Chobit Privacy Policy
Effective date: 2026-05-26 Last updated: 2026-07-02
This Privacy Policy explains what personal data Chobit collects when you use the service, why we collect it, how long we keep it, and the rights you have over it.
If you use Chobit in local mode (self-hosted on your own hardware), this policy applies only to the cloud-managed services (tailnet control plane, push notifications, email delivery, billing). Your companion's chat, memory, and persona data stay on your machine and are not collected by the operator.
This policy applies to:
- The web application (signup, account, billing, top-ups).
- The companion app on iOS, Android, macOS, Windows, and Linux.
- The companion service (both hosted and local modes).
- All cloud-managed services (identity, tailnet, billing, push, email).
0. Our roles
For all tenant data (chat messages, memory, persona, configuration, integration tokens), the user is the data controller and GEFIDO s.r.o. is the data processor. We process your data to run the service for you: receiving it from your devices, dispatching inference, returning results, and storing it on your behalf.
In hosted mode (operator's VPS) we carry out this processing on our servers. In local mode (your own GPU workstation) this data stays on your own hardware and does not reach us, so there is nothing for us to process; our role there is limited to the operational data listed below. Where we do process tenant data, we do so under a Data Processing Addendum with our GPU compute provider (RunPod), who acts as a sub-processor.
The operator acts as a data controller for the following categories:
| Data | Purpose |
|---|---|
| Email address (account data) | Identify your account |
| IP addresses (transient logs) | Abuse prevention, debugging |
| Payment metadata (provider, amount, credits) | Bookkeeping, tax |
| Billing ledger entries | Reconciliation |
| Device public keys (Ed25519, X25519) | Authentication |
| Recovery codes (hashed) | Account recovery |
1. Who we are
The data processor for tenant data and controller for operational data is:
- GEFIDO s.r.o., Koubkova 8, 120 00 Praha 2, established in Czech Republic.
- Privacy contact: privacy@chobit.ai.
For users in the EU/EEA or the UK, you can contact us at the address and email above, and you have the right to lodge a complaint with your local data-protection authority (see Section 8). For users in California, see Section 11 for your CCPA/CPRA-specific rights.
2. What data we collect, and why
We try to collect the minimum needed to run the service. The categories below are exhaustive for all modes.
2.1 Account data
| Data | Source | Purpose | Legal basis (GDPR) |
|---|---|---|---|
| Email address | You, at signup | Identify your account, send magic-link / one-time codes | Contract (Art. 6(1)(b)) |
| Account ID, deployment mode | Generated server-side | Route requests to your companion | Contract |
| Device public keys (Ed25519, X25519) | Your enrolled device | Per-device authentication and end-to-end encryption | Contract |
| Recovery codes (hashed) | Generated server-side, shown to you once | Account recovery if you lose your phone | Contract |
We do not ask for, store, or process your real name, date of birth, phone number, address, or any government-issued identifier as part of the core service.
2.2 Authentication and session data
| Data | Purpose | Legal basis |
|---|---|---|
| Login codes (short-lived, hashed) | Passwordless login flow | Contract |
| Session tokens | Authorize requests to your companion and your account | Contract |
| Private network access keys | Allow your devices to reach your companion privately | Contract |
| IP address (transient logs only) | Abuse prevention, debugging | Legitimate interests (Art. 6(1)(f)) |
2.3 Companion data (the things you tell your companion)
This is the data the product is built around. It lives on your companion's storage and is the most sensitive category we handle. In hosted mode it resides on the operator's VPS; in local mode it resides on your GPU workstation.
| Data | Purpose | Legal basis |
|---|---|---|
| Chat messages between you and your companion | Provide the conversational service | Contract |
| Long-term memory and notes the companion builds about you | Personalize replies over time | Contract |
| Persona / system prompt / configuration you set | Shape your companion's behavior | Contract |
| Third-party integration tokens you provide (e.g. Discord, Telegram) | Let your companion act on those platforms on your behalf | Contract |
How this data is protected, and what that does and does not mean.
