Privacy Policy
Last updated: 5 August 2026
Domain: chatito.com
Product app: app.chatito.com
Contact: info@chatito.com
Terms: chatito.com/terms
Introduction
This Privacy Policy (the "Policy") describes how chatito.com, being the domain through which the Services are made available ("Us", "We", "Our"), collects, uses, discloses, retains, and otherwise processes information in connection with:
- the marketing website at chatito.com (including landing pages, documentation, blog, and public content);
- the product web application at app.chatito.com and related product hosts We designate (including dashboards, terminals, Settings, Challenges, billing, and account surfaces);
- the official Telegram-based trading bot @chatiportalbot; and
- any related APIs, workers, and tools made available under chatito.com domains,
collectively, the "Services". Channels may differ in available features. The Policy is incorporated into and should be read together with the Terms and Conditions available at chatito.com/terms (the "Terms"). Capitalized terms not defined in the Policy have the meanings given in the Terms.
Telegram is a Third-Party Service and maintains its own privacy policy, terms, and technical constraints. The Policy governs only Our processing of information in connection with the Services and does not modify Telegram's relationship with You, the data Telegram independently collects, or how Telegram processes information. Your use of Telegram itself is governed by Telegram's own policies, and We do not control Telegram's independent collection and use of data. Likewise, identity providers, AI model providers, payment rails, venues (exchanges, prediction markets, blockchains), and other Third-Party Services operate under their own policies.
By accessing, using, interacting with, or otherwise engaging with the Platform, Bot, or Services in any manner, You acknowledge that You have read and understood the Policy. If You do not agree, You must immediately discontinue all use of the Services. The Policy may be updated from time to time; continued use after updates constitutes acceptance as described in the Terms.
1. Definitions, Scope, and How to Read the Policy
1.1. Scope and relationship to the Terms
1.1.1. The Policy describes how information may be processed in connection with operating, securing, supporting, improving, and enforcing the Services. It is not a promise that the Services are risk-free, uninterrupted, error-free, or suitable for any particular purpose. The Terms contain separate and additional risk disclosures, disclaimers, and limitations of liability that apply independently of the Policy.
1.1.2. If there is any conflict between the Policy and the Terms regarding personal data processing, the Policy governs that topic; however, nothing in the Policy is intended to create broader duties than those described here or those required by applicable law. Where mandatory local laws grant non-waivable rights, those rights apply to the extent required. Otherwise, the Terms and the Policy are intended to operate together as a single framework.
1.2. Key terms used in the Policy
1.2.1. In the Policy, "Personal Data" means information relating to an identified or identifiable individual, or treated as personal data/personal information under applicable law. "Platform Data" means information generated through use of the website, product app, dashboards, terminals, Settings, Challenges, billing, and related web components (accounts, settings, strategy configurations, paper/live status, plan/credit balances, usage events, and system outputs). "Bot Data" means information generated through interactions with the Bot (commands, button presses, preferences, workflow states, and system outputs), together with operational logs and records associated with those interactions. "On-Chain Data" means information recorded on public blockchains (including wallet addresses, approvals/allowances, transaction hashes, token transfers, and related metadata), which may be public, persistent, and outside Our ability to modify, restrict, or delete.
1.2.2. "KYC Data" means identity verification and compliance screening information and outputs, which may include documents and verification results, sanctions/PEP screening, adverse-media checks, wallet screening, and related risk indicators, whether processed directly by Us or via Third-Party Services. "Billing Data" means information related to plan purchases, invoices, quotes, payment status, auto-renew preferences, transaction hashes, chains, amounts, and related billing events. "Third-Party Services" includes Telegram, identity providers (for example Supabase or similar), AI model providers, and any third-party platforms, protocols, infrastructure, hosting, analytics vendors, verification/KYC providers, payment processors, venues (CEX, DEX, prediction markets), and blockchain infrastructure providers not controlled by Us.
