Privacy Policy
Last Updated: February 12, 2026
1. Introduction
Chameleon Labs, LLC ("we," "our," or "us") respects your privacy and is committed to protecting your personal data. This privacy policy explains how we handle your data when you use our website and products.
2. Information We Collect
We may collect the following types of information:
- Contact information (name, email address, company name)
- Account credentials (encrypted password hash)
- Communications with us through contact forms or email
- Usage data and analytics about how you interact with our products
- Technical data (IP address, browser type, device information)
- Product-specific data as described in Section 3
3. Product-Specific Data Handling
🛡️ RealtyShield
- Documents: Real estate contracts you upload are processed for compliance analysis
- Retention: Uploaded documents are automatically deleted after 30 days
- Early deletion: You can request immediate deletion at any time
- Compliance logs: Compensation logs and audit trails are retained for your records
📦 QuickStock
- Inventory data: Item names, descriptions, quantities, and categories you create
- Images: Product photos are stored securely in AWS S3
- Retention: Data is retained while your account is active
- Deletion: You can delete individual items or request full account deletion
❤️ HealthCheck
- Assessment data: Your health assessment responses and results
- AI conversations: Chat history with AI assistants (if you use premium features)
- Privacy: Health data is never shared with third parties
- Deletion: You can delete your assessment history at any time
💬 Maestro AI
- Conversations: Messages you send and AI responses you receive
- Model selection: Which AI models you choose (OpenAI, Anthropic, Google)
- Retention by tier:
- Free (not signed in): Not saved
- Free (signed in): Last 7 days
- Pro/Enterprise: Unlimited until you delete
- Third-party processing: Conversations are sent to AI providers (OpenAI, Anthropic, Google) for processing. These providers do not use your data for training.
- Deletion controls: You can delete individual conversations or all history at any time from your dashboard
- No training: Your conversations are never used to train our models or improve third-party AI
4. AI and Machine Learning
We do not use your data to train AI models.
Your documents, inventory data, and health information are processed solely to provide you with our services. We use third-party AI providers (such as OpenAI) for analysis, but your data is not used to train or improve their models.
5. How We Use Your Information
We use your information to:
- Provide and improve our products and services
- Respond to your inquiries and provide customer support
- Send product updates and announcements (with your consent)
- Analyze usage patterns to improve user experience
- Comply with legal obligations
6. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, we process your personal data on the following legal bases under the General Data Protection Regulation (GDPR):
- Contract performance: Processing necessary to provide our Services to you (e.g., account management, subscription billing, delivering product features).
- Legitimate interests: Processing for our legitimate business interests, such as improving our Services, preventing fraud, and ensuring security, where those interests are not overridden by your rights.
- Consent: Processing based on your explicit consent, such as sending marketing communications or setting non-essential cookies. You may withdraw consent at any time.
- Legal obligation: Processing necessary to comply with applicable laws and regulations.
7. Cookies and Tracking Technologies
We use cookies and similar technologies to operate our Services, remember your preferences, and understand how you use our products. For full details, including what cookies we use and how to manage them, please see our Cookie Policy.
You can control cookies through your browser settings. Note that disabling certain cookies may affect the functionality of our Services.
8. Data Sharing and Disclosure
We do not sell your personal data. We may share your information with:
- Service providers: AWS (hosting), Stripe (payments), AI providers (analysis)
- Legal requirements: When required by law or to protect our rights
All service providers are bound by confidentiality agreements and data processing terms.
9. Data Security
We implement industry-standard security measures to protect your data. For details about our security practices, including encryption, password handling, and infrastructure, please see our Security page.
10. International Data Transfers
Our Services are hosted on Amazon Web Services (AWS) infrastructure located in the United States. If you are accessing our Services from outside the United States, please be aware that your data will be transferred to, stored, and processed in the United States.
For users in the EEA, UK, or Switzerland, we rely on appropriate safeguards for international data transfers, including Standard Contractual Clauses (SCCs) approved by the European Commission where applicable. By using our Services, you consent to the transfer of your information to the United States as described in this policy.
11. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required by law.
- Account data: Retained while your account is active and for 30 days after deletion request
- RealtyShield documents: Automatically deleted after 30 days
- Maestro AI conversations: Varies by tier (see Section 3)
- Payment records: Retained as required by tax and financial regulations (typically 7 years)
- Support communications: Retained for up to 2 years after resolution
- Analytics data: Aggregated and anonymized within 90 days
12. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your data ("right to be forgotten")
- Portability: Request your data in a portable, machine-readable format
- Restriction: Request that we limit the processing of your data
- Objection: Object to processing based on legitimate interests or for direct marketing
- Withdraw consent: Where processing is based on consent, withdraw it at any time
- Opt-out: Unsubscribe from marketing communications
To exercise any of these rights, contact us at privacy@chameleonlabs.ai. We will respond within 30 days (or sooner if required by applicable law).
Right to lodge a complaint: If you are in the EEA or UK, you have the right to lodge a complaint with your local data protection supervisory authority if you believe we have not adequately addressed your concerns.
13. Data Deletion Requests
To request deletion of your data, please contact us at privacy@chameleonlabs.ai or through our contact page. We will process your request within 30 days.
14. Children's Privacy
Our Services are not directed to individuals under the age of 16 (or under 13 in the United States). We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate consent, we will take steps to delete that information promptly. If you believe we may have collected data from a child, please contact us at privacy@chameleonlabs.ai.
15. Contact Us
If you have questions about this privacy policy or our data practices, please contact us through our contact page, email us at privacy@chameleonlabs.ai, or join our Discord community.