Skip to main content

Legal

Privacy Policy

Last updated: June 3, 2026  ·  Effective date: March 1, 2026

Charigent ("Charigent," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and your rights in relation to it. This policy applies to all users of the Charigent platform at charigent.com and related services.

The data controller responsible for your personal information is Ninefold Ventures LLC, a limited liability company doing business as Charigent. Where this policy says "we," "us," or "Charigent," it refers to that entity. You can reach us about any privacy matter at [email protected].

1. Information We Collect

Account information. When you register, we collect your email address and a hashed version of your password. If you provide a display name or profile picture, those are stored as well.

Usage data. We collect information about how you interact with the Service, including feature usage, AI model selections, credit consumption, and timestamps. This is used to operate the platform, enforce plan limits, and improve the product.

Payment information. Payment processing is handled entirely by Stripe. We do not store your card number, CVC, or full payment details. We receive from Stripe a customer ID and subscription status. Stripe's privacy practices are governed by the Stripe Privacy Policy.

Content you create. Text prompts, images you upload, documents added to Charigent knowledge bases, and AI-generated outputs are stored to provide the Service and are accessible only to you (and your team members, if applicable).

Technical data. We collect IP addresses, browser type, and device information for security purposes (e.g., detecting suspicious login activity) and aggregate analytics. We do not use this data for advertising profiling.

2. How We Use Your Information

  • To create and manage your account and authenticate you.
  • To provide, maintain, and improve the Service.
  • To process payments and manage your subscription via Stripe.
  • To enforce credit limits, plan quotas, and rate limits.
  • To send you transactional emails (receipts, password resets, security alerts). Marketing emails are optional and require your consent; you may unsubscribe at any time.
  • To produce aggregate, anonymised analytics that help us understand how features are used and where to invest in improvements.
  • To detect, investigate, and prevent fraudulent or abusive activity.

3. BYOK API Keys

If you use the Bring Your Own Key (BYOK) feature to connect your own AI provider API keys (OpenAI, Anthropic, Google, etc.), those keys are protected at rest by our credential-encryption layer and stored in our database. They are not intended to be logged in plaintext or shared with third parties beyond being passed to the respective AI provider to execute your requests, and can be deleted by you at any time from Settings > Integrations.

4. AI Provider Data Sharing

When you use AI features (chat, image generation, content writing, etc.), your prompts and relevant context are transmitted to the relevant AI provider (Google, OpenAI, or Anthropic) to generate a response. This is inherent to how generative AI works.

We select AI providers that offer data processing agreements (DPAs) suitable for commercial use and that do not train on API customer data by default. However, you should review the privacy policies of those providers independently:

We recommend avoiding including sensitive personal information (e.g., medical records, financial account details) in prompts sent to AI models.

5. Connected Platforms, OAuth, and API Access

If you connect third-party platforms to Charigent, we collect and store the minimum account and token data needed to provide the requested integration. Depending on the integration, this can include provider account IDs, access and refresh tokens, workspace or page identifiers, calendar metadata, publishing destinations, and connection status.

This applies to integrations such as Google Sign-In, Google Calendar, Meta, LinkedIn, TikTok, Slack, Discord, WordPress, and similar connected platforms. We use this information only to authenticate you, perform the actions you request, maintain the connection, and troubleshoot integration issues.

The use and transfer of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. See our Google API Limited Use Disclosure for additional detail.

We do not sell connected-platform data. We remove stored connection data when you disconnect the integration or delete your account, subject to any limited retention required for security, billing, or audit purposes.

5a. SMS, Voice, and Telephony Consent

Charigent supports SMS, voice, AI assistant, and workflow messaging features. When you or a connected customer uses those features, we may process mobile phone numbers, message content, message metadata, call metadata, call recordings or transcripts when enabled, opt-in and opt-out events, delivery status, and related workflow records.

Charigent SMS messages may include AI assistant replies, customer-care conversations, support follow-ups, reminders, workflow alerts, account notifications, and approved outreach messages where the sender has documented recipient consent. Message frequency varies based on account activity, active workflows, recipient interactions, and the settings selected by the account owner. Message and data rates may apply.

SMS consent and mobile phone numbers are not sold, rented, shared, or disclosed to third parties or affiliates for their marketing or promotional purposes. We share mobile numbers and message data only with service providers that are needed to operate the requested SMS or voice service, such as Telnyx or Twilio, and only for delivery, routing, compliance, security, billing, support, and troubleshooting.

Recipients can reply STOP to opt out of future SMS messages from a Charigent-connected number. Recipients can reply HELP for help or contact [email protected]. Account owners are responsible for ensuring that recipients have given valid consent before activating outbound, outreach, or bulk SMS workflows.

5b. Other Service Providers and Subprocessors

In addition to the AI providers (Section 4), payment processor (Stripe, Section 1), and connected platforms (Section 5), Charigent uses the following infrastructure, analytics, and communications subprocessors to operate the service. Each receives only the minimum data needed to perform its function.

