top of page
Privacy Policy
Last Updated: Aug 26 2026
Effective Date: Aug 26 2026
CHANCE ART & TECHNOLOGY PTE. LTD. (hereinafter referred to as “the Platform”, “we”, “us”, or “our”) is dedicated to safeguarding your privacy and personal data. This Privacy Policy aims to help you understand what information we collect, how we use it, how we protect it, and the rights you hold regarding your data when you use our mobile application, Chance AI (the “App”), and any related services (collectively, the “Services”).
Please read this Privacy Policy carefully and in its entirety. By accessing or using any part of the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices described herein, please do not use our Services.
If you are under 13 years old, do not meet the age requirements for using or accessing the Services in your jurisdiction, or if there are other legal restrictions applicable to your user status, please comply with local laws by refraining from using the Services. You should only access or use the Services if you meet the applicable age requirements in your jurisdiction. If you are between 13 and 18 years old, please ensure that you have understood this Policy and, where required by applicable law, obtained the necessary consent from your parent or legal guardian. If you are a parent or guardian and become aware that your child has provided us with personal data, please contact us immediately. Should we learn that personal data has been collected from anyone under 13 years old (or the applicable legal age) without verified parental consent, we will promptly take measures to delete such data from our servers.
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland (collectively, the “EEA+” areas), please also read carefully and consent to the EEA+ Addendum to this Privacy Policy. If you are a resident of California, Virginia, Colorado, Connecticut, Utah, or any other U.S. state with an applicable comprehensive privacy law, please also read carefully and consent to the US Addendum to this Privacy Policy.
1. INFORMATION WE COLLECT
Depending on how you use the App—whether uploading images for AI-powered editing and generation, utilizing location-based features, or engaging with other functionalities—we collect different types of information.
1.1 Information You Provide Directly
-
Account Information: When you register for an account, we collect your email address, which are used for App login and account management. You may also choose to provide additional information such as your birthday and a brief personal bio; these are optional and not required for using the core features of the Services. If you choose to sign in using your Apple Account or Google Account, we will receive from the respective provider the basic account information you have authorized them to share with us, which may include your email address and name. This limited collection approach is intentional to minimize the personal data we hold about you.
-
Subscription and Transaction Information: If you purchase a subscription, we receive information from Apple or Google that may include the platform, subscription product and plan, transaction or order identifier, purchase and renewal dates, subscription status, trial or promotional eligibility and status, expiration or cancellation information, and limited refund-related information. We do not receive or store the details of your payment card or bank account; those details are handled by the applicable app store and its payment providers. We retain only the information necessary to verify your subscription status, provide paid benefits, and maintain transaction records as required for tax, accounting, and legal purposes.
-
Images, Photos, and Live Visual Input: When you use the App’s visual search, Visual Agents, AI image generation and editing, or live visual features, we collect or process images you upload or capture, selected camera frames, and related visual input. These materials may include photographs containing faces, objects, documents, surroundings, or other information visible in the image or camera view. We process them to provide the feature you request. Uploaded images and resulting content may be retained with your account as described in Section 3; live camera frames may be transmitted and processed in real time to provide the live feature and are handled according to the applicable service configuration.
-
Precise Geolocation Data: When you use location-based features within the App, we may collect your device’s precise latitude and longitude coordinates and location metadata associated with a photo you select, where available and permitted by your device settings. We use this data to provide location-relevant information or recommendations you request. If you refuse to provide location access, location-related features may be unavailable, but other functions will remain available where technically feasible.
-
User Content: Any text, prompts, or other content you input into the App in connection with the Services, including but not limited to text inputs for AI interactions, feedback submissions, and customer support inquiries. If the content you input includes personal data relating to any other individual, you are responsible for ensuring that you have obtained all necessary legal authorizations or consents before providing such data.
-
Voice, Audio, and Transcription Data: When you use voice input, live conversation, or other audio-enabled features, we process microphone audio, speech, transcripts, selected language, and related interaction data to recognize your request, provide a response, and operate the feature. Depending on the feature and device capabilities, audio may be processed on the device or streamed to our servers and service providers for transcription or real-time AI processing.
-
Contacts and Invitations: If you grant contacts permission and use an invitation feature, the App accesses contact names and phone numbers on your device so that you can select a recipient and open your device’s messaging application. We do not upload contact names or phone numbers to our servers or analytics providers. We may collect contacts-permission status, the number of eligible contacts loaded, and invitation-related actions as usage analytics. You may decline or revoke contacts access through your device settings.
-
Customer Support Information: When you submit feedback or support requests to us, we collect information such as your description of the issue, any attached supporting materials, your email address, and any other information you choose to provide. This information is necessary to provide feedback-related services. We may use your email address or other contact details to verify your identity, clarify your concerns, provide relevant support, and help resolve any issues you encounter. To assist with feedback related to your use of the Services, we may access your usage data, including interaction history and past feedback submissions. During the course of feedback, complaint, or consultation, the system may log communications between you and our team. These records help us address your concerns effectively and enhance the quality of our services.
