This policy explains what personal data Disco Shrimp Company, LLC ("we", "us" or "our") collects when you use Chartjuice at chartjuice.com, why we collect it, who we share it with, and the choices you have. We are the controller of this data. If you have a question, email support@chartjuice.com.
The short version
- You can make and download charts without an account. Files you open in the editor are read in your browser, and we don't receive your data unless you save a chart.
- When you save a chart, we store it in your account, including its data, along with a small preview image.
- When you use the AI assistant, your messages and part of your chart go through our server and Vercel's AI Gateway to an AI model provider so it can answer you. We don't store the conversation on our servers.
- If you connect an AI assistant such as Claude or ChatGPT, or give a program an API key, it can read and change the charts saved in your account. You choose which apps, and you can cut one off at any time. The data they send us to make a chart reaches our server.
- An image link shows one of your saved charts as a picture to anyone who has the link. You make the links, and you can stop them.
- Stripe handles payments. We never see your full card number.
- We use PostHog and Fathom Analytics to see how Chartjuice is used, such as which pages people visit and which features they use. They don't use cookies, never receive your chart data, and you can turn them off.
- We don't sell your data or share it for advertising, and Chartjuice has no advertising trackers.
What we collect and why
When you make charts without an account
Files you upload and data you paste are read in your browser and aren't sent to us. Your browser keeps a draft of the chart you're working on in its local storage, so a reload doesn't lose your work. The draft stays on your device until you clear it.
Like every website, Chartjuice receives some technical information when your browser loads a page, such as your IP address, your browser type and the page you asked for. See "Hosting and logs" below.
Your account
To create an account, you give us your email address, either by typing it in or by signing in with Google. If you use Google, Google shares your email address and basic profile details, such as your name and profile picture, with our sign-in provider, which stores them with your account. We only use your email address.
We use your email address to sign you in and to link your saved charts and plan to you. We also keep when you joined, your plan, and how many of your free AI tries you've used.
Charts you save
When you save a chart, we store the whole chart: its data, its settings and its name. We also store a small preview image of it for My charts. Saved charts are private to your account. We look at them only when we need to run or fix Chartjuice, when you ask us to, or when the law requires it.
The AI assistant
You need an account to use the assistant. Each time you send a message, our server sends the AI model:
- your recent messages in that conversation (up to the last 12)
- the chart's settings, such as its type, titles and column names
- a sample of its data: the first 20 rows, after any Steps you've applied
While it works, the model can also ask for a summary of your columns (such as counts, the smallest, largest and average values, and the most common values) or for up to 50 rows at a time. It doesn't receive your whole file at once.
The request goes from our server to Vercel AI Gateway, a service run by Vercel Inc., which passes it to a company that runs the AI model. We use your messages and chart only to answer you. We don't store or log them on our servers. We ask the gateway to send our requests only to model providers that have agreed with Vercel not to keep them (zero data retention) and not to use them to train AI models. Vercel keeps a record of each request, such as which model answered, how much text it processed and what it cost, and handles requests under its own terms. Please don't put sensitive personal information into charts you ask the assistant about.
We do keep usage counts: how many AI messages you've used (in total for free tries, and per day on Pro), plus how much text the model processed and what it cost us each day. We use these to apply plan limits and control costs. They don't contain what you wrote.
Your browser keeps each chart's AI conversation in its local storage, so you can pick it up again later on the same device.
Connected apps
You can let an app, such as the AI assistants Claude and ChatGPT, work with your Chartjuice account. The app sends you to a Chartjuice page that names it and lists what it will be able to do, and nothing is shared unless you choose Allow.
An app you allow can:
- read, make, change and delete the charts saved in your account, including their data, and get them as images
- read and set your brand palette
- see your plan, how many charts you've saved, and how much of your daily and per-minute allowances is left
- see the email address you sign in with
It can't see or change your billing or payment details, see or change your teammates, see or make API keys, change your email address, or delete your account.
When you allow an app, we record which app you allowed and when, and so does our sign-in provider, Supabase, which gives the app a token that works for a short time and that the app can renew. We show you the list on your account page, under Connected apps. Choose Disconnect there and the app loses access right away.
What you type to an AI assistant, and what it reads from your charts, also goes to the company that makes the assistant. That company handles it under its own privacy policy, not this one. Only connect apps you trust.
