🔒 Privacy & Sacred Trust

Privacy Policy

Last Updated: August 31, 2026

🌸 Our Core Privacy Promise

At MyChingu, we believe that emotional journaling, mood tracking, and self-care reflection require unconditional trust and the highest security standards. We operate from France in strict compliance with the European General Data Protection Regulation (GDPR / RGPD) and international privacy laws. We do not sell your personal data, and your private conversations with Chingu AI are never used to train public foundation models.

1. Data Controller & Scope

This Privacy Policy explains how MyChingu ("we", "us", or "our"), operated from France, collects, processes, stores, and protects personal data when you access or use our mobile applications, web companion, software, and related online services (collectively, the "Service").

For the purposes of the General Data Protection Regulation (Regulation (EU) 2016/679 - "GDPR" / "RGPD"), the Data Controller responsible for your personal data is the operator of MyChingu in France, reachable at contact@mychingu.com.

2. Lawful Bases for Processing (GDPR / RGPD Article 6)

We process your personal information only when we have a valid legal basis under applicable European and international law:

  • Performance of a Contract (Art. 6(1)(b) GDPR): Providing core app functionalities, generating emotional analytics, executing cloud data synchronization, and managing active subscription access.
  • Legitimate Interests (Art. 6(1)(f) GDPR): Safeguarding our systems against fraud and security breaches, monitoring app stability and performance, troubleshooting crashes, and maintaining operational integrity.
  • Consent (Art. 6(1)(a) GDPR): Processing optional conversational turns with Chingu AI, sending opt-in push notifications and habit reminders, and processing voluntary profile personalization details.
  • Compliance with Legal Obligations (Art. 6(1)(c) GDPR): Maintaining financial audit records and complying with mandatory statutory requirements.

3. Information We Collect

We adhere strictly to the principle of data minimization, collecting only the information necessary to provide our services:

  • Account & Profile Information: Email address, display name, encrypted authentication credentials, and optional demographic preferences (such as birth date and gender) provided voluntarily during onboarding or profile editing. If you choose Guest Mode, you may use core offline features without creating an account.
  • Journal Entries & Wellness Logs: Daily mood ratings, mascot selections, self-care routine tags (e.g., hydration, study, sleep), text reflections, diary entries, and user-attached photos.
  • Chingu AI Conversational Data: Prompts, questions, and conversational exchanges you transmit to Chingu AI, processed solely to provide real-time, empathetic, and culturally rich contextual responses.
  • Idol Reminders & Calendar Data: Custom reminders, birthdays, and calendar events configured in your personal schedule.
  • Device Identifiers & Technical Diagnostics: Anonymized crash reports, operating system versions, device models, performance telemetry, push notification tokens, and mobile advertising identifiers necessary for system operation and ad delivery.
  • Subscription & Purchase Metadata: Subscription status, product tier, and transaction verification identifiers processed through authorized app stores. We do not store or process your raw credit card numbers.

4. How We Use Your Information

Your information is used strictly for the following purposes:

  • Delivering, maintaining, and enhancing your personalized mood tracking and journaling experience.
  • Enabling Chingu AI to provide supportive, conversational companion reflections.
  • Generating emotional trend statistics, streak milestones, and wellness calendars.
  • Delivering local and cloud-based push notifications, alarms, and schedule reminders that you configure.
  • Verifying subscription entitlements and preventing fraud or abuse of quotas.
  • Diagnosing technical glitches, crashes, and server errors to optimize app performance.

5. Chingu AI & Conversational Confidentiality

Chingu AI is built with privacy-by-design at its core:

  • All AI interactions are transmitted through end-to-end encrypted HTTPS/TLS channels to our secure backend processing engine.
  • Your private journal entries and personal chat logs are never sold, rented, leased, or monetized to any third parties.
  • User reflections and private inputs are strictly never used to train public generative AI foundation models.
  • AI responses are generated dynamically and ephemeral chat context is managed securely in accordance with strict retention policies.