-
Service Communications: You acknowledge and agree that we may use the contact information you provide (your email address) to send you notifications related to the operation of the Services. These may include messages for identity or security verification, service updates and experience research. If you prefer not to receive such promotional messages, you may unsubscribe using the method included in the message or contact us directly to opt out.
1.2 Information Collected Automatically
To protect your account security, improve our service quality, and understand how users interact with the App, we automatically collect certain information generated during your use of the Services:
-
Usage Data, Analytics, and Attribution: Includes features used, session duration, interaction patterns, feature usage frequency, subscription and paywall interactions, invitation actions, content categories viewed or interacted with, app performance, crash information, acquisition source, campaign attribution, and related metrics such as activation and retention. We use AppsFlyer for installation attribution, promotional effectiveness measurement, and product analytics. We do not use AppsFlyer data for personalized advertising, retargeting, or advertising-audience matching.
-
Device, Network, and Identifier Information: We and our service providers may process device type, operating system and version, app version, language, time zone, country or region, IP address, user agent, device or app identifiers, advertising identifier where permitted, and network information. These data support authentication, security, analytics, attribution, diagnostics, compatibility, and service delivery. Some of this information is collected directly by third-party SDKs integrated into the App.
-
Log, Diagnostics, and Push Information: We collect operational logs, API and error information, crash and performance data, push-notification tokens, notification permission status, and notification delivery or interaction information to troubleshoot issues, monitor reliability, send requested or service-related notifications, and protect the Services.
1.3 Biometric Data & Facial Features
When you upload a photo containing a face to use our AI-powered features, our AI models (accessed through third-party AI API providers) analyze facial features and geometry to generate AI suggestions and edited images.
-
Processing Scope: We do not process images for the purpose of identifying or authenticating you. We process images containing faces solely for the purpose of providing AI-powered suggestions and image generation. We do not store raw biometric identifiers separately from the original images. The data we store consists of the original image you uploaded and the AI-generated output.
-
Usage: This data is strictly used for providing the Services you have requested and is never sold to any third party or used for surveillance, identification, or any other purpose outside the specific feature you have initiated.
-
Consent and Jurisdiction: In jurisdictions that classify facial geometry data as biometric identifiers, we will obtain your explicit, prior consent before collecting such data. You have the right to refuse consent, in which case the relevant AI image editing features will not be available to you. You may withdraw your consent at any time by ceasing to upload images containing faces and by deleting your account.
-
Third-Party AI Processing: Your uploaded images and facial data are transmitted to our third-party AI API providers—specifically, OpenRouter, Google Gemini, and Google Vertex AI—for processing. Please refer to Section 4 for further details on third-party data sharing.
2. HOW WE USE YOUR INFORMATION
We use the collected information to provide, maintain, and improve the Services, and to comply with legal obligations. Specifically:
2.1 Provide and Operate Services
-
AI Inference and Image Processing: Send your uploaded images, prompts, and inputs to our third-party AI API providers (OpenRouter, Google Gemini, and Google Vertex AI) to generate AI-powered suggestions and outputs. This processing is essential to deliver the core functionality you have requested.
-
Location-Based Features: Use your precise geolocation data to provide location-based recommendations and services when you request them. For example, if you ask for nearby places, we use your GPS-derived location to return relevant results.
-
Account Management: Use your email address to register and manage your account, provide you with access to different functionalities of the App, and communicate with you about your account, including security alerts, and service updates.
-
Subscriptions and Entitlements: Use subscription and transaction information to verify purchases, activate and synchronize paid benefits across devices and platforms, restore purchases, manage usage allowances, provide support, prevent fraud, and process cancellation or refund status received from Apple or Google.
-
Voice and Live Visual Features: Process audio, transcripts, images, camera frames, prompts, and associated context to provide voice, live visual, and other real-time AI interactions you initiate.
-
Contact Invitations: Access contacts locally on your device to let you select a recipient and prepare an invitation through your device’s messaging application. We use limited aggregate interaction metrics to understand whether the invitation feature works as intended.
-
Customer Support: Use your information to respond to your inquiries, support requests, or feedback, and to resolve any issues you encounter while using the Services.
2.2 Improve and Optimize the Services
-
Monitor usage and analyze how users interact with the App to enhance features, performance, safety, and user experience; diagnose crashes and technical issues; understand installation sources and promotional effectiveness; and assess how subscription and free-tier features are used. Attribution and analytics data are not used by us for personalized advertising, retargeting, or advertising-audience matching.
2.3 Communicate with You
-
Send you service-related communications.
-
Respond to your inquiries, support requests, or feedback.
