SIGNALIST · LEGAL
Privacy Policy
Effective date: July 24, 2026
This Policy explains which data Chanlyst receives, why it is needed and which controls are available to users.
1. Data we process
We may process account data (name and email), submitted product descriptions, selected prospects, drafted messages, integration settings, subscription information, support requests and security logs.
Connected-service tokens and keys are stored server-side in encrypted form when the required secure configuration is enabled. Saved secrets are never displayed back in the browser.
2. Purposes and legal bases
We use data to provide Chanlyst, perform requested integrations, support users, prevent abuse, apply plan limits and meet contractual or legal obligations.
We do not sell personal data or use project content for advertising profiles.
3. Service providers
The service may use Cloudflare for infrastructure and storage; OpenRouter and selected AI providers for analysis; Google/Gmail to send email from the mailbox you connect; and a Merchant of Record for payments and taxes. Telegram and LinkedIn hand-offs are manual and governed by those platforms.
Each provider receives only the information required for the requested function.
4. Retention
Account and project data is retained while the account remains active or as needed to operate the service. Support, consent and security records may be kept longer for legitimate compliance needs. Payment records are retained for legally required tax periods.
Following a verified deletion request, data is deleted or de-identified unless retention is legally required.
5. Your rights
Depending on your jurisdiction, you may request access, correction, export, restriction or deletion and may withdraw consent. Integrations can be disconnected in the interface or through support.
Submit requests through the Contact page. We may verify your identity before acting on a request.
6. Cookies and analytics
Chanlyst counts visits to public pages itself: no cookie, no third party, and nothing that identifies a person. There is no opt-out because there is nothing to opt out of — we do not know who you are.
Separately, behaviour on public pages is recorded through Microsoft Clarity: mouse movement, clicks and scrolling. Text you type is masked by Clarity. In the UK and Europe we ask first: the script does not load until you press Allow, and declining or ignoring the banner means no recording happens. Outside those regions recording starts without a banner. A refusal, once given, applies everywhere and is not asked again. Inside the workspace nothing is ever recorded.
The choice is stored in your browser localStorage and can be changed by clearing site data. Authentication, security and language use only strictly necessary technologies.
7. International processing and security
Providers may process data in other countries. We select providers with contractual and technical safeguards and use encryption in transit.
No system can guarantee absolute security. We will notify affected users and authorities of a material incident where legally required.
8. Contact
Privacy questions and data-subject requests can be submitted through the official Chanlyst contact form.