Chipp Privacy Policy
Last updated: April 20, 2026
Use of AI and AI Products
In Short: Chipp offers a range of AI-powered products and features, all of which are powered by trusted third-party AI providers. We will never use your data to train any AI models. We are committed to transparency, responsible AI use, and compliance with applicable regulations, including the EU AI Act.
Our AI Products:
Chipp provides access to a suite of AI-driven tools and services designed to help users automate tasks, generate content, analyze data, and enhance productivity. These products include, but are not limited to, content generation assistants, workflow automation tools, data analysis modules, and customer support bots. All AI functionalities on our platform are powered by third-party providers, including OpenAI, Anthropic, and Google Cloud AI.
When you use our AI products, the data you provide—such as text, files, images, or other inputs—may be processed by these third-party AI systems to generate outputs or perform requested actions. We do not use your data to train any AI models unless you have given explicit consent and permitted by law. We require all third-party AI vendors to adhere to strict data protection and confidentiality standards.
Compliance with the EU AI Act and Other Regulations:
Chipp is committed to ensuring that the use of AI on our platform complies with the requirements of the EU Artificial Intelligence Act (AI Act), the UK GDPR, and other applicable data protection and AI regulations. In accordance with the EU AI Act and its annexes, we do not offer or support any AI practices that are prohibited under Article 5, including but not limited to:
- AI systems that deploy manipulative, deceptive, or exploitative techniques likely to cause significant harm to individuals.
- AI systems used for social scoring that result in unjustified or disproportionate treatment in unrelated social contexts.
- AI systems that perform profiling or risk assessment for predicting criminal offenses based solely on personality traits or characteristics.
- AI systems that create or expand facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- AI systems for emotion recognition in workplaces or educational settings, except where permitted for medical or safety reasons.
- AI systems that perform biometric categorization to infer sensitive characteristics such as race, political opinions, religious beliefs, or sexual orientation.
- Real-time remote biometric identification systems in publicly accessible spaces for law enforcement, except under the strict conditions and safeguards set out in the AI Act.
We regularly review our AI integrations and the practices of our third-party providers to ensure ongoing compliance with these and other legal requirements. Where required, we implement additional safeguards, conduct risk assessments, and provide transparency to users regarding the operation and limitations of AI systems on our platform.
Responsible AI Use
We are committed to the following principles regarding AI use:
- Transparency: We clearly inform users when they are interacting with AI systems and provide information about how these systems work and the data they process.
- User Control: You retain ownership of your data and outputs generated by our AI tools, subject to our Terms of Service. You may choose which features to use and can opt out of certain AI-driven functionalities where applicable.
- Privacy and Security: All data processed by our AI systems, through third-party providers, is handled in accordance with this Privacy Policy and applicable data protection laws. We implement technical and organizational measures to safeguard your data.
- No Automated Decisions with Legal or Significant Effects: We do not use AI to make automated decisions that produce legal or similarly significant effects on individuals without meaningful human involvement, unless required or permitted by law and with appropriate safeguards in place.
- Continuous Improvement: We regularly review and update our AI integrations to ensure they operate as intended, are free from bias to the extent possible, and comply with ethical and legal standards.
If you have questions or concerns about our use of AI and AI products, or if you wish to exercise your rights in relation to AI-driven processing, please contact us using the details provided in this Privacy Policy.
Introduction
Welcome to Chipp. We are a technology platform based in the United States, serving clients and users globally. This Privacy Policy explains how we collect, use, store, transfer, and protect your personal information when you interact with our platform, website, and related services. We value your privacy and are committed to handling your data responsibly and transparently, in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA/CPRA).
Who We Are
Chipp, Inc. (“we”, “us” and/or “ours”) is a technology company based in the United States, providing digital services to users worldwide. All data processing is conducted under our direct authority and in accordance with this Privacy Policy. If you have questions about this policy or our data practices, please contact us at info@chipp.ai.
