Chorus Privacy Policy
Effective date: August 18, 2026
This version discloses the one-way opening-grant fingerprint that survives account deletion and why we retain it.
This policy explains what Chatb2b LLC, a Delaware limited liability company (“Chorus,” “we”), collects when you use chorusb2b.com and the Chorus service, how it is processed, and what your choices are. We have tried to write it in plain language, and to only describe what the product actually does.
1. Data We Collect
Account data (you provide it at signup):
- Work email address (required; personal email domains are blocked at signup)
- Password. Stored by our sign-in service (Supabase Auth), not as a hash on Chorus. We never store or see your plaintext password.
- If you sign in with Google: your verified work email, from Google’s basic profile scope. We do not receive your Google password, and we do not store a Google account ID.
Service credentials (we generate them):
- A personal connection token that authenticates your AI assistant to your Chorus account. It is shown to you in your dashboard; keep it secret.
- A signed session cookie when you sign in (see §7, Cookies).
Purchase data (when you buy a pack):
- We send Stripe your work email and a purchase record: which pack you chose, and our internal account and checkout-attempt identifiers. Stripe processes the payment on its own checkout page, and also collects whatever you enter there (card details and any billing details Stripe asks for).
- We store the pack, the amount paid, Stripe’s checkout id, and a link to Stripe’s receipt. We never receive or store your card number.
Study content (you or your connected AI assistant provide it):
- Personas you define: name, free-text profile, firmographic markers (company size, industry, role, seniority, budget authority, plus any extra markers you add), and optional pain points and objections
- The marketing messages (“stimuli”) and questions you test
- Study plans and plan documents your assistant writes
- Study results: aggregated statistics and samples of the simulated open-text responses
Note: personas are fictional profiles you write for simulation. Do not put real individuals’ personal data into personas or study content. See the Terms, §8.
Operational data (collected automatically per study run):
- Which account ran the study, when, and through what path (e.g. which assistant integration), including the submitting client’s User-Agent string and the submitter’s email or bot identity
- Run event records (counts and status, not raw response text)
Error and log data:
- Server logs and error reports (via an error-monitoring service) so we can fix failures. Server logs are configured to strip secrets: passwords, tokens, cookies, and authorization headers are redacted before a line is written. Error reports exclude cookies and credentials, and the service that handles your connection link additionally scrubs anything token-shaped from every event before it leaves our servers.
- Two of our three backend services also send a small sample (about 10%) of performance timing data (request paths and durations, not study content) to the error-monitoring service.
2. Data We Do NOT Collect
- No card numbers on Chorus. Card details are entered on Stripe’s checkout page. We never receive or store them.
- No analytics or tracking scripts. Our pages contain no third-party analytics, ad pixels, session recorders, or fingerprinting. The only script on the signed-in dashboard is first-party UI code (copy-to-clipboard and similar) that makes no network calls.
- One third-party page resource: Google Fonts. Our pages load two font families from Google Fonts, which means your browser sends your IP address and browser details to Google when a page loads. Google states these requests set no cookies and are not used for advertising.
- No advertising use. We do not sell personal data and do not share it for advertising.
- Two standing first-party cookies, both functional (§7). A brief code-verifier cookie is set only during Google sign-in, then cleared.
3. How Study Content Is Processed, Including Third-Party AI Providers
Chorus’s simulated respondents are powered by third-party AI model providers. When you run a study, parts of your study content leave our infrastructure and are sent to these providers to generate and score responses:
- What is sent: your persona definitions (name, profile, firmographic markers, pains, objections) and the marketing message and question text, verbatim.
- What is not sent: your account email, password, or connection token are not part of study prompts.
Current provider categories and vendors:
| Purpose | Provider(s) |
|---|---|
| Response generation (simulated respondents) | Moonshot AI (current default); OpenAI (supported alternative) |
| Embeddings (scoring the open-text responses) | OpenAI |
All provider API keys are ours and server-managed. Your content is sent under our accounts, not yours. We will update this list before adding providers.
Stripe is our payment processor. It does not receive study content. What it receives is described in §1 and §4.
Product improvement: We may use your study content and usage information to operate and improve the product. Examples include debugging failures, improving scoring quality, and making the service work better. What we never do is share your messaging, study designs, or survey results with any third party for that party’s own use: no selling, no advertising use, no disclosure to other customers. Sending study content to the providers above is not sharing in that sense. They process it on our behalf, under our instructions, solely to deliver the service (see §4 and §5).
