- Effective date: not yet in force (draft)
- Last updated: 11 September 2026
- Data controller: Chillcore [legal entity to be confirmed] ("Chillcore", "we", "us").
- Contact: privacy@chillcore.app · DPO: dpo@chillcore.app (DPO appointment to be confirmed — see Section 15).
- EU/UK representative: [to be confirmed].
1. Who this policy is for
This Policy explains what data Chillcore collects, how we use it, who we share it with, and the rights you have. It applies to the Chillcore Progressive Web App at chillcore.app and (planned) the Android APK, Play Store, and App Store builds.
A separate section applies to information about buddies — people invited by a user to receive accountability notifications. If you're a buddy who received an invite from Chillcore, see Section 12 and the Buddy Consent Policy.
2. What we collect
2.1 Data you give us directly
- Account info: email, password (hashed), display name, chosen tier (Coach / Drill Sergeant / Demon), age representation.
- Buddy info you provide: buddy's name, email, phone number, and per-task category assignment. This is another person's personal data — see Section 12 for how we handle it.
- Task content: task titles, descriptions, deadlines, categories, micro-steps you write, difficulty level.
- Excuses & typed content: typed excuses, snooze reasons, quit reasons, notes.
- Quit-gate video confessions: up to 10-second self-recorded video, submitted at Heavy quit-gate.
- Photos & screenshots you upload as proof-of-done.
- Payment info (once payment features exist): billing name, address, last four digits, tax ID. Full card data is processed by our payment processor and never touches Chillcore servers. [PROCESSOR to be confirmed — Stripe placeholder]
- Support communications.
2.2 Data collected automatically
- Device & environment: IP address, browser, operating system, device type, screen size, timezone, language.
- Usage & interaction: feature engagement, notification opens, task completion times, latency, error logs, session length, feature flags.
- Behavioral analytics for the crisis off-ramp: engagement/silence patterns, repeated rage-quit sequences, distress-adjacent phrasing signals in your typed content. This is used strictly to trigger the crisis off-ramp described in Section 10 of the Terms.
- Cookies & similar (PWA storage): session cookies, functional storage; analytics cookies only with consent in the EU/UK.
2.3 Data we do NOT collect
- We do not run facial recognition, voiceprint analysis, or any biometric processing on your video confessions, photos, or any content. Videos are stored as raw media only, associated to your account.
- We do not track you across other apps or websites.
3. How we use your data — purposes
- Operate Chillcore: account, authentication, task tracking, notifications, escalations, roasts, buddy relay.
- Personalize roasts: generate content that quotes your own excuse history, task patterns, and completion record — solely to make the accountability engine work.
- Safety & crisis off-ramp: detect distress signals in behavioral data; drop persona to supportive tone; surface crisis resources.
- Improve the Service: analytics, bug diagnosis, safety-filter tuning.
- Communicate: service emails (mandatory), safety notices, and — with consent — marketing.
- Legal & security: fraud prevention, ToS enforcement, response to lawful requests, defense of claims.
- Payments (when applicable).
We do not sell your personal data (as defined by CCPA/CPRA). We do not share it with advertisers. We do not use your task content to train third-party AI models beyond the operation of Chillcore itself.
4. Legal basis for processing (GDPR / UK GDPR)
| Purpose | Legal basis (GDPR Art. 6) | Notes |
|---|---|---|
| Providing the Chillcore Service to you | Contract performance — Art. 6(1)(b) | Core account, task tracking, notifications. |
| Sending marketing emails | Consent — Art. 6(1)(a) | Withdrawable anytime. |
| Analytics / product improvement | Legitimate interests — Art. 6(1)(f) | Balancing test on file. |
| Fraud prevention / security | Legitimate interests — Art. 6(1)(f) | Balancing test on file. |
| Legal compliance | Legal obligation — Art. 6(1)(c) | Tax, subpoenas, GDPR requests themselves. |
| Payment processing | Contract performance — Art. 6(1)(b) | |
| Buddy invitation (first, neutral email) | Legitimate interests — Art. 6(1)(f) | See Section 12 & Buddy Consent Policy. Balancing test on file. |
| Buddy communications post-Accept | Consent (buddy) — Art. 6(1)(a) | Buddy has explicitly Accepted. |
| Crisis off-ramp behavioral analytics | [REQUIRES LEGAL REVIEW] — likely combination of Art. 6(1)(f) legitimate interest for detection + Art. 9(2)(a) explicit consent OR Art. 9(2)(c) vital interests at true-emergency signal | See risk flag below. |
| Demon-mode processing | Consent — Art. 6(1)(a), Art. 9(2)(a) if any health inference | Documented via the Section 5 Demon Addendum assent event. |
5. Retention
- Account data: while your account is active + up to 90 days after deletion (grace period + operational back-ups purge).
- Task content, excuses, notes: deleted with account; individually erasable on request.
- Video confessions (quit-gate): default retention [X months — to be confirmed, recommend 6-12 months], then automatic hard-delete; erasable earlier on request. If a similar task is created within retention, the app may replay the relevant video to you.
