Privacy
Privacy Policy
Effective 27 July 2026
1. Who runs this
Chong (the “Service”) is operated by Yves Boutellier, an individual sole proprietor based in Switzerland. For the purposes of Swiss FADP and EU GDPR, Yves Boutellier is the data controller.
Questions, requests, or complaints: yves.thibaut.boutellier@gmail.com.
2. What this policy covers
This policy applies to the Chong web app (chong.today), the iOS app of the same name, and any related services we operate. It does not cover third-party websites or services we link to or integrate with — those have their own policies.
3. What we collect
We collect only what the Service needs to work. In practice that means:
3.1 Account information
When you sign in with Google or Apple, we receive your email address and display name. We do not receive your password. We store a stable user identifier to link your account across sessions.
3.2 Content you create
The Service stores content you write into it, including:
- Daily journal entries and reflection responses.
- Projects you define and the “what you want” descriptions and avoid-lists attached to them.
- Tasks (titles, scheduled dates/times, locations, durations, status, notes).
- Tool outputs such as trap reflections, AI coach conversations, premortems, twin debates, bullshit detector entries.
- Onboarding answers (age, projects, stuck score, ranking, clarity assessment, action plans).
This content is private to your account by default. It is stored in our database with row-level isolation by user ID, and encrypted in transit (HTTPS/TLS) and at rest at the infrastructure level by our database provider. See 10. Security for how your content is protected and how it is used to power features.
3.3 Witness moments (limited sharing)
Chong has a witness feature where you can invite one person to act as an accountability partner for a specific project. When you accept a witness, the witness can see only the following five things about that project:
- The project title.
- A momentum signal (a coarse direction: gaining / holding / slipping).
- The current trap, if you have escalated one (one of five named patterns).
- The trap pattern across time, if escalations recur.
- Explicit pings you choose to send.
Witnesses cannotsee task names, sub-task names, notes, schedules, journal reflections, general tasks, or anything on your Today view. This boundary is enforced as a server-side data projection — your private content never crosses to the witness's client. You can revoke witness access at any time from the project screen, after which the witness loses all access to the project immediately.
3.4 AI features (Anthropic, LangWatch)
The Service uses Anthropic's Claude API to power AI-assisted features such as an onboarding clarity check and AI coaching that helps you prioritise, stay accountable, and make progress on your tasks. When you use such a feature, we send the content that feature needs to Anthropic's Claude API on your behalf. Depending on the feature, that may include project descriptions, task titles and details, your “what you want” answers, tool outputs, and reflection text — plus the specific inputs a given feature needs (for the clarity check: the focus project title, the stuck-duration label, your three “what you want” answers, and your self-rated clarity slider; for the conversational coach and planner that helps when you feel stuck or want to plan your day, the messages you type in that back-and-forth, so it can respond turn by turn — and, so it can propose scheduled tasks and habits, your list of projects and any tasks that are overdue). We send the minimum content each feature requires, and we never send your name or your payment credentials. Anthropic returns a result — for example a clarity score, an analysis, or a coaching suggestion — which we may store on your account.
AI coach memory.So the coach can be specific across sessions instead of starting cold each time, the Service keeps a private, evolving memory derived from your coach conversations — short notes about your goals, constraints, patterns, and what happened in a session. To build it, after a coaching session we send that session's messages to Anthropic's Claude API to summarise and update these notes; the notes are then stored on your account. This memory is used only to inform your own coach. It is never shown to an accountability partner (a partner only ever sees the limited project structure described in our witness feature — never your content), and it is not used for advertising. You can request an export or deletion of this memory at any time, and it is removed when you delete your account (see §8). This inference is governed by the same no-training terms as the rest of this section.
The onboarding clarity check runs before you create an account. If you use it while signed out, the inputs it needs (as listed above) are sent to Anthropic's Claude API the same way, tied to no account. We store nothing from your onboarding on our servers unless you finish sign-up; if you leave without creating an account, your answers stay on your device only. To prevent abuse, signed-out AI requests are rate-limited by IP address; the IP is used for that throttling and is not joined to any profile.
Anthropic processes this content only to generate the response— this is inference, not training. Anthropic's use of API inputs is governed by its commercial terms, which prohibit training on your inputs. We do not train, and do not permit our subprocessors to train, AI models on your content.
AI observability (LangWatch).So we can debug and improve the coach — understand why it gave a particular answer, proposed a particular change, or got something wrong — we send a record of each coach turn to LangWatch, our AI observability subprocessor. That record contains the same content the coach itself works with: the messages you type, the coach's reply, the project and task context we assembled for that turn, and the actions it proposed. Each record is linked to a conversation identifier rather than to your name or email address, and we never send your payment credentials. LangWatch stores this for our engineering use only — it is not used for advertising, is never shown to an accountability partner, and, as with Anthropic, is not used to train AI models.
3.5 Google Calendar integration (optional)
If you grant Calendar access, the Service creates a dedicated secondary calendar (“Chong”) in your Google account and holds a refresh token to create, update, and delete events only on that calendar. The access scope we request does not permit the Service to see or modify your primary calendar or any events it did not author. Calendar tokens are stored encrypted at rest.
Chong's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use this data for advertising, do not sell it, and do not share it with third parties except as required to operate the Service.