-
Send you promotional information about our services, features, or events. [You may opt out at any time.]
2.4 Legal Compliance and Security
-
Comply with applicable laws, regulations, and legal processes.
-
Detect, prevent, and address fraud, security, or technical issues.
-
Enforce our Terms of Service and other agreements.
-
Detect and prevent content that violates our policies or applicable laws.
2.5 AI Model Training
We do not use your personal data, uploaded images, or generated content to train our own AI models. However, we cannot control or guarantee the data practices of our third-party AI API providers (OpenRouter, Google Gemini, and Google Vertex AI). Please refer to the privacy policies of these third-party providers for information about how they may use data submitted through their APIs.
3. DATA STORAGE AND RETENTION
3.1 Storage Location and Format
We store your personal data, uploaded images, and generated content on Amazon Web Services (“AWS”) servers in the United States. Depending on the feature, your data may also be hosted or processed using infrastructure provided by Google Cloud/Firebase and other service providers identified in Section 4. These providers act as our data processors and are contractually obligated to process your data only in accordance with applicable data protection laws.
We use technical and organizational safeguards designed to protect personal data, which include encryption in transit and, where supported and appropriate for the relevant system, encryption at rest, together with access controls and other security measures described in Section 6.
3.2 Retention Periods
We retain different categories of data for different periods, based on the purpose of collection and applicable legal requirements. The specific retention periods are as follows:
-
Account Information and User Content: retained until you delete your account, with a short grace period after your deletion request to allow for account recovery.
-
Usage Data and Device Information: retained for a limited period from the date of collection, or until you delete your account, whichever occurs earlier.
-
Customer Support Records: retained for the period necessary to address your inquiry and to comply with applicable legal requirements.
-
Subscription and Transaction Records: retained for the duration as long as necessary to provide subscription benefits, maintain transaction and entitlement history, resolve billing or refund issues, prevent fraud, as required by applicable tax, accounting, and legal obligations (typically up to the applicable statute of limitations or tax record retention period, which may be up to 7 years in certain jurisdictions).
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal obligations, including legal, regulatory, tax, accounting, or reporting requirements. When personal data is retained solely to meet legal obligations, we implement safeguards to restrict further processing. Once the personal data is no longer needed for its original purpose or legal compliance, we will securely delete it.
3.3 Data Deletion Methods
When data is deleted (whether by your request or upon expiration of the retention period), personal data is permanently removed from our databases.
3.4 How to Request Deletion
You may request deletion of your data through any of the following methods, but deletion of Account or data will not cancel or interfere a subscription billed by Apple or Google; you must cancel that subscription separately through the applicable platform:
-
In-App: Navigate to the App’s account settings and select “Delete Account”. This will initiate deletion of personal data associated with your account, except information that we are required or permitted to retain for legal, security, fraud-prevention, transaction-record, or dispute-resolution purposes.
-
Email: Send a request to feedback@chance.vision with the subject line “Data Deletion Request.” We will verify your identity and process your request within 30 days or other period as required by applicable law.
-
Specific Data Types: You may delete individual images, AI-generated outputs, or specific content through the respective feature interfaces without deleting your entire account.
4. SHARING & DISCLOSURE
We do not sell, trade, or rent your personal data to third parties. We share information only under the following circumstances:
4.1 Service Providers
In order to operate the Services and deliver requested functionality, we may share personal data with service providers that provide cloud hosting, authentication, AI and voice processing, app-store billing, analytics and attribution, crash and performance monitoring, push notifications, mapping and location services, and related technical support. They process data for the purposes described below and subject to applicable contractual and legal requirements:
Third-Party Partner
Data Shared
Purpose
Amazon Web Services (AWS)
Account information, images, user content, geolocation data, audio where applicable, and service logs
Cloud hosting, storage, compute infrastructure, and selected AI or transcription services
OpenRouter
Uploaded images, prompts, and user content submitted for requested AI processing
AI model routing, inference, and processing
Google Gemini
Images, camera frames, audio, prompts, transcripts, and user content submitted for requested AI processing
AI model inference, live visual and voice processing, and generation
Google Vertex AI
Images, prompts, user content, and related service data submitted for requested AI processing
AI model inference, processing, and generation
Google Analytics / Firebase Analytics
Usage, device, network, attribution-related, subscription-interaction, and aggregate invitation-event data
Product analytics, performance measurement, and service improvement
Google Cloud and Firebase
Account identifiers, authentication data, service data, device and usage data, images, prompts, audio or live visual data where applicable
Authentication, cloud services, AI processing, analytics, and related infrastructure
Apple
Authentication information and App Store transaction, subscription, entitlement, cancellation, and refund-status data
Sign in with Apple and iOS subscription billing and management
Google Play
Google account information where authorized and Play transaction, subscription, entitlement, cancellation, and refund-status data
Google sign-in and Android subscription billing and management
AppsFlyer
Device and app identifiers where permitted, IP address, installation source, campaign attribution, and related app-event data
Installation attribution, promotional effectiveness measurement, and product analytics; not personalized advertising or retargeting
Datadog
Device, network, app-performance, error, crash, log, and account identifier data where configured
Diagnostics, crash reporting, performance monitoring, and reliability
OneSignal
Account or app user identifier, device information, push token, permission status, and notification interaction data
Push-notification delivery and measurement
Map and Location Service Providers (including Mapbox)
Location, map or place queries, device and network information
Maps, place information, and location-based features requested by the user
Such service providers are authorized to access, process, or store personal data solely to the extent necessary for performing their responsibilities on our behalf and strictly under our instructions. We require all third-party service providers to maintain appropriate security measures and to process personal data only in accordance with our instructions and applicable laws. Each provider processes data in accordance with its own privacy policies.
