Privacy Policy

Last updated: July 20, 2026 · Effective immediately

CHYNJ Technologies ("CHYNJ", "we", "us") builds local-first software. This policy explains what data we collect, what we do with it, and what rights you have. The short version: we collect as little as possible, we never sell anything, and CHYNJ does not use your product content for marketing, analytics, model training, profiling, or resale.

1. Who we are

CHYNJ Technologies is a software company based in British Columbia, Canada. You can reach our privacy contact at [email protected].

2. The products this policy covers

3. What we collect — and don't

From our products (Kaptain, Konnect, Konvertex): Local product content stays on your device by default. Kaptain runs on your machine, Konnect stores captured leads locally unless you export them, and Konvertex scripts/audio stay on your laptop unless you choose an online rendering path. We do not receive telemetry, usage tracking, prompts, scans, leads, scripts, code, or generated files for CHYNJ marketing or profiling.

From optional online paths: Account sign-in, license validation, billing, downloads, support, transactional email, and trusted-device certification require limited account or device metadata. Konvertex online Microsoft voice rendering sends the selected script text to the online voice service for that rendering job only. User-directed exports or third-party integrations are controlled by you and governed by the provider you choose. Future sync, CRM, webhook, or similar product features will require explicit setup and should be documented before launch.

From subscribers and trial users (via Stripe): Payment itself is processed by Stripe — we never see or store your full card number, CVC, or PIN. What Stripe does forward to us, and what we therefore hold, is the minimum needed to provision and manage your subscription:

That's the account and license record we intend to keep centrally. Stripe holds the actual payment instrument and is the controller for it; their privacy practices govern that side. We are the controller for the email, license-key, and device-certification records described above.

From this website (chynj.ca): Two things, both privacy-respecting:

We do not run Google Analytics, Facebook Pixel, ad-tech, session-replay tools, or marketing cookies. The public site uses browser storage for preferences such as theme, privacy-notice dismissal, and Terms acceptance. When you sign in to the CHYNJ account or administration portal, the account API sets an opaque, host-only session cookie with HttpOnly, Secure, and SameSite=Strict. Page scripts cannot read that credential; CHYNJ stores only its SHA-256 hash and bounded session timestamps, and it expires after a limited period or sign-out. This is separate from Kaptain's local access credential and from Google or GitHub provider tokens.localStorage flag, not a cookie, not shared with anyone).

From you directly: If you email us, we keep the email so we can reply.

4. What we never do

5. Where your data lives

Kaptain stores project work on the machine you install it on. Konnect stores leads on the phone you install it on unless you export them. Konvertex stores scripts and generated audio on the laptop you install it on unless you choose an online rendering path. Subscriber, account, license-key, and connected-device metadata are stored in Cloudflare D1 (a hosted SQL service); see the Cloudflare privacy policy for their sub-processor details.

6. Lawful basis for processing (GDPR Art. 6)

Where the General Data Protection Regulation (GDPR), UK GDPR, or comparable laws apply, we rely on the following lawful bases:

7. Purposes of processing

8. Retention

We keep personal data only as long as needed for the purposes above:

9. Your rights as a data subject (GDPR Art. 15–22, UK GDPR, CCPA)

If GDPR, UK GDPR, the CCPA, or a comparable framework applies to you, you have the right to:

To exercise any of these rights, email [email protected]. We respond within 30 days. Because we collect very little, most requests resolve quickly to "here is your record" or "deleted, confirmed". We honor these rights globally, regardless of where you live.

10. Children

Our services are not directed at children under 13 (or under 16 in jurisdictions where that is the digital-consent age). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, email [email protected] and we will delete it.

11. Security

License, account, and connected-device metadata is transmitted over HTTPS and stored encrypted at rest by Cloudflare D1. Kaptain access logs hash bearer tokens before recording token identifiers locally. Local product data is protected by the security of the device and integrations you choose. We publish security policy at security.txt; report vulnerabilities to [email protected].

12. International transfers

CHYNJ Technologies is based in Canada. Cloudflare and Stripe may process data in jurisdictions outside Canada (the United States and elsewhere) per their standard infrastructure. Where required (e.g. transfers from the EU/UK to the US), our sub-processors rely on the European Commission's Standard Contractual Clauses and equivalent UK transfer mechanisms.

13. Sub-processors

We use the following third-party services to operate CHYNJ. Each maintains privacy terms or a Data Processing Addendum for business customers, and we rely on those provider terms for the limited processing described here.

User-directed exports and third-party connections are controlled by you and governed by the connected provider's terms. They are not used by CHYNJ for marketing, analytics, model training, profiling, or resale. We do not use any ad-tech, marketing-automation, or session-replay sub-processors. If we add a new CHYNJ-operated sub-processor, we will update this list and notify subscribers by email before they begin processing.

14. Data controller & contact

CHYNJ Technologies is the data controller for the personal data described in this policy. Our designated privacy contact (acting in the capacity of a DPO for inquiries) is reachable at:

We are not required to formally appoint a Data Protection Officer under GDPR Art. 37, as we do not engage in large-scale processing of special-category data or systematic monitoring. Our privacy contact handles the equivalent function.

15. Supervisory authority

If you are in the EU or UK and believe we have mishandled your data, you have the right to lodge a complaint with your local supervisory authority. A list of EU supervisory authorities is published by the European Data Protection Board; UK residents can contact the Information Commissioner's Office (ICO). Canadian residents can contact the Office of the Privacy Commissioner of Canada (OPC). We’d prefer you give us a chance to make it right first, but you don't have to.

16. Changes to this policy

If we materially change this policy we will update the "Last updated" date at the top, and for subscribers we will send notice by email. Continued use of our products after a change constitutes acceptance of the updated policy.

17. Contact

Questions, requests, or complaints: [email protected].