The API and API keys
Chartjuice has an API, so that your own programs can work with your saved charts. A program proves it's yours with an API key, which you make on your account page. Your browser makes the key, and we store only its name, its first 12 characters and a scrambled code made from it (a hash). We can't read a key or show it to you again. We also keep when each key was made, when it was last used and when you revoked it. Anyone who has a key can read, change and delete your saved charts, so keep it private. We delete what we hold about a revoked key the next time you make a key, once it has been revoked for 30 days.
Data that a program or a connected app sends to make a chart, or to replace a chart's data, is saved in your account as a chart, like one you save in the editor. Data sent only to get a picture, either a chart drawn from data alone or a saved chart drawn with other data, is used to draw that picture and isn't stored. Our server draws every image and sends it back without keeping it.
To apply limits, we count each account's API requests by the minute, its images of saved charts by the day and its image renders by the month. An image render is counted once for each different picture in a month. To know whether a picture was already counted, we keep a scrambled code made from the picture's settings and data (a hash), not the data itself, until the first image render of a later month. If a picture can't be drawn, we note the same kind of code with the reason, which can name the chart's columns, so the same request isn't tried over and over. A note is used for a day at most and is deleted the next time one is written. To slow down attempts to guess keys, we count failed attempts by network address. For that we store a scrambled code made from the IP address (a keyed hash), never the address itself. A count over an hour old is deleted the next time a failed attempt is counted.
Image links
An image link is a web address that shows one of your saved charts as a picture. You get one from Copy image link in the editor, and a program or a connected app can ask for one too. Anyone who has the link can see the picture, without signing in, for as long as the link works. The picture shows what the chart shows, so share a link only where you're happy for the chart to be seen. The link can't be used to open the chart, change it, or find your other charts.
A link can carry data of its own, to draw the chart with other numbers. That data is written into the link itself, so anyone who has the link can read it.
Links are signed with an image signing key, which we make for your account the first time a link is asked for. We store the key's secret so that our server can check links, and it is shown to you once, if you ask for it on your account page. Rotate or revoke a key there and every link signed with it stops working. We delete a revoked key the next time a key is made, once it has been revoked for 30 days.
When someone opens a link, their app or mail service asks us for the picture, and our hosts receive that request like any other (see "Hosting and logs"). We don't use analytics on these requests and don't try to work out who is looking. Our hosting provider's network keeps a copy of each picture for up to 5 minutes so that it loads quickly. Mail services and apps that show the picture may keep copies of their own for longer.
To apply limits, we count how often each account's links are asked for by the minute and drawn by the day. Requests for links that don't check out are counted by network address, the same way as failed API keys.
Brand palette (Pro)
If you ask us to pull colors from a website, our server loads that public web page and up to 5 of its stylesheets, and picks colors from them. We don't store the address you entered. We count how many lookups you make each day, to limit them. The palette you save is stored in your account.
Teammates (Pro)
On Pro, you can add teammates by email address. We store those addresses so that each teammate gets Pro when they sign in with that address. We don't email them, so let them know yourself, and only add people who are happy to be added.
Payments
When you upgrade, Stripe runs the checkout page and stores your card details. We create a customer record at Stripe with your email address and your Chartjuice account ID. From Stripe, we keep your Stripe customer ID, your subscription's status, whether you pay monthly or yearly, and when it renews or ends. We don't store your card number or billing address. Stripe also processes data for its own purposes, such as preventing fraud, under its own privacy policy.
Business early access
If you join the Business early-access list, we store the email address you give us, the features you're interested in, any note you write, where you opened the form, and your account if you're signed in. To stop spam, we store a scrambled code made from your IP address (a keyed hash), never the address itself. We use this to email you when Business is ready and to decide what to build.
Emails
We send emails only to sign you in (a code and a link), and to reply when you email us. If you join the Business early-access list, we'll email you when Business is ready. We don't send marketing emails. If you email support, we keep the conversation so we can help you.
Product analytics
We use PostHog, a product analytics service run by PostHog, Inc., to understand how people use Chartjuice so we can improve it. Your browser sends PostHog:
- the pages you visit and the page that sent you to us
- actions you take, described only by counts, types and ids: for example the chart type you picked, whether you pasted, uploaded or used example data and how many rows and columns it had, the file type (such as CSV), the format and size of a download, that you saved a chart or sent the AI assistant a message, and steps in upgrading or managing your plan
- your browser, operating system, device type and screen size
PostHog never receives your chart data, cell values, chart titles, file names, your messages to the AI assistant or its replies. We don't record your screen or your clicks and typing. Web addresses are sent without their query details, except campaign tags and a few of Chartjuice's own page settings, so sign-in codes in links never reach PostHog.