Important Note Regarding Service Providers: Service providers may maintain their own data-handling and retention practices for information they process in their capacity as independent controllers, and their own privacy notices may apply to those activities. Where a provider processes personal data on our behalf, we use contractual and organizational safeguards appropriate to the relationship and, where required, data processing terms and international-transfer safeguards. We do not control and are not responsible for the data practices of these third-party providers, but we encourage you to review the privacy policies of these providers to understand how they handle your data.
Third-Party Authentication Providers: We offer you the option to sign in to the App using your Apple Account or Google Account. If you choose to use these authentication services:
-
Apple will provide us with your email address and, if you choose to share it, your name, in accordance with Apple’s Privacy Policy. Apple may also share a unique identifier with us to facilitate your sign-in. For more information on how Apple handles your data, please review Apple’s Privacy Policy.
-
Google will provide us with your email address, name, and profile information you have authorized, in accordance with Google’s Privacy Policy. For more information on how Google handles your data, please review Google’s Privacy Policy.
We do not receive or store your passwords for these third-party authentication services. You may revoke our access to your Apple Account or Google Account at any time through your account settings with the respective provider. These third-party authentication providers act as independent data controllers with respect to the personal data they collect directly from you. Their processing of your data is governed by their respective privacy policies.
4.2 Legal Requirements
We may disclose your personal data to government authorities, regulatory bodies, or other third parties under certain circumstances: (i) to comply with applicable laws or when we have a good faith belief that such disclosure is necessary to fulfill legal obligations; (ii) to protect and enforce our rights or property; (iii) if we reasonably determine that you have breached our terms, policies, or legal requirements; (iv) to identify, prevent, or address fraud or unlawful activities; (v) to safeguard the safety, security, and integrity of our products, employees, users, or the public; or (vi) to mitigate legal risks or liabilities.
4.3 Business Transfers
In the event of a strategic transaction, restructuring, bankruptcy, acquisition, merger, or transfer of services to another provider (collectively referred to as a “Transaction”), your personal data may be disclosed to the counterparty and other parties involved in the Transaction for due diligence purposes. Furthermore, your personal data may be transferred to a successor or affiliate along with other assets as part of the Transaction. We will notify you of any such Transaction and any material changes to the processing of your personal data.
5. CHILDREN’S PRIVACY
The App is not intended for use by children under the age of 13 (or the digital age of consent in your country/region, or other applicable age thresholds under local law). We do not knowingly collect personal data from children.
If you do not meet the age requirements for using or accessing the Services in your country/region, please comply with local laws by refraining from using the Services. You should only access or use the Services if you meet the applicable age requirements. If you are a parent or guardian and believe your child has provided us with information, please contact us immediately. If we discover that we have collected personal information from a minor without verified parental consent, we will take immediate steps to delete that information from our servers.
For users between the ages of 13 and 18 (or the applicable age of majority in their jurisdiction), we rely on your representation that you are capable of consenting to the Terms of Service and our Privacy Policy on your own behalf, or that you have obtained the necessary consent from your parent or legal guardian, as required by applicable law. If you are a parent or guardian and you believe your child has provided us with personal data without your consent, please contact us immediately. We do not intentionally collect personal data from minors and reserve the right to delete any data discovered to have been collected from a minor without proper consent.
6. DATA SECURITY
We employ administrative and technical security measures designed to protect your personal information from unauthorized access, theft, loss, misuse, alteration, or destruction. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security. We are committed to using commercially acceptable means to protect your personal data.
Our security measures include but are not limited to:
-
Encryption in Transit: All data transmitted between your device and our servers is encrypted using HTTPS protocol, ensuring that data cannot be intercepted during transmission.
-
Access Controls: Access to personal data is restricted to authorized personnel and service providers based on role, business need, and the principle of least privilege. We use authentication, access-management, and review measures appropriate to the relevant systems. We do not publicly guarantee that personal data can be accessed only from one country unless such a restriction is both legally required and consistently implemented.
