ChatOS

Privacy Policy

Effective date: [Effective date not yet set]

Last updated: [Last-updated date not yet set]

Related: Terms of Service

This Privacy Policy explains what information ChatOS collects, why, and how it's used. It should be read together with our Terms of Service.

1. Information received through Google/Firebase authentication

ChatOS uses Firebase Authentication for sign-in, exclusively via "Continue with Google." When you sign in, we receive and store your Google account's unique identifier and your email address. We do not request or store your Google password. We do not read your name, profile photo, or other Google profile fields as part of sign-in.

2. Profile information

You may optionally set a display name on your ChatOS profile. This is a name you choose yourself — it is not automatically pulled from your Google account. We also store your preferred speech-to-text mode (browser-based or server-based transcription) and whether your account has administrator privileges.

3. Conversation messages and transcripts

When you practice a conversation, we store the full text of each turn — both what you typed or said (after transcription) and the AI counterpart's replies — along with metadata such as when each session started and ended, how it ended, and an automated, per-turn quality judgment used to drive in-session feedback. After a session ends, we may generate and store a written summary report, a numeric score, and per-dimension feedback based on the full conversation.

4. Voice recordings

If you speak your responses, how your voice is handled depends on your speech-to-text setting:

  • Browser-based transcription (default): your voice audio is processed entirely by your browser's own built-in speech-recognition feature and never leaves your device. Only the resulting text is sent to ChatOS.
  • Server-based transcription: short audio clips of your speech are uploaded to our backend and sent to our AI transcription provider to be converted to text. This audio is processed in memory only — it is not written to disk, not stored in our database, and not retained after transcription completes. Only the resulting transcribed text is saved, as part of your conversation record described above.

When the AI counterpart "speaks" to you, its reply text is converted to speech on demand by our AI provider and streamed to your browser for playback — this generated audio is not stored by ChatOS.

5. Uploaded files and scenario context

ChatOS does not currently have a general file- or image-upload feature for users. When you start a practice session, you may optionally provide free-text "scenario context" — a short description of your specific situation. This text is stored as part of your session record and sent to our AI provider, along with the rest of the conversation, to tailor the AI's responses.

6. Session results, scores, CP, ranks, streaks, and activity

We track your overall progress across sessions: a running "Conversation Points" (CP) total, a rank derived from it, your current and longest practice streaks, and the dates you were active. This is calculated from your completed sessions and stored on your account so it can be shown on your dashboard.

7. Support cases

If you submit a support case, we store the subject, category, description, your replies, and ChatOS support staff's replies, so the conversation can be tracked and resolved. You may optionally attach images (capped in size, image files only) to a support message.

If you check the optional consent box when submitting a case, we also collect a small, fixed diagnostic snapshot — your browser's user agent string, your browser window's viewport size, the page URL you were on, and a timestamp — to help us troubleshoot. This diagnostic snapshot never includes cookies, authentication tokens, or the content of your messages.

Support cases are visible to you (the case owner) and to ChatOS administrators, for the purpose of responding to and resolving the case. Internal notes that administrators add to a case, and the diagnostic snapshot described above, are visible only to administrators, never to other users.

Support cases are retained as long as your account is active, matching the retention approach described in Retention and deletion below. If an administrator's account is later deleted, their replies remain visible in your case history, attributed to "ChatOS Support," rather than being removed.

We do not currently send email notifications about support case activity — replies appear within ChatOS under "My support cases."

9. Why each type of information is collected

We collect the information above solely to operate ChatOS: to authenticate you, to run practice conversations and generate the AI's responses, to transcribe your speech when you choose server-based transcription, to score and summarize your sessions, and to track and display your progress (CP, rank, streaks) back to you. We do not use this information for advertising, and we do not sell it.

10. Whether conversation content is sent to an AI provider

Yes. Your conversation messages (typed or transcribed), any scenario context you provide, and — if you use server-based transcription — your voice audio, are sent to our AI provider, OpenAI, to generate the AI counterpart's replies, to transcribe speech, to moderate messages for policy violations, to synthesize spoken AI replies, and to generate end-of-session scores and reports. This processing is subject to OpenAI's own terms and privacy practices in addition to this policy.

11. Relevant service providers

The following third-party service providers process data on our behalf:

  • Firebase (Google): authentication (Google sign-in and identity verification).
  • OpenAI: AI conversation responses, content moderation, speech-to-text transcription, text-to-speech, and report/score generation, as described above.
  • Database hosting: your account and conversation data is stored in a PostgreSQL database. [Confirm and disclose the specific database hosting provider].
  • Application hosting: [Confirm and disclose the hosting/deployment provider for the ChatOS website and backend].

We do not currently use Supabase Storage, Vercel Analytics, or any other analytics service beyond what is listed above; this section will be updated if that changes.

12. International data processing

Our service providers may process and store data outside of your home country, including in the United States. [Confirm specific data-residency/region details and any applicable international-transfer safeguards].

13. Retention and deletion

We retain your account information and conversation history for as long as your account is active, so that your practice history, scores, and progress remain available to you. [Specific retention periods (e.g. for inactive accounts, or after individual data categories are no longer needed) have not yet been defined]. You can delete individual practice sessions at any time from your dashboard, which removes that session's transcript, turns, and report. A self-service option to delete your entire account does not currently exist; see Account deletion below.

14. Security practices

We use industry-standard practices such as encrypted connections (HTTPS) and authenticated, per-request access control to protect your data in transit and limit who can access it. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

15. User rights to access, correct, export, or delete their information

You can view and update your display name and speech-to-text preference directly in the app. You can delete individual practice sessions from your dashboard at any time. For requests to access, correct, export, or delete other information we hold about you — including your full account — contact us using the information in Privacy contact information below.

16. Account deletion

ChatOS does not currently have a self-service "delete my account" feature. If you would like your account and associated data deleted, please contact us using the information below and we will process your request manually. [Define and disclose the account-deletion process and expected turnaround time once a formal process exists].

17. Children's privacy

[Minimum age / children's-privacy policy (e.g. COPPA compliance statement) not yet specified].

18. Policy updates

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date at the top of this page. We encourage you to review this page periodically.

19. Privacy contact information

[Privacy contact email/address not yet specified].