Privacy policy
Last updated: 1 October 2026
1. Who we are
The controller of your personal data is Studio 404 d.o.o., Slovenska cesta 55, 1000 Ljubljana, Slovenia, VAT ID SI42531357 ("we", "Chapy"). You can reach us at hello@chapy.eu.
This policy explains how we process personal data when you visit chapy.eu and use the Chapy AI assistant (the "Service"), in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Slovenian Personal Data Protection Act (ZVOP-2).
2. What data we process
- Account data: name, email address, password (stored only as a hash), sign-in method and language preference.
- Conversation content: the messages you send to the assistant and the answers it generates, together with conversation titles and timestamps.
- Subscription and billing data: subscription status, billing period, billing name and address, VAT ID (if you provide one), and invoice records. We do not see or store your full card number; card data is handled by Stripe.
- Technical data: IP address, browser and device type, and server logs needed to run and secure the Service.
- Support communication: messages you send to our support chat or by email, and related contact records.
- Advertising data (only with your consent): the Google Click ID (gclid) and identifiers set by Google Ads cookies, used to measure the effectiveness of our ads.
3. Purposes and legal bases
- Providing the Service, managing your account, running the trial and subscription, and generating AI answers: performance of a contract (Art. 6(1)(b) GDPR).
- Billing, issuing invoices and keeping accounting records: legal obligation (Art. 6(1)(c) GDPR).
- Security, fraud and abuse prevention, fair-use limits, and fixing errors: our legitimate interests (Art. 6(1)(f) GDPR).
- Customer support and responding to your requests: performance of a contract and our legitimate interests.
- Service emails (account, security, billing and trial notices): performance of a contract. Marketing emails are only sent with your consent or where permitted by law, and you can unsubscribe at any time.
- Measuring the effectiveness of Google Ads campaigns: your consent (Art. 6(1)(a) GDPR). You can withdraw consent at any time via "Cookie settings" in the footer; withdrawal does not affect earlier processing.
4. Recipients and processors
We do not sell your personal data. We share data only with service providers that process it on our behalf under data processing agreements (Art. 28 GDPR), and with authorities where the law requires it:
- Railway: hosting of the application and database, in an EU region.
- Stripe: payment processing for subscriptions. Stripe also acts as an independent controller for its own fraud-prevention and legal obligations.
- Space Invoices: issuing invoices and sending them to you by email. Invoice data is kept for the legally required period.
- Hal (chatwithhal.com): customer support chat, transactional and service email delivery, and customer relationship records.
- AI model providers: your messages are sent to the AI model provider(s) we use to generate answers. They act as processors under data processing agreements, and we do not allow them to train their models on your conversations. We currently use Anthropic PBC (Claude models, USA).
- Google Ads (Google Ireland Limited): only if you consent to analytics and advertising cookies.
We may also disclose data to our accountants, legal advisers and competent authorities where necessary and lawful.
5. International transfers
We host the Service in the EU. Some providers (for example Stripe, Google or AI model providers) may process data outside the European Economic Area. In that case, transfers rely on an adequacy decision (such as the EU-US Data Privacy Framework) or on the European Commission's Standard Contractual Clauses together with additional safeguards where needed.
6. How long we keep data
- Account and conversations: until you delete them or your account. When you delete your account, we delete your account data and conversations without undue delay, except for data we must keep by law.
- Invoices and accounting records: 10 years, as required by Slovenian tax and accounting law (including ZDDV-1).
- Server logs and security data: up to 90 days.
- Support communication: up to 3 years after the last contact.
- Advertising identifiers: for the lifetime of the relevant cookie (up to 90 days), or until you withdraw consent.
Trial accounts that have been inactive for a long time may be deleted after prior notice.
7. Cookies and similar technologies
Strictly necessary (no consent required):
- Session cookie of our authentication system: keeps you signed in.
- NEXT_LOCALE: remembers your language.
- chapy-consent (local storage): remembers your cookie choice.
Analytics and advertising (only after you accept):
- _gcl_au, _gcl_aw, _gac_* (Google Ads, up to 90 days): attribute sign-ups and purchases to ad clicks.
- chapy-gclid (local storage, up to 90 days): stores the Google Click ID from the ad you clicked, to attribute a later sign-up or purchase.
Until you choose, Google tags run in a restricted mode with advertising and analytics storage denied. You can change your choice at any time via "Cookie settings" in the footer.
8. Your rights
Under the GDPR you have the right to access your data, to have it rectified or erased, to restrict or object to processing, to data portability, and to withdraw consent at any time. Where processing is based on legitimate interests, you may object on grounds relating to your particular situation.
To exercise your rights, write to hello@chapy.eu. We will respond within one month. You can delete conversations and your account in the app settings.
9. Right to lodge a complaint
If you believe we process your data unlawfully, you have the right to complain to the supervisory authority: Informacijski pooblaščenec Republike Slovenije (Information Commissioner of the Republic of Slovenia), Dunajska cesta 22, 1000 Ljubljana, www.ip-rs.si, gp.ip@ip-rs.si. We would appreciate the chance to resolve your concern first.
10. Security
We use encryption in transit, hashed passwords, access controls and EU hosting to protect your data. No system is completely secure, so please do not share highly sensitive information (such as health data, passwords or payment card numbers) in conversations with the assistant.
11. Automated decisions and AI
Answers are generated automatically by an AI model. We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing.
12. Children
The Service is intended for people aged 18 and over. We do not knowingly collect data from minors. If you believe a minor has registered, please contact us and we will delete the data.
13. Changes to this policy
We may update this policy from time to time. We will publish the current version on this page and, for material changes, notify you by email or in the app.