Share Chorus
These are the policies that apply to Chorus at sharechorus.com. Questions about them: support@sharechorus.com.

Privacy Policy

What Chorus collects, what it deliberately does not collect, and how accounts, conversations, AI usage, payments, files and diagnostics are handled.

Last updated: 18 September 2026.

1. Overview

This Privacy Policy explains how Chorus AI ("Chorus", "we") collects, uses, stores and protects information when you use the Chorus web app at sharechorus.com, the sign-up and billing flows, support, and related services. Chorus is a collaborative AI chat workspace: people share one conversation, choose among AI models, and work privately in side chats before merging findings back.

Chorus is designed to collect only what is needed to run the product, prove who you are, charge for what you use, prevent abuse, provide support, and keep the service reliable.

2. Information we collect

  • Account: name, email address, password hash (bcrypt, never the password itself), and the workspaces you belong to.
  • Accounts created with Google: if you choose "Continue with Google", we receive your name, email address and profile picture from Google, together with a confirmation that Google verified the address. See section 4.
  • Conversations and content: the messages you post, the AI replies, side chats, rolling summaries, pushed findings, and the files or images you attach. This is the substance of the product and is required to provide it.
  • AI usage records: for every model call, which model answered, the tokens involved, and the usage it consumed against your plan. This drives your remaining allowance, our accounting, and abuse prevention.
  • Payments: handled by Stripe. We store your Stripe customer, subscription and invoice identifiers, amounts, currency and payment status. We never see or store your full card number.
  • API keys you connect: stored encrypted with AES-256-GCM and never shown again after you save them.
  • Technical data: IP address, request metadata, and rate-limit counters, used for security and abuse prevention.
  • Diagnostics: error reports through Sentry, with request bodies and message content stripped before they leave our systems.
  • Support: whatever you send us when you ask for help, kept only for as long as needed to resolve the issue and keep a record.

3. Information we do not collect

  • We do not run advertising or third-party analytics trackers on the app or the website.
  • Signing in with Google does not give us access to your Gmail, Drive, Calendar, Contacts, or any other Google service. We receive only your name, email address and profile picture.
  • We never receive your full card number or bank details; card data goes directly to Stripe.
  • We do not use your conversations, files, or AI outputs to train models, and we do not sell personal data.
  • Chorus does not ask for or need access to your device's files, camera, microphone, contacts or location.

4. Signing in with Google

When you use "Continue with Google", Google confirms your identity and returns your name, email address, profile picture and whether it has verified the address. We use that to create or open your Chorus account, to confirm the address, and to keep the account secure. We do not request any Google scopes beyond basic profile and email. You can revoke Chorus's access at any time in your Google account's security settings, and you can keep using Chorus with an email and password instead.

5. Conversations, files and who can see them

  • Shared threads: everyone invited to a conversation can read and write in its main thread, and can see its context, its pushed findings and its attachments.
  • Side chats: a private side chat is visible only to the person who opened it, until they deliberately share a summary or the full transcript with the group.
  • Workspace owners and admins: can open the conversations inside their workspace and can see membership, billing and activity records.
  • Guests: join a single conversation through a share link, and see only what that conversation shares. A guest's own conversations stay in their own workspace.
  • Files: attachments and documents produced by the AI are stored with the conversation, in object storage operated by Cloudflare, and removed when the conversation or the account is deleted. A sweep also removes orphaned files that no longer belong to any conversation.

6. How we use information

We use information to provide the service and keep it working, to know who may access what, to measure and charge AI usage, to process subscriptions and top-ups, to prevent fraud and abuse, to answer support requests, to diagnose faults and improve reliability, to meet legal, tax and accounting obligations, and to enforce our Terms.

We may use aggregated or de-identified information (for example, the number of calls per model) to understand how the service performs. That information does not identify you or your conversations.

7. Legal bases

Where the GDPR applies, we rely on: performance of our contract with you (providing Chorus, managing your account and subscription); legitimate interests (securing the service, preventing abuse, improving reliability, and keeping business records); legal obligation (tax, accounting and lawful requests); and consent where we ask for it. You may withdraw consent at any time without affecting prior processing.

