Skip to content
ChimeIn

LEGAL

Privacy policy

How ChimeIn handles personal information on our website and in the ChimeIn app.

Last updated

This policy explains what personal information ChimeIn collects, why, and what you can do about it. It covers our website at joinchimein.com and the ChimeIn app at app.joinchimein.com, including the pages participants use to join sessions. In this policy, “ChimeIn”, “we” and “us” mean the team that runs ChimeIn.

The short version

  • We collect only what we need to run ChimeIn and answer you.
  • Participants can join sessions and vote without an account. By default, they don’t give a name.
  • We don’t sell personal information, and we don’t use it for advertising.
  • We use Google Analytics on our website only if you accept analytics cookies. The app doesn’t use analytics.
  • We never store raw IP addresses. Where we need one to stop abuse, we keep only a salted, one-way hash for a short time.

Our website

Contact and demo requests

When you use our contact form, we collect your name, email address, what you’d like to talk about and your message. You can also tell us your company, role and team size. We record the country your request came from, which we get from our hosting provider rather than asking you. We use this to reply to you and follow up on your request.

Spam protection

Forms are protected by Cloudflare Turnstile, which checks that a request comes from a person rather than a bot. To limit how often a form can be submitted, we keep a salted hash of your IP address for a short time. The hash can’t be turned back into your IP address, and we keep it separately from anything you write.

Analytics

If you accept analytics cookies, we use Google Analytics to understand how people find and use our website, such as which pages are visited and roughly where visitors are. If you reject them, or don’t choose, Google Analytics doesn’t load. You can change your choice at any time with Cookie settings at the bottom of every page.

The ChimeIn app

Interest list

If you join our interest list, we store your email address and use it only to tell you about ChimeIn’s launch and your access.

Accounts and sign-in

To create an account, you give us your email address. We sign you in with a one-time code sent by email instead of a password. We store only a hash of each code, and codes expire after 10 minutes. If someone invites you to their team, we store your email address and the role they chose until you accept the invitation or it expires.

Sessions, polls and responses

Hosts create sessions and write the questions and answer options. We store this content in the host’s account. Participants join with a session code and don’t need an account. We store their votes, and when they voted, with the session.

By default, participants are anonymous: no name is asked for or stored. A host can turn this off for a session, for example to pick a quiz winner. Participants in that session are then asked for a name, which the host and possibly other participants can see.

AI writing help

Hosts can ask for AI help to reword a question or suggest answer options. When they do, the question and session details are sent to an AI model run by Cloudflare Workers AI to generate suggestions. We record only that a request was made, to apply a daily limit. Participants’ responses are never sent to the AI model.

Video meetings

If you host or join a video meeting, your audio, video, screen sharing and chat are carried by Cloudflare RealtimeKit so the other people in the meeting can see and hear you. Guests give a display name when they join. On plans that include recording, a host can record a meeting.

Cookies and similar storage

We use a small number of cookies and browser storage:

  • Sign-in cookie (app): keeps you signed in for up to 30 days. Required for the app to work.
  • Participant cookie (app): a random token that lets you vote once per question and come back to a session, kept for 30 days. Required for voting to work.
  • Cookie choice (website): remembers whether you accepted analytics, kept in your browser’s local storage for 12 months.
  • Turnstile (website and app): Cloudflare’s spam check may use storage in your browser to tell people from bots.
  • Google Analytics (website only, only if you accept): _ga cookies that tell visits apart. Rejecting removes them.

We don’t use advertising cookies or cross-site tracking.

How we use information

We use personal information to:

  • provide ChimeIn: run sessions, count votes, show results and host meetings
  • sign you in and keep your account secure
  • reply to your messages and requests
  • send service emails, such as sign-in codes, invitations and launch updates you asked for
  • prevent spam, abuse and misuse, and enforce plan limits
  • understand and improve our website, when you’ve accepted analytics

Where laws such as the GDPR apply, we rely on: performing our contract with you (running the service), our legitimate interests (security, spam prevention and replying to enquiries), and your consent (analytics cookies, which you can withdraw at any time).

Service providers

We use a few trusted providers to run ChimeIn. They process data on our behalf and only to provide their service:

  • Cloudflare: hosting, database, spam protection (Turnstile), AI writing help (Workers AI) and video meetings (RealtimeKit).
  • Resend: sending sign-in codes and other service emails.
  • Google: website analytics, only with your consent, and the web fonts our website uses.

These providers may process data in countries other than yours, including the United States. Where the law requires it, we rely on appropriate safeguards for these transfers, such as the providers’ standard contractual clauses.

We may also disclose information if the law requires it, to protect people’s safety, or as part of a sale or reorganisation of ChimeIn. If that happens, this policy continues to apply to your information.

How long we keep data

  • Sign-in codes expire after 10 minutes and can be used only once.
  • IP address hashes used to stop abuse are deleted after about an hour.
  • Sign-in sessions end after 30 days without use, or when you sign out.
  • Accounts and session content, including polls and responses, are kept while the account exists. If you ask us to delete your account, we delete its sessions and responses too.
  • Contact requests and interest list emails are kept as long as we need them to follow up, and deleted when you ask.

Security

All traffic uses HTTPS. We store sign-in codes and session tokens only as hashes, never store raw IP addresses, and keep abuse-prevention data separate from the content you write. No system is perfectly secure, but we work to protect your information and will tell you if a breach affects you, as the law requires.

Your choices and rights

You can ask us to access, correct, delete or export your personal information, or to stop using it. Depending on where you live, laws such as the GDPR, UK GDPR or California privacy laws may give you these rights and others, including the right to object and to complain to your local data protection authority. We’ll honour reasonable requests wherever you live.

To make a request, email [email protected]. We may need to confirm your identity first. If you took part in a session as a participant, let us know the session so we can find your responses. Anonymous responses can’t be linked back to you, so we may not be able to identify them.

You can withdraw analytics consent at any time with Cookie settings at the bottom of this page.

Children and schools

ChimeIn accounts are for adults. We don’t knowingly create accounts for children under 16. Students may take part in sessions run by their teachers without an account. Sessions are anonymous by default, and schools that turn on names are responsible for doing so appropriately. If you believe a child has given us personal information, contact us and we’ll delete it.

Changes to this policy

We’ll update this policy when our practices change and change the date at the top. If a change is significant, we’ll tell account holders by email or in the app before it takes effect.

Contact us

Questions about privacy or this policy? Email [email protected] or use ourcontact form.