Privacy Notice

This notice explains how Chains handles personal data for the personal experimental free beta.

Controller

The data controller is Andrey Kovlyagin, acting as an individual maintainer of Chains. Chains is not presented as a registered company product in this beta.

For privacy requests, deletion requests, or other data questions, email privacy@chains.design .

Request-access data

The public request-access form collects your email address and, if you choose to write it, an optional short workflow note.

This data is used only to review beta access requests and send early-access invites. It is not used for newsletters, marketing messages, advertising, analytics, tracking, profiling, or sale/sharing with third parties.

The legal basis for request-access processing is your consent. Request-access submissions are retained for 6 months unless you ask for deletion earlier.

Beta account and product data

If you later receive an invite and create a beta account, Chains may process account, authentication, team, project, workflow, file, comment, and activity data needed to provide the beta app.

This notice does not enable paid services, advertising, marketing email, or optional browser analytics. Those require separate review before they are introduced.

Authenticated product analytics

Chains uses limited server-side product analytics to understand whether beta users can configure templates, create chains, approve review phases, and invite team members. This processing uses internal user and team identifiers, the user's role, the successful product action, and whether a phase approver authored the approved commit. It does not include names, email addresses, file names, uploaded content, comments, or free text.

The legal basis is the controller's legitimate interest in measuring, maintaining, and improving the experimental beta. Product analytics events are retained for up to 6 months.

PostHog processes these events on behalf of Chains. Events are stored in PostHog EU Cloud in Frankfurt. PostHog and its subprocessors may perform limited processing outside the EEA under the safeguards in the PostHog Data Processing Agreement, including the EU-US Data Privacy Framework and Standard Contractual Clauses. Server-side product analytics does not place analytics cookies or analytics identifiers in your browser.

Cookies, storage, and analytics

The public marketing site does not use optional browser analytics, advertising pixels, session replay, autocapture, or tracking cookies for the MVP.

The authenticated app may use strictly necessary authentication and security storage to provide sign-in and beta app access.

Operational logs

The public marketing routes may use short-retention operational logs to count visits and diagnose service issues. These public access logs do not store raw IP addresses, query strings, cookies, request bodies, email addresses, or workflow notes.

Public raw access logs are retained for 14 days. Host nginx error logs used for operations and security diagnostics are retained for 30 days.

Processors and vendors

Processors may include Supabase for authentication and database storage, PostHog for authenticated product analytics, hosting infrastructure for serving the site and app, and email providers used to send beta access invites.

Final provider names, data-processing agreements, subprocessors, and data-transfer details are reviewed before the relevant processing is enabled in production.

Your rights

You can ask to access, correct, delete, or export your personal data, or object to authenticated product analytics based on legitimate interests, by emailing privacy@chains.design . You can also withdraw request-access consent by asking for your request to be deleted.

Related consent page

For the short consent text specific to the request-access form, see the Consent Policy .

Last updated

June 30, 2026.