Privacy

Plain-language privacy boundaries of Chargineer's V1 planning tool. These are not a legal contract, and nothing here is legal advice.

What is processed

Your project inputs (the prompt, source files such as documents, images, and PDFs, and the input file you add) are processed to build the planning package: extracted facts, the Studio topology, BOM and reviewed private prices, compliance guidance, and next actions. Reviewed private prices are owner-only and never enter public or shared surfaces.

Who can see what

  • Owner only: full Project data is accessible only to the signed-in owner (database row-level security). Signed-out previews create nothing and keep nothing: no Project exists until you sign in and create one.
  • Sharing recipients: when you publish a project, recipients open a read-only preview of the latest saved version, an allowlisted subset without private prices, input files, prompts, or chat content. Recipients have no export.
  • Public catalogue and compliance: public surfaces serve only published, allowlisted registry and rule data, never project, price, or personal data.

Retention and deletion

A temporary project expires 24 hours after creation unless it is claimed; access becomes unavailable immediately at expiry or lost-session, and physical cleanup runs on a scheduled sweep. Claimed projects persist until you delete them: deletion hides the project at once, revokes every share link, and keeps a seven-day recoverable window before physical purge. Deletion removes data from the application database and storage; provider-managed backups may retain copies for their own retention periods. The deletion and cleanup policies are documented in docs/project-02/.

Chat and files

The raw Assistant transcript lives only in your browser session and is never logged or persisted server-side. Chat files stay ephemeral until an applied, grounded proposal explicitly promotes them into the project's inputFile store; promoted inputFile survives a session Undo and is removed only through a separate destructive removal with confirmation.

Export privacy

  • Exported files contain only what you selected for that export.
  • People you share with see a preview of the saved version and cannot export.

Providers and data placement

  • Database and storage: Supabase in the EU; project data is private and row-level secured.
  • AI processing: OpenRouter (Zero Data Retention; data-collection deny) - input is sent for the requested generation only and is not persisted or collected by the provider.
  • Job orchestration: Trigger.dev in the EU (eu-central-1); task payloads carry opaque job and project ids only, never source content or private data.
  • Transactional email: sent from the auth.chargineer.com subdomain via Resend with the sending region set to Ireland (eu-west-1). Resend stores account metadata, logs, and API records in the United States regardless of the sending region.
  • TED discovery: the EU Tenders Electronic Daily search API is called without an account; only a small lot index is cached.
  • Analytics: optional product analytics run on an EU allowlisted endpoint and never include private project content, email bodies, prompts, or chat text; analytics are disabled locally.

Preliminary planning only. Not certification, legal advice, or a guarantee.