Chat between the app and your companion is encrypted in transit with forward secrecy. Notifications that pass through our infrastructure carry only ciphertext, which we cannot read.
At rest, your companion stores your messages, memory, and configuration in readable form, because it has to read them to work. That storage sits on a volume encrypted with keys unique to your account. This protects your data if hardware is lost, stolen, or improperly accessed. It is not, however, zero-knowledge: we hold the technical ability to read companion data at rest. The service is not designed so that reading it is mathematically impossible for us.
What actually keeps that data private is a strict commitment backed by access controls, not a claim that access is impossible. Operator staff have no standing access to the systems that hold your companion's data. There is no "break-glass" or routine-diagnostics path into it. We will not access it for any reason without your express, case-specific consent (for example, if you ask us to help diagnose a problem with your account). When a diagnostic like that is needed, it is requested up front and turns on only after you approve it on your own device. It covers a single, time-limited session (a day at most) and turns itself off afterward, and you can turn it off sooner at any time. We do not read chat or memory contents, and we never use them for any purpose other than running the service for you.
2.4 Billing data
We do not store your card number, bank details, or cryptocurrency wallet addresses. Payments are processed by external providers:
- A third-party payment processor for card / Apple Pay / Google Pay / SEPA payments. They send us a transaction ID and the settled EUR amount, and they retain payment instrument data themselves.
- A self-hosted crypto-payment server for cryptocurrency payments. It records an invoice ID and the settled EUR amount. Cryptocurrency payments are pseudonymous but recorded permanently on the relevant public blockchain. We do not link on-chain addresses back to your account, but we cannot prevent third parties from analyzing the chain.
What we store about a payment:
| Data | Purpose | Legal basis |
|---|---|---|
| Provider name, provider-side transaction ID | Reconciliation with the provider | Legal obligation (accounting) |
| Gross EUR amount (integer cents) and provider fee | Bookkeeping, tax | Legal obligation |
| Credits issued to your wallet | Run the service | Contract |
| Per-call debit ledger (credits plus the cost we paid the compute provider) | Bill you accurately | Contract |
2.5 Operational telemetry
We collect minimal server-side logs (request paths, status codes, error stack traces, timing). These logs may include IP address and account ID but are scrubbed of chat or memory content. They are retained for 30 days for incident response and then deleted.
Optional app and web diagnostics. You can choose to share diagnostics that help us find and fix problems: app errors, performance timings, and which screens you use. This is off by default. You turn it on with the "Help improve the app" control (in the app's settings, and in your account settings on the web), and you can turn it off again at any time. It never includes your messages or your companion's memory. It goes only to our own servers, and it is never shared with a third party, used for advertising, or used to train models. In the app, the "What the app collects" screen lets you see exactly what was gathered on your device. We keep these diagnostics for 30 days and then delete them.
On the web, if you turn this on, the diagnostics can include a masked replay of your session (where you move, click, scroll, and where you get stuck) so we can find pages that are confusing or broken. It is masked: all text and anything you type are hidden, so a replay never shows your messages, your email, your balance, amounts, recovery codes, or anything else you enter or that is displayed. It records the shape of the page and how you interact with it, not its readable contents. It is off unless you turn the same control on, and you can turn it off at any time.
| Data | Purpose | Legal basis |
|---|---|---|
| App and web error and crash diagnostics | Find and fix problems | Consent |
| Performance timings | Make the app faster | Consent |
| Which screens you use (screen and page names, not their content) | See which parts of the app to improve | Consent |
| Masked replay of your web session (no readable text, nothing you type) | See where web pages are confusing or broken | Consent |
We do not use third-party analytics SDKs in the mobile app, and we do not place tracking cookies on the web app beyond what is strictly necessary for the session. Remembering whether you turned the optional diagnostics on is a strictly necessary preference, not tracking.
2.6 Health and fitness data (optional)
The companion app includes an optional Health feature that you turn on yourself. When it is on, the app reads health and fitness data from your device's health store (Google Health Connect on Android; Apple Health support comes later) and sends it to your companion so it can understand your activity and well-being and talk with you about it.
