Free
Updated July 30, 2026

Privacy Policy

See what ChatRook processes, why it is needed, who supports the service, and the controls available to you.

ChatRook, Inc. • 685 1st Ave, New York, NY 10016
Mobile app disclosure

Mobile app & sensitive data at a glance

This summary highlights the data categories used by the ChatRook website and mobile apps. The detailed sections below explain the same practices in context.

Profile, contacts and communications

We process account and profile details such as your name, email, optional phone number, avatar, profile fields, presence and preferences. We store messages and media you send. If you choose contact discovery or invitations, contact identifiers may be normalized or hashed for matching, while invitation details may be retained to deliver and secure the request.

Calls and workspace activity

We process room and call participation, timestamps and connection information, plus content you create in rooms, tasks, comments, files, calendar events, whiteboards and stories. Live audio and video are transmitted to participants. Recordings, transcripts or recaps are processed only when someone uses the relevant feature and any required participant notice applies.

Device, location, notifications and purchases

We process app, browser, device, network, IP, performance and usage information to operate and secure the service. A push token is stored when notifications are enabled. Precise or live location is processed only when you actively share it. Payment providers process checkout data; we retain transaction and subscription identifiers and status needed for your purchase.

Selected sensitive uploads and AI features

If you choose a DNA or genetic-analysis feature, we process the file you select and derived ancestry, trait, health or risk results. These results are informational and are not medical advice. AI-assisted analysis, transcription or recap inputs and outputs are processed only when you invoke those features or a room participant enables them with the required notice. RookGPT sends the command you enter, an account identifier and current signed-in account context to ChatRook's command service; a command may retrieve account or market data or run server-side AI and prediction models.

Why we use it

To provide the feature you request, authenticate accounts, deliver communications, synchronize workspaces, process purchases, prevent abuse, troubleshoot, support users and understand service reliability.

Who supports processing

Google Firebase Cloud Messaging supports mobile push delivery. OpenAI may process the room or message content submitted when an authorized user invokes an AI recap or summary. Google and, where offered, Apple, X or Yahoo process identity data when you choose their sign-in option. Stripe processes checkout and billing. Cloud, object-storage and email infrastructure supports content hosting and service-message delivery. Each provider receives data for its stated role.

Your controls

You control device permissions, optional analytics consent, what you upload or share, and whether you invoke optional AI features. Use in-product delete controls where available, request account deletion, or contact us about access, correction, deletion or safety.

Introduction

Welcome to ChatRook's Privacy Policy. Your privacy and the security of your data are fundamental to our business.

ChatRook, Inc. ("ChatRook," "we," "us," or "our") with headquarters at 685 1st Ave, New York, NY 10016, provides messaging, calls, rooms, tasks, calendars, whiteboards, stories, games and optional analysis features across web and mobile apps ("Services"). This Privacy Policy explains how we collect, use, disclose, retain and safeguard information when you use those Services.

As a company built on security and privacy, we have designed our systems with encryption, access controls, and privacy-by-design safeguards. This Privacy Policy reflects our commitment to transparency and data minimization principles.

PLEASE READ THIS PRIVACY POLICY CAREFULLY. By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by all terms of this Privacy Policy. If you do not agree with our policies and practices, please do not use our Services.

Information We Collect

We collect information using the principle of data minimization - we only collect what is necessary to provide, improve, and secure our Services.

2.1 Information You Provide to Us

Account Information:

  • Name, email address, optional phone number, avatar, profile fields and company information
  • Authentication credentials (encrypted and never stored in plaintext)
  • Payment information (processed through PCI-DSS compliant providers)

Content Information:

  • Messages, room content, task comments, calendar entries, stories and other content you create
  • Photos, videos, audio, voice messages and other media you choose to send or upload
  • Shared files, whiteboards, transcripts or recaps created through features you invoke
  • DNA, genetic or other sensitive files you select for optional analysis and the reports derived from them

User Preferences:

  • Settings and configurations
  • User interface preferences
  • Notification preferences and mobile push token when notifications are enabled

2.2 Information We Collect Automatically

Device Information:

  • IP address and related network information
  • Browser or application type
  • Operating system
  • Device identifiers
  • Network information

Usage Information:

  • Room and call participation, durations, timestamps and connection information
  • Features utilized
  • Interactions with messages, tasks, rooms, calendar events, stories and other workspace tools
  • Performance and error data

Analytics Information:

  • Aggregated statistical data
  • Performance, reliability and diagnostic metrics
  • Service utilization patterns

2.3 Information from Third Parties

When you choose a connected feature, we may receive:

  • Account identity and profile information from the sign-in provider you select, such as Google and, where offered, Apple, X or Yahoo
  • Purchase, subscription and transaction status from payment providers
  • Data from integrations you authorize or content another user shares with you