- Behavioral analytics used for crisis off-ramp: minimally sufficient window; pseudonymized where feasible; deleted or fully anonymized on account deletion. [X days — to be confirmed]
- Support communications: 3 years for defense of claims.
- Payment records: as required by tax/accounting law (7 years typical — verify jurisdiction).
- Consent proofs (Demon opt-in, buddy Accept): duration of the account + 3 years for evidentiary defense.
- Server / access logs: 30-90 days for security.
- Legal-hold override: anything under active investigation or litigation preservation duty is retained regardless of default schedule.
6. Sharing — who we share data with
We share personal data only with:
- Sub-processors we use to operate Chillcore. Current list (as of drafting — SUBJECT TO CHANGE):
- Hosting & infrastructure: [PROCESSOR to be confirmed — e.g. AWS/GCP/Fly.io]
- Email delivery: [PROCESSOR to be confirmed — e.g. Postmark/Resend/SendGrid]
- Push notification delivery: [PROCESSOR to be confirmed — VAPID web push provider]
- AI/LLM roast generation: [PROCESSOR to be confirmed — e.g. Anthropic/OpenAI]
- Analytics: [PROCESSOR to be confirmed — privacy-first tool preferred]
- Error monitoring: [PROCESSOR to be confirmed]
- Payment processing: [PROCESSOR to be confirmed — Stripe placeholder]
All sub-processors are bound by written contract (DPA / GDPR Art. 28 terms; CCPA "service provider" clauses).
- Buddies you have paired. We disclose to your paired, Accepted buddies the information described in Sections 7 and 12 — nothing more.
- Payment processor — when payment features are live, only the data required to process the transaction.
- Legal & safety: law enforcement, courts, and administrative authorities in response to valid legal process; and where necessary to prevent imminent harm to a user or third party.
- Business transfers: in the event of a merger, acquisition, or sale of assets, personal data may transfer to the acquirer subject to this Policy (users notified).
We do not sell, rent, or trade your personal data.
7. Buddy data flow — special disclosure
Chillcore lets you invite another person as a "buddy" to receive accountability notifications about you.
7.1 When you provide a buddy's email or phone number, Chillcore sends a single neutral Accept/decline invitation to that person. No insults, no automated behavior messages, are sent before Accept. If your buddy declines or never responds, we retain their contact information only long enough to (a) honor a "decline"/"do-not-contact" record and (b) prevent duplicate re-invites (Section 12 details).
7.2 After your buddy Accepts, they may receive: - notifications that you missed a deadline, quit, or completed a task; - (optional, if you pre-armed it) roast-content aimed at your excuse/behavior; - reply buttons ("Roast him", "One more day", "I'm disappointed").
7.3 Your buddy does NOT see: - your task descriptions in detail (only the task label, if you set one); - your typed excuses in full; - your quit-gate video confessions; - your Records history beyond the specific notification event.
7.4 See Section 12 for the buddy-side view and the Buddy Consent Policy for the buddy's rights.
8. International data transfers
Chillcore is operated from [Chillcore's jurisdiction — to be confirmed]. Data may be transferred to, and processed in, countries outside your country of residence — including the United States and jurisdictions in the European Economic Area — depending on our sub-processors' data centers.
For transfers out of the EU/EEA/UK, we rely on: - Standard Contractual Clauses (EU Commission Decision 2021/914 / UK ICO IDTA or Addendum) with sub-processors; - Adequacy decisions where applicable (e.g. UK-US Data Bridge, EU-US Data Privacy Framework for enrolled US recipients — check current status); - Additional technical & organizational measures (encryption in transit and at rest, key management, access controls).
You may request more information about transfer safeguards via privacy@chillcore.app.
9. Security
We use industry-standard technical and organizational measures: - TLS in transit; - encryption at rest for identifiable data; - role-based access control on personal data; - audit logging on production access; - video confession storage on separately-permissioned buckets; - MFA on administrative accounts; - vendor security review before onboarding; - documented incident-response plan.
No system is perfectly secure. In the event of a personal-data breach, we will notify affected users and the relevant supervisory authority as required by law (GDPR Art. 33/34 — 72 hours for the supervisory authority; individual notification "without undue delay" when high risk). US state laws impose their own timelines (California, Colorado, others). We commit to a "notification without undue delay" standard globally.
10. Your rights
10.1 Under GDPR / UK GDPR (EU/EEA/UK residents)
You have the right to: - access the personal data we hold about you (Art. 15); - rectification of inaccurate data (Art. 16); - erasure / "right to be forgotten" (Art. 17), subject to legal-hold and legitimate exceptions; - restriction of processing (Art. 18); - portability — receive your data in a structured, machine-readable format (Art. 20); - object to processing based on legitimate interests, including any profiling (Art. 21); - withdraw consent at any time where processing is based on consent (does not affect processing before withdrawal); - not to be subject to solely automated decisions with legal or similar effects (Art. 22) — Chillcore's tier/roast/notification decisions are not "solely automated decisions with legal or similarly significant effects" as we understand the term, but you may still object; - lodge a complaint with your national supervisory authority (list at edpb.europa.eu).
