Privacy Policy
See what ChatRook processes, why it is needed, who supports the service, and the controls available to you.
Mobile app & sensitive data at a glance
This summary highlights the data categories used by the ChatRook website and mobile apps. The detailed sections below explain the same practices in context.
Profile, contacts and communications
Calls and workspace activity
Device, location, notifications and purchases
Selected sensitive uploads and AI features
Why we use it
Who supports processing
Your controls
Table of Contents
Introduction
Welcome to ChatRook's Privacy Policy. Your privacy and the security of your data are fundamental to our business.
ChatRook, Inc. ("ChatRook," "we," "us," or "our") with headquarters at 685 1st Ave, New York, NY 10016, provides messaging, calls, rooms, tasks, calendars, whiteboards, stories, games and optional analysis features across web and mobile apps ("Services"). This Privacy Policy explains how we collect, use, disclose, retain and safeguard information when you use those Services.
As a company built on security and privacy, we have designed our systems with encryption, access controls, and privacy-by-design safeguards. This Privacy Policy reflects our commitment to transparency and data minimization principles.
PLEASE READ THIS PRIVACY POLICY CAREFULLY. By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by all terms of this Privacy Policy. If you do not agree with our policies and practices, please do not use our Services.
Information We Collect
We collect information using the principle of data minimization - we only collect what is necessary to provide, improve, and secure our Services.
2.1 Information You Provide to Us
Account Information:
- Name, email address, optional phone number, avatar, profile fields and company information
- Authentication credentials (encrypted and never stored in plaintext)
- Payment information (processed through PCI-DSS compliant providers)
Content Information:
- Messages, room content, task comments, calendar entries, stories and other content you create
- Photos, videos, audio, voice messages and other media you choose to send or upload
- Shared files, whiteboards, transcripts or recaps created through features you invoke
- DNA, genetic or other sensitive files you select for optional analysis and the reports derived from them
User Preferences:
- Settings and configurations
- User interface preferences
- Notification preferences and mobile push token when notifications are enabled
2.2 Information We Collect Automatically
Device Information:
- IP address and related network information
- Browser or application type
- Operating system
- Device identifiers
- Network information
Usage Information:
- Room and call participation, durations, timestamps and connection information
- Features utilized
- Interactions with messages, tasks, rooms, calendar events, stories and other workspace tools
- Performance and error data
Analytics Information:
- Aggregated statistical data
- Performance, reliability and diagnostic metrics
- Service utilization patterns
2.3 Information from Third Parties
When you choose a connected feature, we may receive:
- Account identity and profile information from the sign-in provider you select, such as Google and, where offered, Apple, X or Yahoo
- Purchase, subscription and transaction status from payment providers
- Data from integrations you authorize or content another user shares with you
Privacy-Focused Architecture
ChatRook uses privacy-focused architecture and controls designed to protect customer content:
- Encryption: Video and audio streams are encrypted using modern protocols where supported by the meeting configuration.
- Modern Protocols: We evaluate modern cryptographic protocols and update our safeguards as standards evolve.
- Content Access Controls: We limit internal access to customer content and use role-based controls for authorized support and operations.
- Local Processing: Where supported, selected processing can happen locally on your device or under user-controlled settings.
- Encrypted Storage: Stored content is encrypted according to the applicable feature, plan, and retention settings.
- Access Controls: Administrative access is limited, logged, and governed by internal security procedures.
How We Use Your Information
We use your information for the following purposes:
4.1 Provide and Maintain our Services
- Deliver messaging, calls, rooms and collaborative workspace capabilities
- Process selected uploads and content only as needed for features you invoke
- Generate requested transcripts, recaps, task assistance or sensitive-data reports
- Authenticate users and maintain account security
- Process transactions and billing
4.2 Improve and Develop our Services
- Analyze usage, reliability and performance patterns to improve features
- Identify and fix technical issues
- Develop new features and capabilities
- Process inputs and outputs needed to provide AI-assisted features when a user invokes them
4.3 Communicate with You
- Respond to your inquiries and support requests
- Send service-related notifications
- Provide information about new features and updates
- Send security alerts and privacy notices
4.4 Ensure Security and Compliance
- Detect and prevent fraud, abuse, and security incidents
- Verify identity and enforce access controls
- Conduct security audits and vulnerability assessments
- Comply with legal obligations and enforce our terms
Data Sharing and Disclosure
We limit sharing of your information to the following circumstances:
5.1 At Your Direction
- We disclose information when you choose to share content, invite another person, connect a provider or otherwise direct the disclosure.
