ChadAI Privacy Policy
Effective date: 1 October 2026
ChadAI is a browser productivity assistant operated by Rose Ramlochan, and published as Chadwell deGenerative AI Technologies. It is intended for adults aged 18 and over.
Privacy questions and deletion requests: help@madesimple.app.
What we collect and why
- Account and login information: your name, email, profile, sign-in information and session tokens. These support registration, verification, sign-in and remembering your session. With Google sign-in, we receive permitted account information, not your Google password.
- Conversations and content: messages, attachments, voice input, transcripts, assistant replies and saved memories/preferences. These let the assistant respond, continue conversations and personalize help. Information you choose to share may be sensitive.
- Billing information: plan, subscription, checkout and payment-status records. Stripe processes payment details. We use billing records to manage your subscription and allowances.
- Usage and diagnostic information: token and voice usage, request outcomes, errors, tool requests/results, signup steps and feature/payment events. These support service operation, troubleshooting and product improvement. Some diagnostic logs can contain conversation text or tool content as well as identifiers and timestamps.
- Connection and device information: IP address, approximate IP-based location, browser/device details, timezone, language and screen characteristics. These support session records and compatibility troubleshooting. The reviewed session path does not collect GPS location.
The avatar does not automatically read a website's text, forms or images. The extension does not automatically scrape host pages, take screenshots or control their contents. You choose what text, images or links to share in chat.
To display the hosted assistant and validate its communication, the extension sends the current site's origin, such as https://example.com, to our hosted ChadAI service. This identifies the site where the assistant is displayed. The overlay does not send the page's full path, query string or title as page context. Ordinary network requests can also provide IP and referrer information to servers.
Voice and AI processing
Starting voice with microphone permission sends audio for speech, transcription and responses. A separate transcription pass may correct a completed utterance, and transcripts can be saved in chat. Stopping voice does not delete earlier conversations.
Relevant messages, media, conversation context and selected memories are sent to the configured AI service to answer your requests. Storing a memory or its search index on our infrastructure does not mean it stays entirely on your device or never reaches an AI provider. When you use web search, relevant queries or URLs are sent to the search provider.
Providers we use
The following providers receive information needed for the features they supply:
- OpenAI: assistant responses, image understanding, transcription and speech.
- Amazon Web Services (AWS), including S3: infrastructure, media and file storage, and avatar assets.
- Vercel: website and hosted assistant delivery, including ordinary hosting/request information.
- Stripe: payment processing, subscriptions and billing management when payment features are used.
- Resend: verification, password-reset and other account emails when email features are used.
- Bright Data: web search and page retrieval when those tools are used.
- Google: sign-in and permitted account/profile information if you choose Google sign-in.
Provider processing depends on the feature you use and the applicable service arrangements. Information may be processed outside your country. Additional connected services must be disclosed before their use; they receive information needed for the actions you authorize.
How we limit data use
We use personal data to provide, secure and improve the disclosed assistant functionality. We do not sell personal data, use it for targeted advertising, or use or transfer it for creditworthiness or lending. Browsing-origin information is not used to build advertising profiles.
Transfers are limited to service purposes, legal obligations, and permitted security or fraud-prevention purposes. Human access is limited to permitted support with consent, necessary security/legal work, and permitted internal operations using aggregated, anonymized information. Our use and transfer of user data follows the Chrome Web Store User Data Policy, including its Limited Use requirements.
Storage and your choices
The extension stores preferences and assistant view information in your browser profile. If Keep me signed in is enabled, it also stores session/account information locally. Signing out clears the extension's saved session/view data; turning off Keep me signed in removes its saved token. These actions do not delete server-side records.
You can disable automatic display, restrict site access in Chrome, revoke microphone permission, sign out or uninstall. Uninstalling does not delete your account or cancel a subscription. Manage subscriptions through Usage & Plan or contact us for help.
Retention and deletion
Account information, saved conversations and memories are retained to provide the service until you request deletion. You can request access, correction or deletion by emailing help@madesimple.app. We may verify ownership to protect your account.
Deletion requests are handled manually. We delete or anonymize the personal data covered by your request within 30 days of verifying account ownership, except for the limited retention situations described below. This is a request-handling period, not automatic deletion of all messages after 30 days.
Separate logs and backups: deleting a main account record does not automatically remove every diagnostic, tool-use or backup copy. These records can include identifiers and conversation/tool content. We review them as part of a deletion request and remove or anonymize personal data unless a specific retention exception applies.
Limited records may need to remain for a legal obligation, necessary security/fraud investigation, or an unresolved payment or legal dispute. They are retained only for that purpose and as long as necessary. If an exception or a backup/provider constraint prevents complete deletion within the request period, we explain what remains, why, and the applicable next step or timeframe. Retained copies are not used to continue personalization or for advertising.
Security and changes
We use secure connections for production data transmission and access controls for service operation. No system can guarantee absolute security.
We update this page when our practices change and show the effective date above. Material changes will be communicated through the service, with any required notice or consent before the changed use begins.
Contact help@madesimple.app for privacy questions or requests.