Privacy-Focused Architecture

ChatRook uses privacy-focused architecture and controls designed to protect customer content:

  • Encryption: Video and audio streams are encrypted using modern protocols where supported by the meeting configuration.
  • Modern Protocols: We evaluate modern cryptographic protocols and update our safeguards as standards evolve.
  • Content Access Controls: We limit internal access to customer content and use role-based controls for authorized support and operations.
  • Local Processing: Where supported, selected processing can happen locally on your device or under user-controlled settings.
  • Encrypted Storage: Stored content is encrypted according to the applicable feature, plan, and retention settings.
  • Access Controls: Administrative access is limited, logged, and governed by internal security procedures.

How We Use Your Information

We use your information for the following purposes:

4.1 Provide and Maintain our Services

  • Deliver messaging, calls, rooms and collaborative workspace capabilities
  • Process selected uploads and content only as needed for features you invoke
  • Generate requested transcripts, recaps, task assistance or sensitive-data reports
  • Authenticate users and maintain account security
  • Process transactions and billing

4.2 Improve and Develop our Services

  • Analyze usage, reliability and performance patterns to improve features
  • Identify and fix technical issues
  • Develop new features and capabilities
  • Process inputs and outputs needed to provide AI-assisted features when a user invokes them

4.3 Communicate with You

  • Respond to your inquiries and support requests
  • Send service-related notifications
  • Provide information about new features and updates
  • Send security alerts and privacy notices

4.4 Ensure Security and Compliance

  • Detect and prevent fraud, abuse, and security incidents
  • Verify identity and enforce access controls
  • Conduct security audits and vulnerability assessments
  • Comply with legal obligations and enforce our terms

Data Sharing and Disclosure

We limit sharing of your information to the following circumstances:

5.1 At Your Direction

  • We disclose information when you choose to share content, invite another person, connect a provider or otherwise direct the disclosure.
  • Room, message, task, calendar, story and report content is available to the people or workspace members you select, subject to the feature's access controls.

5.2 Service Providers

We share minimal necessary information with trusted service providers who help us deliver our Services, including:

  • Cloud and object-storage infrastructure for hosting content; email infrastructure for account and service messages; and Google Firebase Cloud Messaging for mobile push delivery
  • Stripe for checkout and billing, including returning transaction, receipt and subscription status to ChatRook
  • Google and, where offered, Apple, X or Yahoo for sign-in identity; and OpenAI for room recaps or message summaries only when an authorized user invokes the relevant AI feature

We limit provider access to information reasonably needed for its role and use contractual and technical safeguards appropriate to the service.

5.3 Compliance with Laws

We may disclose information when required by:

  • Valid legal process such as a court order or subpoena
  • Governmental requests that comply with applicable laws
  • Protection of our legal rights or prevention of harm

When legally permitted, we will notify you of such requests.

5.4 Business Transfers

In connection with a corporate transaction such as a merger, acquisition, or sale of assets, your information may be transferred. Any such transfer will be subject to commitments that the information will remain protected as described in this Privacy Policy.

5.5 What We Do NOT Share

  • We do not sell personal information for money.
  • We do not use private communication content for third-party targeted advertising.
  • We do not provide genetic, health or sensitive-analysis data to advertisers.
  • We do not disclose personal information to data brokers for their independent marketing.

International Data Transfers

ChatRook is headquartered in the United States, but operates globally. When we transfer personal data outside your region:

  • We implement technical safeguards such as encryption and pseudonymization.
  • We execute appropriate data transfer agreements incorporating standard contractual clauses.
  • We utilize regional data processing where required by law.
  • We use technical, organizational, and contractual safeguards designed to support applicable data protection obligations.

Data Retention and Deletion

7.1 Retention Periods

  • Account Information: Retained while your account is active and for a limited period after closure to support reactivation.
  • User Content: Messages, media, rooms, tasks, calendar entries, stories, files, transcripts and other saved content are retained while needed to provide the feature or until deleted, expired or the associated account or workspace is closed, subject to applicable exceptions.
  • Selected Sensitive Uploads and Reports: Retained while the related feature or account remains available, until you delete the content or request account deletion, subject to legal, security and dispute-preservation requirements.
  • Usage Data: Retained for periods reasonably necessary for service operation, reliability, fraud prevention and security, then deleted or de-identified according to operational retention practices.

7.2 Data Deletion

  • You can delete certain content through available in-product controls and can submit a verified account-deletion request from Settings.
  • A verified close-account request deactivates the account and starts a 30-day grace period during which reactivation may be requested.
  • The request covers account profile data and associated user content. Some records may be retained when reasonably necessary for legal obligations, transaction records, fraud or security, disputes, or proof that a deletion request was handled.
  • Data retained for those limited reasons is access-restricted and is not used for ordinary product activity. Backup copies follow operational retention and recovery schedules rather than an individually guaranteed purge date.