-
Infrastructure Security: We use established cloud and technical service providers and configure safeguards appropriate to the relevant services and data. Provider certifications and security features support, but do not replace, our own responsibility for protecting personal data.
-
Incident Response: We maintain a data breach incident response plan. In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within the timeframes required by applicable law.
-
Security Review: We assess and improve safeguards based on the nature of the data, and applicable legal requirements.
-
Organizational Measures: We maintain internal policies and procedures designed to support responsible handling of personal data and response to security incidents.
7. YOUR RIGHTS AND CHOICES
Depending on applicable privacy laws, you have certain rights regarding your personal data. We respect these rights and provide you with mechanisms to exercise them.
7.1 Your Rights
Depending on your jurisdiction, you may have certain rights regarding your personal data, including the right to access, rectify, delete, restrict processing of, and object to processing of your personal data, as well as the right to data portability and the right to withdraw consent. To exercise any of these rights, please contact us by email, and we will respond to your request within the timeframes required by applicable law. For detailed information about your rights under the GDPR and CCPA, please refer to the EEA+ Addendum and US Addendum to this Privacy Policy.
7.2 AI Generated Content Disclaimer
The App generates responses and edits using third-party generative artificial intelligence models. Please be aware that AI-generated output may not always be factually accurate, complete, or appropriate for your specific circumstances. Therefore, you should not rely solely on the factual correctness of the output provided by our models. We do not engage in automated decision-making that produces legal or similarly significant effects concerning you, as defined under applicable law (including Article 22 of the GDPR).
7.3 How to Exercise Your Rights
To exercise any of these rights, please contact us at:
-
Email: feedback@chance.vision
-
Subject Line: “Privacy Request – [Your Name]”
When submitting your request, please specify which rights you wish to exercise and how we can assist you. To verify your identity and confirm your authorization to make the request, we may ask you to provide certain information (such as your email address associated with your account). These security measures help prevent unauthorized disclosure or improper processing of personal data. We may reach out to you for further details to clarify your request and expedite our response.
7.4 Response Timeline
We will respond to all verifiable privacy rights requests within 30 days of receipt. If additional time is required, where permitted by applicable law, we will notify you of the extension and the reason for it within the initial 30-day period. If we deny your request, we will provide an explanation of the reasons for denial and, where applicable, information about how you may appeal the decision.
We will not charge a fee for processing your request unless it is manifestly unfounded, repetitive, or excessive. In such cases, we may charge a reasonable fee or refuse to act on the request.
8. INTERNATIONAL DATA TRANSFERS
Our Services are global, and your information may be stored and processed in countries outside your residence. We implement appropriate safeguards to protect your data in accordance with applicable laws.
In particular, information may be transferred to or processed in the United States and other countries where our cloud, authentication, AI and voice, billing, analytics, attribution, diagnostics, push-notification, and mapping service providers operate. The destination and provider depend on the feature you use and the applicable technical configuration.
For transfers from the European Economic Area (EEA), the United Kingdom, or Switzerland to countries not recognized as providing an adequate level of data protection (including the United States), we rely on the following lawful transfer mechanisms:
-
Standard Contractual Clauses (SCCs) adopted by the European Commission, as supplemented by appropriate safeguards, to ensure an adequate level of data protection for your personal data;
-
UK International Data Transfer Addendum (for transfers from the UK); and
-
Such other lawful transfer mechanisms as may be applicable under Swiss law (for transfers from Switzerland).
9. PRIVACY POLICY UPDATES
To continually improve our services, updates and changes may be made from time to time. We will update this Privacy Policy accordingly, and any such updates will become an integral part of this Privacy Policy.
Once this Privacy Policy is updated, we will publish the revised version on our website. If you do not agree with the updated policy or have objections to any modifications, please discontinue your use of the Services. Please note that any activities or actions you performed before deactivating your account or stopping use of the Services will still be governed by the version of this Privacy Policy in effect at the time of such activities.
For any significant changes that materially reduce your rights under this Privacy Policy, we will provide you with more prominent notifications. For material changes that require consent under applicable law, we will seek your renewed consent before implementing such changes.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data.
10. CONTACT US
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us by email at feedback@chance.vision. For privacy-specific inquiries, please include “Privacy” in the subject line of your email.
EEA+ ADDENDUM
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland (collectively, the “EEA+” areas), please refer to this EEA+ Addendum. This addendum is specifically designed for individuals in the EEA+ regions. It complements our Privacy Policy and provides detailed information on how we handle your personal data when you use or interact with our Services. In the event of any discrepancies between the Privacy Policy and this EEA+ Addendum, the provisions of this Addendum shall prevail.