PostHog receives your IP address with each request and uses it to estimate your approximate location (country and city). It runs without cookies: to count visitors, PostHog combines your IP address and browser details with a secret value that changes every day into a scrambled code (a hash), so it can't follow a signed-out visitor from one day to the next. If you're signed in, events also carry your Chartjuice account ID (never your email address) and your plan, so we can see how free and Pro accounts use Chartjuice.
Website analytics
We also use Fathom Analytics, a website analytics service run by Conva Ventures Inc., to count visits to our pages. Your browser sends Fathom:
- the page you're on and the page that sent you to us
- how long you stayed on the page
- your browser, operating system and device type
Fathom doesn't receive what you do in Chartjuice beyond the pages you visit, and it never receives your account ID, your email address or your chart data. Web addresses are sent without their query details, except a fixed list of common ones such as campaign tags, so sign-in codes in links never reach Fathom.
Fathom receives your IP address with each request and uses it to estimate your approximate location. It runs without cookies: to count visitors, Fathom combines your IP address and browser details with a secret value that changes every day into a scrambled code (a hash), so it can't follow you from one day to the next.
Turning analytics off
You can turn analytics off, for PostHog and Fathom together:
- If you're signed in: in Account settings, turn off "Share anonymous usage analytics". It stops right away, and on every device you sign in on. Your browser also remembers the choice, so analytics stays off on that device when you're signed out.
- Anyone, signed in or not: turn on Global Privacy Control or Do Not Track in your browser. If your browser sends either signal, we don't load PostHog or Fathom at all.
Hosting and logs
Netlify hosts Chartjuice and runs our server code. Supabase runs our database, file storage and sign-in. Like any hosting provider, they receive your IP address and details of each request, such as your browser and the address requested, and may keep them in logs for a short time for security and troubleshooting.
Cookies and local storage
Chartjuice doesn't use analytics or advertising cookies, and there's no advertising script on the site. Our analytics (PostHog and Fathom, see "Product analytics" and "Website analytics" above) run without cookies and don't store anything in your browser to recognize you. We use your browser's local storage only for things the site needs to work:
- your sign-in session, so you stay signed in
- drafts of the charts you're working on
- the AI conversation for each chart
- a save or upgrade you started before signing in, so it can finish afterward
- that you turned off analytics, if you did, so it stays off on that device
We also use session storage to remember, for one visit, that we've already suggested saving your chart.
Stripe's checkout page and Google's sign-in page are run by Stripe and Google, and they set their own cookies under their own policies.
Google Fonts
Our pages load fonts from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). To do that, your browser connects to Google, which receives your IP address and browser details.
Our legal bases (EEA, UK and Switzerland)
If you're in the European Economic Area, the UK or Switzerland, we rely on these legal bases:
- Contract: to provide your account, saved charts, the AI assistant, the API, the apps you connect, Pro and its seats, and to take payments.
- Legitimate interests: to keep Chartjuice secure and working, to prevent abuse with usage limits and rate limits, to control our AI costs, to load the site's fonts, and to understand how Chartjuice is used so we can improve it (product and website analytics). We've weighed these interests against your rights, and you can object to them (see "Your rights").
- Consent: for the Business early-access list. You can withdraw it any time by emailing us.
- Legal obligation: to keep billing records that tax and accounting laws require.
Who we share data with
We don't sell your personal information, and we don't share it for cross-context behavioral advertising. We share it only with these service providers, who process it for us to run Chartjuice:
- Supabase: our database, file storage and sign-in. It stores your account, saved charts, preview images, plan, usage counts, teammate list, API key records, image signing keys and the list of apps you've connected, and sends sign-in emails.
- Stripe: payments and subscriptions.
- Vercel (AI Gateway), and the AI model provider it sends each request to: answering your requests to the AI assistant.
- Netlify: hosting the site, running our server code, and keeping a short-lived copy of the pictures that image links show.
- PostHog: product analytics, as described above.
- Fathom Analytics: website analytics, as described above.
- Google: sign-in with Google, if you choose it, and the fonts our pages load.
