Privacy Policy
Mataki Labs LLC (“Chimatic,” “we,” “us,” or “our”), a Wyoming limited liability company, operates the chimatic.dev website, the Chimatic Cloud platform, and related services (collectively, the “Services”). This Privacy Policy explains how we collect, use, disclose, and protect information when you use our Services.
By using our Services, you agree to the collection and use of information as described in this policy.
Information We Collect
Information You Provide
When you create an account, subscribe to a plan, or contact us, we may collect:
- Account information: Name, email address, password (hashed), and company or organization name
- Billing information: Payment method details are collected and processed by our payment processor (Stripe). We do not store full credit card numbers on our servers.
- Communications: Any information you include when you contact us via email, support tickets, or Discord, including your name, email address, and message content
- API keys and configuration: Provider integration configurations, notification channel settings, callback URL settings, and other content you create through the Services
- Notification data: Event data, notification content, delivery metadata, and related records processed through the notification flows you configure. This data is encrypted at rest and is never used for any purpose other than notification delivery and delivery health monitoring.
Information Collected Automatically
When you use our Services, we automatically collect:
- Usage data: API call volumes, event counts, delivery frequencies, provider usage patterns, and feature usage metrics
- Server logs: IP address, browser type and version, operating system, referring URL, pages visited, timestamps, and request/response metadata
- Performance data: Page load times, API response latencies, notification delivery latencies, and error logs used to maintain service reliability
- Device information: Device type, screen resolution, and timezone
How We Use Information
We use the information we collect to:
- Provide and maintain the Services: Manage notification channels, store and deliver notifications, deliver API responses, manage your account, and handle billing
- Notification delivery and health monitoring: Automatically process and deliver notifications and monitor delivery health to ensure uninterrupted notification delivery to the third-party providers you have connected
- Improve the Services: Analyze usage patterns to identify bugs, optimize performance, and develop new features
- Ensure security: Detect and prevent fraud, abuse, and unauthorized access to accounts, notification data, or APIs
- Communicate with you: Send transactional emails (account verification, billing receipts, delivery alerts), respond to support requests, and provide product updates you have opted into
- Comply with legal obligations: Respond to lawful requests from government authorities and comply with applicable laws
We do not sell your personal information to third parties.
Important: We never access, read, or process data from the third-party provider APIs beyond what is necessary for notification delivery. Chimatic stores and delivers notification data on your behalf — we do not use that data to retrieve, inspect, or analyze any data from third-party services.
Information Sharing and Disclosure
We share information only in the following circumstances:
Service Providers
We use third-party service providers to help operate our Services, including:
- Stripe for payment processing
- Cloud infrastructure providers for hosting and data storage
- Monitoring and logging services for operational visibility
These providers access information only as necessary to perform their services and are bound by contractual obligations to protect your information.
Notification Data Handling
We do not share, transmit, or expose your stored notification data to any third party. Notification data is used exclusively to communicate with the provider APIs you have authorized, solely for the purpose of notification delivery and delivery health checks. We never access, read, or process data from provider APIs beyond what is necessary — we only store and deliver notification data.
Legal Requirements
We may disclose information if required to do so by law or in response to valid legal process, including subpoenas, court orders, or government requests. We will notify you of such requests when legally permitted to do so.
Business Transfers
In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email or prominent notice on our website before your information becomes subject to a different privacy policy.
Data Retention
- Notification data is retained for as long as the corresponding notification channel is active. Upon deactivation, notification data is retained for 30 days to allow for reactivation, after which it is permanently deleted.
- Audit logs are retained according to your plan tier (7 days for Free, 30 days for Pro, 90 days for Scale, as configured for Enterprise).
- Account data is retained for as long as your account is active. Upon account deletion, we will remove your personal information within 30 days, except where retention is required by law.
- Billing records are retained for 7 years as required by applicable tax and accounting regulations.
- Server logs are retained for 90 days for security and debugging purposes.
Data Security
We implement security measures designed specifically for the sensitive nature of notification data storage:
- Encryption at rest: All notification data is encrypted using AES-256-GCM before storage. Authenticated encryption ensures both confidentiality and integrity of stored data.
- Per-tenant key isolation: Each workspace’s notification data is encrypted with a distinct data encryption key (DEK), preventing cross-tenant exposure. A compromise of one workspace’s key material cannot affect any other workspace.
- HSM-backed key management: Key encryption keys (KEKs) are managed through hardware security modules (HSMs), ensuring keys are never exposed in plaintext outside secure hardware boundaries. Key rotation is automatic and transparent.
- Sensitive data never logged: Notification data is never written to application logs, error reports, crash dumps, or monitoring systems. Log redaction is enforced at the serialization layer.
- Sensitive data never displayed in raw form: The Chimatic dashboard never displays full notification data values. Only masked prefixes are shown for identification purposes. Full notification data cannot be retrieved through the dashboard UI.
- Separation of secrets: Provider credentials are stored separately from notification data, using distinct storage backends with independent access controls and encryption keys.
- Encryption in transit: All communications use TLS 1.3. Older TLS versions are not supported.
- Access controls: Employee access to production data stores is restricted, logged, and requires multi-party approval.
No method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
Self-Hosted Notification Delivery Engine
Enterprise customers may deploy the Chimatic notification delivery engine on their own infrastructure. When using the self-hosted delivery engine, notification data never transits to Chimatic Cloud. Notification storage, delivery, and health checks occur entirely within your infrastructure. In this configuration, Chimatic Cloud communicates only with the delivery engine’s control plane for notification channel metadata and orchestration — notification data remains within your network boundary.
The self-hosted delivery engine is open source, enabling your security team to audit the code that handles your notification data.
Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate or incomplete information
- Delete your personal information and stored notification data (subject to legal retention requirements)
- Export your data in a portable format, including notification channel metadata
- Withdraw consent for optional data processing activities
To exercise any of these rights, contact us at privacy@chimatic.dev. We will respond to your request within 30 days. If we need additional time to fulfill your request, we will notify you of the delay and the reason for it.
Data Residency
By default, all data is stored in the United States. Enterprise customers may elect EU data residency (in which case account data and encrypted notification data are stored within the European Union) or request custom data residency configurations to meet specific regulatory requirements.
Data residency selection is made at the workspace level and applies to all notification data and event data within that workspace.
Cookies and Tracking
The Chimatic dashboard uses strictly necessary cookies to maintain your authenticated session. We do not use third-party advertising trackers, social media pixels, or cross-site tracking cookies. Analytics, if any, are privacy-respecting and do not track individual users across sites.
Children’s Privacy
Our Services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
International Data Transfers
Mataki Labs LLC is based in the State of Wyoming, United States. If you access our Services from outside the United States, your information may be transferred to and processed in the United States, unless you have elected an alternative data residency option. By using our Services, you consent to such transfer and processing.
For customers who require specific transfer mechanisms (such as Standard Contractual Clauses), please contact us to discuss available options.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last updated” date. For significant changes, we will provide additional notice via email to the address associated with your account.
Governing Law
This Privacy Policy is governed by the laws of the State of Wyoming, United States, without regard to its conflict of law provisions.
Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
Mataki Labs LLC State of Wyoming Email: privacy@chimatic.dev