Privacy Policy
Last updated: April 15, 2026
1. Introduction
ChudoII is a mobile and web application for multi-AI chat. The service lets you send one prompt to several language models at once and compare their answers. This Policy explains what data we collect, how we use it and what rights you have. It applies to all users of our Android app, the web version at chudoii.com and the backend API.
2. Data controller
The data controller is the ChudoII team. Our registration with Roskomnadzor as a personal data operator is in progress. For any data-related question, please write to privacy@chudoii.com or support@chudoii.com.
3. What data we collect
We only collect data that is strictly necessary to deliver the service.
Account data
- Name (optional)
- Email address
- Password hash (bcrypt, factor 12) — we never store the plaintext
- Profile picture (optional)
- Preferred interface language
Usage data
- Content of your conversations with AI models (prompts and answers)
- Metadata: timestamps, selected model, token counts
- Daily usage counter (daily_usage) to enforce plan limits
- Chat history for easy navigation
Technical data
- IP address
- User-Agent and device type
- App and Android OS version
- Anonymised device identifier used for abuse prevention
Payment data
Payments are handled by Lava.top. We never see or store card details. Lava.top only shares with us: the customer identifier (lava_customer_id), plan name, amount, payment date and subscription status.
4. Legal basis for processing
We process personal data on the following grounds:
- Consent — given when you create an account
- Performance of a contract — to give you access to the AI models and paid features
- Legitimate interest — for security, fraud prevention and product improvement
- Legal obligation — including Russian Federal Law 152-FZ on Personal Data
5. How we use data
- Delivering the service: forwarding your prompts to the selected AI models and returning their answers
- Enforcing plan limits and keeping your chat history
- Content moderation — automated detection of prohibited or abusive material
- Customer support and replies to your enquiries
- Product improvement via aggregated, anonymised statistics
- Transactional emails via Resend (payment receipts, password reset, critical updates)
We do not use the content of your conversations to train our own or any third-party AI models.
6. Who we share data with
We share the minimum amount of data required with a short list of trusted providers:
- OpenRouter — AI model aggregator (GPT-4o, Claude, Gemini, Llama and more). Receives the text of your prompt to return the selected model's answer.
- Google — Only if you choose Google Sign-In — Google shares your email and account ID with us.
- Lava.top — Payment provider. Handles ruble payments and returns your subscription status and customer identifier.
- Resend — Email delivery service for transactional emails (receipts, security notifications).
We do not sell your data. We do not run ads and we do not share data with advertising networks.
7. Where your data lives
- Servers located in Russia (Selectel, Moscow data center)
- Backups are encrypted and stored on Selectel S3 (Moscow)
- We do not transfer personal data of Russian citizens outside of the Russian Federation — in line with Article 18 of Federal Law 152-FZ
8. Retention periods
- Active accounts — for as long as you use the service
- Deleted accounts — full cascade delete within 30 days (backups may contain your email for up to 7 more days)
- Payment logs — 5 years, as required by Russian tax law
- Technical logs without direct identifiers — 90 days
9. Your rights
Under Russian Federal Law 152-FZ (and aligned with GDPR principles) you have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and all linked data
- Receive a copy of your data in a machine-readable format (JSON export)
- Withdraw your consent to data processing
- Lodge a complaint with the data protection authority (Roskomnadzor)
To exercise any of these rights, email privacy@chudoii.com from the address linked to your account. We respond within 30 days.
10. Children
ChudoII is not directed at users under 14. We do not knowingly collect data from children below that age. If we become aware of such an account, we will close it and contact the parents.
11. Cookies and tracking
- Session cookies — strictly necessary for authentication
- We do not use advertising cookies or cross-site tracking
- We do not embed aggressive analytics trackers (e.g. Facebook Pixel)
12. Security
- All traffic is encrypted with HTTPS (TLS 1.2+)
- Passwords are stored as bcrypt hashes with factor 12
- JWT tokens have a short lifetime and are rotated
- Hosting in certified Russian data centers
- Only admins with 2FA have access to production data
No system is perfectly secure. If an incident affects your data, we will notify you within 72 hours.
13. Changes to this Policy
We publish material changes to this Policy here and send an email notification 30 days before they take effect. The last-updated date always appears at the top of this page.
14. Contact
For data protection questions: privacy@chudoii.com. General support: support@chudoii.com.
15. Russian 152-FZ notice
- Applicable law — the Russian Federation
- Roskomnadzor registration as a personal data operator — in progress (registry number will appear here once issued)
- Initial collection and storage of Russian citizens' data is performed on servers located in Russia
- Supervisory authority — Roskomnadzor, https://rkn.gov.ru