Privacy Policy
Effective Date: August 11, 2026
Chaos To Intention, LLC, a North Carolina limited liability company ("we," "us," or "our") operates the Chaos To Intention application ("CTI," "the Service") accessible at my.chaostointention.com. This Privacy Policy describes how we collect, use, and protect your information when you use our Service.
By creating an account or using CTI, you agree to the collection and use of information as described in this policy.
1. Information We Collect
Account Information
When you create an account, we collect:
- Email address — used for authentication, account recovery, and service communications
- Password — stored in hashed form by our authentication provider (Firebase Authentication); we never have access to your plaintext password
- First name and last name — used for personalization, delegation display names, and profile identification
- Profile photo — optionally uploaded by you or imported from Google Contacts; stored in Firebase Storage
Content You Create
When you use CTI, you create and store:
- Tasks, notes, and their descriptions
- Contexts (people, places, and things)
- Projects, areas, and domains (your organizational taxonomy)
- File attachments, images, and slide presentations
- Delegation messages exchanged with other users
- Support messages submitted through the in-app help feature
This content is created by you and stored to provide the Service. We do not access, review, or use your content for any purpose other than delivering the Service to you.
Organizational Preferences
During onboarding, you provide information about your life areas, domains, and organizational structure. This data helps CTI organize your experience and may reveal personal life categories and priorities. It is treated with the same protections as all other content you create.
Google Calendar Data
If you choose to connect a Google Calendar account, we access your calendar data in read-only mode. We collect:
- Calendar names and identifiers
- Event titles, descriptions, dates, times, and locations
We do not modify, delete, or write any data to your Google Calendar. Calendar data is synced periodically to your account within CTI to display alongside your tasks. You can disconnect your Google Calendar integration at any time from within the app, which stops all future syncing.
Google Contacts Data
If you choose to import contacts, we access your Google Contacts data in read-only mode through the Google People API. We collect:
- Contact names, email addresses, phone numbers, addresses, and organizations
- Contact profile photos
Contact data is imported only when you explicitly initiate the import process, not automatically or on a schedule. We do not modify, delete, or write any data to your Google Contacts.
Voice Input
When you use voice input, audio is processed by your browser's built-in speech recognition (Web Speech API). We receive only the transcribed text, not the audio recording itself. No audio is sent to or stored on our servers.
Website Email Capture
If you provide your email address on our marketing website (chaostointention.com), we collect it for product updates and communications. This is separate from account registration and is not linked to a CTI account unless you subsequently create one.
Forum Session Data
If you register for live forum sessions, we collect registration information including session preferences and training topic selections.
Automatically Collected Information
We store the following in your browser's local storage to preserve your preferences between sessions:
- Navigation state and UI settings (such as which sidebar sections are expanded)
- Display preferences (such as color theme and filter selections)
- Editor state (such as undo/redo history)
This data is stored only in your browser, is never transmitted to our servers, and is automatically cleared when you sign out.
We do not use cookies, tracking pixels, web beacons, or any third-party analytics or advertising services. We do not track you across websites.
2. How We Use Your Information
To operate the Service for you
- Provide the Service — store and display your tasks, calendar events, contacts, and organizational structure
- Authenticate your account — verify your identity when you sign in
- Sync calendar data — retrieve your Google Calendar events on a periodic schedule when you have connected an integration
- Import contacts — retrieve and organize your Google Contacts data when you explicitly initiate an import
- Provide AI-assisted features — classify and organize your data, assess progress, and improve suggestions using artificial intelligence (see Section 4)
- Facilitate delegation — enable task sharing, messaging, and coordination between you and other CTI users you choose to collaborate with
- Process payments — when subscription plans are active, process billing through Stripe. We do not store your full payment details
- Generate derived intelligence — create AI-powered classifications, suggestions, and assessments based on your content to enhance your organizational experience. This derived data exists solely within your account
- Manage forum sessions — process registrations, track session preferences, and coordinate scheduling for live forum sessions
To communicate with you
- Transactional communications — send password reset emails, account verification emails, and essential service notifications
- Product updates — with your consent, send newsletters, feature announcements, or other marketing communications. You may opt out at any time by contacting us at support@chaostointention.com or by using an unsubscribe link if one is provided in the email
- Process support requests — receive and respond to your in-app support messages
To protect the Service and comply with law
- Enforce our terms — investigate potential violations of our Terms of Service
- Comply with law — respond to legal requests, enforce our rights, and protect the safety of our users
- Improve the Service — use aggregated, anonymized statistics that cannot identify you to understand usage patterns and improve features. We never use your individual content for this purpose
What we do NOT do
- We do NOT sell, rent, or trade your personal information to third parties
- We do NOT transfer your data to advertising platforms, data brokers, or information resellers
- We do NOT use your content to train AI models
- We do NOT display advertising or share data with advertisers
- We do NOT track you across other websites or services
- We do NOT build profiles of you for third-party use
- We do NOT access your content except as needed to operate the Service
- We do NOT use your data to determine credit-worthiness or for lending purposes
3. Cross-User Data Sharing
CTI shares data between users only when you explicitly initiate or accept a task delegation. We never share your data with other users without your direct action.