What Data We Collect
We collect and process various categories of personal data to provide, maintain, and improve our services. The types of data we collect depend on your interactions with our platform and the choices you make regarding your privacy settings.
Information You Provide Directly
When you interact with our platform, you may provide personal data such as your name, email address, profile photograph, account credentials, and contact details. If you make purchases or subscribe to paid features, your payment information (such as card details) is processed securely by our third-party payment processor (Stripe); we do not store or retain your full payment card information. Additionally, we collect information you submit through communications with us, responses to surveys, feedback forms, and any other content you voluntarily provide via our services.
Information Collected Automatically
When you access or use our platform, we automatically collect certain technical and usage information. This includes your Internet Protocol (IP) address, device identifiers, browser type and version, operating system, language preferences, access times, referring URLs, and information about your activity on our platform (such as pages viewed, features used, and actions taken). We utilize analytics technologies, such as cookies and similar tracking tools, as well as third-party analytics providers, to help us understand how users interact with our services and to enhance your experience.
Information from Third Parties
We may receive personal data about you from third-party sources as necessary to provide our services. This may include information from authentication providers (such as Google or other single sign-on services), payment processors, business partners, and service providers who support our operations. The data received from these third parties is processed in accordance with this Privacy Policy and applicable data protection laws.
Sensitive Data
We do not intentionally collect sensitive personal data, such as information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health information, or data concerning a person’s sex life or sexual orientation (“special categories of personal data” under the GDPR), unless required by law or with your explicit consent when you are building a Chipp. If you believe you have inadvertently provided such information, please contact us so we can take appropriate action.
How We Collect Data
We collect personal data through a combination of direct interactions, automated technologies, and third-party sources, as described below.
Direct Collection from You
We collect information that you provide to us directly when you interact with our platform. This includes data submitted during account registration, profile creation, use of our services, completion of forms or surveys, participation in promotions or events, and when you communicate with us via email, support channels, or other means.
Automated Collection
When you access or use our website or platform, we automatically collect certain information about your device and usage through the use of cookies, web beacons, pixels, and similar tracking technologies. These tools enable us to gather data such as your IP address, device type, browser characteristics, operating system, referring URLs, and information about your interactions with our services. We also use analytics providers to help us understand user behavior and improve our offerings.
Collection from Third Parties
We may receive personal data about you from third-party sources in order to facilitate your use of our services or to enhance our platform. This includes information obtained from authentication providers (such as when you sign in using Google or other single sign-on services), payment processors, business partners, and service providers who assist us in delivering, maintaining, or improving our services. The data we receive from these third parties is processed in accordance with this Privacy Policy and applicable data protection laws.
We ensure that all methods of data collection are conducted in compliance with relevant legal requirements, and we provide you with appropriate notice and choices regarding the use of your personal data.
How We Use Data
In Short: We use the personal data we collect for a variety of purposes, all of which are necessary to provide, maintain, and enhance our services, to fulfill our contractual and legal obligations, and to protect both our users and our platform.
We use your data to establish and manage your account, including facilitating account creation, authentication, and secure access to our services. Your information is also used to process payments and transactions, which are handled securely through our third-party payment processor (Stripe). We do not store your full payment card details.
We rely on your data to provide customer support, respond to your inquiries, and address any issues or requests you may have. To improve our platform and user experience, we analyze usage data and trends using analytics tools, which help us understand how our services are accessed and used.
We may use your contact information to send you service-related communications, such as updates about your account, changes to our terms or policies, and important notifications regarding the operation of our services. With your consent, we may also send you marketing communications about new features, products, or promotions. You may withdraw your consent to receive marketing communications at any time.
We process personal data as necessary to comply with applicable legal obligations, resolve disputes, enforce our terms and policies, and protect our rights and interests. Additionally, we use data to detect, investigate, and prevent fraudulent activities, unauthorized access, and other security threats to our platform and users.