Apps you connect and programs you give an API key to aren't our service providers. They get your charts and the account details listed under "Connected apps" because you chose to let them, and they handle what they read under their own terms. The same goes for a place you paste an image link into, such as a mail service or a notes app: it fetches the picture because you put the link there.
We may also share information if the law requires it, to protect someone's safety or our rights, or as part of a merger or sale of our business. In a sale, this policy would keep applying to your data.
How long we keep data
- Your account, saved charts, preview images, brand palette and teammate list: until you delete them or delete your account.
- AI conversations: not stored on our servers. The copy in your browser stays until you clear it.
- API keys: the name, first 12 characters and hash of a key until you revoke it and then make another key 30 days or more later, or until you delete your account.
- Connected apps: the record that you allowed an app until you disconnect it or delete your account.
- Image signing keys: an active key until you rotate or revoke it, and a revoked key until a key is made 30 days or more later, or until you delete your account.
- API request and image counts: each count covers one minute, one day or one calendar month, and is replaced by a new one the next time you use the API or one of your links is opened after that. The codes that record which pictures were counted are deleted as described under "The API and API keys", and so are counts of failed attempts.
- AI and brand-lookup usage counts: kept per day under your account ID. They don't contain what you wrote. Once you delete your account, they're no longer connected to your email address.
- Billing records: Stripe keeps payment records as the law requires. We keep your Stripe customer ID and subscription status until you delete your account.
- Business early-access entries: until you ask us to remove them. If you delete your account, the entry stays but is no longer linked to your account.
- Hosting and database logs: kept for a short time by Netlify and Supabase.
- Product analytics: kept by PostHog for the retention period set in our PostHog account, then deleted. You can ask us to delete the events linked to your account ID.
- Website analytics: kept by Fathom as page and visit counts, which aren't linked to your account, for as long as we use Fathom.
You can delete your account from your account page. That deletes your account, your saved charts, their preview images, your brand palette, your teammate list, your API keys and your image signing keys, disconnects the apps you connected, and cancels your Pro subscription. Your image links stop working.
Your rights
You can view, change and delete your saved charts in the app, and delete your account at any time.
Depending on where you live, you may also have these rights:
- EEA, UK and Switzerland: to access your data, correct it, delete it, restrict or object to how we use it, get a copy in a portable format, and withdraw consent. You can also complain to your local data protection authority.
- California: to know what personal information we collect and how we use and disclose it, and to access, correct and delete it. We don't sell or share your personal information as California law defines those terms, and we don't use sensitive personal information beyond what's needed to provide Chartjuice. We won't treat you differently for using your rights.
- Other US states with privacy laws give similar rights, and we honor them in the same way.
In the last 12 months, we've collected these categories of personal information, for the purposes described above: identifiers (your email address, account ID, and IP address in hosting logs and analytics), commercial information (your plan and subscription records), internet activity (request logs, API and image link usage counts, and the pages you visit and features you use in Chartjuice), approximate location (from your IP address), and the content you save.
To use any of these rights, email support@chartjuice.com from the address on your account. We may ask you to confirm the request from that address before we act on it. We'll answer within one month, or sooner if the law where you live requires it. You can also have an authorized agent make a request for you.
Children
Chartjuice isn't meant for children under 13, and we don't knowingly collect personal data from them. If you think a child under 13 has given us personal data, email us and we'll delete it.
International transfers
We're based in the United States, and our service providers may process data in the United States and other countries. When we transfer personal data from the EEA, the UK or Switzerland, we rely on safeguards that the law accepts, such as the European Commission's Standard Contractual Clauses in our providers' data processing terms.
Security
Chartjuice uses HTTPS everywhere. Saved charts and preview images are private to your account: database access rules stop other users from reading them, preview images sit in private storage, and the links that show them expire after an hour. Card details stay with Stripe. Sign-in uses one-time codes and links or Google, so we don't store passwords. API keys are stored only as hashes, and an app you connect is held to the list under "Connected apps" by our server and our database. An image signing key's secret has to be stored as it is, because our server needs it to check a link. Only our server can read it, and an app you connect can't see or change your signing keys. No system is perfectly secure. If a breach affects your personal data, we'll tell you as the law requires.
Changes to this policy
We may update this policy. The date at the top of this page shows when it last changed. If a change matters to you, we'll tell you before it takes effect, by email or with a notice in Chartjuice.
Contact
Chartjuice is run by Disco Shrimp Company, LLC. For questions about privacy or to use your rights, email support@chartjuice.com.