1.3. Interpretation rules
1.3.1. Headings are for convenience only and do not affect interpretation. Terms such as "including", "without limitation", and "such as" are illustrative and do not limit scope. The Policy applies worldwide to all Users and all use of the Services, subject to mandatory local law. The Policy describes how information may be processed; it does not guarantee that any particular processing will or will not occur in every case, since processing may depend on how You use the Services, which features are enabled, and operational and legal requirements at the relevant time.
2. Telegram-Specific Disclosures and Practical Limitations
2.1. What the Bot can (and cannot) access in Telegram
2.1.1. The Bot generally processes information You provide through interactions with the Bot (commands, button presses, replies, settings) and the metadata Telegram makes available for bot functionality (such as your Telegram user ID, username/handle, language/locale signals, and certain chat context identifiers where applicable). This processing is necessary to identify your session, apply preferences, prevent abuse, and deliver outputs to the correct user or chat context.
2.1.2. The Bot does not inherently have access to your Telegram password, the content of your messages in other chats, or your phone number, except to the extent Telegram discloses certain information through platform features You choose to use or through platform behavior outside Our control. Telegram may independently collect, store, and process data under Telegram's own policies; the Policy does not control Telegram's independent processing.
2.1.3. Telegram delivery behavior can cause delays, missing messages, message ordering differences, and UI inconsistencies across devices. We may log delivery errors, timestamps, and interaction records to operate the Services, prevent abuse, and investigate incidents. We do not control Telegram's infrastructure and do not guarantee delivery, timing, or availability of Telegram.
2.2. High-risk environment and user responsibility overlap
2.2.1. The Services operate in a high-risk environment involving public blockchains, self-custody wallets, venue accounts, API Credentials, and third-party infrastructure. Some information that relates to Your use of the Services, particularly On-Chain Data, may be publicly visible and outside Our control. Linking your Telegram identifier, Platform account, or email to a wallet address may increase privacy risk by making activity more attributable.
2.2.2. You are responsible for safeguarding your Platform account, Telegram account, device, Wallet credentials, and API Credentials. If your account is compromised, an attacker may interact with the Services as if they were You. We may have limited ability to distinguish authorized from unauthorized activity, and certain activity (especially on-chain or on venues) may be irreversible.
2.2.3. The Policy describes data processing and does not reduce or replace the risk disclosures, disclaimers, and responsibility allocations in the Terms. The Terms remain the controlling document regarding risk, liability, and responsibility for trading activity.
3. Information We Collect
3.1. Information You provide to Us
3.1.1. You may provide information when using the Services, including Account details, Telegram handle/ID, Bot and Platform settings and preferences, wallet addresses You connect or submit, strategy configurations, paper/live arming choices, risk limits, Challenges submissions (including social post URLs where required), Custom Avatar prompts, referral codes, billing selections, and communications with Us.
3.1.2. You may choose to provide additional contact details such as an email address for notices, support, waitlist, verification, sign-in, or account recovery where such features exist. You are not required to provide an email unless We require it for a specific feature.
3.1.3. You must not send seed phrases, private keys, or similar secrets via Telegram or any channel. We do not need seed phrases to operate non-custodial technology. If You choose to connect API Credentials for automation, provide them only through official Platform or Bot flows designed for that purpose-not via unsolicited messages or third-party "support".
3.1A. Account authentication and identity linking
3.1A.1. Depending on how You sign in, We may process identifiers and tokens from identity methods such as: (a) email / magic-link or OAuth via an identity provider (for example Supabase Auth or similar); (b) Wallet signature login (for example SIWE) and linked wallet address(es); (c) Telegram login / bot linkage (Telegram user ID, username/handle); (d) invite records and operator grants; and (e) session cookies or tokens that keep You signed in.
3.1A.2. Identity providers are Third-Party Services. They may process Your email, IP address, device metadata, and authentication events under their own policies. We receive the minimum references needed to create or resume Your Account and enforce access controls (including whether new sign-ups are open).