Where required by law, we will obtain your explicit consent before using your information for certain purposes, such as direct marketing or processing special categories of personal data. We ensure that all uses of your data are consistent with applicable data protection laws, including the GDPR, UK GDPR, and relevant US privacy regulations.
Legal Bases for Processing
In Short: We only process your personal data when we have a valid legal basis to do so, as required by applicable data protection laws such as the GDPR and UK GDPR.
For users in the European Union, United Kingdom, and other jurisdictions with similar data protection requirements, we process your personal data on one or more of the following legal grounds: consent, performance of a contract, compliance with a legal obligation, protection of vital interests, and our legitimate interests (including operating, maintaining, and improving our services, ensuring platform security, preventing fraud and abuse, and conducting business analytics), carefully balanced against your rights and freedoms.
If you have questions about the specific legal basis for any particular processing activity, or if you wish to exercise your rights under applicable data protection laws, you may contact us at any time using the contact details provided in this Privacy Policy.
How We Share Data
In Short: We do not sell your personal information. We share your data only when necessary to deliver our services, comply with legal obligations, or protect our rights and interests.
We engage trusted service providers to support the operation of our platform and the delivery of our services. This includes vendors such as Stripe for payment processing, PostHog for analytics, Google Cloud Platform for hosting, Cloudflare for edge routing and security, and reputable cloud hosting providers. These service providers act on our behalf and are contractually obligated to protect your personal data, process it only for the purposes we specify, and comply with applicable data protection laws.
We may disclose your personal data to legal or regulatory authorities, courts, or law enforcement agencies if required to do so by law, regulation, legal process, or governmental request. In the event of a business transaction such as a merger, acquisition, reorganization, or sale of all or a portion of our assets, your personal data may be transferred to the acquiring entity or successor as part of the transaction, and we will notify you of any material changes to the ownership or use of your personal data.
We may share your personal data with third parties when you have provided your explicit consent for us to do so. We take appropriate measures to ensure that any third parties with whom we share your data provide an adequate level of protection and process your data in accordance with applicable data protection laws, including the GDPR and UK GDPR where relevant.
Google User Data Disclosure
In Short: When you choose to sign in with Google or connect a Google service (Gmail, Drive, Calendar, Sheets, Tasks, Meet, or YouTube) to a Chipp AI agent, we only access the information needed for the specific feature you activated. We do not sell your Google user data, do not use it to train AI models, do not transfer it to third parties other than the cloud-hosting and AI providers required to deliver the feature you requested, and honor your request to disconnect or delete it at any time.
Chipp’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Data Accessed
Chipp uses Google OAuth scopes only when you explicitly initiate a feature that requires them. The scopes we request, and the reason for each, are:
1. “Sign in with Google” (account authentication)
openid,email,profile— via OpenID Connect, to create or authenticate your Chipp account. We read and store your Google account identifier (sub), email address, display name (optional), and profile picture URL (optional). No other Google data is read and no Google API is called after login.
2. Gmail integration (only when a builder or end-user connects a Gmail account to a Chipp agent)
https://www.googleapis.com/auth/gmail.modify— list, search, read, trash, and modify labels on messages in the connected inbox.https://www.googleapis.com/auth/gmail.send— send replies and new messages on your behalf when you ask the agent to do so.https://www.googleapis.com/auth/userinfo.email— identify which Google account is connected.
3. Google Calendar integration
https://www.googleapis.com/auth/calendar.events— list, create, update, and delete events on the connected calendar.https://www.googleapis.com/auth/userinfo.email— identify the connected account.
4. Google Drive integration (read-only)
https://www.googleapis.com/auth/drive.readonly— search, list, and read files you select so the agent can answer questions about them or include them as a knowledge source.https://www.googleapis.com/auth/userinfo.email— identify the connected account.
