Privacy Policy

Last Updated: February 13, 2026

This privacy policy is provided for informational purposes. We recommend consulting with a legal professional for specific advice regarding your situation.

Introduction

Welcome to Charisma ("Service"), operated by Engine Seven LLC ("Engine Seven," "we," "our," or "us"), a Wyoming limited liability company. We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and website (collectively, the "Service").

Information We Collect

We collect information that you provide directly to us and information that is collected automatically when you use our Service.

Account Information

  • Email address (required for account creation and waitlist)
  • Name (optional, for personalization)
  • Profile preferences and settings

Usage Information

  • Features you use and actions you take within the app
  • Conversation analysis data (processed locally or with encryption)
  • App interaction patterns and preferences

Device Information

  • Device type, operating system, and version
  • Unique device identifiers
  • IP address and general location (country/region level)

Third-Party Data in Screenshots

When you upload screenshots of conversations for AI analysis, these may contain messages from your contacts. Regarding this third-party data:

  • We process it ONLY to generate conversation suggestions for you
  • We do NOT create profiles of your contacts
  • We do NOT store contact data beyond the session lifecycle
  • We do NOT share contact data with any third parties
  • We do NOT use contact messages for AI model training
  • Contact data is automatically deleted when you delete a session or your account

How We Use Your Information

We use the information we collect for the following purposes:

  • To provide, maintain, and improve our Service
  • To personalize your experience and deliver relevant suggestions
  • To communicate with you about updates, features, and support
  • To analyze usage patterns and optimize app performance
  • To protect against fraud, abuse, and unauthorized access

Legal Basis for Processing (GDPR)

If you are in the European Economic Area (EEA), we process your personal data based on the following legal grounds:

  • Consent: You have given us permission to process your data for specific purposes, such as marketing communications.
  • Contract: Processing is necessary to provide you with our Service and fulfill our agreement with you.
  • Legitimate Interests: Processing is necessary for our legitimate business interests, such as improving our Service and preventing fraud.

How We Share Your Information

We may share your information with the following types of third parties:

  • Analytics Providers: Google Analytics to understand how users interact with our Service (anonymized data).
  • Cloud Hosting: Cloudflare R2 for media storage and Vercel for application hosting. Your data is stored on servers located in the United States.
  • Payment Processors: Stripe or Apple/Google for processing payments (we never store your payment card details).

We do not sell your personal information to third parties. We do not share your conversation data with advertisers.

Data Retention

We retain your personal information for as long as necessary to provide our Service and fulfill the purposes described in this policy:

  • Account data: Retained while your account is active, plus 30 days after deletion request
  • Usage logs: Retained for up to 90 days for analytics and debugging
  • Payment records: Retained for 7 years as required by law

Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Right to Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure: Request deletion of your personal data ("right to be forgotten").
  • Right to Data Portability: Request your data in a structured, machine-readable format.
  • Right to Withdraw Consent: Withdraw your consent at any time where we rely on consent for processing.

To exercise any of these rights, please contact us at the email address provided below.

Cookies and Tracking

We use cookies and similar tracking technologies to collect information about your browsing activities. You can control cookie preferences through our cookie consent banner.

  • Necessary Cookies: Required for the website to function properly.
  • Analytics Cookies: Help us understand how visitors use our website.
  • Marketing Cookies: Used for advertising and measuring campaign effectiveness.

Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. This includes encryption of data in transit (TLS/SSL) and at rest, regular security assessments, and access controls. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

International Data Transfers

Your data is stored on servers located in the United States, operated by Cloudflare R2. For users in the European Economic Area (EEA) and United Kingdom, data transfers are conducted under Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring GDPR-compliant protection of your personal data.

California Privacy Rights (CCPA)

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: You can request information about the categories and specific pieces of personal information we have collected about you.
  • Right to Delete: You can request deletion of your personal information, subject to certain exceptions.
  • Right to Opt-Out: You can opt-out of the sale of your personal information. Note: We do not sell personal information.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.

In the past 12 months, we have collected the following categories of personal information: identifiers (email, device ID), internet activity (usage data, app interactions), and geolocation data (country/region level).

To exercise your CCPA rights, email us at privacy@charismaai.app or use the in-app account deletion feature.

UK Privacy Rights (UK GDPR)

If you are a resident of the United Kingdom, you have rights under the UK General Data Protection Regulation (UK GDPR):

You have the same rights as EU residents, including the right to access, rectify, erase, restrict processing, data portability, and object to processing of your personal data.

You have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection:

  • Website: ico.org.uk
  • Phone: 0303 123 1113

Before lodging a complaint, we encourage you to contact us first at privacy@charismaai.app so we can try to resolve your concerns.

EU Privacy Rights (GDPR)

If you are a resident of the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):

You have the right to lodge a complaint with your local data protection supervisory authority if you believe we have violated your privacy rights. A list of EU supervisory authorities is available at: ec.europa.eu/justice/data-protection/bodies/authorities/

For privacy-related inquiries, you may contact us at privacy@charismaai.app. We will respond to your request within 30 days as required by GDPR.

We process your data based on: (1) your consent, (2) performance of a contract with you, (3) compliance with legal obligations, or (4) our legitimate interests that do not override your rights.

Canadian Privacy Rights (PIPEDA)

If you are a resident of Canada, you have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA):

  • Right to Access: You can request access to your personal information held by us and information about how it has been used and disclosed.
  • Right to Accuracy: You can request correction of any inaccurate or incomplete personal information.
  • Right to Withdraw Consent: You can withdraw your consent for the collection, use, or disclosure of your personal information, subject to legal or contractual restrictions.

You have the right to file a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca if you believe your privacy rights have been violated.

To exercise your PIPEDA rights, contact us at privacy@charismaai.app.

Australian Privacy Rights (Privacy Act)

If you are a resident of Australia, you have rights under the Privacy Act 1988 and the Australian Privacy Principles (APPs):

  • Right to Access: You can request access to the personal information we hold about you.
  • Right to Correction: You can request correction of personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading.
  • Right to Anonymity: Where practicable, you have the option of not identifying yourself or using a pseudonym when dealing with us.

You have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au if you believe we have breached your privacy.

To exercise your rights under Australian privacy law, contact us at privacy@charismaai.app. We will respond within 30 days.

Children's Privacy

Our Service is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately and we will take steps to delete such information.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last Updated" date. We encourage you to review this policy periodically.

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Email: privacy@charismaai.app