3.1A.3. If You enable two-factor authentication (TOTP), We process authenticator secrets (protected), enrollment status, verification challenges, and hashed backup codes. We do not need Your authenticator app contents beyond verification codes You submit. Step-up checks may apply to sensitive actions (for example vault/credential changes).
3.2. Information generated through use of the Services
3.2.1. We may automatically collect Platform Data and Bot Data, including usage logs, feature interaction events, session signals, performance and reliability metrics, error logs, and security logs. Such information helps us maintain reliability, prevent abuse, and improve the Services.
3.2.2. We may maintain records of interactions (commands, button presses, API calls, strategy lifecycle events, paper/live toggles, Challenges progress, billing events, notification delivery states) for operational continuity, security, fraud prevention, and dispute handling. These logs may contain identifiers (Telegram ID, Account ID, wallet address) if necessary to operate the Services.
3.2.3. When You use web components under chatito.com or app.chatito.com (landing pages, product app, dashboards, terminals, documentation, blog, gate/waitlist), we may use cookies or similar technologies for session management, security, preferences, and analytics as described in Section 9.
3.3. Blockchain and wallet-related information (On-Chain Data)
3.3.1. To support trading-related workflows and outputs, we may process wallet addresses, transaction hashes, approvals/allowances, routing metadata, slippage settings, position or order-related data, and related metadata. Much of this information may be publicly visible on-chain and may be accessible to anyone via blockchain explorers or analytics.
3.3.2. We may associate an off-chain identifier (Telegram user ID/handle, Platform account, or email) with one or more wallet addresses you submit or link so the Services can operate as configured. You acknowledge that such linking may increase privacy risk and that on-chain activity is generally public and permanent.
3.3.3. Private keys and seed phrases should remain under Your control via your Wallet environment; however, we may store technical records necessary to display status, history, or configuration You request.
3.4. API Credentials and venue automation (where used)
3.4.1. If You connect API Credentials for venue automation (for example, CEX or similar), we may process credential material and related metadata (key labels, permission scopes, last-used timestamps, error codes) solely to operate automation You enable. You should use trade-only / least-privilege keys (no withdraw or transfer where the venue allows), optionally IP-restrict keys on the venue, and revoke them when not needed. We do not accept seed phrases or recovery word lists through official credential flows.
3.4.2. We treat API Credentials as sensitive technical secrets. We apply commercially reasonable safeguards (which may include encryption at rest, access controls, and secrets management). No safeguard is perfect. Compromised credentials can cause irreversible trading losses on the venue; You remain responsible for venue-side risk controls and revocation.
3.4.3. We do not take deposit custody of Your venue balances. Balances remain under Your account relationship with the venue. Credential processing supports automation technology; it does not convert Us into a custodian, broker, or exchange.
3.5. Strategy, Lab, paper/live, and performance information
3.5.1. We may process strategy parameters, Lab experiment metadata, paper and live performance metrics, rankings inputs/outputs, kill/promote events, Trade For Me wizard inputs/outputs, and related operational data to run automation, improve Lab features, prevent abuse, and operate leaderboards or public performance displays where offered.
3.5.2. Public boards, rankings, or marketing displays-if any-are designed to show performance information and must not expose seed phrases or private keys. You should assume that performance metrics You choose to make public may be visible to others.
3.5.3. When You use AI-powered Lab features, We may send prompts, strategy context, market/context snippets, and related technical inputs to AI model providers (Third-Party Services) solely to generate the requested output. Do not include secrets (seed phrases, private keys, full API secrets, passwords, or 2FA codes) in Lab prompts. Model providers process data under their policies; We configure commercial/reasonable settings available to Us but cannot guarantee how every provider retains logs.
3.5.4. Custom Avatar craft may process Your text prompt and generate image assets associated with Your Account (and optional share packages). Generated images may be stored to serve Your profile, leaderboards, and share tools.