What is shared. During an active delegation, both parties can see data directly related to the delegated task, including task content, associated files, and messages.
Email address visibility. When initiating a delegation, you provide the other person's email address. The Service confirms whether that email is associated with a CTI account. This limited disclosure is necessary for delegation to function, but it means a user can confirm whether a specific email address has a CTI account.
What is NOT shared. Your organizational taxonomy, areas, domains, projects, contacts, calendar events, notes, AI-derived assessments, and all other account data remain private regardless of delegation activity.
Duration. Data sharing lasts only for the duration of the active delegation. When a delegation ends, the other party's access to your task data is removed.
Message retention. Messages exchanged during a delegation are retained for both parties as part of the delegation record, even after the delegation ends. Either party can request deletion of the delegation record through account management.
No bulk data exposure. Delegation is task-by-task. There is no mechanism to share your entire account, export another user's data, or gain broad access to another user's information.
Your control. You choose whether to delegate, whom to delegate to, and you can end a delegation at any time. No one can access your data through delegation without your participation.
4. AI-Assisted Features
CTI uses artificial intelligence to help organize your data and improve your experience.
Scope. AI features include classification and organization of your data, progress assessment, and continuous improvement of suggestions based on your usage.
Data sent for processing. We send only the minimum data necessary for each AI operation. Data categories include: task and event content, your organizational structure (area and project names), and entity names (people, places, things you have created).
AI provider. Our current AI provider is Anthropic. If we change AI providers, we will update this policy and the new provider will be held to equivalent data protection standards.
What the AI provider receives. Your AI provider receives data for real-time processing and returns results. They do not have access to your account or identity. Processing occurs through our secure server-side infrastructure (Google Cloud Functions); no data is sent directly from your browser to any AI provider.
Data retention by AI provider. By default, inputs and outputs may be retained by our AI provider for up to 30 days for operational purposes, after which they are automatically deleted. In rare cases where content is flagged by automated safety systems, it may be retained for up to 2 years. We do not currently have a zero data retention (ZDR) arrangement with our AI provider.
No model training. Retained data is never used for model training without express permission. We have not granted such permission.
What stays on our servers. The results of AI processing (classifications, suggestions, assessments) are stored within your account on our infrastructure. These results are Your Content, governed by all the same protections as content you create directly.
No human review. Your data is processed by AI systems only. No Chaos To Intention personnel review your content as part of normal operations. Operational logs may contain metadata about AI processing results for diagnostic purposes, but not your source content. The only exceptions are: (1) if you contact us through in-app support and share information voluntarily, (2) if required to investigate a Terms of Service violation with evidence, or (3) if required by law.
Account-specific learning. The Service learns from your usage and corrections to improve suggestions over time. These improvements are specific to your account and are not shared with other users, not sent to our AI provider, and not used to train any external model.
For more details on AI data processing, see Section 13 of our Terms of Service.
5. Third-Party Services
We use the following third-party services to operate CTI:
| Function | Provider | Data Shared |
|---|---|---|
| Authentication | Firebase Auth (Google) | Email, password (hashed) |
| Task and note storage | Firebase Realtime Database (Google) | Your tasks and notes |
| Organizational data | Cloud Firestore (Google) | Contexts, projects, settings, delegation records |
| File storage | Firebase Storage (Google) | Attachments, photos, slides |
| Calendar sync | Google Calendar API | OAuth tokens (server-side) |
| Contact import | Google People API | OAuth tokens (server-side) |
| AI processing | Anthropic (current provider) | Task/event content, organizational structure |
| Payment processing | Stripe | Payment details (direct to Stripe) |
| Email delivery | Microsoft Graph API | Recipient email, message content |
| Forum scheduling | Microsoft Bookings (Azure AD) | Session data, registrations |
| Server-side processing | Google Cloud Functions | Intermediary for API calls |
| Voice transcription | Web Speech API (browser-native) | Audio processed locally by browser |
We select third-party providers who maintain security and privacy practices appropriate to the data they process. We require that providers use your data only to perform services on our behalf and not for their own purposes. If we add or change providers, we will update this policy.