3.6 Subscription and payment data
Paid subscriptions on iOS are processed by Apple via StoreKit. Paid subscriptions on the web are processed by Stripe. We never see your card number or full payment credentials. We receive only an entitlement signal (is the subscription active, what tier, when it renews) via RevenueCat or directly from Apple/Stripe webhooks.
3.7 Device and diagnostic data
To keep the Service running we automatically collect limited technical data: IP address (for security and rate-limit purposes), user agent, app version, device model and OS version, crash reports, and timing of key requests. Crash and error reports are processed by Sentry. This data is retained for 30 days and is not used to build marketing profiles.
4. How we use what we collect
We use your data only to:
- Run the Service — sign you in, store your content, sync your calendar, deliver push notifications you opted into.
- Enforce the accountability rituals you opt into (closure gates, weekly quota, witness moments).
- Provide AI-assisted features — clarity checks, prioritisation, and accountability coaching — by sending, when you use them, the minimum necessary content to our AI subprocessor for inference (never for training; see 3.4), and by recording coach turns with our AI observability subprocessor so we can debug and improve the coach (see 3.4).
- Respond to your support requests.
- Detect, prevent, and address abuse, fraud, and security incidents.
- Comply with our legal obligations.
We do not sell your personal data. We do not use it for behavioural advertising. We do not train AI models on your journal content, and we do not allow our subprocessors to do so.
5. Legal bases (GDPR / FADP)
- Performance of a contract — to deliver the Service you signed up for, including the AI-assisted coaching, prioritisation, and accountability features that are core to how it works.
- Consent — for optional integrations and features (Google Calendar, push notifications, the onboarding AI clarity check).
- Legitimate interest — for security logging, fraud detection, and product quality monitoring (we balance this against your rights and use the minimum data necessary).
- Legal obligation — when responding to lawful requests.
6. Who we share with (subprocessors)
We use a small number of vetted infrastructure providers to operate the Service. Each one only receives the data it needs to perform its function.
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Web app hosting, edge compute, request logs; optional Blob storage for a downloadable copy of your AI coach memory. | USA / EU |
| Turso (libSQL) | Per-user database hosting. | EU / USA |
| Auth.js (NextAuth) | Authentication runtime — in-process, no third-party transfer. | — |
| OAuth sign-in; optional Calendar API access. | USA | |
| Apple | Sign in with Apple; StoreKit subscriptions on iOS; APNs push. | USA |
| Anthropic | AI features — clarity check, coaching, and prioritisation (Claude API). Inference only; no training on inputs. | USA |
| RevenueCat | Subscription entitlement state. | USA |
| Stripe | Web subscription billing (if applicable). | Ireland (EU customer-of-record) |
| Sentry | Crash and error reporting. | USA / EU |
| LangWatch | AI coach observability — a record of each coach turn (your messages, the coach's reply, the task context, and proposed actions) for debugging and improving the coach. No training on your content. | EU / USA |
We will update this list as the Service evolves. Material changes will be reflected here and, where required, notified to you.
7. International transfers
If you are in Switzerland or the European Economic Area, some of the subprocessors above are located in the United States. Such transfers are governed by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and equivalent mechanisms recognised under Swiss law, as adopted in our subprocessor agreements.
8. How long we keep your data
- Account content — kept for as long as your account is active.
- After account deletion — content is removed from the live database within 30 days. Any remaining backup copies age out per our database provider's standard retention window.
- Security logs and crash reports — 30 days.
- Billing records — kept for the period required by tax and accounting law (typically 10 years in Switzerland).
9. Your rights
You have the right to:
- Access the personal data we hold about you.
- Correct it if it is wrong or incomplete.
- Have it deleted (subject to legal retention obligations).
- Restrict or object to certain processing.
- Receive a copy in a portable format.
- Withdraw consent for optional features at any time.
- Lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC), or your local EU supervisory authority.
To exercise any of these rights, email yves.thibaut.boutellier@gmail.com or use the in-app account deletion control. We respond within 30 days. You can also revoke witness access from the project screen directly.
10. Security
All data is transmitted over HTTPS. Databases are encrypted at rest by the storage provider. OAuth refresh tokens are encrypted at the application layer. Access to production infrastructure is limited to the data controller and protected by multi-factor authentication.
What “encrypted at rest” means here. Storage-provider encryption protects against stolen disks or unauthorized physical access to the underlying hardware. It does not make your journal content opaque to the data controller or to authorized infrastructure access — the application needs to read your content to operate features such as the AI coach, the accountability rituals, and the witness wall. Only OAuth credentials (refresh / access / ID tokens) are additionally encrypted at the application layer, so they remain unreadable even to operators inspecting raw database rows.
No system is perfectly secure. If we become aware of a breach that affects your personal data, we will notify you and the relevant supervisory authority within 72 hours, as required by GDPR Article 33 and FADP Article 24.
11. Children
The Service is not directed at children under 13. If you are under 16 and live in the EEA or the UK, you must have parental consent to use the Service. We do not knowingly collect data from children under these ages. If you believe we have, contact us and we will delete the data.
12. Changes to this policy
We may update this policy as the Service evolves. The “Effective” date at the top of this page reflects the most recent change. Material changes will be highlighted in-app or by email before they take effect.
13. Contact
Yves Boutellier · sole proprietor · Switzerland
yves.thibaut.boutellier@gmail.com
See also: Terms of Service