3.5A. Billing, plans, AI Credits, Challenges, and referrals
3.5A.1. Billing Data. If You purchase AI Lab plan time or credit packs, We may process Billing Data including selected SKU, chain, quoted amounts, invoice identifiers, payment status, receive addresses We designate, transaction hashes You submit or We detect, linked Wallet used for payment, auto-renew preferences, plan entitlement start/end timestamps, and related events. Onchain payment details may also appear as public On-Chain Data.
3.5A.2. AI Credits and plan entitlement. We process credit balances, allowance grants, spend events (action type, cost, timestamp), and plan tier/expiry so the product can enforce Free vs AI Lab gates and metered AI actions.
3.5A.3. Challenges and Points. We may process challenge task progress, campaign membership, self-reported or operator-reviewed submissions (including URLs), Points balances, redeem transactions, pot/leaderboard placements, and related anti-abuse signals.
3.5A.4. Referrals. We may process Your referral code, invite links, first-touch attribution (including UTM parameters where present), invitee Account linkage, and reward grant events when program rules are met. We design attribution to reduce self-referral abuse; We may retain denial reasons for enforcement.
3.5A.5. Notifications. If You enable in-app, email, or Telegram notifications, We process preference toggles and delivery metadata for lifecycle events (for example strategy create/pause/live/kill, fills where enabled, plan expiring). Defaults may be off until You opt in, as described in product Settings.
3.6. KYC / screening information (if requested)
3.6.1. If We request identity verification and/or compliance screening, You may provide KYC Data directly to Us and/or to Third-Party Services.
3.6.2. KYC Data may include identity documents, selfies/liveness checks, proof of address, and related materials, together with outputs such as pass/fail decisions, risk flags, sanctions/PEP results, adverse-media signals, and wallet screening risk signals. We may also re-run checks over time.
3.6.3. We may retain KYC-related records and outputs to the maximum extent permitted by law for compliance, security, dispute handling, and enforcement of the Terms.
3.7. Information from Third-Party Services
3.7.1. We may receive information from Third-Party Services that support the Services, such as identity providers (auth events), infrastructure/hosting providers (security logs), analytics services (aggregated usage metrics), email/waitlist providers, AI model providers (completion metadata), payment processors or onchain RPC verification (payment confirmation), verification providers (KYC outputs), venues (order/position status where integrated), and blockchain infrastructure (network telemetry). We may combine such information with other information we hold to operate, secure, and improve the Services.
3.7.2. In order to read blockchain data, simulate routes, estimate fees, and broadcast transactions (where applicable), the Services may send requests to third-party remote procedure call providers, node operators, or endpoint providers ("RPC Providers"). RPC Providers may receive and process certain technical information as part of providing connectivity, which may include Your IP address (or network identifiers), user-agent/device metadata, wallet address queries, transaction payloads, transaction hashes, and timing data. RPC Providers operate as Third-Party Services under their own policies and practices.
3.7.3. Third-Party Services may collect information independently under their own policies. We do not control how they use your information when they act as separate controllers (for example, Telegram as a platform, or an exchange as a venue).
4. How We Use Information
4.1. Provide, operate, and maintain the Services
4.1.1. We use information to operate the Platform and Bot, provide automation technology features, maintain sessions, store settings, deliver outputs, and perform technical functions that allow the Services to work. This includes using Telegram identifiers to route messages and responses, using Account identifiers for web sessions, enforcing plan/credit gates, processing billing and Challenges redemptions, delivering notifications You enable, and using Platform Data / Bot Data to maintain feature state and workflow continuity (including paper/live modes and strategy lifecycle).
4.1.2. We use logs and usage data to monitor performance, debug issues, detect outages, measure reliability, and improve usability and functionality over time. We may also use data to run internal testing, feature rollouts, and operational changes, including feature gating and phased releases.
4.1.3. We use communications and support requests to respond to inquiries, investigate issues, and maintain records for quality control, disputes, and enforcement of the Terms. Support is provided on a best-efforts basis as stated in the Terms and does not create any duty to resolve issues.