To exercise: privacy@chillcore.app. We respond within 30 days (extendable to 90 for complex requests per Art. 12(3)).
10.2 Under CCPA/CPRA (California residents)
You have the right to: - know what personal information we collect, use, share (this Policy); - access — request a copy of personal information we hold about you (last 12 months by default, extended lookback available); - delete personal information, subject to statutory exceptions; - correct inaccurate personal information; - opt-out of sale/sharing — Chillcore does not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of; - limit use of sensitive personal information — see below; - non-discrimination for exercising rights; - portability — receive information in a portable format.
To exercise: privacy@chillcore.app or the in-app "Manage my data" control.
Sensitive Personal Information under CCPA/CPRA. We may hold what could qualify as sensitive personal information under CPRA — including account credentials (password hash), and inferences about health-adjacent behavioral state from the crisis-off-ramp analytics. You may request that we limit use of such information to purposes strictly necessary to provide the Service.
Response time: 45 days, extendable to 90 for complex requests.
Authorized-agent requests: accepted per CCPA §1798.135, with verification.
10.3 Other US state laws
Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have substantially similar rights (access, delete, correct, opt-out of targeted advertising / sale, opt-out of profiling with significant effects). Use the same intake — privacy@chillcore.app — and we will honor the version applicable to your residence.
10.4 Canada (PIPEDA + Québec Law 25)
Access, correction, withdrawal of consent, complaint to the Office of the Privacy Commissioner. Québec residents have additional rights (portability, automated decision transparency) under Law 25.
10.5 Australia (Privacy Act 1988)
Access and correction rights; complaint to the Office of the Australian Information Commissioner (OAIC).
11. Data Subject Access Request (DSAR) process
To make any rights request: 1. Email privacy@chillcore.app or use the in-app "Manage my data" control. 2. Verify your identity via the email address associated with the account. Additional verification may be requested for sensitive requests (deletion of a specific event, video confession). 3. We acknowledge within 5 business days and respond substantively within the timeline required by applicable law (30 days GDPR / 45 days CCPA / equivalent). 4. Responses are free for a first request per year; further requests may incur a reasonable fee only where permitted by law. 5. If we cannot fulfill a request (e.g. legal-hold, ongoing dispute), we explain in writing. 6. Appeals: contact dpo@chillcore.app; you may complain to your supervisory authority at any time.
12. Buddy privacy — special section
If you received a Chillcore invitation from someone who listed you as their "buddy": we have your email or phone number because our user provided it. We are contacting you once to ask whether you Accept being paired.
Before you Accept: we hold your name/email/phone with a legitimate-interest legal basis (GDPR Art. 6(1)(f)) — sending a single neutral invitation. If you decline (or ignore for [X days — to be confirmed]), we mark your contact as opt-out and do not send further messages related to this user.
If you Accept: you become a data subject in your own right, and your relationship with Chillcore is governed by the Buddy Consent Policy. You may withdraw at any time.
Your rights either way — the same rights described in Section 10 apply. Contact privacy@chillcore.app.
13. Cookies & tracking
Chillcore uses: - Strictly necessary storage for authentication and PWA operation (no consent required). - Functional storage for user preferences (retained across sessions). - Analytics only with consent in the EU/UK (via a cookie banner). Disabled by default in those regions. - No advertising / targeting cookies. No cross-site tracking.
14. Children
Chillcore is not intended for users under 13 (US) or under the applicable GDPR Art. 8 minimum (EU/EEA — 13/14/15/16 depending on Member State). Coach mode is available from 13 (US floor). Drill Sergeant requires 16 (EU) / 18 (US). Demon requires 18 everywhere. We do not knowingly collect data from users below these floors; if we learn of it, we delete the account.
15. Data Protection Officer & Representative
Data Protection Officer (DPO): [Appointment to be confirmed — assess GDPR Art. 37 mandatory-appointment triggers: large-scale processing of special categories (health inferences via crisis off-ramp arguably qualifies); regular systematic monitoring of behavior at large scale (likely qualifies)]. Interim contact: dpo@chillcore.app.
EU Representative: [to be confirmed]. UK Representative: [to be confirmed].
16. Automated decision-making
The tier assignment, roast generation, escalation ladder, and crisis-off-ramp trigger are automated. These are not "solely automated decisions producing legal or similarly significant effects" under GDPR Art. 22 as we understand the term — they affect what messages you receive within an entertainment product, not employment, credit, housing, or legal status. You may still object to profiling under Art. 21.
17. Changes to this Policy
Material changes: 30 days' in-app + email notice. Non-material: on posting. Version history preserved on request.
18. Contact & complaints
- Privacy questions & rights requests: privacy@chillcore.app
- DPO: dpo@chillcore.app
- EU supervisory authorities: edpb.europa.eu/about-edpb/board/members_en
- UK ICO: ico.org.uk
- California AG: oag.ca.gov/privacy
- Canada OPC: priv.gc.ca
- Australia OAIC: oaic.gov.au
You always have the right to complain to your supervisory authority regardless of whether you have contacted us first.