Privacy Policy
Effective 7 August 2026
Chalk is a real-time collaboration platform operated by Q9 Labs ("we", "us"). This policy explains what personal data Chalk collects, why, and what your rights are. It covers the Chalk web app at chalkmeet.com, the Chalk mobile app, and the APIs behind them.
What we collect
Account data. When you create an account we store your name, email address, and either a hash of your password or, if you sign in with Google, the identity Google returns to us (your Google account ID, verified email, and name). We never see or store your Google password. We also store your tenant memberships and roles.
Sign-in and security data. When you sign in we record your IP address, browser user agent, and device name against that sign-in, and we keep the same details for API keys. We use this to secure your account, to let you review and revoke active sign-ins, and to rate-limit abusive traffic.
Spaces, Episodes, and participation. Chalk stores the Spaces you create (names, settings, admission rules), the Episodes that run in them (timing and configuration), and participant records for each Episode: display name, role, capabilities, and join and leave times.
Chat and files. Messages you send in an Episode are stored with your display name and timestamps. Files you attach are stored as private objects with their filename, type, and size, and expire on a schedule.
Audio and video. Your microphone, camera, and screen-share streams are processed in real time to deliver them to other participants. We do not store media streams unless recording is turned on for the Episode, and the product shows when that is the case.
Recordings and transcripts. Where recording or transcription is enabled, we store the recording files, transcript text, and processing metadata as private objects. Temporary audio chunks used for transcription are deleted automatically within 24 hours.
Integrations and webhooks. If your tenant connects an external integration or configures webhooks, we store the connection metadata and deliver event payloads to the endpoints your tenant chose. Webhook target URLs, signing secrets, and payloads are encrypted at rest.
Operational data. We keep audit logs of administrative actions, structured request logs, and bounded diagnostic events (route, outcome, duration, trace IDs). We use these to run and secure the service, and we do not use them for advertising.
Cookies
Chalk uses only functional cookies. We do not use advertising or cross-site tracking cookies.
| Cookie | Purpose | Lifetime |
|---|---|---|
__Host-chalk_account | Keeps you signed in (HttpOnly, Secure) | Until you close your browser |
__Host-chalk_csrf | Protects against cross-site request forgery | Until you close your browser |
__Host-chalk_oauth_return | Returns you to the right page after Google sign-in | 10 minutes |
__Host-chalk_space_guest_{arrival_handle} | Keeps your public Space arrival available in this browser (HttpOnly, Secure) | Until you leave or close your browser |
Who processes your data
We use a small set of infrastructure providers, each bound by a data processing agreement:
- Cloudflare hosts the web app, routes API traffic, carries real-time audio and video (Realtime SFU), and stores files, recordings, and transcripts (R2). Cloudflare Workers AI performs speech-to-text when transcription is enabled.
- Google processes your sign-in only if you choose "Continue with Google".
- Amazon Web Services runs the transcription pipeline (job scheduling and secret storage) when transcription is enabled.
- DeepInfra may perform speech-to-text as an alternative provider when transcription is enabled.
- DigitalOcean runs recording workers when recording is enabled.
- Composio processes integration connections if your tenant enables integrations.
We do not sell personal data, and we do not share it with anyone else except when the law requires it.
Legal bases
We process account, sign-in, and content data to perform our contract with you. We process security and operational data in our legitimate interest of keeping the service safe and reliable. Where we rely on consent (for example, a recorded Episode), you can withdraw it going forward at any time.
Recording notice
The person who runs an Episode controls recording and transcription. Chalk shows participants when an Episode is being recorded. If you record, you are responsible for having the agreement of your participants under the laws that apply to you.
Retention and deletion
We keep your data while your account or tenant is active. Chat attachments and temporary transcription files expire automatically. To delete your account or specific content, contact us at the address below and we will delete or anonymize the data within 30 days. Copies can persist in encrypted backups for a limited period after deletion before they are overwritten.
Your rights
If you are in the EEA, the UK, or a similar jurisdiction, you have the right to access, correct, export, and delete your personal data, to object to or restrict certain processing, and to complain to a supervisory authority (in Norway, Datatilsynet). Write to us at the address below and we will respond within the legal deadline.
International transfers
Our providers operate globally, so your data can be processed outside your country. Where data leaves the EEA we rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
Children
Chalk is not directed at children under 16, and we do not knowingly collect their data.
Changes
If we change this policy in a way that matters, we will announce it in the product before the change takes effect. The effective date above always reflects the current version.
Contact
Q9 Labs — privacy@chalkmeet.com