If you are located in the EEA, the EU General Data Protection Regulation (Regulation (EU) 2016/679) applies to our processing of your personal data, as well as local data protection laws, as the case may be. If you are located in the UK, the UK General Data Protection Regulation (as retained in UK law) applies to our processing of your personal data. References to the “GDPR” are references to the General Data Protection Regulation as it applies in the country where you are located. If you are located in Switzerland, the Swiss Federal Data Protection Act (the “FDPA”) applies to our processing of your personal data, and references to the GDPR below shall be interpreted analogously for the purposes of applying the FDPA.
A. WHO IS THE DATA CONTROLLER?
The data controller is CHANCE ART & TECHNOLOGY PTE. LTD., and its affiliates.
B. WHAT TYPES OF PERSONAL DATA DO WE COLLECT AND HOW DO WE COLLECT IT?
Please see Section 1 of the main Privacy Policy for a detailed description of the categories of personal data we collect, including:
-
Account Information (email address)
-
Images and Photos (including those containing faces)
-
Precise Geolocation Data
-
User Content (prompts, text, feedback)
-
Usage Data and Device Information (collected through third-party analytics services)
-
IP Address (collected through third-party analytics services)
-
Subscription and Transaction Information (purchase and renewal dates, subscription status, transaction identifiers, and entitlement information)
C. FOR WHAT PURPOSES DO WE PROCESS PERSONAL DATA?
Please see Section 2 of the main Privacy Policy for a detailed description of the purposes for which we process your personal data, including:
-
Providing and operating the Services
-
Improving and optimizing the Services
-
Communicating with you
-
Managing subscriptions and activating cross-platform entitlements
-
Legal compliance and security
-
We do not use your data to train our own AI models
D. WHAT LAWFUL BASES OF PROCESSING AND LEGITIMATE INTERESTS DO WE RELY ON?
We process your personal data only when we have a lawful basis to do so under the GDPR and UK GDPR. The lawful bases we rely on are as follows:
Processing Activity
Lawful Basis
Explanation
Providing the core Services (Visual Search, Visual Agents, AI image and content generation, voice and live visual interactions, account management, contact invitations, and location-based features)
Performance of a contract (Article 6(1)(b))
Processing is necessary to provide the Services you have requested and to perform our contract with you. Without this processing, we cannot deliver the core functionality of the App.
Customer support, service communications, and responding to your inquiries
Performance of a contract (Article 6(1)(b)) or Legitimate interests (Article 6(1)(f))
Processing is necessary to fulfill our contractual obligations to support your use of the Services, or is in our legitimate interest to provide effective customer service and maintain user relationships.
Improving the Services, performance analytics, and crash monitoring
Legitimate interests (Article 6(1)(f))
We have a legitimate interest in understanding how users interact with the App, identifying technical issues, and continuously improving our Services to enhance user satisfaction and safety.
Legal compliance, fraud prevention, security, and enforcement
Legal obligation (Article 6(1)(c)) or Legitimate interests (Article 6(1)(f))
Processing is necessary to comply with legal obligations to which we are subject, or is in our legitimate interest to protect our Services, users, and infrastructure from security threats, fraud, and unlawful activities.
Collection of precise geolocation data and processing of images containing faces
Consent (Article 6(1)(a))
We rely on your explicit consent to collect and process these categories of sensitive data. You may withdraw your consent at any time through your device settings or by ceasing to use the relevant features.
Processing subscriptions, transactions, and cross-platform entitlements
Performance of a contract (Article 6(1)(b)) or Legal obligation (Article 6(1)(c))
Processing is necessary to verify purchases, provide paid benefits, manage subscription status, maintain required transaction records, prevent fraud, and comply with billing, accounting, and legal obligations.
Special Categories of Personal Data (Sensitive Data)
We do not process your images for the purpose of identifying or authenticating you. We process images containing faces solely for the purpose of providing AI-powered suggestions and image generation — the processing is content-based, not identification-based.
Nevertheless, out of an abundance of caution and to ensure transparency, we process images containing faces only with your explicit consent. By uploading images containing faces, you consent to our processing of such images for the purpose of providing the Services. You have the right to withdraw this consent at any time by ceasing to upload such images and deleting your account.
For precise geolocation data, we similarly rely on your consent under Article 6(1)(a) and, where applicable, Article 9(2)(a) of the GDPR. You may withdraw your consent at any time through your device’s location settings.
Legitimate Interest Assessments
Where we rely on legitimate interests (Article 6(1)(f)), we have conducted a balancing test to ensure that our interests do not override your fundamental rights and freedoms. Our legitimate interests include: (a) understanding user behavior to improve our product; (b) maintaining the security and integrity of our Services; (c) optimizing operational efficiency; and (d) preventing fraud and abuse. We have determined that these interests are not overridden by the potential impact on your privacy, given that we collect only limited personal data (primarily email address, usage data, and device information) and we implement appropriate safeguards. Further details regarding our legitimate interest assessments are available upon request.