  • AWS (Amazon Web Services) — transactional and drip email delivery via Amazon Simple Email Service (SES). We share recipient address, subject, and body content for emails you have opted to receive.
  • Sentry — application error tracking. We share error stack traces, request metadata (route, status), and a hashed user identifier so we can diagnose production issues. Personal data in error contexts is scrubbed before transmission.
  • Google Analytics 4 (GA4) — anonymized usage analytics, only after explicit cookie consent. We share page views, anonymized IP, and event metadata.
  • ElevenLabs — premium voice synthesis and voice cloning. We share text and (for cloning) audio samples you have explicitly uploaded.
  • Telnyx and Twilio — telephony providers for SMS and voice features. We share phone numbers, message contents, and call audio when you use those features.
  • LiveKit — WebRTC infrastructure for real-time voice sessions. We share session participant identifiers and transient audio streams.
  • Cloudflare — DNS, TLS, and DDoS-protection proxy in front of charigent.com. Cloudflare receives request metadata (URL, IP, user-agent) for routing and security purposes.
  • Hetzner Cloud — physical hosting provider for the application servers and database. All operational data (databases, files, logs) is physically located on Hetzner infrastructure.

We update this list when we add or remove a subprocessor. Customers on enterprise plans may review our Data Processing Agreement or request a customer-specific copy via [email protected].

6. Data Retention

Active accounts. We retain your data for as long as your account is active and for a reasonable period thereafter to comply with our legal obligations.

Deleted accounts. If you use Charigent's in-product account deletion flow, core account data is deleted or anonymised immediately after confirmation. If you request deletion manually because you cannot access the account, we target completion within 30 days after verification. Anonymised or aggregated data derived from your usage may be retained indefinitely as it cannot be used to identify you. Transaction records may be retained for up to 7 years to comply with financial regulations. Voice-abuse safety signals (used to detect abusive usage patterns) are similarly stripped of your account link and any IP address on deletion and are then kept, pseudonymously, for up to 12 months so we can still detect a repeat abuser who re-registers, after which they are automatically deleted.

Backups. Deleted data may persist in access-restricted backups for up to 90 days before being overwritten.

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access. Request a copy of the personal data we hold about you.
  • Rectification. Correct inaccurate or incomplete data.
  • Deletion. Request that we delete your personal data ("right to be forgotten").
  • Portability or export. Request eligible personal data in a machine-readable format, subject to applicable law, identity verification, and technical availability.
  • Restriction. Ask us to restrict the processing of your data in certain circumstances.
  • Objection. Object to processing based on our legitimate interests.

To exercise any of these rights, contact us at [email protected]. We will verify the request and respond within the timeframe required by applicable law. You may also have the right to lodge a complaint with your local data protection authority (e.g., the ICO in the UK, CNIL in France).

8. Cookies

We use strictly necessary cookies to operate the Service and, only after consent where required, limited analytics cookies:

  • Session cookies — to keep you authenticated between page loads.
  • Preference cookies — to remember UI settings such as sidebar state and colour mode.
  • Analytics cookies — to measure product usage after you opt in through the cookie banner.

We do not use third-party advertising cookies. Analytics cookies are optional and controlled through the consent banner.

For more detail about consent choices and cookie categories, see our Cookie Policy.

9. Your Privacy Choices

Charigent does not sell personal information for money and does not use third-party advertising cookies for cross-context behavioural advertising. We also do not share personal information with data brokers.

You can still control optional tracking and preference technologies through the cookie banner, by choosing essential cookies only, or by contacting [email protected] if you want help exercising privacy choices available in your jurisdiction.

10. Children's Privacy

The Service is not directed at children under the age of 18. We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected such data, we will delete it promptly. If you believe a child under 18 has provided us with personal information, please contact us at [email protected].

11. International Data Transfers

Charigent operates in the United States. If you access the Service from outside the US, your data will be transferred to and processed in the US. Where required, we use an applicable transfer mechanism, which may include European Commission standard contractual clauses.

12. Security Measures

We take data security seriously and implement the following measures:

  • Credential encryption for supported stored API keys and connection secrets.
  • TLS/HTTPS for supported production traffic in transit.
  • Rate limiting and abuse controls on API endpoints.
  • Dependency review and security checks as part of release and maintenance work.
  • Access controls limiting employee access to personal data on a need-to-know basis.

No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. In the event of a data breach that affects your rights, we will notify you and relevant authorities as required by law.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email or a prominent notice within the platform at least 14 days before the changes take effect. The "Last updated" date at the top of this page will always reflect the most recent revision.

14. Contact

For privacy-related questions, requests, or concerns, please contact us at:

Charigent Privacy

[email protected]

[email protected]

PO Box 843
Las Vegas, NV 89124