasonably be used to identify you. This may include statistical trends, assessment patterns, and demographic insights derived from user data.
We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others, investigate fraud, or respond to a law enforcement request.
If we are involved in a merger, acquisition, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your information.
We may share your information with third parties when you have given us explicit consent to do so.
When the Service first presents the AI consent screen, you may uncheck the profile-sharing option. If you opt out, AI-generated features will still work but will not include your personality profile, health data, personal story, or dealbreakers in requests to AI providers. You can change this setting at any time.
You can opt out of promotional communications at any time by using the unsubscribe link in any email or by adjusting your notification settings in the app. Account-related communications (such as payment confirmations, security alerts, and Terms updates) are not optional while your account is active.
You can delete your data at any time using the delete control in the app. If you have an account, you may also request deletion of your account and all associated server-side data by contacting us at privacy@chumi.app. We will process deletion requests within thirty (30) days.
Deletion does not retroactively delete data that was previously transmitted to third-party AI providers or payment processors during the processing of your requests or transactions.
Certain information may be retained after deletion as required by law, for legitimate business purposes (such as fraud prevention), or to resolve disputes. Any retained data will be de-identified or minimized to the extent practicable.
You may request a copy of your personal data in a commonly used, machine-readable format by contacting us at privacy@chumi.app.
We retain your personal information for as long as your account is active or as needed to provide you the Service. If you delete your account, we will delete or de-identify your personal information within thirty (30) days, except as required by law or for legitimate business purposes.
Data stored only on your device (local storage) is retained until you delete it, clear your browser data, or uninstall the app.
Payment records and transaction history may be retained for up to seven (7) years as required by tax and financial reporting regulations.
Server logs containing metadata (timestamps, IP addresses, request sizes) are retained for no more than ninety (90) days for operational and security purposes.
We use commercially reasonable measures to protect your information, including:
However, no method of electronic transmission or storage is perfectly secure. We cannot guarantee absolute security, and you use the Service at your own risk. You are responsible for maintaining the security of your account credentials.
The Service is not directed to children under the age of sixteen (16). We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided personal information through the Service, please contact us at privacy@chumi.app and we will take steps to remove that information and terminate the associated account.
If you are a California resident, you have the right to: (a) know what personal information we collect, use, disclose, and sell; (b) request deletion of your personal information; (c) opt out of the sale or sharing of your personal information; (d) correct inaccurate personal information; (e) limit the use of sensitive personal information; and (f) not be discriminated against for exercising these rights.
To exercise these rights, contact us at privacy@chumi.app or use the in-app controls. We will verify your identity before processing your request.
Do Not Sell or Share My Personal Information: We do not currently sell your personal information as defined under the CCPA. If this changes, we will update this policy, provide notice, and honor opt-out requests via the in-app controls or by emailing us.
If you are located in the EEA, UK, or Switzerland:
In accordance with Article 50 of the EU AI Act: this application uses AI systems to interact with you. All AI-generated content is clearly labeled within the app. Your input is processed by third-party AI providers to generate responses. No biometric data processing, emotion recognition, or deep-fake technology is used.
The Service may use cookies, local storage, and similar technologies to:
You can control cookies through your browser settings. Disabling cookies may affect the functionality of the Service.
Chumi is not therapy, counseling, medical care, or crisis support, and it is not a substitute for any of those. The Service does not provide medical diagnoses, treatment recommendations, or professional advice of any kind. Content generated by the Service, including content related to health, personality, and relationships, is for informational and entertainment purposes only.
If you are in danger or experiencing a mental health crisis: call or text 988 (Suicide & Crisis Lifeline), text HOME to 741741 (Crisis Text Line), or call 1-800-799-7233 (National Domestic Violence Hotline).
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the “Last updated” date at the top of this page and, where required by law, by providing additional notice (such as an in-app notification or email). Your continued use of the Service after changes are posted constitutes your acceptance of the revised policy.
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:
© 2026 Chumi. All rights reserved.