4.2. Security, abuse prevention, and risk management
4.2.1. We use information to protect the Services and Users, including detecting and preventing abuse, spam, scraping, denial-of-service activity, attempted circumvention of controls, impersonation campaigns, and other harmful behavior. We may use security logs, rate limiting, anomaly detection, and other safeguards.
4.2.2. We may use automated signals (unusual usage patterns, repeated failed attempts, high-risk indicators) to impose limits, require additional verification, restrict access, or terminate access. Such systems may be imperfect and may result in false positives. To the maximum extent permitted by law, we are not obligated to disclose internal thresholds, scoring criteria, or details of our security systems.
4.2.3. We may preserve logs and relevant records to investigate misuse, respond to incidents, enforce the Terms, and defend against claims. We may also use information to coordinate with service providers and advisers during incident response.
4.3. Compliance and verification (including KYC)
4.3.1. We may use information to comply with legal obligations, respond to lawful requests, and enforce our policies and Terms. Where verification is requested under the Terms, we may process KYC Data and related outputs to determine eligibility, impose limits, and manage risk.
4.3.2. We may use verification outcomes to decide whether to provide Services, whether to provide particular features, and whether to apply limits, restrictions, or terminations consistent with the Terms. We may also re-run checks, request updates, or apply additional screening based on risk and compliance needs.
4.3.3. To the maximum extent permitted by law, verification requirements or outcomes do not create a duty for Us to monitor your activity, prevent losses, reverse transactions, or provide remediation, and we may make verification-related decisions in our sole discretion.
4.4. Communications, updates, and informational messaging
4.4.1. We may use information to send operational messages through the Platform and/or Bot (service notices, security alerts, feature changes, policy updates). If You provide an email, we may send notices by email as well, but Telegram delivery behavior and email filters may affect timeliness and visibility of messages.
4.4.2. We may administer waitlists, community channels, and informational communications, including announcements and updates. We may process identifiers necessary to manage participation, prevent spam, and enforce community guidelines.
4.4.3. We may deliver in-product messages we believe are relevant (for example, changes to fees, features, risk warnings, or security guidance). Where required by applicable law, we may offer opt-outs for certain communications, but some communications may be necessary for operation and security.
4.5. Analytics, improvement, and development
4.5.1. We may use aggregated and/or de-identified information to analyze trends, administer the Services, study usage patterns, measure feature performance (including Lab and automation features), and improve reliability. De-identification may reduce risk but may not be irreversible in all cases depending on data type and context.
4.5.2. We may use information to improve fraud prevention, develop security features, and test new workflows. Testing may occur in live environments. Any risk controls are best-effort and do not guarantee prevention of losses.
4.5.3. If You submit feedback, suggestions, ideas, bug reports, or other materials, processing and rights related to those submissions are addressed in the Terms (including ownership and license to use feedback).
5. Legal Bases for Processing (Where Required)
Where applicable law requires a legal basis (for example, under GDPR-style regimes), We may rely on one or more of the following, depending on context:
- Contract / performance of a contract: processing necessary to provide the Services You request;
- Legitimate interests: operating, securing, improving, and enforcing the Services, preventing abuse, and defending legal claims, balanced against Your rights;
- Consent: where required (for example, certain cookie categories or marketing);
- Legal obligation: where processing is necessary to comply with applicable law;
- Vital interests / public interest: only where applicable and appropriate.
You may have rights to withdraw consent where processing is consent-based, without affecting the lawfulness of processing before withdrawal. Withdrawal may limit certain optional features.
6. How We Share Information
6.1. We may share information with service providers that help us operate the Services, including hosting/infrastructure providers, identity providers, AI model providers (for Lab features You request), analytics vendors, email/waitlist providers, payment processors, verification/KYC providers, customer support tools, and security vendors, under contractual or operational arrangements appropriate to the service.
6.2. We may share information with venues and other Third-Party Services You choose to connect or interact with through the Services (for example, when You place orders, connect wallets, or use API Credentials). Those parties process information under their own policies.