This feature is off by default. Nothing is read until you enable it and grant permission, and you choose which data types to share in the platform's own permission screen. You can turn it off at any time, which stops all reading. What your companion already has is kept so you can turn it back on later, and you can delete that copy whenever you want.
| Data | Purpose | Legal basis |
|---|---|---|
| Activity and fitness (steps, distance, energy, workouts, sleep) | Let your companion understand and discuss your activity | Consent |
| Heart and vitals (heart rate, heart-rate variability, blood oxygen, respiratory rate, body and skin temperature) | Same | Consent |
| Body measurements (weight, height, body fat, lean mass, body water) | Same | Consent |
| Metabolic readings (blood glucose, blood pressure) | Same | Consent |
| Intake (water, nutrition) | Same | Consent |
| Reproductive health (menstruation) | Same | Consent |
We treat this as companion data: it lives on your companion's storage, under the same protections described in section 2.3, and it follows the same data flow described in section 3. It is read only. The app never writes anything back to your device's health store.
We do not sell health data, we do not share it for advertising, and we do not use it to train models. It is used only to run the Health feature for you. If you turn the feature off, your companion stops reading new health data but keeps what it already has, so you can turn it back on without losing your history. You can delete that stored copy at any time with the Delete health data control on the Health screen, and deleting your account removes it along with everything else. The health data on your device is never touched.
Health data read through Google Health Connect is handled in line with Google's Health Connect permissions policy, including its limited-use requirements: it is used only to provide the Health feature you enabled, is not transferred to third parties except as needed to run that feature for you, and is never used for advertising.
2.7 Location data (optional)
The companion app includes an optional Location feature that you turn on yourself, on each device separately. When it is on, the app records where that device is and sends it to your companion, so it can know where you are and where you have been and talk with you about it.
This feature is off by default. Nothing about your location is recorded until you enable it on a device and grant the location permission. You control, in your device's own settings, whether the app may use your location only while you are using it or also in the background. You can turn it off at any time, which stops all recording. What your companion already has is kept so you can turn it back on later, and you can delete that copy whenever you want.
How much is captured depends on the permission you grant and on your device's operating system. Phones deliberately limit what apps can do in the background, so your history may have gaps; we record what the device gives us and do not try to work around those limits. Some computers cannot report a useful location at all.
| Data | Purpose | Legal basis |
|---|---|---|
| Your device's location (coordinates, accuracy, altitude, speed, heading) with timestamps | Let your companion know where you are and discuss it | Consent |
| Visits your companion works out from that location (places you stayed, and for how long) | Let your companion understand where you spend time | Consent |
| Place labels you or your companion create (for example "home", "the gym") | Let your companion refer to places by name | Consent |
We treat this as companion data: it lives on your companion's storage, under the same protections described in section 2.3, and it follows the same data flow described in section 3.
Naming places and showing a map: an optional connection to your device's map provider. By default, your location never leaves your companion's storage for maps. Place names come from you telling your companion where you are, or from your companion recognizing the places you go often, both without contacting anyone outside. There is a separate setting, also off by default and set on each device on its own, that lets your phone use its own built-in map service (Apple Maps on iPhone, Google Maps on Android) to turn coordinates into place names and to draw your history on a map. If you turn this setting on, your device's own map provider receives your location (the coordinates being named, and the area of the map you are viewing), the same way it does for the maps app already on your phone. This happens on your device. We never receive it, and it never passes through us. We tell you this plainly at the moment you turn it on. With the setting off, place naming still works from your own input, and your history is shown as a list instead of a map. On computers, the map is not available yet, so the list is always used there. Turning it on is your choice, and you can turn it back off at any time.
We do not sell location data, we do not share it for advertising, and we do not use it to train models. It is used only to run the Location feature for you. The only outside connection that can happen is the optional place-naming and map feature described above, which goes to your own device's map provider, never to us, and which you control. If you turn the feature off, your companion stops recording new location data but keeps what it already has. You can delete that stored copy at any time with the Delete location data control on the Location screen, and deleting your account removes it along with everything else.