4. Storage and Hosting
- Application hosting: Railway (cloud platform)
- Database: Neon (managed Postgres). Holds account records and study data
- Sign-in service: Supabase Auth (credentials, reset and confirmation email, Google sign-in)
- Workspace study-plan files: stored on service disk within our hosting environment
- Error monitoring: Sentry
- Payment processing: Stripe. Receives your work email and the purchase record (which pack, our account and checkout-attempt identifiers). Card details stay with Stripe.
These vendors are processors acting on our instructions.
5. Sharing
We share personal data only with:
- the processors listed in §3 and §4, to run the service;
- authorities, when legally compelled (we will notify you unless prohibited);
- a successor entity in a merger, acquisition, or asset sale (this policy would continue to apply or you would be notified of changes).
That is the whole list. No data brokers, no advertisers, no selling.
6. Retention
Honest current state: except for private content mode (below), we keep data until you ask us to remove it.
- Study data, plans, and account records are retained indefinitely by default; there is currently no automatic expiry.
- Private content mode: if you turn it on, we delete our copy of that study’s messages, questions, audience descriptions, responses, and results within 24 hours after the study finishes. We keep only content-free records — that a study ran, when, its status, and how many respondents it used. Failed private studies are deleted on the same sweep.
- Session cookies last until you sign out, reset your password, we revoke the session, or you close the browser.
- On account closure: you can delete the account yourself from the Data tab of your account page (or email us and we will do it after we verify you control the account). Deletion takes effect immediately. We delete your studies, plans, results, personas, connection token, and sign-in. Purchase and ledger records survive with the link to you removed — tax and accounting law requires us to keep a record of money that changed hands; those rows no longer name you. Anything else a law requires us to keep also remains.
We keep one additional record after account closure: an opening-grant email hash, which is a one-way fingerprint of the work email that claimed the free grant. We use it only to prevent repeat free grants. The fingerprint survives account deletion and cannot be reversed into the email address.
7. Cookies
We set these first-party cookies:
| Cookie | Purpose | Lifetime |
|---|---|---|
sb-<project>-auth-token (chunked as .0, .1 when the value exceeds 4KB) |
Keeps you signed in (httpOnly, set by the sign-in service) | Until you sign out, reset your password, we revoke the session, or you close the browser |
chorus_last_method |
Remembers whether this browser last used Google or a password, so the door can hint. Not a credential. | 180 days |
During Google sign-in we briefly set a first-party code-verifier cookie, then clear it. When you buy a pack you leave our site for Stripe’s checkout page, which uses Stripe’s own cookies. No advertising, analytics, or third-party cookies on Chorus pages. (The Google Fonts requests described in §2 set no cookies.)
8. Security
- Passwords are stored by our sign-in service, not as hashes on Chorus. Google sign-in never gives us your password.
- Session cookies are httpOnly and marked secure in production.
- Secrets (passwords, tokens, cookies, auth headers) are redacted from server logs; error reports exclude cookies and credentials (§1 describes exactly what the error-monitoring service receives).
- Your connection token is high-entropy and is deliberately never returned in signup/sign-in responses; it is shown only in your dashboard. Treat it as a secret. It appears in your personal connection link, so don’t share that link.
No system is perfectly secure; we cannot guarantee absolute security.
9. Security Incident Notification
If we discover a security breach affecting your personal data, we will notify affected accounts by email without undue delay after confirming the incident, describe what was affected, and say what we are doing about it, in addition to any notification the law requires.
10. Your Rights and Choices
- Access / export: ask us and we will provide a copy of your account data and study history. You can also download a copy from your account page. Your dashboard shows recent studies, and your connected assistant can list and read your studies at any time.
- Correction: ask us to fix inaccurate account data.
- Deletion: delete the account from the Data tab of your account page, or email us and we will close it. Effect is immediate. See §6 for what is removed and what survives.
- Token rotation: reset the connection link from your dashboard; the old link stops working immediately. You can also contact us and we will replace it.
Requests go to james@chatb2b.com. We will verify you control the account email before acting. Depending on where you live (e.g. EEA/UK GDPR, California CPRA), you may have additional statutory rights; we will honor valid requests under applicable law.
11. Children
Chorus is not for anyone under 18, and we do not knowingly collect data from minors. If you believe a minor has an account, contact us and we will delete it.
12. Changes to This Policy
We may update this policy. For material changes we will notify you (email or in-product notice) before they take effect. The effective date at the top always reflects the current version.
13. Contact
Privacy questions and requests: james@chatb2b.com · Chatb2b LLC