Effective Date: April 26, 2026
Privacy Policy
ChromaAI ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how your personal information is collected, used, and disclosed by ChromaAI.
This Privacy Policy applies to our website chromacolorai.com and its associated subdomains (collectively, our "Service") alongside our application, ChromaAI. By accessing or using our Service, you signify that you have read, understood, and agree to our collection, storage, use, and disclosure of your personal information as described in this Privacy Policy and our Terms of Service.
Definitions and Key Terms
To help explain things as clearly as possible in this Privacy Policy, every time any of these terms are referenced, they are strictly defined as:
- Cookie: a small amount of data generated by a website and saved by your web browser. It is used to identify your browser, provide analytics, and remember information about you such as your language preference or login information.
- Company: when this policy mentions "Company," "we," "us," or "our," it refers to ChromaAI, that is responsible for your information under this Privacy Policy.
- Country: where ChromaAI or the owners/founders of ChromaAI are based, in this case Israel.
- Customer: refers to the person or entity that signs up to use the ChromaAI Service.
- Device: any internet-connected device such as a phone, tablet, computer, or any other device that can be used to visit ChromaAI and use the Service.
- IP Address: Every device connected to the Internet is assigned a number known as an Internet Protocol (IP) address. These numbers are usually assigned in geographic blocks. An IP address can often be used to identify the general location from which a device is connecting to the Internet.
- Personnel: refers to those individuals who are employed by ChromaAI or are under contract to perform a service on behalf of ChromaAI.
- Personal Data: any information that directly, indirectly, or in connection with other information allows for the identification or identifiability of a natural person.
- Service: refers to the AI-powered color grading service provided by ChromaAI.
- Third-party service: refers to providers we use to operate the Service, such as hosting, payment processing, and analytics partners.
- Website: ChromaAI's site, accessible at chromacolorai.com.
- You/User: a person or entity that is registered with ChromaAI to use the Service.
What Information Do We Collect?
We collect information from you when you visit our website, register on our site, subscribe to our newsletter, or upload media for processing through the Service.
- Name / Username
- Email Address
- Password (encrypted)
- Video frames and images uploaded for color grading analysis
- LUT files generated by the Service
- Camera profile preferences and grading parameters
- Usage logs (which features are used, frequency, and patterns)
- Payment is processed by our third-party payment provider (Paddle). We do not store your full credit card details on our servers. We only retain transaction records and the last 4 digits of the card for billing reference.
- IP address, browser type, device type, operating system
- Referring URL and pages visited
- Cookies and similar tracking technologies
How Do We Use the Information We Collect?
Any of the information we collect from you may be used in one of the following ways:
- To provide, maintain, and improve the Service
- To personalize your experience and improve color grading recommendations
- To process transactions and manage your subscription
- To respond to customer service requests and support needs
- To send transactional emails (account updates, billing, security notices)
- To send periodic marketing emails (only with your consent — you can unsubscribe at any time)
- To detect, prevent, and address technical issues, fraud, and abuse
- To comply with legal obligations
How Do We Use Your Email Address?
By creating an account, you agree to receive transactional emails from us related to your account, subscription, and the Service. You may opt out of marketing communications at any time by clicking the unsubscribe link in any marketing email.
We do not send unsolicited commercial emails. We will never sell or share your email address with unrelated third parties for marketing purposes.
Do We Share the Information We Collect with Third Parties?
We do not sell your personal information. We may share information with the following categories of third-party service providers, only as necessary to operate the Service:
- Cloud infrastructure providers — for storing data and operating the platform
- Payment processor (Paddle) — for handling subscriptions and billing
- Analytics providers — for understanding how the Service is used
- Email service providers — for sending transactional and marketing emails
- Support platforms — for managing support requests
We may also disclose information about you to government or law enforcement officials when we believe in good faith that disclosure is necessary to comply with applicable laws, respond to lawful requests, protect our rights, or prevent harm.
If ChromaAI is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your personal information is transferred and becomes subject to a different privacy policy.
How Long Do We Keep Your Information?
We retain your personal information only for as long as necessary to provide the Service and fulfill the purposes described in this policy:
- Account data: retained while your account is active and for up to 24 months after account deletion (for legal and accounting purposes)
- Billing records: retained for 7 years to comply with Israeli tax law
- Generated content (LUTs, grades): retained as long as your account is active. You can delete individual items at any time
- Marketing preferences: retained until you unsubscribe
How Do We Protect Your Information?
We implement a variety of security measures to maintain the safety of your personal information:
- All data transmission is encrypted via SSL/TLS
- Passwords are stored using industry-standard hashing algorithms
- Payment information is handled by PCI-DSS compliant payment processors
- Access to personal data is restricted to authorized personnel only
Despite our best efforts, no method of transmission or electronic storage is 100% secure. We cannot guarantee absolute security.
International Data Transfers
ChromaAI operates from Israel. Information collected may be transferred to and processed in countries other than your own, including the United States and European Union, where our service providers operate.
We ensure that transfers of personal data are protected by appropriate safeguards, such as Standard Contractual Clauses approved by the European Commission, in compliance with the EU-US Data Privacy Framework where applicable.
