Private family-activity planning

Privacy Policy

This policy explains the information Chudoly handles while operating its invitation-only family-activity planning service. It describes the current implementation; it is not a promise that Chudoly satisfies every law in every location. The owner should obtain legal review before expanding availability, changing data uses, or inviting families in additional jurisdictions.

Effective July 19, 2026

Who provides information

Parents and other invited adult caregivers provide information about themselves and children. Chudoly is not intended for children to register for or use independently. Adults should provide only information reasonably needed for family-activity planning and should not enter a home address or unnecessary medical detail.

Information and why it is collected

How information is used

Chudoly uses information to operate the invitation-only service, authenticate members, save and retrieve profiles and defaults, generate and optionally rerank family-activity options, maintain a private family adventure history, calculate family badge progress, use favorites and completed categories to improve recommendations, deliver a weekly digest only to adults who opted in, deliver a one-time event reminder only after an adult requests it, maintain security, troubleshoot, respond to adults, and learn whether recommendations create value. Product-learning records are first-party operational measurements, not third-party analytics. Chudoly does not sell personal information and does not use it for advertising, behavioral profiling, cross-site tracking, session replay, or marketing-cookie targeting.

Provider request information is used to verify authority, review and correct factual listings, suppress or remove content, stop source access, manage permissions, prevent duplicate claims and abuse, communicate about the request, and preserve an auditable decision history. Provider access is separate from family accounts and does not reveal family profiles, recommendations, saved activities, or private engagement histories.

Service providers

These providers process information for Chudoly under their own service terms and privacy documentation. Their infrastructure and support operations may process data in locations different from the family’s location.

Sharing

Information is shared with service providers as needed to operate Chudoly and may be disclosed when reasonably necessary to protect users, investigate abuse, comply with a valid legal request, or complete a business reorganization. Child profiles and family adventure histories are private to the parent account that created them. Raw product-learning records are service-only. Administrators receive aggregate metrics rather than individual-family histories, and activity-demand rows are hidden until at least five different families were shown the activity.

Retention and deletion

Access cookies expire with the account grant and can be ended earlier on a browser. Account grants have expiration, disabling, and revocation fields. Chudoly deletes raw first-party product-learning events, associated recommendation runs, and newsletter edition metadata after 180 days; administrator invitation-rate records after 30 days; returning-sign-in rate records after 24 hours; pending or denied access requests after 90 days; and approved or fulfilled access requests after 180 days. Parent and child profiles, family adventure history and attendee snapshots, favorites, family and newsletter preferences, observations, and related account records otherwise remain until an authenticated account-deletion request or the announced service-closure process, subject to documented security or legal exceptions. Deleting the Auth account cascades to family adventures and attendees, family preferences, newsletter preferences, editions, recommendation runs, and raw product-learning records.

Historical venue claims, access grants, decisions, transfers, revocations, and rollback records are preserved after management access ends so Chudoly can resolve disputes and prevent accidental re-authorization. Private evidence is access-restricted and should be minimized and redacted. Its production retention period remains a release-blocking decision in Chudoly’s retention register; claimants may request review or deletion where applicable, subject to necessary security, dispute, and legal records.

OpenAI requests set store: false, which disables stored response application state but does not by itself enable Zero Data Retention. Chudoly's reranking requests also disable the implicit prompt-cache breakpoint and define no explicit breakpoint, so those requests do not use prompt caching. The Production project uses OpenAI's standard abuse-monitoring treatment, under which minimized request or response content may be retained in abuse-monitoring logs for up to 30 days, or longer when legally required by the provider. Other provider logs, safety processing, suppression records, and backups may persist for their configured periods before deletion cycles complete.

Chudoly has implemented a daily service-role-only operation for the fixed internal periods above. The owner must deploy and verify the first hosted run before broader release. Provider logs, backups, support copies, and aggregate reports remain subject to separate documented controls and legal/provider review.

Adult access, correction, and deletion requests

An invited parent or caregiver may change family and newsletter preferences from the Account menu, unsubscribe there, or use the signed one-click unsubscribe link in a newsletter without signing in. They may ask to access, correct, or delete the parent information they provided and child information they manage by emailing hello@chudoly.com from the invited address. Chudoly may need to verify identity and authority over the profile. Clearing browser storage, unsubscribing, or ending a private session does not delete server-side profiles or revoke account access.

Providers may use the provider-access area or email providers@chudoly.com to correct, claim, restrict, or request removal of a listing. Chudoly retains request and audit history when a listing is suppressed unless deletion is required by applicable policy or law.

Security

Chudoly uses invitation-only confirmed-email access, signed HttpOnly cookies, active account-grant checks, row-level security, owner-bound edits, expiration and revocation controls, Turnstile, and restricted server-side secrets. No system can guarantee absolute security; adults should avoid submitting unnecessary sensitive details.

Changes and contact

This policy may change as the service changes. Material changes should be reflected by updating the effective date and, where appropriate, notifying invited adults. Questions and privacy requests can be sent to hello@chudoly.com.

See the Cookie and browser storage notice for the current device-storage inventory and controls.