Privacy
CHIMERA / PRIVACY POLICY1. Introduction
ChimeraMind processes account, billing, device, security, usage, and product data needed to operate the website, API, desktop app, support flow, and Whop-based billing. This policy explains what we collect, why we use it, and how to request access, export, correction, or deletion.
2. Data We Collect
- Account data: email, display name, user ID, authentication metadata, session metadata, and support messages.
- Billing data: Whop membership identifiers, plan, subscription status, invoices, payment event metadata, and refund workflow data.
- Trading and product data: watchlists, settings, paper trading state, orders, positions, P&L, model telemetry, alerts, and usage preferences.
- Credential metadata: provider, key type, status, timestamps, and masked key metadata. We do not display raw exchange secrets after storage.
- Developer API key metadata: key name, prefix, last four characters, hash, scope, creation, last-used, and revocation timestamps. Raw developer keys are shown once and not stored.
- Device and security data: IP address, user agent, platform, device label, session records, CSRF data, rate-limit signals, and audit logs.
- Website usage data: pages visited, feature interactions, diagnostics, crash reports, performance events, and cookie preferences.
3. How We Use Data
- Authenticate users, maintain sessions, and protect accounts.
- Operate paper trading, analytics, model telemetry, alerts, API access, and desktop app workflows.
- Sync billing status, plan access, invoices, cancellations, and refund requests through Whop.
- Detect abuse, investigate security incidents, enforce rate limits, and keep audit trails.
- Provide support, service notices, release updates, and account recovery.
- Improve reliability, performance, product quality, and documentation.
4. Processors and Infrastructure
ChimeraMind uses service providers to run the product. Current core processors include Supabase for authentication and database services, Resend for transactional authentication email, Cloudflare for hosting, edge routing, caching, DNS, and security controls, Whop for checkout, membership, billing, and payment event processing, PostHog for privacy-scoped product analytics, Better Stack for public uptime and incident visibility, and Sentry or comparable observability tools for crash and diagnostic reporting.
5. Retention
We keep account and billing records while your account is active and as needed for legal, tax, security, fraud-prevention, and dispute purposes. Revoked sessions, logs, webhook events, and key metadata may be retained for a limited audit window. Paper trading, profile, and product data can be removed or exported on request where technically and legally feasible.
6. Export, Deletion, and Correction
You may request access, export, correction, deletion, or restriction of personal data by contacting [email protected] from your account email. We may need to verify your identity and may retain records that are required for security, legal, accounting, dispute, or abuse-prevention reasons.
7. International Processing
Your data may be processed in countries where ChimeraMind, Supabase, Cloudflare, Whop, and other processors operate. We use contractual, technical, and organizational safeguards appropriate to the data and processing purpose.
8. Security of Data
We use access controls, HTTPS, token-based auth, rate limits, row-level isolation, secret hashing or encryption where appropriate, audit logs, and operational monitoring. No internet service can guarantee absolute security. Report security issues to [email protected].
9. Changes to This Privacy Policy
We may update this policy as the product, providers, laws, and security controls change. Material changes will be posted on this page and, where appropriate, communicated through account or product notices.
10. Contact
Privacy requests: [email protected]. Security reports: [email protected].