Why this page matters to us
ChatterPilot exists for one reason: the person you most want to talk to should not have to share your language. Our mission is to connect people across that gap — the new relationship that started on a dating app, the mother and son a continent apart, the small business whose customers write in a language its owner never learned. That is the work, and it means the messages passing through ChatterPilot are some of the most personal text a piece of software can touch.
We decided early that the honest way to build a product like this is to keep your linked accounts and conversation archive on your computer, send only the text needed for a translation, and never store message text in your ChatterPilot account. Most of this notice is that decision, spelled out.
Who we are
ChatterPilot is made by KOOMPANY. When this notice says “we” or “us”, that is who it means. When it says “you”, it means the person holding the account — and your data, which stays yours. ChatterPilot is for adults: accounts require you to be 18 or older.
How the product is built
ChatterPilot runs on your computer. Your message history, the names and photos of the people you talk to, and the login sessions for the services you connect are stored on your machine, in your user folder, readable by you and not by us. There is no copy on our servers. If you delete the app's local data, it is gone, and you do not need our permission or our help.
Your complete conversation archive is never copied to our servers. A requested Luna translation may pass the selected source text, your optional translation-style preference, and the recent context retained by your settings through our translation service in memory; they are not written into your account, billing record, or message database. Purchased Luna and Plus Luna use the same context rules.
What our servers do hold
Running an account takes a small amount of information, and we keep it to that. When you sign in with Google, we receive your email address and your name. Alongside those we keep your subscription state, your credit balances and how many credits you have used, any support messages you send us, and the security and diagnostic logs that let us notice abuse or a malfunction. That list is the whole inventory, and those records live on servers in the United States.
Our billing records count things — credits spent, characters translated — and are deliberately built not to contain the words themselves. We can see that you translated a 300-character message on a Tuesday. We cannot see what it said.
One more record exists so that each person gets one free trial. When your trial starts, and when you link a messaging account, the app sends us a one-way hash — a scrambled fingerprint that cannot be turned back into the original — of your sign-in identity, of the computer you signed in on, and of each messaging account you link. If one of those fingerprints has already been seen with a trial, your account continues that trial instead of starting a new one. These fingerprints contain no email address, no name, no phone number, and no raw device identifier. We use them for nothing else, and they cannot be used to look you up.
What happens when you translate
Translation requires a translator. When you translate a message, the selected source and any retained preference or context go to the engine you chose — Google Translate, or our translation service and the AI provider behind Luna — for that one request, and the answer comes back to your machine. ChatterPilot's fixed system instruction is added by the service and is not customer-billed. It happens at your instruction, and ChatterPilot does not retain the message or result in your cloud account.
Voice is different: recordings are transcribed on your own device by a local model, so audio is never uploaded anywhere. And if you use your own API keys during your free trial or with ChatterPilot Plus, those keys are stored on your computer and your requests go from your machine to your provider directly — we never see the keys or the traffic.
Payments
Stripe handles every payment. Your full card number goes to Stripe, not to us. We keep the payment and subscription records needed to manage your account and review billing requests.
What we never do
Some things are worth saying flatly. We do not sell your data. We do not rent it, share it for advertising, or profile you for anyone. We do not use your conversations to train AI models — ours or anyone else's — because they never reach us in the first place, and we do not use your account records for training either. If any of this ever changes, this page will say so before it happens, not after.
Security, and what happens if it fails
Everything that moves between your computer, our servers, and our providers travels encrypted. The desktop app stores your sign-in session using your operating system's own encryption, and the credentials that guard our infrastructure are held by the smallest number of hands we can manage. No honest company promises perfect security, so here is our promise instead: if a breach ever touches your data, we will tell you what happened, what was exposed, and what we are doing about it — quickly, and in plain language.
If the law comes asking
Governments sometimes compel companies to produce user data. If we are legally required to respond, what we can produce is what this page describes: an account record — name, email, plan, payment state, balances, and logs. Your conversation archive and linked messaging sessions are not stored on our servers. Where the law allows it, we will tell you about a request concerning your account before we answer it.
If you delete your account
Deleting your account removes your records from our systems after a 30-day window in which it can be restored, in case you did not mean it or change your mind. Your conversations were never on our servers to begin with, so there is nothing to purge there.
Existing protected identity and payment records may be retained for account recovery, disputes, fraud prevention, and accounting obligations. These records do not contain your full card number or conversation data. Signing up again after the recovery window does not restore a deleted credit balance.
How long things last
Billing records stay as long as tax and accounting law makes us keep them. Security logs stay long enough to investigate abuse and no longer. Everything else lives exactly as long as your account does, subject to the 30-day deletion window above. We do not keep data because it might be useful someday; that is how companies end up with things they regret holding.
Your rights
You can ask for a copy of what we hold about you, ask us to correct it, or have it deleted — deletion is built into the product, and the rest takes one message through the contact form. We answer within 30 days. Where your local law grants you further rights over your data, those rights stand. Please keep your private conversations out of any request; we would rather never see them.
Changes
When this notice changes, the effective date above changes with it, and changes that affect what happens to your data are announced where you will actually see them.