Can I Update or Correct My Information?
You have the right to request updates, corrections, or deletion of your personal information at any time. You can:
- Update your profile information through your account settings
- Request data export (a copy of all personal data we hold about you)
- Request data deletion by closing your account
- Contact us through our website contact form for any privacy-related request
Some data may persist in backups for a limited period before being permanently deleted. We will respond to all requests within 30 days.
Sale of Business
We reserve the right to transfer information to a third party in the event of a sale, merger, or other transfer of all or substantially all of the assets of ChromaAI, provided that the third party agrees to adhere to the terms of this Privacy Policy.
Governing Law
This Privacy Policy is governed by the laws of Israel without regard to its conflict of laws provisions. You consent to the exclusive jurisdiction of the courts of Israel in connection with any action or dispute arising under or in connection with this Privacy Policy.
By using ChromaAI, you signify your acceptance of this Privacy Policy. If you do not agree to this Privacy Policy, you should not use our Service.
Your Consent
By using ChromaAI, registering an account, or making a purchase, you hereby consent to our Privacy Policy and agree to its terms.
Links to Other Websites
This Privacy Policy applies only to the Services. The Services may contain links to other websites not operated or controlled by ChromaAI. We are not responsible for the content or privacy practices of such websites. We encourage you to read the privacy policies of any third-party websites you visit.
Cookies for Advertising
We may use cookies for advertising purposes. These cookies collect information over time about your online activity on the website and other online services to make online advertisements more relevant and effective to you (interest-based advertising). They also perform functions like preventing the same ad from continuously reappearing.
Cookies
ChromaAI uses cookies to identify the areas of our website that you have visited. A cookie is a small piece of data stored on your computer or mobile device by your web browser. We use cookies to enhance the performance and functionality of our website. Most web browsers can be set to disable the use of cookies. However, if you disable cookies, you may not be able to access functionality on our website correctly or at all. We never place Personally Identifiable Information in cookies.
Blocking and Disabling Cookies
You may set your browser to block cookies, but this may prevent our website from functioning properly. You may also lose some saved information (such as login details and site preferences). Different browsers make different controls available — please consult your browser's help menu for more information.
Remarketing Services
We may use remarketing services from time to time. Remarketing (or retargeting) is the practice of serving ads across the internet to people who have already visited your website. If you wish to opt out of personalized advertising, you can do so through your browser settings or through the platforms' opt-out tools.
Payment Details
Payment processing is handled by our third-party payment provider, Paddle, which acts as the Merchant of Record. We do not store full credit card details on our servers. All payment information is transmitted via secure, PCI-DSS compliant systems.
Kids' Privacy
ChromaAI is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from anyone under the age of 16. If you are a parent or guardian and you are aware that your child has provided us with personal data, please contact us. If we become aware that we have collected personal data from anyone under the age of 16 without verification of parental consent, we will take steps to remove that information from our servers.
Changes to Our Privacy Policy
We may change our Service and policies, and we may need to make changes to this Privacy Policy. We will notify you (for example, through our Service or by email) before making material changes and give you an opportunity to review them. If you continue to use the Service after changes take effect, you will be bound by the updated Privacy Policy. If you do not agree to any updated Privacy Policy, you can delete your account.
Third-Party Services
We may display, include, or make available third-party content, including data, applications, and services, or provide links to third-party websites or services ("Third-Party Services").
You acknowledge and agree that ChromaAI shall not be responsible for any Third-Party Services, including their accuracy, completeness, timeliness, validity, copyright compliance, legality, decency, quality, or any other aspect thereof. ChromaAI does not assume and shall not have any liability or responsibility for any Third-Party Services.
Information about General Data Protection Regulation (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, this section explains how your personal data is collected and protected under GDPR.
What is GDPR?
GDPR is an EU-wide privacy and data protection law that regulates how EU residents' data is protected by companies and enhances the control EU residents have over their personal data. We have implemented GDPR controls as our baseline standard for all operations worldwide.
Data Protection Principles We Follow
- Personal data must be processed in a fair, legal, and transparent way
- Personal data is only collected for specific purposes and used only for those purposes
- Personal data is held no longer than necessary
- You have the right to access, update, delete, restrict, or move your personal data
Your Rights Under GDPR
- Request a copy of your personal data
- Request correction of inaccurate data
- Request deletion of your data
- Request that we limit how we use your data
- Receive your data in a structured, commonly used format
- Object to certain types of processing, including direct marketing
- Withdraw consent at any time where processing is based on consent
- Lodge a complaint with your local data protection authority
To exercise any of these rights, please contact us through our website contact form. We will respond within 30 days.
California Residents (CCPA)
The California Consumer Privacy Act (CCPA) grants California residents specific rights regarding their personal information:
- Request information about the categories of personal information we collect, use, or share
- We will not discriminate against you for exercising your privacy rights
- Request deletion of your personal information
- We do not sell personal information of our users
If you make a request, we will respond within 45 days. To exercise these rights, please contact us through our website contact form.
Contact Us
For any privacy-related questions or requests, please use our Contact Form.