Each provider operates under their own privacy policies and terms of service. We encourage you to review:
- Google Cloud Privacy Notice
- Google API Services User Data Policy
- Anthropic Privacy Policy
- Stripe Privacy Policy
- Microsoft Privacy Statement
6. Data Storage and Security
Storage locations. Your account data and organizational content are stored on Google's Firebase infrastructure in the United States. Files and media are stored in Firebase Storage in the United States. Payment information is held directly by Stripe and is not stored on our servers. Emails are processed through Microsoft's infrastructure.
Access controls. Your data is accessible only to you and to users you explicitly share with through delegation. Our systems enforce authentication and authorization checks on every data access. No other CTI user can access your data without your action.
No employee access to your content. No Chaos To Intention personnel access your content as part of normal operations. Exceptions: (1) if you contact us through in-app support and share information voluntarily, (2) if required to investigate a Terms of Service violation with evidence, or (3) if required by law. Human access to data obtained through Google APIs is further limited in accordance with Google's API Services User Data Policy. All exceptions are logged.
Administrative safeguards. We limit access to production systems, use strong authentication for administrative access, and review access controls as part of ongoing operations. We implement reasonable safeguards appropriate to the size and nature of our organization to protect your data.
Infrastructure security. Our infrastructure providers (Google Cloud, Firebase) maintain SOC 2, ISO 27001, and other industry certifications for their platforms. Our security benefits from their investments in physical security, network security, and operational controls.
Encryption. All data is encrypted in transit (HTTPS/TLS). All stored data is encrypted at rest by Firebase. Authentication credentials are hashed and salted by Firebase Auth. Payment data is encrypted by Stripe per PCI DSS requirements.
Vulnerability management. We keep our application dependencies updated and address known security vulnerabilities in a timely manner.
Honest limitations. While we implement reasonable safeguards and rely on infrastructure providers with strong security track records, no system is completely immune to security risks. We cannot guarantee absolute security of your data.
7. Data Breach Notification
In the event of a security breach that results in unauthorized access to your personal information, we will notify affected users as promptly as reasonably practicable.
Notification method. We will notify you by email to the address associated with your account. If the breach affects a large number of users, we may also post a notice on our website.
What we will tell you. Notification will include: a description of what happened, the types of data involved, what steps we are taking in response, and what steps you can take to protect yourself (such as changing your password).
Timeline. We will notify affected users without unreasonable delay, and in any event within the timeframes required by applicable law.
Law enforcement exception. Notification may be delayed if law enforcement determines that notification would impede a criminal investigation. We will provide notification as soon as the delay is no longer necessary.
Scope. This commitment covers data in our control and our infrastructure providers' systems. We are not responsible for breaches of third-party services you connect to CTI (such as your Google account).
8. Data Retention
We retain your data for as long as your account is active. Specific retention details:
- Account data — retained until you request account deletion
- Tasks, contexts, projects, and notes — retained until you delete them individually or request account deletion
- Google Calendar data — retained until you disconnect your integration or request account deletion
- Google Contacts data — retained until you delete imported contacts individually or request account deletion
- Attachments and files — retained until you delete them individually or request account deletion
- Browser local storage — automatically cleared when you sign out
- Backup copies — after you delete content or your account, residual copies may remain in our backup systems for up to 30 days before being permanently removed. Backups exist solely for disaster recovery and are not used for any other purpose
- Delegation data — when a delegation ends, your access to the other party's task data is removed immediately. Delegation message history is retained for both parties. Upon account deletion, we will remove or anonymize your identifying information from delegation records within a reasonable timeframe
- Support messages — retained for as long as your account is active plus 12 months after account deletion, to allow reference for dispute resolution or if you reactivate
- Website email captures — retained until you unsubscribe or request deletion. Not linked to a CTI account unless you subsequently create one
- AI-derived data — classifications, suggestions, and learned patterns generated by the Service are deleted when the underlying content is deleted or when your account is deleted. They do not persist independently of your content
- Payment records — billing history and transaction records are retained for the period required by applicable tax and financial reporting laws (typically 7 years), even after account deletion. Payment details (card numbers, billing address) are held by Stripe and governed by their retention policy
- Aggregated data — anonymized, aggregated statistics that were derived from your usage before deletion may be retained indefinitely, as they cannot be re-identified to you
Account deletion. Upon receiving a deletion request, we will begin processing within a reasonable timeframe. We will confirm completion by email. Deletion is permanent and cannot be reversed.
