Private by default
Account workspace content and stored images are private unless you deliberately share or publish them.
Last updated August 27, 2026
This notice explains what the current product handles, when information leaves Chromelier, and which controls exist today. It avoids promising controls or retention periods that have not been built.
Account workspace content and stored images are private unless you deliberately share or publish them.
A prompt and the context needed to answer it go to the selected AI provider when you request an AI operation.
Unlisted links can be opened by anyone who has the link. Public and Community content may be discoverable.
Chromelier does not currently sell personal information or share it for cross-context behavioral advertising.
Chromelier limits collection to information used for the workspace, requested AI operations, sharing, safety, and reliability.
Email address, Supabase user identifier, sign-in method, session records, and Google account information returned when you choose Google sign-in.
Palettes, color roles, projects, settings, versions, workspace snapshots, saved items, shares, Community listings, and likes.
Threads, prompts, responses, tool results, palette context, run state, model and provider choices, latency, token counts, usage events, and sanitized error metadata.
JPEG, PNG, and WebP references you upload, image-generation prompts and settings, generated results, private object paths, and short-lived display links.
Optional API credentials, credential fingerprints, connection status, and related operation events when you choose BYOK. Personal provider credentials are encrypted at rest by the server before storage; the complete saved secret is not returned to the UI.
Functional browser state, theme and layout choices, cached catalog information, service usage, provider route outcomes, and infrastructure request or error logs.
Depending on the law that applies, processing may be necessary to provide a service you requested, based on consent for an optional transfer, required by law, or supported by a legitimate interest in security and reliability. This notice does not claim that one jurisdiction-specific legal basis applies everywhere. Chromelier does not use Copilot output to make decisions that produce legal or similarly significant effects about you.
A provider receives only the information needed for the feature you activate, but its own handling can vary by model, route, account, and upstream service.
Authentication, database records, and private object storage.
Supabase privacyApplication hosting, delivery, and infrastructure request logs.
Vercel privacyChromelier does not promise that every provider uses submitted data in the same way or that provider policies never change. Review the just-in-time disclosure in AI Models & Limits before sending confidential, regulated, or identifying content. Optional provider transfer is not enabled merely because this notice exists.
Uploads and generated results follow different processing paths.
Original reference images are retained as uploaded after file-type, size, and ownership validation. Embedded metadata is not currently stripped. When a vision request needs the image, its bytes are sent to the selected provider.
Generated images are re-encoded to WebP before private storage. Re-encoding the generated output does not change how an original upload is retained.
Stored images use a private bucket and temporary signed URLs for display and download. Expiring a signed URL does not delete the stored file; it only ends access through that particular URL. Do not upload an image containing hidden or identifying metadata unless you are comfortable retaining and processing it as described above.
Supabase authentication persists session information, including refresh credentials, in browser storage. Chromelier also uses browser storage for local drafts, preferences, workspace snapshots, layout and theme choices, and cached catalog information. A functional sidebar cookie remembers navigation state. Clear site data or sign out to remove or invalidate applicable local state, understanding that doing so can discard unsaved drafts.
The current product has no advertising tracker, third-party analytics SDK, or Sentry integration. Vercel and Supabase may retain infrastructure logs under their own policies. Chromelier also keeps a limited operational error ledger for up to 30 days; it contains only an allowlisted event type, a technical record identifier, and an optional sanitized error code—not prompts, generated responses, images, credentials, browser fingerprints, or IP addresses.
Chromelier does not publish a fixed retention period that the product cannot yet enforce.
Account and workspace records are generally retained while needed to provide the saved workspace, keep a share or Community entry available, enforce allowances, protect the service, resolve disputes, or meet legal obligations. Provider credentials remain until removed through the available credential control. Infrastructure providers apply their own backup and log-retention practices.
Available controls can delete eligible palettes or projects, remove a saved provider credential, revoke a share, unpublish eligible Community content, clear browser state, and sign out. No self-service control currently deletes your entire account or removes every uploaded and generated image from both database records and object storage. Signed-link refresh and expiry are access operations, not file deletion.
The rights available to you depend on where you live and which law applies.
Applicable law may give you rights to access, correct, export, delete, or restrict use of personal information; object to certain processing; withdraw consent without affecting earlier lawful processing; and complain to a privacy regulator. Current in-product controls cover only the actions listed above.
Chromelier uses private object storage, ownership checks, server-side authorization boundaries, and server-side encryption for stored personal provider credentials. These controls reduce risk but cannot guarantee absolute security. Do not place secrets in prompts or upload regulated material unless the selected provider and your intended use are appropriate.
Chromelier currently operates from Ontario, Canada. Vercel, Supabase, and selected AI providers may process information in countries other than yours. Their locations and transfer safeguards are described in their linked notices. Chromelier is not directed to children, does not verify age, and should not be used by anyone who cannot lawfully agree to the Terms or whose use requires parental consent that has not been obtained.
The notice may change when product data flows, providers, or legal requirements change. The updated date identifies the published version. Material changes will be presented with additional notice or consent when applicable law requires it.
Questions, privacy requests, and privacy complaints can be sent to the dedicated address below.
Contact privacy@chromelier.com. Include enough information to identify your account and request, but do not send passwords, provider keys, or other secrets by email.
For a suspected vulnerability or security incident, use security@chromelier.com instead.