Your Rights and Choices

Depending on your location, you may have various rights regarding your personal information:

8.1 Access and Portability

  • View your personal information through your account settings.
  • Contact us to request access to or a portable copy of eligible personal information.
  • Ask questions about account activity and the processing associated with your account.

8.2 Correction and Update

  • Modify and update your personal information via account settings.
  • Request correction of any inaccurate information we hold about you.

8.3 Deletion and Restriction

  • Use in-product deletion controls where available or submit a verified request to close your account.
  • Request restriction of eligible processing where applicable law provides that right.
  • Withdraw optional analytics consent or ask us to remove eligible information from a feature.

8.4 Objection and Automated Decision-Making

  • Opt-out of non-essential data processing activities.
  • Ask how an automated or AI-assisted feature processes the information you provide.
  • Choose whether to invoke optional AI-assisted analysis, transcription and recap features.

8.5 Exercising Your Rights

To exercise any of these rights, please:

We respond to verified requests within the period required by applicable law and may request information needed to confirm identity or scope.

Security Measures

ChatRook uses technical and organizational safeguards intended to protect information based on its sensitivity and the feature involved:

9.1 Technical Safeguards

  • Modern Encryption: Encryption protocols designed to protect data in transit and at rest where applicable.
  • Privacy-Focused Architecture: Access controls and encryption are designed to limit internal access to customer content.
  • Account Security: Credential protections, email verification and session controls are applied according to the sign-in method.
  • Session Security: Authentication tokens and room access controls are used to reduce unauthorized access.
  • Sensitive Workflows: Access controls are applied to optional sensitive-data and payment workflows.
  • Security Testing: We review, test and update safeguards based on identified risk and product changes.

9.2 Organizational Safeguards

  • Security First Development: Security review is incorporated into development and incident-response practices.
  • Employee Access Controls: Administrative access is limited by role and operational need.
  • Security Training: Team procedures address secure handling, access and incident escalation.
  • Vendor Assessment: We consider data access, purpose and safeguards when selecting service providers.
  • Vulnerability Reports: Security concerns can be reported through our verified contact channel.

9.3 Compliance and Security Practices

  • Risk-based security governance and access management
  • Monitoring, logging and investigation of suspected security incidents
  • Updates to safeguards as the service and identified risks change
  • Privacy and security reviews for applicable features and obligations

Children's Privacy

Our Services are not intended for children under 18. We do not knowingly permit children to create accounts. If you believe a child is using ChatRook, or need to report child sexual abuse or exploitation, review our Community Safety and Child Safety Standards and contact [email protected] immediately.

Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, and other factors. We will post the updated Privacy Policy on our website and, if the changes are significant, we will provide a more prominent notice, including email notification for substantial changes.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. Your continued use of our Services after any changes to this Privacy Policy constitutes your acceptance of the revised policy.

Sensitive Uploads, Purchases and AI

Optional features may involve particularly sensitive uploads, purchase records or AI-assisted processing. We apply the following additional explanations:

12.1 Genetic and Health-Related Data

  • A DNA or genetic file is processed only when you select and submit it for the relevant feature.
  • Derived reports may include ancestry, traits and health or risk indicators linked to your account.
  • Reports are informational, may contain errors and are not medical diagnosis or advice.
  • Do not upload another person's genetic information unless you have lawful authority and any required consent.

12.2 Purchases and Subscriptions

  • Payment details are entered with the payment processor rather than stored as full card data by ChatRook.
  • We receive and retain purchase, transaction, receipt and subscription status needed to provide and support the purchase.
  • Payment and transaction records may be retained where required for tax, accounting, fraud prevention, disputes or legal compliance.
  • A payment provider's own privacy policy also applies to its processing.

12.3 AI-Assisted Features

  • AI-assisted analysis, transcription or recap runs when you or an authorized room participant invokes the feature.
  • Inputs and outputs may be processed and retained as needed to return the requested result, maintain the feature, prevent abuse and troubleshoot.
  • AI-generated content may be incomplete or inaccurate and should be reviewed before it is relied upon.
  • You control what you submit and whether to invoke optional AI features; contact us to ask about deletion of eligible inputs or outputs.

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Data Protection Officer

ChatRook, Inc.

685 1st Ave

New York, NY 10016

For urgent security concerns or to report vulnerabilities, please contact us.

This Privacy Policy was developed to provide transparency about our data practices and to reflect our commitment to security and privacy by design.

Your Privacy Matters

Have questions about our privacy practices? Our dedicated privacy team is here to help you understand how we protect your data.