5. Google Sheets integration
https://www.googleapis.com/auth/spreadsheets— read, write, append rows to, and create spreadsheets you select.https://www.googleapis.com/auth/drive.readonly— list and discover spreadsheets in your Drive.https://www.googleapis.com/auth/userinfo.email— identify the connected account.
6. Google Tasks integration
https://www.googleapis.com/auth/tasks— list, create, update, and delete tasks and task lists.https://www.googleapis.com/auth/userinfo.email— identify the connected account.
7. Google Meet integration
https://www.googleapis.com/auth/meetings.space.created— create meeting spaces on your behalf.https://www.googleapis.com/auth/meetings.space.readonly— read details of meeting spaces you created, including conference records, participants, and recordings metadata.openid,email— identify the connected account.
8. YouTube integration
https://www.googleapis.com/auth/youtube.readonly— list your channels and videos.https://www.googleapis.com/auth/youtube.force-ssl— reply to comments on your videos (required by the YouTube Data API for comment moderation).https://www.googleapis.com/auth/yt-analytics.readonly— read channel and video analytics.openid,email— identify the connected account.
Data Usage
Google user data is used solely to deliver the specific feature you activated:
- Authentication data (Google account ID, email, name, profile picture) is used to create and identify your Chipp user account and to display your profile within the platform.
- Gmail data is used to let the connected agent list, read, search, send, reply to, and label emails in response to prompts you (or your end-users) give it.
- Calendar data is used to let the agent list, create, update, or delete events on your behalf.
- Drive files are used to let the agent read file contents when you ask about them, and — only if you explicitly choose to add a file as a “knowledge source” — to extract and store the text of that file so the agent can reference it in future conversations.
- Sheets data is used to let the agent read, write, and append rows at your request (for example, to log a form submission or return a report).
- Tasks data is used to let the agent read or manage your task lists at your request.
- Meet data is used to let the agent create meeting links and retrieve records of meetings you created.
- YouTube data is used to let the agent list your channel’s videos, surface analytics, and reply to comments on your behalf.
We do not use Google user data to train, develop, or improve any machine-learning or AI model — neither our own nor our third-party AI providers’. When Google user data is passed to an AI provider (see “Data Sharing” below), it is sent in real-time solely to produce the response the end-user requested, and our providers are contractually prohibited from using it to train their models. Organizations that require additional assurances can opt into zero-data-retention (ZDR) mode, where supported by the underlying AI provider, so that prompts and completions are not retained on the provider’s side.
We do not use Google user data for advertising, profiling, or any purpose other than delivering the feature the user activated and maintaining the Chipp service (including fraud prevention, security monitoring, and customer support).
Data Sharing
Google user data is not sold, not licensed, and not shared with any third party for advertising or marketing. The only third parties that may process Google user data are the infrastructure providers strictly necessary to deliver the Chipp service:
- Google Cloud Platform (us-central1) — hosts our application servers and PostgreSQL database where encrypted OAuth tokens and (in the case of Drive knowledge sources) extracted text are stored.
- Cloudflare — edge routing, TLS termination, DDoS protection, and bot management for traffic to our platform. Traffic passes through Cloudflare in-transit.
- AI model providers — when a Chipp agent processes a prompt that references Google data (for example, summarizing a Drive file), the relevant text is sent to the AI provider configured for that agent (OpenAI, Anthropic, or Google’s own Vertex AI). These providers act as subprocessors under data-processing agreements that forbid them from training models on our traffic.
- LlamaIndex (LlamaParse) — used only when ingesting a document-type Drive file (PDF, Word, PowerPoint, etc.) as a knowledge source, to extract readable text. Chipp does not persist the raw file after extraction — only the extracted text chunks are stored. LlamaIndex’s server-side handling of the upload is governed by their privacy policy.
We may also disclose Google user data (i) to comply with a valid legal process, (ii) to enforce our Terms of Service, or (iii) to a successor entity in the event of a merger, acquisition, or sale of assets, in which case we will give you notice.
