Trust & Compliance
Last updated: June 17, 2026
CHYNJ builds local-first software. Product content stays on the user's device by default: Kaptain project work stays on the Kaptain machine, Konnect leads stay on the phone unless exported by the user, and Konvertex scripts/audio stay on the laptop unless the user selects an online rendering path. CHYNJ does not use product content for marketing, analytics, model training, profiling, or resale. The data CHYNJ stores centrally is limited to account, licensing, billing, support, download, and device-certification metadata needed to operate the service. This page is the single place to understand how we handle that data, who our sub-processors are, and where we stand on formal frameworks.
Privacy rights and regulatory posture
- GDPR (EU) & UK GDPR — We are standardizing our privacy program around documented lawful bases, data-subject rights, limited records for the data we hold, and provider transfer mechanisms such as Standard Contractual Clauses where required. See our Privacy Policy.
- CCPA / CPRA (California) — We do not sell or share personal information, and we are aligning our request process around access, deletion, correction, portability, and opt-out rights.
- PIPEDA (Canada) — We are a British Columbia company and are standardizing around Canadian privacy principles for the limited personal data we hold.
This is an operating posture and standardization effort, not a statement that CHYNJ has completed a formal legal review, external certification, or audit. For audited frameworks, see the roadmap below.
Compliance standardization & audit roadmap
- Privacy program — In progress. The CHYNJ team is standardizing policies, internal records, deletion/export procedures, sub-processor review, and customer notices around GDPR, UK GDPR, PIPEDA, CCPA/CPRA, and any additional privacy requirements that become relevant to customers we serve.
- SOC 2 Type II — Planned. We will begin a Type II observation window when enterprise demand warrants it, using a compliance-automation platform for continuous evidence collection. Available under NDA once underway.
- ISO 27001 — Under consideration for EU/global enterprise customers.
- PCI DSS — Inherited at SAQ-A level: all cardholder data is handled by Stripe; CHYNJ never sees or stores card numbers.
Sub-processors
We use a deliberately short list of established providers. Each operates under a signed Data Processing Agreement.
- Cloudflare, Inc. — website hosting (Pages), edge network, D1 database (subscriber + license records), R2 storage, cookieless Web Analytics, Email Routing. DPA · Privacy
- Stripe, Inc. — subscription payment processing; independent controller for payment-instrument data. DPA · Privacy
- Resend, Inc. — transactional email delivery (verification, password reset, billing + security alerts). Recipient address and message body only; no contact lists, no marketing. DPA · Privacy
- Microsoft — optional online neural voice rendering for Konvertex only, when the user selects an online Microsoft voice. Script text is sent only for the requested rendering job. Privacy
User-directed exports and third-party connections are controlled by the user and governed by the connected provider's terms. They are not used by CHYNJ for marketing, analytics, model training, profiling, or resale. We use no ad-tech, marketing-automation, or session-replay sub-processors. We notify subscribers by email before adding a new CHYNJ-operated sub-processor.
Data residency & what we hold
Local content stays on the device unless the user explicitly exports it or chooses a product path that requires an outside service, such as Konvertex online voice rendering. The personal data CHYNJ holds by default is the minimum needed to run accounts, subscriptions, licensing, support, and downloads: your checkout/account email, country, subscription lifecycle events, the last 4 digits / brand of your card as provided by Stripe, issued license keys, connected-device metadata such as hashed device fingerprints or certificate status, and transactional email records. These live in Cloudflare D1 or the listed providers' systems, protected in transit and at rest by those services.
Your data rights
To access, export, correct, or delete your data, email [email protected]. We respond within 30 days. Because we collect so little, most requests resolve quickly. Full detail of your rights is in the Privacy Policy.
Security
Data in transit is protected with HTTPS; subscriber and license records are encrypted at rest. We publish a security.txt and welcome coordinated disclosure. Report vulnerabilities to [email protected].
Contact
- Privacy / data requests: [email protected]
- Security disclosures: [email protected]
- Legal: [email protected]