6.3. We may disclose information if required by law, regulation, legal process, or governmental request, or if we believe disclosure is reasonably necessary to protect rights, safety, security, or integrity of the Services, Users, or the public.
6.4. We may share or transfer information in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to appropriate continuity of protection where required.
6.5. We do not sell Personal Data for money in the ordinary sense of a data broker sale. Some jurisdictions define "sale" or "sharing" broadly, and we may use analytics and advertising technologies that could be characterized as "sharing" under certain laws; jurisdiction-specific rights and opt-outs, where available, are described in Section 10.
6.6. Public rankings or performance boards (if offered) may display strategy or performance metrics. They are not intended to display private keys or seed phrases.
7. Data Security
7.1. We implement commercially reasonable technical and organizational measures designed to protect information, which may include encryption in transit where supported, access controls, least-privilege practices, envelope encryption or equivalent secrets management for API Credentials and other sensitive vault material, protected storage of 2FA secrets and hashed backup codes, monitoring, and incident response procedures.
7.2. No method of transmission or storage is completely secure. You acknowledge residual risk, including risks from Third-Party Services and public blockchains.
7.3. You are responsible for securing Your devices, accounts, Wallets, and API Credentials. We cannot reverse irreversible on-chain or venue actions resulting from compromise.
8. Data Retention and Accuracy
8.1. We retain information for as long as reasonably necessary to operate the Services, comply with legal obligations, resolve disputes, enforce agreements, and maintain security and audit trails.
8.2. Retention periods may vary by data category. Security logs, compliance records, and financial records may be retained longer where required or appropriate.
8.3. On-Chain Data is generally outside Our control and may persist indefinitely on public networks.
8.4. You represent that information You provide is accurate, complete, and not misleading, and You agree to keep it current where relevant. If inaccurate or incomplete information affects verification outcomes, compliance screening, or access decisions, We may restrict or terminate access consistent with the Terms.
9. Cookies, Tracking, and Embedded Content (Web Components)
9.1. Web components of the Services (including the marketing site at chatito.com, documentation/blog pages, and product dashboards or terminals when served under chatito.com) may use cookies and similar technologies (including HTTP cookies, local storage, and session storage) to operate the Services, remember preferences, maintain sessions, prevent abuse, and-only if You consent-measure usage with analytics. Cookies may be session cookies or persistent cookies. Your browser may allow you to restrict or delete cookies and site storage; doing so may limit functionality or prevent certain features from working.
9.2. Categories we use (current implementation).
- Strictly necessary (no analytics consent required): When site access control is enabled, we set an HTTP-only cookie named
chatito_site_auth(about 30 days) so returning visitors stay unlocked after entering a valid access code. This cookie is used only for access control and is not used for advertising. - Functional / preference storage (first-party, local or session storage): We may store UI preferences in browser storage, for example theme or reading-mode choices on the marketing site, and product-shell preferences on dashboards/terminals (such as light/dark/system theme, markets rail state, chart layout, and short-lived wizard handoff keys). These are first-party settings that make the interface work as You left it; they are not advertising identifiers.
- Analytics (optional - consent required): We may load Google Analytics (Google tag / gtag.js) only after You choose Accept analytics in our cookie preference control. Analytics helps us understand traffic, navigation patterns, content performance, and product usage (for example page views and coarse product events such as sign-in method or strategy-create venue). If You choose Reject analytics, we do not load Google Analytics for that choice, and we make a best-effort attempt to clear common Google Analytics cookies if they were previously set. Your choice is stored in first-party local storage under the key
chatito.cookieConsent(acceptedorrejected) on the origin where You made the choice. You can change it anytime via the Cookies control in the site footer or product app (or by clearing site data in your browser).- Marketing website (chatito.com): measurement ID
G-2C0KM0GXVZ(dedicated marketing data stream). - Product app (app.chatito.com and related product hosts): measurement ID
G-0G3FECJG98(dedicated product data stream, separate from marketing). Product analytics does not intentionally send email addresses, wallet addresses, or free-text strategy names as event parameters.
