Privacy Policy
Last updated May 27, 2026
This policy explains what Chatlr ("we", "us") collects when you visit chatlr.ai or use the Chatlr service, how we use it, who we share it with, and the rights you have over your data. This document is written in plain English on purpose. If anything is unclear, write to hello@chatlr.ai.
1. Who runs Chatlr
Chatlr is operated by CliqStream B.V., registered at Stadhouderskade 85, 1073 AT Amsterdam, Netherlands ("the operator"). Chatlr is the data controller for the personal data described below. You can reach the operator at hello@chatlr.ai.
2. What we collect
Account data
- Email address, supplied at sign-up.
- A hashed password, if you choose email/password authentication.
- Account creation date and last-sign-in timestamp.
Conversation data
- The prompts you send to Chatlr and the model responses you receive.
- Per-conversation metadata: chosen tier, provider, model alias, message timestamps, and token/credit usage accounted to your plan.
Anonymous-session data
- When you chat without an account, we mint an anonymous Supabase identity tied to a browser cookie. We count your usage against a daily-salted SHA-256 hash of your IP address. The raw IP is never stored.
Billing data
- Stripe customer ID, current subscription status, and the last four digits / brand of the card on file. Full card numbers are handled by Stripe and never reach Chatlr's servers.
Technical & analytics data
- IP address (only at request time — see above re hashing), browser user agent, country derived from IP, and the URL of pages you visit.
- Anonymous interaction events: which plan card you clicked, whether you hit the anonymous cap, whether you joined the waitlist.
3. How we use it
- Operate the service. Authenticate you, route your prompts to AI providers, store your conversation history, and meter usage against your plan.
- Billing. Charge the right amount via Stripe and send receipts.
- Abuse prevention. Detect bot traffic, enforce rate limits, and protect the anonymous tier from cost amplification.
- Product improvement. Aggregate, anonymised metrics on which features get used. We do not train AI models on your conversations.
- Communication. Send transactional emails (waitlist confirmation, billing receipts, security alerts). We will not send marketing email without your separate consent.
4. Who we share data with
We use the following sub-processors:
- Supabase — primary database and authentication. Stores your account, conversations, and usage rows.
- Cloudflare — hosting, edge networking, DDoS mitigation, transactional email delivery, and bot detection.
- Stripe — subscription billing and card-on-file storage.
- AI providers (OpenAI, Anthropic, and others routed through our LiteLLM gateway).Your prompts and conversation context are sent to whichever provider you select via the tier/provider picker. We use each provider's API in zero-retention mode where available. We do not control the providers' own logging policies; consult their privacy policies linked from our Disclaimer.
- Google Analytics 4 & Google Tag Manager — aggregate site analytics and conversion measurement. We do not pass conversation content to these tools.
We do not sell your data, share it with data brokers, or use it for cross-context behavioural advertising.
5. How long we keep it
- Account & conversation data: retained while your account is active. Deleted within 30 days of account deletion.
- Anonymous-session conversations: retained for 30 days after last activity, then purged by a daily cron job.
- Billing records: retained for 7 years to satisfy financial-record requirements.
- IP-hash counters: rotated daily (24-hour salt window). After 30 days, all derived counters are deleted.
6. Your rights
Under GDPR/UK GDPR and equivalent regulations, you can:
- Request a copy of the personal data we hold about you.
- Ask us to correct inaccurate data.
- Delete your account and all associated conversations.
- Object to or restrict certain processing.
- Lodge a complaint with your local data protection authority.
Email hello@chatlr.aiwith the subject line "Data request" and we will respond within 30 days.
7. Cookies
We use a small number of cookies, all strictly functional:
- Supabase auth cookies — keep you signed in across requests. Required.
- Anonymous-session cookie — links you to your anonymous conversations between visits. Required for the free tier to remember your usage.
- Theme preference — remembers your light/dark mode choice.
- Analytics cookies set by Google Tag Manager and GA4— anonymous device + session counters. You can disable these via your browser's Do Not Track or by blocking the GTM/GA domains.
8. Security
All traffic to chatlr.ai is encrypted in transit (TLS 1.3 via Cloudflare). The Supabase database is encrypted at rest. Secrets (Stripe keys, AI provider keys, the Supabase service-role key) live in Cloudflare Worker secret bindings and never appear in our source code or client bundle. Row-Level Security policies enforce data isolation at the database layer — each user can read only their own conversations.
No system is perfectly secure. If you discover a vulnerability, report it to hello@chatlr.ai and we will respond promptly.
9. Children
Chatlr is not directed at children under 13 (under 16 in the EU / EEA). We do not knowingly collect personal data from children. If we learn that a child has created an account, we will delete the account and associated data.
10. International transfers
Your data may be processed in jurisdictions outside your country of residence, including the United States and the European Union, where our sub-processors operate. Where data leaves the EEA / UK we rely on the European Commission's Standard Contractual Clauses or equivalent safeguards.
11. Changes to this policy
If we make material changes we will email account holders and update the "Last updated" date at the top of this page. Continued use of Chatlr after a change means you accept the revised policy.
12. Contact
Questions, data requests, or complaints? hello@chatlr.ai.
This page is provided as a transparent summary of our practices. It is not legal advice; if your jurisdiction requires specific disclosures we may not have anticipated, contact us and we will address them.