- Room, message, task, calendar, story and report content is available to the people or workspace members you select, subject to the feature's access controls.
5.2 Service Providers
We share minimal necessary information with trusted service providers who help us deliver our Services, including:
- Cloud and object-storage infrastructure for hosting content; email infrastructure for account and service messages; and Google Firebase Cloud Messaging for mobile push delivery
- Stripe for checkout and billing, including returning transaction, receipt and subscription status to ChatRook
- Google and, where offered, Apple, X or Yahoo for sign-in identity; and OpenAI for room recaps or message summaries only when an authorized user invokes the relevant AI feature
We limit provider access to information reasonably needed for its role and use contractual and technical safeguards appropriate to the service.
5.3 Compliance with Laws
We may disclose information when required by:
- Valid legal process such as a court order or subpoena
- Governmental requests that comply with applicable laws
- Protection of our legal rights or prevention of harm
When legally permitted, we will notify you of such requests.
5.4 Business Transfers
In connection with a corporate transaction such as a merger, acquisition, or sale of assets, your information may be transferred. Any such transfer will be subject to commitments that the information will remain protected as described in this Privacy Policy.
5.5 What We Do NOT Share
- We do not sell personal information for money.
- We do not use private communication content for third-party targeted advertising.
- We do not provide genetic, health or sensitive-analysis data to advertisers.
- We do not disclose personal information to data brokers for their independent marketing.
International Data Transfers
ChatRook is headquartered in the United States, but operates globally. When we transfer personal data outside your region:
- We implement technical safeguards such as encryption and pseudonymization.
- We execute appropriate data transfer agreements incorporating standard contractual clauses.
- We utilize regional data processing where required by law.
- We use technical, organizational, and contractual safeguards designed to support applicable data protection obligations.
Data Retention and Deletion
7.1 Retention Periods
- Account Information: Retained while your account is active and for a limited period after closure to support reactivation.
- User Content: Messages, media, rooms, tasks, calendar entries, stories, files, transcripts and other saved content are retained while needed to provide the feature or until deleted, expired or the associated account or workspace is closed, subject to applicable exceptions.
- Selected Sensitive Uploads and Reports: Retained while the related feature or account remains available, until you delete the content or request account deletion, subject to legal, security and dispute-preservation requirements.
- Usage Data: Retained for periods reasonably necessary for service operation, reliability, fraud prevention and security, then deleted or de-identified according to operational retention practices.
7.2 Data Deletion
- You can delete certain content through available in-product controls and can submit a verified account-deletion request from Settings.
- A verified close-account request deactivates the account and starts a 30-day grace period during which reactivation may be requested.
- The request covers account profile data and associated user content. Some records may be retained when reasonably necessary for legal obligations, transaction records, fraud or security, disputes, or proof that a deletion request was handled.
- Data retained for those limited reasons is access-restricted and is not used for ordinary product activity. Backup copies follow operational retention and recovery schedules rather than an individually guaranteed purge date.
Your Rights and Choices
Depending on your location, you may have various rights regarding your personal information:
8.1 Access and Portability
- View your personal information through your account settings.
- Contact us to request access to or a portable copy of eligible personal information.
- Ask questions about account activity and the processing associated with your account.
8.2 Correction and Update
- Modify and update your personal information via account settings.
- Request correction of any inaccurate information we hold about you.
8.3 Deletion and Restriction
- Use in-product deletion controls where available or submit a verified request to close your account.
- Request restriction of eligible processing where applicable law provides that right.
- Withdraw optional analytics consent or ask us to remove eligible information from a feature.
