Skip to policy content

Last updated August 27, 2026

Privacy at Chromelier

This notice explains what the current product handles, when information leaves Chromelier, and which controls exist today. It avoids promising controls or retention periods that have not been built.

Privacy at a glance

Private by default

Account workspace content and stored images are private unless you deliberately share or publish them.

AI is request-driven

A prompt and the context needed to answer it go to the selected AI provider when you request an AI operation.

Sharing changes visibility

Unlisted links can be opened by anyone who has the link. Public and Community content may be discoverable.

No advertising sale

Chromelier does not currently sell personal information or share it for cross-context behavioral advertising.

Data we handle

Chromelier limits collection to information used for the workspace, requested AI operations, sharing, safety, and reliability.

Account and sign-in

Email address, Supabase user identifier, sign-in method, session records, and Google account information returned when you choose Google sign-in.

Workspace

Palettes, color roles, projects, settings, versions, workspace snapshots, saved items, shares, Community listings, and likes.

Copilot and AI operations

Threads, prompts, responses, tool results, palette context, run state, model and provider choices, latency, token counts, usage events, and sanitized error metadata.

Images

JPEG, PNG, and WebP references you upload, image-generation prompts and settings, generated results, private object paths, and short-lived display links.

Personal provider credentials

Optional API credentials, credential fingerprints, connection status, and related operation events when you choose BYOK. Personal provider credentials are encrypted at rest by the server before storage; the complete saved secret is not returned to the UI.

Device and operations

Functional browser state, theme and layout choices, cached catalog information, service usage, provider route outcomes, and infrastructure request or error logs.

Why it is used

  • Provide sign-in, saved work, requested AI operations, exports, shares, and Community features.
  • Enforce provider and product allowances, prevent abuse, protect accounts, and diagnose failures.
  • Remember functional preferences and restore in-progress workspace state.
  • Meet legal obligations or respond to valid legal process where applicable.

Depending on the law that applies, processing may be necessary to provide a service you requested, based on consent for an optional transfer, required by law, or supported by a legitimate interest in security and reliability. This notice does not claim that one jurisdiction-specific legal basis applies everywhere. Chromelier does not use Copilot output to make decisions that produce legal or similarly significant effects about you.

Infrastructure and AI providers

A provider receives only the information needed for the feature you activate, but its own handling can vary by model, route, account, and upstream service.

Supabase

Authentication, database records, and private object storage.

Supabase privacy

Vercel

Application hosting, delivery, and infrastructure request logs.

Vercel privacy

Google Gemini API

Selected prompts, palette context, and a reference image when the requested operation needs vision. OpenRouter may pass the request to the selected upstream model provider.

OpenRouter

Selected prompts, palette context, and a reference image when the requested operation needs vision. OpenRouter may pass the request to the selected upstream model provider.

OpenAI

Selected prompts, palette context, and a reference image when the requested operation needs vision. OpenRouter may pass the request to the selected upstream model provider.

Anthropic

Selected prompts, palette context, and a reference image when the requested operation needs vision. OpenRouter may pass the request to the selected upstream model provider.

Pollinations

Selected prompts, palette context, and a reference image when the requested operation needs vision. OpenRouter may pass the request to the selected upstream model provider.

Cloudflare Workers AI

Selected prompts, palette context, and a reference image when the requested operation needs vision. OpenRouter may pass the request to the selected upstream model provider.

Chromelier does not promise that every provider uses submitted data in the same way or that provider policies never change. Review the just-in-time disclosure in AI Models & Limits before sending confidential, regulated, or identifying content. Optional provider transfer is not enabled merely because this notice exists.

Images and private links

Uploads and generated results follow different processing paths.

Reference uploads

Original reference images are retained as uploaded after file-type, size, and ownership validation. Embedded metadata is not currently stripped. When a vision request needs the image, its bytes are sent to the selected provider.

Generated results

Generated images are re-encoded to WebP before private storage. Re-encoding the generated output does not change how an original upload is retained.

Stored images use a private bucket and temporary signed URLs for display and download. Expiring a signed URL does not delete the stored file; it only ends access through that particular URL. Do not upload an image containing hidden or identifying metadata unless you are comfortable retaining and processing it as described above.

Sharing, Community, and MCP

Visibility changes only when you use a sharing or publication control.

Unlisted shares

An unlisted link is not placed in the Community catalog, but anyone who receives the bearer link can open it. Revoking it stops future use of that share URL.

Public & Community

Public shares may be indexed. Community publication stores a public palette snapshot, descriptive fields, source and license information, rights attestation, and like records.

ChatGPT and Claude MCP

Chromelier exposes a public, stateless MCP surface. It does not connect the model host to your private Chromelier account or private workspace. The host handles its own conversation and account data under its policies.

Browser storage, cookies, and diagnostics

Supabase authentication persists session information, including refresh credentials, in browser storage. Chromelier also uses browser storage for local drafts, preferences, workspace snapshots, layout and theme choices, and cached catalog information. A functional sidebar cookie remembers navigation state. Clear site data or sign out to remove or invalidate applicable local state, understanding that doing so can discard unsaved drafts.

The current product has no advertising tracker, third-party analytics SDK, or Sentry integration. Vercel and Supabase may retain infrastructure logs under their own policies. Chromelier also keeps a limited operational error ledger for up to 30 days; it contains only an allowlisted event type, a technical record identifier, and an optional sanitized error code—not prompts, generated responses, images, credentials, browser fingerprints, or IP addresses.

Retention, deletion, and available choices

Chromelier does not publish a fixed retention period that the product cannot yet enforce.

Account and workspace records are generally retained while needed to provide the saved workspace, keep a share or Community entry available, enforce allowances, protect the service, resolve disputes, or meet legal obligations. Provider credentials remain until removed through the available credential control. Infrastructure providers apply their own backup and log-retention practices.

Available controls can delete eligible palettes or projects, remove a saved provider credential, revoke a share, unpublish eligible Community content, clear browser state, and sign out. No self-service control currently deletes your entire account or removes every uploaded and generated image from both database records and object storage. Signed-link refresh and expiry are access operations, not file deletion.

Your rights and choices

The rights available to you depend on where you live and which law applies.

Applicable law may give you rights to access, correct, export, delete, or restrict use of personal information; object to certain processing; withdraw consent without affecting earlier lawful processing; and complain to a privacy regulator. Current in-product controls cover only the actions listed above.

Security, international processing, and children

Chromelier uses private object storage, ownership checks, server-side authorization boundaries, and server-side encryption for stored personal provider credentials. These controls reduce risk but cannot guarantee absolute security. Do not place secrets in prompts or upload regulated material unless the selected provider and your intended use are appropriate.

Chromelier currently operates from Ontario, Canada. Vercel, Supabase, and selected AI providers may process information in countries other than yours. Their locations and transfer safeguards are described in their linked notices. Chromelier is not directed to children, does not verify age, and should not be used by anyone who cannot lawfully agree to the Terms or whose use requires parental consent that has not been obtained.

Changes to this notice

The notice may change when product data flows, providers, or legal requirements change. The updated date identifies the published version. Material changes will be presented with additional notice or consent when applicable law requires it.

Privacy contact

Questions, privacy requests, and privacy complaints can be sent to the dedicated address below.

Contact privacy@chromelier.com. Include enough information to identify your account and request, but do not send passwords, provider keys, or other secrets by email.

For a suspected vulnerability or security incident, use security@chromelier.com instead.