1. Controller (data controller)
Chroma-Codex is operated by Roberto Pizziol — chroma-codex@proton.me. You can contact us at chroma-codex@proton.me.
The service is not intended for users under 16 years of age.
2. Personal data we collect
We collect and process personal data only to provide the service. In particular, we may collect:
- Email address (for account management and sign-in).
- Username.
- Display name.
- Avatar image (profile thumbnail).
- Pattern content you create or upload, including text and images.
If you sign up with Google or Discord OAuth, or later connect a Google or Discord account from Settings, we also receive the relevant identity/profile information they provide during the OAuth flow.
3. How we use your data (purposes) and legal basis
- Provide and operate Chroma-Codex (including creating accounts, authenticating users, storing and displaying your patterns). Legal basis: GDPR Art. 6(1)(b) (contract / pre-contract steps).
- Security, abuse prevention, and maintenance of the service. Legal basis: GDPR Art. 6(1)(f) (legitimate interests).
- Respond to requests and manage user accounts (including support and account-related communications). Legal basis: GDPR Art. 6(1)(b) and/or Art. 6(1)(f).
Where processing is based on consent (if applicable), you can withdraw it at any time.
4. Recipients of personal data (third parties)
We share personal data with the following categories of third parties:
- Supabase (database, authentication, and storage). Privacy policy: https://supabase.com/privacy
- Netlify (hosting). Privacy policy: https://www.netlify.com/privacy/
- Resend (Resend Inc.) — delivery of transactional authentication emails (signup confirmation, password reset). Data processed: the user's email address and the content of those emails. Privacy policy: https://resend.com/legal/privacy-policy
- Anthropic PBC — processing of pattern content you submit via the “Import with AI” feature, for the purpose of interpreting and structuring that content. Privacy policy: https://www.anthropic.com/legal/privacy
- Google and Discord (OAuth sign-in).
5. International data transfers (extra-EEA/UK)
- Personal data is stored (database, authentication, storage) on Supabase infrastructure in the EU region (eu-west-3, Paris).
- Transactional authentication emails are sent via Resend infrastructure in the EU region (eu-west-1, Ireland). This data remains within the EEA, so no extra-EEA transfer applies for that processing.
- Server-side request processing (Netlify Functions/Server Actions) runs on Netlify infrastructure located in the United States (US East region, Ohio). This involves a transfer of personal data to the USA during request processing.
- This transfer relies on Netlify's certification to the EU-U.S. Data Privacy Framework (and its UK extension), a mechanism recognized by the European Commission as providing an adequate level of protection for data transfers to the USA. More information: https://www.dataprivacyframework.gov/s and https://www.netlify.com/gdpr-ccpa/.
- When you use the “Import with AI” feature, the pattern content you submit is sent to Anthropic PBC for processing. This involves a transfer of personal data to the USA. This transfer relies on Standard Contractual Clauses (SCCs) incorporated into Anthropic's data processing terms, a mechanism recognized under GDPR Art. 46 for transfers to countries without an adequacy decision.
- Static hosting (public assets, pages) relies on a global CDN for content delivery.
- Should the EU-US Data Privacy Framework be invalidated or amended, Chroma-Codex will adopt alternative transfer mechanisms provided for under applicable law (e.g. Standard Contractual Clauses) and will update this notice accordingly.
6. Cookies and tracking technologies
At the moment, we do not use third-party tracking/analytics services and do not deploy third-party tracking cookies. We use only the following technical cookies:
- Supabase authentication session cookies — strictly necessary to keep you signed in and to protect your account session.
7. Payments
No payments are currently processed in Chroma-Codex. In the future, if we add paid features, we will update this notice accordingly.
8. Data retention
We keep your personal data only as long as necessary for the purposes described above, including for operating your account and providing the service. In general:
- Your account information and your pattern content are stored while your account is active.
- After a deletion request, account data and pattern content are deleted within 30 days.
- Residual backup copies may persist for up to a maximum of 90 days, after which they are removed in accordance with our service providers’ processes.
For more details on how service providers handle backups, see Supabase’s privacy documentation.
9. Your rights (GDPR)
Under applicable data protection law, you may have the following rights:
- Access to your personal data.
- Rectification of inaccurate or incomplete data.
- Erasure (deletion) of your personal data. You can delete your own account at any time via account settings. Account deletion removes your personal data and account information directly, separate from any additional retention needed for backups as described in the Data retention section.
- Portability of certain data you provided to us.
- Objection to processing based on legitimate interests (where applicable).
- Restriction of processing (where applicable).
You can exercise these rights by contacting the controller at chroma-codex@proton.me. We may ask you to verify your identity before responding.
You also have the right to lodge a complaint with a competent data protection authority. The relevant authority for Chroma-Codex is the Italian Garante per la Protezione dei Dati Personali. Users in other EU countries retain the right to lodge a complaint with the supervisory authority of their own country of residence.
10. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page.