Privacy Policy
Last updated: July 27, 2026
The short version: Your data is yours. We collect only what we need to make Chora work for you. We never sell your personal information to anyone — ever. We use it solely to deliver a better experience and improve our service.
1. Who We Are
Chora ("we", "us", "our") is an ambient intelligence service operated by withChora. We can be reached at hello@withchora.com.
2. What We Collect
We collect only the information needed to run the service:
- Account information: Your email address, used to communicate with you and manage your account.
- Profile & preferences: Information you provide to personalize your experience (e.g. household, language, timezone, goals). Used exclusively to tailor the service to you.
- Interaction signals: How you respond to suggestions (accept, swap, ignore) — used to refine future recommendations. This is how Chora learns over time.
- Billing information: Processed securely by Stripe. We never store your card details.
- Phone number (optional): If you connect WhatsApp, we collect your phone number to deliver suggestions on that channel. You can disconnect it at any time from your settings.
- Calendar events (optional): If you connect a calendar (Google Calendar or an ICS link), we access event times and titles solely to adapt meal suggestions to your schedule — for example, a faster meal on a busy evening.
- Grocery receipts (optional): If you scan a receipt, we process the store name, items, and totals to update your pantry and budget tracking.
- Usage analytics: Anonymized data about how the app is used, collected only with your explicit cookie consent.
3. How We Use Your Information
Your information is used strictly to operate and improve Chora:
- Generate and deliver personalized suggestions tailored to your profile
- Learn from your interactions to improve future recommendations
- Manage your subscription and process payments
- Send transactional emails (account updates, subscription notices, important alerts)
- Improve the service through aggregated, anonymized usage analysis
4. We Never Sell Your Data
We do not sell, rent, trade, or share your personal information with third parties for marketing or commercial purposes. Your preferences, profile, and interaction history belong to you. They exist solely to make Chora work better for you — nothing else.
5. Third-Party Services
We use a small number of trusted third-party services to operate Chora. Each processes only the data strictly necessary for their function. These providers may store and process data in the United States and Canada:
- Supabase — Authentication and database hosting. Stores your account, preferences, and interaction history.
- Stripe — Payment processing. Handles all billing data in a PCI-DSS compliant environment. We never store card details.
- Resend — Transactional email delivery. Receives your email address solely to deliver communications from Chora.
- Twilio — WhatsApp message delivery. Receives your phone number and message content only if you connect the WhatsApp channel.
- Google Calendar API — Only if you choose to connect Google Calendar, we access your events (read-only) to adapt suggestions to your schedule. Chora's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- AI model providers — Used to generate personalized suggestions and to parse receipts you choose to scan. Requests include only the data needed for the task (preferences, pantry items, or the receipt contents) — never your name, email, or account identifiers.
- Google Analytics — Usage analytics, loaded only after you accept cookies. Data is anonymized and used solely to understand how the app is used in aggregate.
6. Cookies
Chora uses cookies solely for authentication (keeping you logged in) and, with your explicit consent, for anonymized usage analytics. We do not use advertising cookies or tracking pixels. You can withdraw your consent at any time via the cookie banner.
7. Data Retention
We retain your data for as long as your account is active. If you delete your account, we permanently delete your personal data within 30 days. Anonymized, aggregated data may be retained indefinitely as it cannot be linked back to you.
8. Your Rights (GDPR)
If you are located in the European Economic Area, you have the following rights regarding your personal data:
- Right to Access: Request a copy of all personal data we hold about you.
- Right to Rectification: Correct inaccurate or incomplete data via your account settings.
- Right to Erasure: Delete your account and all associated personal data permanently.
- Right to Portability: Export your data in a machine-readable format.
- Right to Object: Object to processing based on legitimate interests.
To exercise any of these rights, contact us at hello@withchora.com. We will respond within 30 days.
9. US State Privacy Rights
Depending on your state of residence (including California, Colorado, Connecticut, Texas, Utah, Virginia, and others), you may have the right to: know and access the personal information we hold about you; correct inaccurate information; delete your personal information; obtain a portable copy; and opt out of the sale or sharing of personal information and of targeted advertising.
Chora does not sell your personal information and does not share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes that would require a right to limit. We will never discriminate against you for exercising your rights.
To exercise any of these rights, email hello@withchora.com. We will verify your request using the email associated with your account and respond within 45 days. You may use an authorized agent, and if we decline a request, you may appeal by replying to our decision.
10. Canada — PIPEDA & Quebec Law 25
withChora is based in Quebec, Canada. We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec's Act respecting the protection of personal information in the private sector (Law 25). The person in charge of the protection of personal information can be reached at hello@withchora.com. You have the right to access and rectify your personal information and to withdraw your consent. You may also file a complaint with the Commission d'accès à l'information du Québec (CAI) or the Office of the Privacy Commissioner of Canada (OPC). Your data may be stored and processed outside your province or country — including in the United States — by the service providers listed above.
11. Children's Privacy
Chora is not directed to children. You must be at least 16 years old to create an account, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact hello@withchora.com and we will delete it.
12. Security
We use industry-standard security measures: encrypted connections (HTTPS/TLS), secure authentication, and strict access controls. No payment data is stored on our servers — Stripe handles all financial data in a PCI-DSS compliant environment.
13. Changes to This Policy
If we make material changes to this policy, we will notify you by email before they take effect. Continued use of Chora after that date constitutes acceptance of the updated policy.
14. Contact
Questions about this policy? We are happy to help. hello@withchora.com