Overview
This Privacy Policy applies to Chaviar's website, app, onboarding flows, browser-capture tools, generation workers, dashboards, and related services. Chaviar is a product of Oglofus Ltd, a company registered in England and Wales (company no. 14840351) with its registered office at 25 Easten Terrace, Wallsend, NE28 0JW. "Chaviar", "we", "us", and "our" refer to Oglofus Ltd, the data controller for the Chaviar service. "You" means the person or organization using Chaviar.
Chaviar is built for business users who want to generate, review, schedule, and publish brand content. Because the product learns from your brand materials, we may process information about your account, your brand, your website or app, connected social channels, generated content, and the technical data needed to run the service.
We do not sell personal information. We also do not share personal information for cross-context behavioral advertising. If that changes, we will update this policy and provide any required choices.
Information we collect
Account and workspace information
We collect information you provide when creating or using an account, including your name, email address, organization or brand membership, authentication data, account settings, and communication preferences.
Brand, website, and content information
We collect the brand names, website URLs, app URLs, crawl URLs, brand profile details, colors, logos, fonts, tone, audience notes, positioning, screenshots, product information, gallery images, uploads, captions, prompts, generated posts, generated stories, generated images, email drafts, ad creative drafts, review decisions, schedule settings, and publishing metadata you create or authorize us to collect.
Browser-capture information
If you choose to connect a login-walled site, Chaviar gives you a controlled remote browser so you can log in yourself. We do not ask for or store your password. After you confirm that you are logged in, we may capture the resulting browser session state, such as cookies and local storage, so our crawler can take the screenshots needed to build your brand catalog.
Connected integration information
If you connect third-party services, we collect the information needed to operate those integrations. For example, Meta connections may include access tokens, scopes, connected Page or Instagram Business account identifiers, display names, handles, token expiry details, and deauthorization status. Stripe billing may provide customer, subscription, checkout, invoice, and payment-status metadata. Google sign-in, Resend email delivery, Backblaze B2 storage, and AI model providers may process information as needed to provide their parts of the service.
Usage, device, and log information
We collect standard technical information such as IP address, user agent, device and browser characteristics, session data, app events, job status, crawl logs, generation cost records, error logs, security events, and timestamps. We also use cookies and local storage for authentication, brand selection, app state, and service reliability.
How we use information
We use the information we collect to:
- Provide, maintain, secure, and improve Chaviar.
- Create accounts, authenticate users, send one-time sign-in codes, and manage sessions.
- Scan authorized websites and apps, capture screenshots, and build brand catalogs.
- Generate, render, store, display, review, schedule, and publish brand content.
- Operate connected integrations such as billing, storage, email delivery, and social platforms.
- Apply usage limits, plan allowances, cost ceilings, abuse controls, and security controls.
- Respond to support, privacy, security, billing, and legal requests.
- Detect, investigate, and prevent fraud, spam, abuse, security incidents, and policy violations.
- Comply with legal obligations and enforce our Terms of Service.
Where laws such as UK or EU data protection law apply, we rely on the legal bases of contract, legitimate interests, consent where required, and legal obligations, depending on the context.
AI processing
Chaviar uses AI models to analyze screenshots, summarize brand context, generate captions, draft prompts, render images, and produce content variants. Inputs to those systems may include your brand profile, prompts, screenshots, product data, gallery images, generated drafts, review signals, and other context needed to provide the requested output.
We may process this information through model providers such as OpenAI, Anthropic, and Google/Gemini, depending on the feature and configuration. You are responsible for making sure you have the rights and permissions needed to submit brand materials, website content, screenshots, images, prompts, and other inputs to Chaviar for processing.
Browser sessions and connected accounts
When you use the login handoff, you drive the browser yourself. Chaviar does not receive your password. After you confirm capture, we encrypt the captured browser session and use it only to complete the authorized scan for that brand.
Captured browser sessions are designed to be short-lived. The current service stores them with an approximately two-hour expiry and deletes them after the full crawl consumes them, when you cancel or reset the connection, or when they are no longer needed for the authorized scan.
If you connect Meta, Threads, or another publishing provider, you can disconnect the integration in the app where available, or remove Chaviar from your account in the provider's own settings. Disconnecting or deauthorizing revokes the stored access token and stops Chaviar from using the connection for future publishing.
Deleting your connected-account data. If you remove Chaviar from Meta or Threads using the provider's data-deletion option — or ask us directly at [email protected] — Chaviar automatically deletes the data we derived from that account: stored access tokens, the connected profile, any of your posts or captions we learned from, the voice and style we distilled from them, fetched photos, and inbound comment data. When a provider sends us a deletion request, we complete it immediately and return a status page where you can confirm it with the request's confirmation code. For LinkedIn and Mailchimp, which do not send automated deletion requests, we delete connected-account data on disconnect or on request in the same way.
Retention and deletion
We keep information for as long as needed to provide Chaviar, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support legitimate business needs.
- Account, organization, and billing records are kept while your account is active and as legally required.
- Brand profiles, generated content, screenshots, and assets are kept until you delete them or your account is closed, unless retention is required.
- Captured browser sessions are short-lived and are not intended to be kept as durable account records.
- Logs, backups, and security records may persist for a limited period after deletion from the live app.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, export, restrict, object to, or opt out of certain processing of your personal information. California residents may have rights to know, delete, correct, opt out of sale or sharing, limit certain sensitive personal information uses, and not be discriminated against for exercising privacy rights.
You can update many account, brand, and integration settings directly in Chaviar. To make a privacy request, email [email protected]. We may need to verify your identity and authority before acting on a request.
You can also choose not to provide certain information, but some features may not work without it. For example, Chaviar cannot scan a login-walled site without an authorized session, and it cannot publish to a social account you have not connected.
Security
We use technical and organizational measures designed to protect information, including encrypted captured browser sessions, short-lived signed asset URLs, private asset storage, scoped account access, and worker-only session decryption controls. No system is perfectly secure, and we cannot guarantee that information will never be accessed, disclosed, altered, or destroyed.
International processing
Chaviar and its providers may process information in countries other than where you live or where your organization is located. Those countries may have data protection laws that differ from your local laws. Where required, we use appropriate safeguards for cross-border transfers.
Children
Chaviar is a business service and is not intended for children. You must be at least 18 years old, or the age of majority where you live, to use Chaviar.
Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice as required by law, such as by posting the updated policy in the app or sending an account notice.
Contact
For privacy questions, rights requests, or connected-account deletion requests, contact [email protected].