Legal

Privacy Policy

Effective date: May 2026

1. Introduction

CHAIOS ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and disclose information when you use the CHAIOS mobile application and web application (collectively, the "Services").

By creating an account or using our Services, you agree to the collection and use of information as described in this policy.

2. Information We Collect

Account information: When you register, we collect your name, email address, and password (stored securely via Supabase Auth).

Event data: Information you enter about events, guests, budgets, vendors, tasks, and other event-related content.

Uploaded files: CHAIOS stores only one category of files on its own servers: images uploaded by businesses to their Supplier Directory listing (logos, banner images, and gallery photos). These are stored in our Supabase file storage (vendor-assets bucket) so they can be displayed publicly on the listing. All other files — such as vendor contract attachments, run-sheet documents, or vision board inspiration images — remain on your device and are never transmitted to our servers.

Usage data: We may collect anonymised usage analytics (e.g. which features are used) to improve the Services. No personally identifiable information is included in these analytics.

3. File Storage

CHAIOS uses file storage in one specific context: Supplier Directory listings. When a business partner uploads a logo, banner, or gallery images for their public listing, those files are stored in our secure Supabase storage bucket (vendor-assets) and served publicly as part of the directory.

For all other content within the event planner — such as vision board inspiration images — files are encoded and stored as data directly within your event record in the database. They are not uploaded to any separate storage bucket.

Vendor record file attachments (contracts, quotes, photos) remain on your device only and are never transmitted to our servers.

4. How We Use Your Information

  • To provide, maintain, and improve the Services
  • To authenticate your account and maintain security
  • To respond to support enquiries and feedback
  • To send transactional emails (e.g. account verification, password reset)
  • To analyse aggregate, anonymised usage patterns

We do not sell your personal information to third parties.

5. Data Sharing

We share data with the following third-party service providers, solely to operate the Services:

  • Supabase — database, authentication, and file storage for Supplier Directory listing images (logos, banners, gallery photos). All data is hosted in a SOC 2-compliant environment.

We do not share your data with advertisers or data brokers. Each provider is bound by their own privacy policy and data processing agreements.

6. Data Retention

Your account data is retained for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, unless we are required to retain it by law.

7. Security

We implement industry-standard security measures including encrypted connections (HTTPS/TLS), password hashing, and Supabase Row Level Security to ensure only authorised users can access your event data. However, no method of transmission over the internet is 100% secure.

8. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Request correction or deletion of your data
  • Object to or restrict processing of your data
  • Export your data in a portable format

To exercise these rights, contact us at privacy@chaios.app.

9. Children's Privacy

CHAIOS is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by updating the effective date above and, where appropriate, by sending an email notification.

11. Contact

If you have questions about this Privacy Policy, please contact us at privacy@chaios.app or visit our Contact page.