3. How your data flows
In hosted mode, every model inference call your companion makes is dispatched to an external GPU compute provider (RunPod). The data sent to that provider consists of the prompt and parameters needed to run that single inference, typically a recent conversation window, your persona text, and any retrieved memory chunks. Outputs are returned and forwarded to you over the tailnet.
In local mode, inference runs entirely on your GPU workstation. No inference data leaves your machine. The operator's cloud only handles email delivery, push notifications, and billing.
We have a data-processing arrangement with the GPU provider obliging them to process the data only to execute the inference and not to retain it beyond what is needed for that purpose. The models themselves are ours. Your conversations are never handed to an outside chatbot or generative service that could change, throttle, or retire your companion.
When your companion uses a web tool (for example searching the web or fetching a page you asked about), the request leaves our network by default, so the website sees our servers' IP address, not yours. If you choose to route your companion's web requests through your own device, those requests leave from your device instead: websites see your home IP address, and the lookup that turns a website name into an address happens on your device, so we do not see which sites your companion visits on your behalf. In that case we can still see that your device is handling these requests (your companion opens an encrypted connection to your device, sometimes through a relay), but not the destinations it reaches or the contents it exchanges. You can see and change which mode is in use in the app.
Other categories of recipient:
- Email provider: receives your email address and one-time codes so it can deliver login emails.
- Push providers (Apple and Google): receive opaque ciphertext push payloads addressed to your device tokens. They do not receive readable chat contents.
- Payment processors: see Section 2.4.
We do not sell, rent, or share personal data with advertisers, data brokers, or marketing platforms.
4. International transfers
Some of our processors (notably the GPU compute provider, the email provider, and the push providers) are located outside the EU/EEA, typically in the United States.
Where data is transferred outside the EU/EEA or the UK, we rely on the European Commission's Standard Contractual Clauses (and, where applicable, the UK Addendum) as the transfer mechanism, and we have performed transfer impact assessments. You can request a copy of the relevant SCC summary from privacy@chobit.ai.
5. How long we keep your data
| Category | Retention |
|---|---|
| Account data, devices, recovery codes | Until you delete your account |
| Chat messages and companion memory | Until you delete them, or until 30 days after account closure, whichever comes first |
| Persona / configuration / integration tokens | Until you remove them, or 30 days after account closure |
| Authentication codes (login OTPs) | Minutes (single-use), then deleted |
| Session tokens | Hours to days, by token expiry |
| Operational logs | 30 days |
| Optional app/web diagnostics (if you turn them on) | 30 days |
| Billing ledger entries and invoices | Retained for the period required by tax/accounting law in Czech Republic (typically 5 to 10 years), even after account closure |
When you delete your account, a 30-day grace period applies during which your data is suspended but recoverable on request. After that period the companion's databases and all reconstructable personal data are permanently purged, except for billing records that we are legally required to keep (see above) and minimal records of the deletion itself.
You may delete individual chats, memories, devices, and integration tokens at any time from inside the product. Such deletions are effective immediately and are not subject to the 30-day grace period.
6. AI / model training
We do not use your chat content, memory, persona, integration data, or any other content you provide to the companion to train, fine-tune, evaluate, or otherwise improve any machine-learning model. Not ours, not a third party's. There is no opt-in toggle for this. It is simply not part of the service.
Our GPU compute provider acts as a data processor under a signed Data Processing Addendum and may only process the data we send them for the purposes we instruct, namely executing the inference call. Using that data to train, fine-tune, or evaluate any model is outside the instructed purposes and therefore not permitted.
If we ever wish to change this, for example to invite users to voluntarily contribute conversations to model training, we will do so through an explicit, separately granted opt-in, and we will update this policy.
7. Security
- All transport to public endpoints uses TLS. Internal links between components run over an authenticated private network.
- Chat between your device and your companion is encrypted in transit with forward secrecy, and notifications are encrypted too. At rest, companion data is stored on a volume encrypted with keys unique to your account (see Section 2.3).
- Authentication is passwordless: an email magic-link plus per-device cryptographic keys held in your device's secure enclave. A second enrolled device acts as a 2FA approver.
