Privacy Policy

Last updated: July 2026

Summary

This policy explains what information ChatOSS collects, how we use it, and the choices you have.

ChatOSS runs locally by default — we never see your prompts or data when you use models already in Ollama. When you use cloud-hosted models, your prompts and responses are processed transiently to serve the request and are never used to train models. We collect basic account information and limited usage metadata that doesn't include prompt or response content. We don't sell your data, and you can delete your account at any time.

1. Introduction

McCarty Ventures, Inc., d/b/a ChatOSS ("ChatOSS," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, desktop app, and related services (the "Service"). Disputes related to this Privacy Policy are subject to the dispute resolution and governing law provisions in our Terms of Service. If you do not agree with any part of this policy, please discontinue use of the Service.

2. How ChatOSS Works

ChatOSS is a desktop app that talks to the models you already run in Ollama. When you use a local model, everything — your prompts, responses, and files — stays on your machine. We do not collect, store, transmit, or have any access to that content, and no account is required to use local models.

When you choose to run a cloud-hosted model on a paid plan, your prompt and the model's response are processed transiently through our infrastructure to fulfill the request and are not retained beyond what's needed to do so. We do not use your inputs or outputs to train any AI models, and we don't request prompt or response content in support conversations. If you voluntarily include it in a support request, we use it only to resolve your issue.

3. Information We Collect

Information you provide to us

We collect information you give us directly, such as when you create an account, subscribe to a plan, or contact us for support. This can include:

  • Account information (name, email address, password, or the profile info shared by GitHub or Google when you sign in with those providers)
  • Payment information, processed by Stripe
  • Communications with us, such as support requests

Information collected automatically

We automatically collect limited technical and usage information needed to operate, secure, and bill for the Service. This does not include the content of your prompts or model responses. It can include:

  • Usage metadata such as request counts, model selected, and timestamps, used for billing and plan limits
  • Short-lived desktop login codes used to link the desktop app to your account
  • Device, browser, and IP address information
  • Cookies used for essential site functionality

Analytics

We use our own privacy-friendly, first-party analytics (not Google Analytics or any third-party tracker) to understand how the website and desktop app are used. This records events such as page views, install-command copies, downloads, sign-ups, sign-ins, and desktop-app opens. Anonymous visitors are identified only by a random ID stored in a first-party cookie (to count unique visitors) and a per-tab session ID (to count visits); the desktop app uses a random, per-device ID. These IDs are not tied to your identity unless you sign in, and we never record the content of your prompts or model responses. We use this information solely to improve the Service and do not sell it or use it for advertising.

4. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Create and manage your account and subscription
  • Process payments and prevent fraud
  • Respond to support requests
  • Maintain security and enforce our Terms of Service
  • Improve the Service and develop new features

We process this information based on the need to perform our contract with you, our legitimate business interests, your consent where applicable, and to comply with legal obligations.

5. Information Sharing

We do not sell your personal information. We share information only in these circumstances:

  • With service providers who help us operate — for example, Stripe for payments, Supabase for account and database infrastructure, and our model-inference providers for cloud model requests
  • When you give us specific consent to do so
  • When required by law, legal process, or to protect our rights and the safety of our users

Information may be processed in the United States or other countries where our service providers operate. Where required by law, we use appropriate safeguards for these transfers.

6. Data Retention

We keep your information for as long as your account is active or as needed to provide the Service, and as required by law for things like billing records. You can request deletion of your account and associated data at any time by contacting us or from your account settings.

Once we no longer have a legitimate need to retain your information, we delete or de-identify it, or securely isolate it until deletion is possible.

7. Data Security

We use commercially reasonable technical and organizational measures to protect your information, including encryption in transit. No method of transmission or storage is completely secure, so we can't guarantee absolute security — please use the Service in a secure environment.

8. Your Rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Delete your personal information
  • Object to or restrict certain processing
  • Request a copy of your data (portability)
  • Withdraw consent where processing relies on it

California residents: under the CCPA/CPRA, you have the right to know, access, correct, and delete your personal information, and to opt out of the sale or sharing of personal information. We do not sell or share your personal information for cross-context behavioral advertising.

EU/UK residents: under the GDPR, you have additional rights, including the right to lodge a complaint with your local supervisory authority.

To exercise any of these rights, contact us at the email below. We may need to verify your identity before acting on your request.

9. Children's Privacy

The Service is intended for users aged 18 and older. We do not knowingly collect personal information from anyone under 13. If you are between 13 and 18, you may use the Service only with the consent of a parent or guardian. If we learn we've collected information from a child in violation of this policy, we will delete it promptly.

10. Data Breach Notification

If we become aware of a security incident that results in unauthorized access to, or disclosure of, personal information, we will investigate promptly and notify affected users and, where required, the applicable supervisory authority without undue delay — and no later than 72 hours after we become aware of it, unless the incident is unlikely to result in a risk to your rights and freedoms.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We'll reflect material changes by updating the "Last updated" date above and, where appropriate, providing additional notice. Continued use of the Service after changes take effect means you accept the revised policy.

12. Contact Us

McCarty Ventures, Inc. is the data controller of this Privacy Policy. If you have questions or want to exercise your rights, contact us at support@chatoss.ai.