9. Your Rights
You have the right to:
- Know what personal information we collect, how we use it, and with whom we share it. This Privacy Policy is our primary disclosure. You may also contact us for additional detail about your specific data
- Access your data — all your data is visible to you within the app
- Correct your data — you can edit any content you have created
- Delete your data — you can delete individual tasks, contexts, projects, calendar events, attachments, and other content within the app
- Delete your account — contact us at support@chaostointention.com to request complete account deletion, including all associated data
- Request a copy — you may request a portable copy of your data in a commonly used format
- Restrict processing — where technically feasible, we will limit processing of disputed data while we investigate your concern
- Withdraw consent — where our processing is based on your consent (such as marketing communications or optional integrations), you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal
- Non-discrimination — we will not deny you service, charge you different prices, or provide a different quality of service because you exercised any of your privacy rights
- Disconnect integrations — you can disconnect your Google Calendar and Google Contacts integrations at any time from within the app
- Opt out of marketing — you can unsubscribe from marketing communications at any time
How to exercise your rights. All rights can be exercised by contacting us at support@chaostointention.com. We will verify your identity before processing any request. We will respond within a reasonable timeframe.
Self-service. Many rights can be exercised directly within the app without contacting us: viewing your data, editing your data, deleting individual items, disconnecting integrations, and managing marketing preferences. We encourage self-service as the fastest path.
10. State Privacy Laws
California (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act. These include the right to know what personal information we collect, sell, or share; the right to delete; the right to opt out of the sale or sharing of personal information; and the right to non-discrimination.
We do not sell or share your personal information as defined by California law. Because we do not sell data, there is no "Do Not Sell" toggle to offer. California residents may contact us to exercise any CCPA/CPRA right.
Virginia (VCDPA)
Virginia residents have rights to access, correct, delete, obtain a copy of, and opt out of targeted advertising and the sale of personal data. We do not engage in targeted advertising or sell personal data.
Colorado (CPA)
Colorado residents have similar rights to Virginia, including opting out of profiling in furtherance of decisions that produce legal or similarly significant effects. We do not engage in such profiling.
Other States
Several additional states have enacted or are enacting privacy laws with similar consumer rights. If your state of residence grants you privacy rights beyond those described in this policy, we will honor those rights. Contact us at support@chaostointention.com and reference your state's privacy law, and we will respond in accordance with its requirements.
Authorized Agents
Where permitted by applicable law, you may designate an authorized agent to exercise your privacy rights on your behalf. We may require verification of the agent's authority before processing the request.
Appeals
If we decline a privacy rights request, we will explain why and provide instructions for how to appeal the decision.
11. International Data Transfers
Data location. Your data is stored and processed in the United States on Google's Firebase infrastructure. If you access the Service from outside the United States, your data will be transferred to the United States.
Legal basis. By using the Service, you consent to the transfer of your data to the United States. You acknowledge that US data protection laws may differ from those in your country of residence.
EU/EEA/UK users. If you are located in the European Economic Area or United Kingdom, we rely on your explicit consent as the legal basis for transferring your data to the United States. Our infrastructure provider (Google) maintains appropriate safeguards for international transfers, including Standard Contractual Clauses.
No active targeting. We do not currently target or market the Service to users outside the United States. If we expand internationally, we will update this policy to address applicable data protection requirements.
Honest scope. We are a US-based service. While we respect the privacy principles embodied in international data protection frameworks, we do not currently represent full compliance with GDPR or other international privacy regulations. If compliance with your country's data protection laws is a requirement for your use, please contact us to discuss before creating an account.
12. Children's Privacy
CTI is designed for adults. The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from individuals under 18.
If we become aware that we have collected personal information from an individual under 18, we will take prompt steps to delete that information. If you are a parent or guardian and believe your child has provided personal information to us, please contact us at support@chaostointention.com.
We do not employ age verification technology. We rely on users to provide accurate information about their age during registration.
13. Changes to This Policy
Material changes. We distinguish between material changes (changes to how we collect, use, or share your data) and non-material changes (clarifications, formatting, corrections). Material changes require active notification; non-material changes take effect upon posting.
Notification. For material changes, we will make reasonable efforts to notify you by email to the address associated with your account, in addition to posting the updated policy on our website.
Opt-out right. If you disagree with a material change, you may delete your account. Your continued use after reasonable notice constitutes acceptance of the revised policy.
Previous versions. Previous versions of this policy are available upon request.
No retroactive changes. Changes apply prospectively only. Data collected under a prior version of this policy continues to be governed by the terms under which it was collected.
14. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
Chaos To Intention, LLC
A North Carolina limited liability company
Email: support@chaostointention.com
Privacy inquiries: support@chaostointention.com (include "PRIVACY" in subject line)
Last updated: August 4, 2026