E. WHAT CATEGORIES OF RECIPIENTS RECEIVE PERSONAL DATA FROM US?
Please see Section 4 of the main Privacy Policy for a detailed description of the categories of recipients with whom we share personal data, including:
-
Cloud infrastructure providers (AWS)
-
AI API providers (OpenRouter, Google Gemini, Google Vertex AI)
-
Analytics providers (Google Analytics)
-
App store providers (Apple App Store and Google Play) for subscription and transaction processing
-
Diagnostics and performance monitoring providers (Datadog)
-
Push notification providers (OneSignal)
-
Map and location service providers (Mapbox)
All such recipients process data as data processors on our behalf, pursuant to data processing agreements that require them to process data only in accordance with our instructions and applicable data protection laws. Where a recipient processes personal data in its capacity as an independent controller, its own privacy policy shall apply to such processing.
F. WHERE IS YOUR PERSONAL DATA PROCESSED AND ON WHAT BASIS DO WE TRANSFER PERSONAL DATA ACROSS BORDERS?
We may transfer and disclose personal data to AWS in the United States. To ensure an adequate level of data protection, we implement appropriate safeguards and data transfer mechanisms with our processors as required in the GDPR. These include:
-
Standard Contractual Clauses (SCCs) adopted by the European Commission (Implementing Decision (EU) 2021/914) for transfers of personal data to controllers or processors established in third countries, as supplemented by appropriate technical, organizational, and contractual safeguards to ensure an adequate level of protection for your personal data;
-
UK International Data Transfer Addendum to the SCCs, as issued by the UK Information Commissioner’s Office, for transfers from the UK; and
-
Such other lawful transfer mechanisms as may be applicable under Swiss law (including the FDPA) for transfers from Switzerland.
Where we use SCCs, we apply supplementary measures as necessary to address the legal and regulatory landscape of the destination country, including but not limited to technical encryption measures and enhanced access controls to ensure that your personal data receives an essentially equivalent level of protection as it would within the EEA.
G. HOW LONG DO WE PROCESS PERSONAL DATA?
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal obligations. The retention period varies depending on the specific purposes of data collection and applicable laws, including legal, regulatory, tax, accounting, or reporting requirements.
Please see Section 3.2 of the main Privacy Policy for our specific data retention periods. Payment and billing records are retained for the duration required by applicable tax, accounting, and legal obligations. When personal data is retained solely to meet legal obligations, we implement safeguards to restrict further processing. Once the personal data is no longer needed for its original purpose or legal compliance, we will securely delete it in accordance with Section 3.4 (Data Deletion Methods).
H. WHAT DATA PROTECTION RIGHTS DO YOU HAVE?
In the EEA, Switzerland, and the UK, you have the following rights, subject to the conditions and limitations under the GDPR and/or local data protection law. These rights are designed to give you control over your personal data and to ensure transparency in how we process it.
-
Right to Object: You have the right to object, based on your specific situation, to our processing of your personal data where we rely on legitimate interests or the public interest. You also have the right to object to direct marketing at any time. If you object, we will stop processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or for legal claims.
-
Right of Access: You have the right to obtain confirmation as to whether your personal data is being processed, and if so, to access that data along with information about the processing (including purposes, categories of data, recipients, retention period, and the existence of automated decision-making).
-
Right to Rectification: You have the right to request correction of any inaccurate personal data we hold about you, and to have incomplete personal data completed, taking into account the purposes of processing.
-
Right to Erasure: You have the right to request deletion of your personal data where, for example, the data is no longer necessary for the purposes for which it was collected, you withdraw consent and no other legal ground applies, you object to processing based on legitimate interests and there are no overriding grounds, the processing is unlawful, or erasure is required by law. Please note that your right to erasure does not apply where we are required to retain payment and billing records to comply with applicable tax, accounting, or other legal obligations, but all data will be retained under security measures in accordance with Section 6 of the Privacy Policy.
-
Right to Restrict Processing: You have the right to request restriction of processing where you contest the accuracy of the data, the processing is unlawful, we no longer need the data but you require it for legal claims, or you have objected to processing pending verification. Where processing is restricted, data may only be processed with your consent or for legal claims, protection of rights, or important public interest.
-
Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller, where processing is based on consent or contract and carried out by automated means. Where technically feasible, you have the right to have the data transmitted directly to another controller.
-
Right to Withdraw Consent: You have the right to withdraw your consent to data processing at any time. This withdrawal will not affect the legality of any processing conducted prior to the withdrawal. You may withdraw consent by adjusting your preferences in the App, through your device settings, or by contacting us.