6. Third-Party Service Providers & International Transfers

To deliver a seamless, world-class mobile application, we partner with specialized, vetted infrastructure providers across the following categories:

  • Cloud Database & Authentication Infrastructure: Secure, encrypted server architectures for account authentication, document storage, and cloud synchronization.
  • Payment & App Store Platforms: Official app distribution channels (Apple App Store, Google Play Store) and subscription infrastructure partners for purchase verification.
  • Analytics, Diagnostics & Crash Reporting: Privacy-compliant telemetry tools to track aggregated stability metrics and resolve technical defects.
  • Mobile Advertising Partners: Authorized advertising networks serving privacy-compliant banner and interstitial ads for free-tier users.

Where data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are implemented in compliance with Chapter V of the GDPR (including Standard Contractual Clauses approved by the European Commission and data processing agreements).

7. Data Storage, Security & Encryption

We implement robust organizational, technical, and physical security measures to protect your personal data against unauthorized access, destruction, loss, or alteration:

  • All network communications between the mobile application and our servers are encrypted using modern Transport Layer Security (TLS/HTTPS).
  • Local sensitive tokens and biometric settings are stored in encrypted device keystores.
  • Cloud databases utilize industry-standard encryption at rest (AES-256) with strict role-based access controls.

8. Account Deletion & Data Retention Policy

We believe in giving you complete control over your digital footprint:

  • Self-Service In-App Deletion: You can initiate the immediate deletion of your account and data directly within the app at any time by navigating to Settings → Security & Data → Delete Account.
  • Deletion via Support Request: You may also request account and data deletion by sending an email from your registered address to contact@mychingu.com.
  • Immediate Production Purge: Upon confirming account deletion, your user profile, journal reflections, mood records, photos, and idol reminders are immediately removed and permanently disconnected from live production environments.
  • 90-Day Security & Audit Retention: For legitimate security, anti-abuse, fraud prevention, and dispute resolution purposes, isolated system logs and encrypted database backup snapshots may be retained in secure, access-restricted archives for a maximum duration of up to 90 days following deletion, after which they are automatically and irreversibly overwritten and destroyed.

9. Your Global Rights (GDPR / RGPD, CCPA/CPRA & International)

Under European data protection law (GDPR / RGPD Articles 15 to 22) and applicable global regulations, you are entitled to exercise the following rights free of charge:

  • Right of Access (Art. 15): Request a copy of the personal data we hold about you.
  • Right to Rectification (Art. 16): Correct inaccurate or incomplete information.
  • Right to Erasure / Right to be Forgotten (Art. 17): Request the permanent deletion of your personal data.
  • Right to Restriction of Processing (Art. 18): Request temporary limits on how we process your information.
  • Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, and machine-readable format.
  • Right to Object (Art. 21): Object to the processing of your data based on our legitimate interests.
  • Right to Withdraw Consent (Art. 7(3)): Withdraw your consent at any time where processing is based on consent.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with the competent European supervisory authority. In France, this is the Commission Nationale de l'Informatique et des Libertés (CNIL) (www.cnil.fr).

To exercise any of these rights, simply email us at contact@mychingu.com. We respond to all verified requests within thirty (30) days in accordance with statutory requirements.

10. Children's Privacy

MyChingu is not directed to children under the age of 13 (or under 16 in certain jurisdictions within the European Union). We do not knowingly collect personal data from children below these age thresholds. If we discover that a minor under the minimum legal age has registered without verifiable parental consent, we will take immediate steps to delete the associated account and data. If you believe a child has provided us with personal information, please contact us immediately at contact@mychingu.com.

11. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect modifications in our operational practices, new features, or evolving legal frameworks. When updates occur, we will revise the "Last Updated" date at the top of this page. For significant modifications, we may provide prominent in-app notices or notify you via email prior to the changes taking effect.

12. Contact Our Privacy Team

If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact our privacy representative directly at:

✉️ Official Legal & Privacy Contact: contact@mychingu.com