8.4 Objection and Automated Decision-Making
- Opt-out of non-essential data processing activities.
- Ask how an automated or AI-assisted feature processes the information you provide.
- Choose whether to invoke optional AI-assisted analysis, transcription and recap features.
8.5 Exercising Your Rights
To exercise any of these rights, please:
- Use the privacy controls in your account settings
- Contact our dedicated Data Protection Office
- Write to us at: Data Protection Officer, ChatRook Inc., 685 1st Ave, New York, NY 10016
We respond to verified requests within the period required by applicable law and may request information needed to confirm identity or scope.
Security Measures
ChatRook uses technical and organizational safeguards intended to protect information based on its sensitivity and the feature involved:
9.1 Technical Safeguards
- Modern Encryption: Encryption protocols designed to protect data in transit and at rest where applicable.
- Privacy-Focused Architecture: Access controls and encryption are designed to limit internal access to customer content.
- Account Security: Credential protections, email verification and session controls are applied according to the sign-in method.
- Session Security: Authentication tokens and room access controls are used to reduce unauthorized access.
- Sensitive Workflows: Access controls are applied to optional sensitive-data and payment workflows.
- Security Testing: We review, test and update safeguards based on identified risk and product changes.
9.2 Organizational Safeguards
- Security First Development: Security review is incorporated into development and incident-response practices.
- Employee Access Controls: Administrative access is limited by role and operational need.
- Security Training: Team procedures address secure handling, access and incident escalation.
- Vendor Assessment: We consider data access, purpose and safeguards when selecting service providers.
- Vulnerability Reports: Security concerns can be reported through our verified contact channel.
9.3 Compliance and Security Practices
- Risk-based security governance and access management
- Monitoring, logging and investigation of suspected security incidents
- Updates to safeguards as the service and identified risks change
- Privacy and security reviews for applicable features and obligations
Children's Privacy
Our Services are not intended for children under 18. We do not knowingly permit children to create accounts. If you believe a child is using ChatRook, or need to report child sexual abuse or exploitation, review our Community Safety and Child Safety Standards and contact [email protected] immediately.
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, and other factors. We will post the updated Privacy Policy on our website and, if the changes are significant, we will provide a more prominent notice, including email notification for substantial changes.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. Your continued use of our Services after any changes to this Privacy Policy constitutes your acceptance of the revised policy.
Sensitive Uploads, Purchases and AI
Optional features may involve particularly sensitive uploads, purchase records or AI-assisted processing. We apply the following additional explanations:
12.1 Genetic and Health-Related Data
- A DNA or genetic file is processed only when you select and submit it for the relevant feature.
- Derived reports may include ancestry, traits and health or risk indicators linked to your account.
- Reports are informational, may contain errors and are not medical diagnosis or advice.
- Do not upload another person's genetic information unless you have lawful authority and any required consent.
12.2 Purchases and Subscriptions
- Payment details are entered with the payment processor rather than stored as full card data by ChatRook.
- We receive and retain purchase, transaction, receipt and subscription status needed to provide and support the purchase.
- Payment and transaction records may be retained where required for tax, accounting, fraud prevention, disputes or legal compliance.
- A payment provider's own privacy policy also applies to its processing.
12.3 AI-Assisted Features
- AI-assisted analysis, transcription or recap runs when you or an authorized room participant invokes the feature.
- Inputs and outputs may be processed and retained as needed to return the requested result, maintain the feature, prevent abuse and troubleshoot.
- AI-generated content may be incomplete or inaccurate and should be reviewed before it is relied upon.
- You control what you submit and whether to invoke optional AI features; contact us to ask about deletion of eligible inputs or outputs.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Data Protection Officer
ChatRook, Inc.
685 1st Ave
New York, NY 10016
For urgent security concerns or to report vulnerabilities, please contact us.
This Privacy Policy was developed to provide transparency about our data practices and to reflect our commitment to security and privacy by design.
Your Privacy Matters
Have questions about our privacy practices? Our dedicated privacy team is here to help you understand how we protect your data.