How to Exercise Your EEA+ Rights
To submit a request to exercise your privacy rights, you can contact us by emailing feedback@chance.vision. When submitting your request, please specify which rights you wish to exercise and how we can assist you. To verify your identity and confirm your authorization to make the request, we may ask you to provide certain information (such as your email address associated with your account). These security measures help prevent unauthorized disclosure or improper processing of personal data. Additionally, we may reach out to you for further details to clarify your request and expedite our response. We will handle all requests to exercise your privacy rights in accordance with applicable laws and will respond within one month of receipt (with a possible extension of up to two additional months where necessary, taking into account the complexity and number of requests).
I. ARE YOU REQUIRED TO PROVIDE US WITH YOUR PERSONAL DATA?
Providing personal data to us is voluntary. You are not under any statutory or contractual obligation to provide your personal data. However, without certain personal data (such as your email address for account creation), we may be unable to deliver the core Services to you or may not be able to provide you with certain features (such as account management, personalized AI interactions, or location-based services). If you choose not to provide certain data, you may still use some functionalities of the App, subject to their availability.
US ADDENDUM
If you reside in California, Virginia, Colorado, Connecticut, Utah, Oregon, Texas, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Kentucky, Tennessee, Indiana, or any other state with an applicable comprehensive privacy law, please refer to this US Addendum.
We address this US Addendum to U.S. residents only. This Addendum does not reflect our collection and processing of U.S. residents’ personal information where an exception under U.S. privacy laws applies. In the event of any discrepancies between the main Privacy Policy and this US Addendum, the provisions of this Addendum shall prevail for U.S. residents.
VIRGINIA, COLORADO, CONNECTICUT, UTAH, OREGON, TEXAS, MONTANA, DELAWARE, IOWA, NEBRASKA, NEW HAMPSHIRE, NEW JERSEY, MINNESOTA, MARYLAND, KENTUCKY, TENNESSEE, AND INDIANA
The following provisions are addressed specifically to residents of Virginia, Colorado, Connecticut, Utah, Oregon, Texas, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Kentucky, Tennessee, and Indiana.
Subject to the conditions and limitations under applicable state laws, you have the following rights with respect to your personal data:
-
Right to Confirm and Access: You have the right to confirm whether your personal data is being processed and, if so, to access your personal data and obtain a copy of it in a portable format.
-
Right to Correct: You have the right to correct inaccuracies in your personal data, considering the nature of the data and the purposes for which it is processed. Please note this right is not available in Iowa and Utah.
-
Right to Delete: You have the right to delete personal data provided by you or collected about you, subject to certain exceptions (such as legal compliance, security, and fraud prevention).
-
Right to Opt-Out: You have the right to opt out of the processing of your personal data for: (i) targeted advertising, (ii) the sale of personal data, or (iii) profiling used to make decisions that have legal or similarly significant effects on you.
-
Right to Data Portability: You have the right to obtain a copy of your personal data in a portable, usable format that allows you to transmit it to another entity.
-
Right to Appeal: If we deny your request to exercise any of these rights, you have the right to appeal our decision. To appeal, please contact us by email with the subject line “Privacy Rights Appeal.”
We do not sell your personal data, engage in targeted advertising as defined under these state laws, or engage in profiling that produces legal or similarly significant effects concerning you. To exercise any of these rights, please contact us at feedback@chance.vision with the subject line “State Privacy Request — [Your State].”
CALIFORNIA
The following provisions apply to residents of California under the California Consumer Privacy Act (“CCPA”) as amended.
Notice of Collection
We collect the following categories of personal information as defined by the CCPA: identifiers (email address, account name), internet/electronic network activity information (usage data, interaction patterns), geolocation data (precise latitude/longitude), commercial information (subscription and transaction records), and inferences drawn from the above. If you upload images or videos, they may contain additional personal information. We collect this information directly from you or automatically from your device, and use it for the purposes described in Section 2 of this Privacy Policy. We disclose this information to our service providers (AWS, OpenRouter, Google Gemini, Google Vertex AI, Google Analytics) for business purposes. We do not “sell” or “share” personal information for cross-context behavioral advertising.
Your California Privacy Rights
California residents have the following rights:
-
Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the sources of that information, the purposes of collection, and the categories of third parties with whom we have shared it.
-
Right to Correct: You may request correction of inaccurate personal information we hold about you.
-
Right to Delete: You may request deletion of your personal information, subject to certain exceptions under applicable law.
-
Right to Opt-Out: You have the right to opt out of the “sale” or “sharing” of your personal information. As we do not engage in these practices, no action is required on your part.
-
Right to Non-Discrimination: You will not receive discriminatory treatment for exercising any of your CCPA rights.
To exercise any of these rights, please email feedback@chance.vision with the subject line “California Request — [Request Type]” (e.g., “California Request — Know”). We will verify your identity using information associated with your account before responding. You may also designate an authorized agent to submit a request on your behalf by providing written authorization signed by you.
bottom of page


