Effective 2026-07-31
Privacy Policy
This Privacy Policy explains how ChatStory handles account data, private uploads, generated outputs, public stories where available, and legal acceptance records.
Version: 2026-07-31-v1
Information we process
We process account information such as Firebase Auth UID, email address, display name, photo URL where provided, role, status, and login timestamps.
We process uploaded chat exports, uploaded documents, images and attachments, generated outputs, order metadata, technical/security logs, support messages, and consent/acceptance records.
Uploads may contain information about third parties. You should upload only material you have rights, permissions, consent, or lawful authority to process.
Private uploads
Private uploads are separate from public stories. A private upload never automatically becomes public.
Private uploads are processed only as necessary to provide the requested service, create the requested output, deliver the output, handle support or security needs where necessary, prevent fraud or abuse, and comply with legal obligations.
ChatStory does not sell private chats. ChatStory does not use private uploads for AI/model training unless a separate feature is implemented with explicit consent.
Publicly published stories
If public publishing is available, public stories may be visible to other users and potentially the public. Publishing requires a deliberate separate action and separate publishing consent.
Public stories may remain available until removed by the author, restricted by ChatStory, or removed for legal, safety, or policy reasons.
Purposes
We use information for authentication, account management, providing requested processing, generating and delivering outputs, order tracking, customer support, security, fraud and abuse prevention, legal compliance, and maintaining audit records of required consents.
Infrastructure and processors
The current application uses Firebase for authentication and Firestore database functionality, Backblaze B2 through an S3-compatible server-side integration for private storage, and Vercel/Next.js serverless functionality for application hosting and route handlers.
B2 credentials are server-side. The browser receives short-lived signed URLs for authorised storage actions; privileged storage credentials are not exposed to the client.
Retention
Original private uploaded processing files are intended to be deleted within 72 hours after processing is completed, subject to limited operational, security, support, and legally required retention. The timer begins when processing is completed, not when the file is first uploaded.
Generated outputs may be retained separately where operationally necessary to provide downloads and account history. Public stories are not governed by the private-upload 72-hour rule.
Legal acceptance records are audit/compliance records and are not subject to the private-file deletion rule.
Security and access
We use reasonable technical and organisational safeguards, including authenticated storage route handlers and user-scoped private storage paths. No internet service can guarantee perfect security.
Customer private content may be accessed only when reasonably necessary for fulfilment, customer support, security or abuse investigation, or legal compliance.
Your choices and contact
You may contact admin@chatstory.in for privacy questions, support, or complaints. We may need to retain limited information where legally required or necessary for security, dispute handling, or audit evidence.