Data Storage & Protection
Google OAuth access tokens and refresh tokens are encrypted at rest at the application layer using AES-256 (CTR mode) before being written to our database. Encryption keys are managed by Chipp outside the database and are not stored in source control. Tokens are decrypted only in-memory at the moment the agent makes an API call on your behalf. In addition, the managed PostgreSQL database itself provides transparent disk-level encryption.
All Chipp servers run on Google Cloud Platform in the United States (us-central1). Data in transit is protected by TLS 1.2+ end to end, including from the Cloudflare edge to our origin. Pods running in Google Kubernetes Engine reach the database over Google’s private service networking; direct database access is restricted to a small allowlist of engineer IPs required for operational maintenance.
We do not mirror your Google Drive, Gmail, Calendar, Sheets, Tasks, Meet, or YouTube account. When a Drive file is ingested as an optional knowledge source, we store the extracted text (not the original binary) so the agent can cite it later; this copy is clearly identified in the app’s builder as a “Google Drive” knowledge source and can be deleted at any time. For all other integrations, Google data is fetched on-demand for each agent action and is not retained beyond what is needed to produce the response.
We restrict access to production data to a small number of Chipp engineers. All access is authenticated, audit-logged, and scoped to specific administrative tasks. Chipp undergoes regular internal security reviews and follows industry-standard change-management, secrets-handling, and incident-response practices.
Data Retention & Deletion
You can disconnect any Google integration, or delete your entire Chipp account, at any time. Google user data is removed on both paths:
- Disconnecting a single integration — Open the Chipp app, go to “Connect”, and click “Disconnect” next to the Google service you want to remove. Chipp deletes the stored OAuth tokens for that integration and revokes the token on Google’s side (via the
https://oauth2.googleapis.com/revokeendpoint), so Chipp can no longer access that account. If you had ingested Drive files as knowledge sources, you can also remove them individually from the app’s knowledge base. - Deleting your Chipp account / organization — As the owner of an organization, visit your account settings and choose “Delete Organization”. All Chipp apps, sessions, chat histories, knowledge sources, and Google OAuth tokens belonging to that organization are deleted from active systems immediately via database CASCADE. Copies may remain in our encrypted database backups (Google Cloud SQL retains up to 30 rolling daily backups plus 7 days of point-in-time-recovery logs) until those backups age out. You may also email info@chipp.ai to request deletion.
- Revoking access directly on Google — At any time, independent of Chipp, you may revoke Chipp’s access to your Google account at https://myaccount.google.com/permissions. Once revoked, any cached token Chipp holds will fail on next use and will be removed.
Tokens associated with a deleted Chipp app or a deleted organization are removed by database CASCADE within the same transaction as the deletion.
If you have any questions about how your Google user data is handled, or to exercise any of the rights described above, contact us at info@chipp.ai.
International Data Transfers
In Short: Your personal data may be transferred to, stored, and processed in countries outside of your jurisdiction, including the United States and other locations where our service providers or partners operate.
For users located in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, we implement appropriate safeguards to ensure that your personal data remains protected in accordance with applicable data protection laws. These safeguards may include the use of Standard Contractual Clauses (SCCs) approved by the European Commission or the UK Information Commissioner’s Office, which contractually require recipients of your data to provide a level of protection essentially equivalent to that guaranteed within the EEA or UK.
Additionally, we participate in and comply with the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework as set forth by the U.S. Department of Commerce.
Data Retention
In Short: We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, or as required by applicable law.
We will keep your personal data for the duration of your relationship with us and as long as your account remains active. Once your data is no longer needed for the purposes for which it was collected, or if you request deletion of your account, we will take appropriate steps to securely delete or anonymize your personal data. In some cases, we may be required to retain certain information for a longer period to comply with legal, regulatory, tax, accounting, or other statutory obligations, to resolve disputes, or to enforce our agreements.
You have the right to request the deletion of your account and associated personal data at any time. Upon receiving such a request, we will promptly take steps to delete your data from our active systems, subject to any legal or contractual retention requirements.
Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience, analyze usage, and support the functionality of our platform.
- Strictly necessary cookies: These handle authentication, session management, and security. You cannot opt out of these cookies as the platform will not work without them.
- Analytics cookies: We use Google Analytics and PostHog to understand how users interact with our platform. This data is aggregated and does not personally identify you. You may opt out through your browser settings or our cookie consent banner.
- Third-party cookies: Our platform integrates with third-party services (such as Stripe for payments and Google for authentication) that may set their own cookies. These cookies are governed by the respective third-party privacy policies.
Cookie retention: Session cookies are deleted when you close your browser. Persistent cookies (such as authentication and preference cookies) are retained for up to 12 months unless you delete them sooner.
Data Security
In Short: We are committed to protecting your personal data and employ industry-standard security measures to safeguard it against unauthorized access, disclosure, alteration, or destruction.
We implement a comprehensive set of technical and organizational security measures designed to protect your personal data throughout its lifecycle. These measures include data encryption both in transit and at rest, secure server infrastructure, strict access controls, multi-factor authentication, and regular security assessments. Our systems are monitored for vulnerabilities, and we apply timely updates and patches to address emerging threats.
Access to personal data is restricted to authorized personnel who require it to perform their job functions, and all such personnel are subject to confidentiality obligations. We also require our service providers and partners to adhere to robust security standards and to process your data only as instructed by us.
Security Breach Notification
In the event of a security incident that results in the unauthorized access, disclosure, alteration, or destruction of your personal data, we will assess the potential impact and, where required by law, notify you without undue delay, including (as applicable) within 72 hours under the GDPR and UK GDPR.
Your Rights — United States (CCPA/CPRA)
If you are a user in the United States, and especially if you are a California resident, you have specific rights regarding your personal information under applicable state and federal privacy laws, including the right to know what information we collect, to request deletion, to request correction, to opt out of the sale or sharing of your personal information (we do not sell your personal information), and not to receive discriminatory treatment for exercising any of your privacy rights. To exercise these rights, please email info@chipp.ai.
Your Rights — European Union (GDPR) and United Kingdom (UK GDPR)
If you are located in the European Union or the United Kingdom, you have the following rights with respect to your personal data: access, rectification, erasure (“right to be forgotten”), restriction of processing, objection to processing, data portability, and withdrawal of consent where processing is based on consent. To exercise any of these rights, please contact us atinfo@chipp.ai. You also have the right to lodge a complaint with your local data protection authority; UK users can contact the Information Commissioner’s Office at https://ico.org.uk/.
Exercising Your Rights
To exercise any of your rights described in this Privacy Policy, please email us atinfo@chipp.ai. We may need to verify your identity before fulfilling your request. We aim to respond to all legitimate requests within the timeframes required by applicable law.
Children’s Privacy
Our platform is not intended for use by children under the age of 18, and we do not knowingly collect personal data from children under 13. If we become aware that we have inadvertently collected personal data from a child under the applicable threshold, we will take immediate steps to delete such information from our records.
Links to Other Websites
Our website may contain links to third-party websites or services that are not operated or controlled by us. This Privacy Policy applies solely to the data practices of Chipp and our platform. We encourage you to review the privacy policy of any website or service you visit before providing any personal data.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. Any changes will be posted on this page, and the “Last Updated” date at the top of the policy will be revised accordingly. If we make material changes that significantly affect your rights or the way we process your personal data, we will provide additional notice prior to the changes taking effect.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the way we handle your personal data, please contact us by email atinfo@chipp.ai, or by mail at:
Chipp, 1744 8th St S, Fargo, ND 58103, USA
Supervisory Authorities
If you are not satisfied with our response, you have the right to contact your local data protection authority. EU users: contact your national data protection authority. UK users: Information Commissioner’s Office (ICO) athttps://ico.org.uk/.