- Our authentication signing keys are rotated periodically.
- Operator staff have no standing access to the systems holding your companion's data. Access requires your express, case-specific consent and is logged.
No system is perfectly secure. If we become aware of a personal-data breach affecting you, we will notify you and the relevant supervisory authority as required by law.
8. Your rights
Subject to the laws that apply to you, you have the right to:
- Access: get a copy of the personal data we hold about you.
- Rectification: correct inaccurate data.
- Erasure ("right to be forgotten"): request deletion of your data, subject to legal retention obligations.
- Restriction: ask us to limit how we process your data.
- Portability: receive your data in a machine-readable format.
- Objection: object to processing based on legitimate interests.
- Withdraw consent: where processing relies on consent, withdraw it at any time.
- Lodge a complaint with your local data-protection authority.
To exercise any of these rights, email privacy@chobit.ai. We will respond within 30 days (extendable by up to 60 days for complex requests, as permitted by GDPR Art. 12(3)).
Most of these actions can also be performed directly from inside the product: account deletion, individual chat/memory deletion, integration token removal, and data export are all available from the app's settings.
9. Adults only
The Service is exclusively for adults. You must be at least 18 years old, or older if the age of majority where you live is higher (for example 21 in some jurisdictions). The Service is not directed to minors, and we do not knowingly provide it to them or collect their personal data. If you believe a minor has created an account or given us personal data, contact privacy@chobit.ai so we can close the account and delete the data.
10. Cookies
The web application uses only strictly necessary cookies and local storage entries needed to keep you logged in, to remember billing-flow state, and to remember whether you turned on the optional diagnostics described in section 2.5. We do not use advertising, analytics, or cross-site tracking cookies. Because we use no non-essential cookies, no consent banner is shown.
Our public marketing pages use our own, self-hosted analytics to understand which pages and content are useful and where visitors come from. It is configured to set no cookies and to store no information that identifies you: your network address is anonymized, and we never track you across other websites. Because it stores nothing on your device, it needs no consent banner. It is first-party (it runs on our own servers, never a third party) and is never used for advertising. You can opt out at any time using the control below.
On those same public marketing pages we may also record an anonymized replay of your visit (mouse movement, scrolling, and clicks) so we can see how the pages are used and improve them. Only a small, random fraction of visits is recorded, and only on the anonymous marketing pages, never inside your account and never anywhere your companion data appears. Like the analytics above, it sets no cookies and stores nothing on your device, your network address is anonymized, and the contents of form fields are masked out of the recording. It honors the Do Not Track browser setting, and the same opt-out control below turns it off.
Use the control below to turn analytics and replay off for this browser at any time. Turning it off stores a single strictly-necessary entry on your device that tells us to collect nothing; turning it back on removes that entry.
11. California residents (CCPA / CPRA)
If you reside in California, the CCPA/CPRA gives you the following rights in addition to those in Section 8:
- Right to know what categories of personal information we collect, the sources, the business purpose, and the categories of third parties with whom we share it. All of this is described above.
- Right to delete your personal information, subject to legal exceptions (notably accounting records).
- Right to correct inaccurate personal information.
- Right to opt out of "sale" or "sharing." We do not sell or share personal information as those terms are defined under CCPA/CPRA, and we have not done so in the preceding 12 months.
- Right to limit use of sensitive personal information. We do not use sensitive personal information for purposes beyond providing the service.
- Right to non-discrimination for exercising your rights.
To exercise these rights, email privacy@chobit.ai. You may also authorize an agent to make a request on your behalf, and we will ask for proof of authorization.
12. Changes to this policy
We will post any material changes to this policy at this URL and update the "Last updated" date at the top. For substantive changes, we will also notify you by email and inside the app at least 14 days before the changes take effect.
Continued use of the service after a change takes effect constitutes acceptance of the updated policy.
13. Contact
For any privacy question, request, or complaint:
GEFIDO s.r.o.
Koubkova 8, 120 00 Praha 2
Czech Republic
privacy@chobit.ai