← Back to Chirai

PRIVACY POLICY

Last updated: 9 August 2026

1. What we collect

Account data — your email address, and if you sign in with Google, your name and profile picture from that account. We never receive your Google password.

Build data — the prompts you write, any reference images you upload, and the source code generated for you. This is stored so you can return to past projects.

Payment data — plan, amount, transaction ID and status, from PayU. We never see or store your card, UPI or netbanking details. Those go directly to PayU, which is PCI-DSS compliant.

Technical data — basic logs needed to run and debug the service.

2. Why we process it

To operate your account, generate and deploy your applications, take payment via PayU, provide support, and diagnose failures. We do not sell your data, and we do not show third-party advertising.

3. AI processing

To generate your application, your prompt and relevant project context are sent to third-party AI model providers. Reference images you upload may also be sent where they inform the design. Only what is needed for generation is transmitted — never your payment details.

These providers process the data to return a result. Their handling is governed by their own terms, and we choose providers that do not train foundation models on API traffic by default.

4. Who else touches your data

Our hosting and deployment infrastructure, our database, and PayU for payments. Each receives only what their function requires. We do not share your data with anyone else except where the law requires it.

5. Retention

Account and project data is kept while your account is open. Delete a project and its stored files are removed. Close your account and we delete your personal data within 30 days, except transaction records we are legally required to retain for tax and audit purposes.

6. Your rights

Under India's Digital Personal Data Protection Act you may request access to your data, correction of it, or its erasure, and you may withdraw consent. Email the address on our Contact page and we will respond within 30 days. If you are unsatisfied you may escalate to the Data Protection Board of India.

7. Security

Data is encrypted in transit. Access to production systems is restricted. No system is perfectly secure, and if a breach affects your personal data we will notify you and the relevant authority as required by law.

8. Cookies

We use cookies strictly to keep you signed in and to remember basic preferences. No advertising or cross-site tracking cookies are used.

9. Payment providers inside your generated apps

If you configure Stripe, Razorpay, or another payment provider inside an app you generate, that provider processes your own customers' data directly — Chirai does not see or store it, and this policy does not cover it. That relationship is between you, your customers, and the provider you chose.

Terms of ServicePrivacy PolicyCancellation & RefundsContact & Grievance