8. Who we share it with

  • Model providers: the content that a model needs in order to answer (your conversation up to that point, the files attached to it, and your prompt) is sent to the provider of the model chosen for that message, routed through OpenRouter, or directly to the provider when you use your own API key. Providers are asked not to train on this content; on Business and Enterprise plans, calls are routed only to providers that do not retain or train on data. Each provider's own terms also apply: Anthropic, OpenAI, Google, DeepSeek, xAI, Alibaba (Qwen), Mistral, Moonshot, Z.ai, Meta, Amazon, Cohere, NVIDIA, MiniMax, Perplexity, Inception and others reachable through OpenRouter.
  • Stripe: payments, subscriptions, invoices and fraud checks.
  • Cloudflare: object storage for conversation files, DNS, and network protection.
  • Railway (application hosting) and Neon (database): in the United States.
  • Resend: sending account emails (confirmation, password reset, invitations).
  • Sentry: error reports, with message content and personal details removed before they leave our systems.
  • Google: sign-in, when you choose "Continue with Google".
  • Authorities: when the law requires it, or to protect Chorus, its users or others.

If Chorus is ever involved in a merger, acquisition, financing or sale of assets, information may be transferred as part of that transaction; we would tell you before your data became subject to a different policy.

We do not sell personal data, and we do not share it for advertising.

9. Cookies

Chorus uses one essential cookie to keep you signed in, and short-lived cookies for sign-in security (the Google sign-in round trip and rate limiting). We do not use advertising cookies and we do not track you across other sites. Blocking the session cookie means you cannot sign in.

10. Data retention

  • Conversations, side chats and files: until you delete them, or 30 days after your account is closed.
  • Usage and payment records: 7 years, for tax, accounting and dispute purposes.
  • Security and rate-limit logs: 90 days.
  • Email tokens (confirmation, password reset, invitations): until used or expired.
  • Error reports: per our error-tracking provider's retention period, with content stripped.

Where a record is needed to prevent abuse, resolve a dispute, or comply with the law, it may be kept for longer than the windows above, but only for that purpose.

11. Security

Traffic is encrypted in transit with TLS. Passwords are stored as bcrypt hashes. Customer API keys are encrypted with AES-256-GCM using a deployment key held outside the database. Sessions store only a hash of the session token. Access to production systems is limited to what is needed to operate the service. No system is perfectly secure and we cannot promise that unauthorised access will never happen, but when an incident affects your data, we will tell you and the authorities as the law requires.

You are responsible for keeping your email account, password, Google account and devices secure, and for whom you invite to your conversations.

12. International transfers

Our providers process data in the United States and in Cloudflare's global network. Where required, transfers rely on the European Commission's standard contractual clauses or an equivalent safeguard. Model calls are made to providers that may process them in other countries, as described in section 8.

13. Your rights

Depending on where you live (under the GDPR in Europe, the LGPD in Brazil, the CCPA in California and comparable laws elsewhere), you may have the right to: know what we hold about you; get a copy of it; correct it; delete it; restrict or object to certain processing; receive it in a portable form; and withdraw consent where processing is based on consent.

  • Built in: workspace settings has "Download my data" (a full export, including the conversations you took part in) and "Delete my account", which cancels subscriptions and removes your data.
  • By email: write to privacy@sharechorus.com; we answer within 30 days. We may need to verify your identity first.
  • Complaints: you can complain to your local authority, in Brazil the ANPD, or in Europe your national data protection authority.
  • California: we do not sell or share personal information as those terms are defined by the CCPA, and we will not discriminate against you for exercising your rights.

14. Children

Chorus is not for children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has created an account, write to privacy@sharechorus.com and we will delete it.

15. Changes to this Policy

We may update this Policy as the product changes. The current version is always on this page with a new "Last updated" date, and for material changes we will email workspace owners before the change takes effect.

16. Contact

For privacy, legal, billing or support questions: privacy@sharechorus.com or support@sharechorus.com. Chorus AI is the controller of the personal data described here.