- Marketing website (chatito.com): measurement ID
- Consent record: Storing Your Accept/Reject choice itself is treated as necessary to honor Your preference.
9.3. Product app surfaces (app.chatito.com and related product hosts) use first-party cookies/session tokens for authentication and first-party local/session storage for preferences and operational handoff. Optional Google Analytics on the product app uses the product measurement ID above and loads only after Accept analytics; it is a separate Google Analytics data stream from the marketing site.
9.4. We may use third-party analytics or similar measurement tools as described above. Google Analytics is provided by Google; Google may process technical data (such as IP address truncated or processed under Google’s product settings, device/browser signals, and page views) under Google’s terms and privacy policy. We do not use Google Analytics on the marketing site or product app to serve third-party ads from that tag alone. Other embedded content (videos, images, articles from third parties), if any, may behave as if You visited the originating website and may collect data under that website’s policies.
9.5. Telegram-based Bot interactions are separate from browser cookie systems, but linked websites, dashboards, terminals, and documentation may use the technologies in this section. This section applies only where You access web components.
10. Your Rights and Choices
10.1. Depending on your jurisdiction, you may have rights to request access, correction, deletion, portability, restriction, or objection, and rights related to automated decision-making and profiling. We may require reasonable verification to process requests, including to prevent fraud and protect Users. We may refuse or limit requests to the extent permitted by law, including where retention is required for legal, security, compliance, or dispute reasons.
10.2. On-chain data is generally public and immutable. We cannot delete or modify blockchain records and cannot guarantee removal of on-chain traces, including wallet addresses and transaction history that may be visible through third-party explorers and analytics.
10.3. Requests should be submitted to: info@chatito.com. Your request should include sufficient information to identify you, such as your Platform account identifier and/or Telegram handle/ID and, where relevant, wallet address(es). We may respond within a reasonable period subject to legal requirements and operational constraints, and we may request additional information.
10.4. Cookie and analytics preferences. On the marketing website and the product app, You can accept or reject optional analytics (Google Analytics) via the cookie preference control, and reopen that control from the Cookies link (site footer or product Home footer). Rejecting analytics does not block strictly necessary access cookies, session authentication, or basic functional storage required for the Services to work. You may also clear cookies and site storage through Your browser settings.
11. Children / Age Limits
11.1. The Services are not intended for individuals under 18. We do not knowingly process Personal Data of minors. If You believe a minor has provided information, contact info@chatito.com. We may restrict or terminate access consistent with the Terms.
12. Cross-Border Processing
12.1. Your information may be processed and stored in multiple jurisdictions due to global infrastructure and Third-Party Services. Where required by law, we may rely on lawful mechanisms for cross-border transfers. You acknowledge that protections may differ between jurisdictions and that cross-border processing may be necessary to operate the Services.
12.2. By using the Services, You acknowledge and accept cross-border processing to the maximum extent permitted by applicable law.
13. Changes to the Policy
13.1. We may amend, modify, supplement, or replace the Policy at any time in Our sole discretion. Any updated Policy becomes effective upon posting at chatito.com or being presented through the Services, whichever occurs first. We may provide notice through the Platform, the Bot, by posting, or by email if provided. Continued use after updates constitutes acceptance.
13.2. The Policy is intended to evolve with the Services, operational changes, legal developments, and industry practices.
14. Governing Law
14.1. To the maximum extent permitted by applicable law, the Policy (and any disputes arising out of or relating to the Policy) is governed by the laws of the Republic of Panama, without regard to conflict of laws principles, consistent with the Terms. Where mandatory local law grants non-waivable rights, those rights apply to the extent required. Nothing in the Policy is intended to waive non-waivable rights.
15. Contact
- Domain: chatito.com
- Product app: app.chatito.com
- Privacy Policy: chatito.com/privacy
- Terms: chatito.com/terms
- Data inquiries email: info@chatito.com
- Support email: info@chatito.com
