Legal
Privacy Policy
This policy explains what information ChatMiniApp handles, why it is needed, and the choices available to you.
Last updated: October 3, 2026
1. Information we collect
We may collect and process the following categories of information:
- Account information: your email address, authentication identifiers, and basic profile details supplied by your sign-in provider.
- Workspace content: conversations, visual workspace documents, structured session memory, settings, and related metadata that you choose to save.
- Provider configuration: your selected AI providers, models, endpoints, and optional MCP server configuration. Provider secrets are encrypted before storage.
- Technical and usage information: limited request, device, browser, approximate location, page-view, diagnostic, security, and performance data needed to operate, understand, and protect the service.
2. How we use information
We use information to authenticate you, save and restore your sessions, generate and update visual workspaces, provide support, prevent abuse, diagnose failures, and improve service reliability and security.
ChatMiniApp does not sell your personal information or use your private conversation content to build advertising profiles.
3. AI providers and connected tools
When you send a message, relevant content is transmitted to the AI provider and model you selected. Those providers process data under their own terms and privacy policies. Review a provider's policies before using it with sensitive information.
If you enable an MCP server, ChatMiniApp may send the confirmed tool name and arguments to that server. Tool metadata and results are treated as untrusted data. You are responsible for evaluating third-party servers before connecting them.
If you opt into Google Stitch design for a conversation, ChatMiniApp sends a limited description of the visual workspace—such as its title, purpose, component types, and section headings—to Google Stitch so it can propose a layout and theme. ChatMiniApp does not intentionally send the full conversation, provider credentials, MCP payloads, or detailed block content to Stitch. Your Stitch API key is encrypted before storage.
4. Service providers
We rely on infrastructure and service providers to operate ChatMiniApp, including Vercel for application hosting, Supabase for authentication and database services, and—when you enable it—Google Stitch for visual design generation. Public-image searches may use Wikimedia Commons and Openverse. These services may process technical information according to their own policies.
We use Google Analytics to understand aggregate page usage and service performance. Google Analytics may receive page URLs, browser and device details, approximate location, and interaction data. Advertising signals and ad-personalization signals are disabled in our configuration. We do not intentionally send conversation content, provider credentials, or MCP tool payloads to Google Analytics.
5. Storage, security, and retention
We use technical and organizational safeguards intended to protect stored information. Provider credentials are encrypted at rest, database access is restricted by user ownership policies, and supported remote connections require HTTPS. No system can guarantee absolute security.
We retain account and workspace information while your account is active or as reasonably needed to provide the service, meet legal obligations, resolve disputes, and protect the service. Operational logs may be retained for shorter periods based on infrastructure settings.
6. Your choices
You can choose which providers and tools to connect, remove stored provider credentials, and delete conversations within the product where those controls are available. You may also request access, correction, or deletion of personal information, subject to applicable law and necessary verification.
7. Cookies and local storage
ChatMiniApp uses authentication cookies and local browser storage necessary to maintain sessions, remember interface preferences such as theme, and support application functionality. Google Analytics may use analytics cookies or similar technologies to measure visits and usage. We do not use third-party advertising cookies.
8. Children
ChatMiniApp is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Additional age requirements may apply in your country.
9. Changes and contact
We may update this policy as the service evolves. Material changes will be reflected by a new date on this page. Privacy questions or requests may be sent to privacy@chatminiapp.com.