HeyChintu MascotheyCHINTU
Privacy Verified · On-Device

Privacy Policy

Last updated: September 2026 · Effective for HeyChintu iOS, Android & Web

1. The Fundamental Principle: Local-First Artwork Storage

HeyChintu was created with absolute artist sovereignty at its core. By default, we do not upload, sync, host, view, or process your creative challenge artwork or daily check-in photos on remote cloud servers. All photos and sketches captured or selected within the app are compressed locally and stored exclusively in your device's sandboxed browser storage (IndexedDB).

We will never claim any copyright or intellectual property rights over your work, and your creations are never used to train artificial intelligence or machine learning models.

Voluntary Cloud Integrations:
  • Optional Google Drive Backup: Pro creators can voluntarily connect their personal Google Drive account. When activated, artwork backups are transferred directly from your device to your private Google Drive folder using official Google APIs. HeyChintu servers do not store or intermediate your private artwork files.
  • Profile Avatars: If you voluntarily choose to upload a custom profile picture, that image is securely processed and hosted on HeyChintu/Cloudflare storage solely to display on your public profile and community leaderboards.

2. Information We Collect and Why

When you create an account using Google Sign-In or Apple Sign-In, we collect and store only the minimal data strictly necessary to authenticate your account, prevent fraud, and calculate fair community streak tallies:

  • Account Identifier & Email: Transmitted via OAuth tokens to authenticate you securely without holding raw passwords.
  • Artist Handle / Username: Displayed publicly on community leaderboards and country scoreboards.
  • Country Code (ISO 3166-1): Selected during onboarding to allocate your daily 1-point streak check-in to your nation's standing.
  • Daily Streak Completions: Numeric day indices, challenge slugs (e.g., "chintus-list"), timestamps, and streak counts used solely to verify consecutive daily creative practice.
  • Referral & Pack Codes: Non-personal alphanumeric codes used when you invite friends or join through a creator link.

3. Third-Party Payment Processing (Stripe & Razorpay)

Paid subscriptions (Studio Monthly, Studio Yearly, Founder Passes) and physical printed artbooks are processed by leading PCI-DSS Level 1 certified payment gateways:

  • Stripe: Processes international credit cards, debit cards, Apple Pay, and Google Pay.
  • Razorpay: Processes domestic Indian payments including UPI, Net Banking, and local RuPay/Visa/Mastercard.

HeyChintu does not collect, process, or store credit card numbers, CVVs, or bank credentials on its servers. All sensitive financial data is tokenized directly by Stripe and Razorpay. We only store transaction confirmation IDs, purchase dates, plan tiers, and subscription renewal status.

4. Device Hardware Permissions (Camera & Photos)

When you photograph your creative work or choose an image from your photo album, the app requests system camera and photo library access. These permissions are used exclusively in real time to generate your client-side share card and persist the artwork in your local device IndexedDB. Photos are never transmitted over the network unless you explicitly upload a profile avatar or invoke your operating system's native share sheet.

5. In-App Account Deletion & Right to Erasure (GDPR / CCPA)

In compliance with Apple App Store Guideline 5.1.1(v), Google Play User Data policies, and international privacy regulations (GDPR, CCPA), you can initiate complete account deletion at any time directly within the application:

In-App Deletion Path:Profile Screen (/me) → Data & Privacy Controls → Permanently Delete Account & Local Data

Executing this action immediately cascades deletion across all server database tables and wipes your local IndexedDB artwork cache. You may also request a full backup of your account data via the "Export Account Data" feature in your Profile before deletion.

6. Children's Privacy (COPPA Compliance & Under-13 Age Gate)

HeyChintu is designed for general creative audiences and artists. We do not knowingly collect or solicit personal identifiable information from children under the age of 13. During onboarding, a mandatory age confirmation gate requires users to verify that they are at least 13 years of age (or have verified parental permission). If we learn that we have collected personal data from a child under 13 without verified parental consent, we will promptly delete that information from our servers.

7. Security & Data Safety Summary (Apple & Google Play)

All server communications are strictly encrypted in transit using Transport Layer Security (TLS/HTTPS). We enforce strict security headers and do not allow cleartext HTTP network traffic in production builds. We do not integrate third-party ad networks, advertising trackers, or data brokerage SDKs.

Data TypeCollectedPurposeLinked to User
User Artworks & PhotosNo (On-Device)Saved in local IndexedDB (or user's personal Google Drive)No
Name / Email / HandleYesAccount Authentication & Community StandingsYes
Payment HistoryYes (Receipt token)Subscription & Purchase entitlement via Stripe / RazorpayYes

8. Contact & Data Protection Inquiries

If you have questions regarding this Privacy Policy, wish to exercise your legal data rights, or need assistance, please reach out to our team:

Privacy Officer: ceo@mellite.app
Help & Support Center: heychintu.com/support
Terms of Service: heychintu.com/terms