Privacy Policy
Last Updated: September 2, 2026
1. Introduction
Welcome to Aisha Social, an artificial intelligence-powered social media management application owned, operated, and provided by ChromaticsAI LLC ("Chromatics," "we," "us," or "our"), available at aisha-amp.chromatics.ai (including all subdomains and related application shells, collectively referred to as the "App" or the "Service").
ChromaticsAI LLC is committed to protecting the privacy of our users. This Privacy Policy explains what personal information we collect, how we use it, how we secure it, and how you can manage your data rights.
When you connect a social media account (such as Facebook, Instagram, or TikTok), we process the data described in this Policy in order to provide the Service you have asked us to provide - that is, to perform our contract with you, and in some cases to meet a legal obligation. Using the Service is not treated as agreement to anything beyond that.
We do not use third-party analytics, advertising, or session-recording tools, and we set no tracking cookies. See Section 4.
2. Who We Are (Data Controller)
The legal entity responsible for the collection and processing of your personal information (the "Data Controller") is:
Company Name: ChromaticsAI LLC
Official Domain: aisha-amp.chromatics.ai
Registered Office Address: 8 The Green, Suite A, Dover, Delaware 19901, USA
Technical & Privacy Contact: support@chromatics.ai
Aisha Social acts as a Data Controller for your account registration, billing, and subscription data. We act as a Data Processor for page analytics, social media data, and chat session data generated and retained on your behalf within the Service.
3. Information We Collect
We collect only the minimum information necessary to deliver, maintain, and secure the Aisha Social Service. We do not collect payment card numbers, billing addresses, follower lists, post content archives, comment histories, or any other data beyond what is explicitly listed below.
A. Registration Details
Your email address, password (secured as a salted hash - the original password is never readable by anyone, including Chromatics administrators), and basic registration metadata (e.g., account creation timestamp, last login).
B. Billing Data (Stripe)
We receive and retain your Stripe Customer ID and associated billing invoice records (plan tier, amount, date, status) from our third-party payment processor, Stripe. We do not receive, access, or hold your full payment card number, CVV, or billing address - those are handled exclusively by Stripe under their own privacy policy.
C. Connected Social Media Platform Data
When you link your Instagram Business Account, Facebook Page, or other supported social channels via OAuth, we collect only:
- Profile Name: The display name or handle of your connected page or account.
- Profile Picture / Logo: The avatar or logo image associated with your connected account.
- Encrypted Access Token: An OAuth access token, held in encrypted form, used solely to authenticate API calls on your behalf (e.g., publishing content, fetching analytics, or syncing messages). This token is encrypted end-to-end - it cannot be read by Chromatics administrators or system operators.
- Encrypted Direct Message (DM) Data (Opt-In Only): If and only if you explicitly grant messaging permissions during the profile connection flow, Aisha Social programmatically accesses your page's direct messages. This message text and sender metadata is ingested solely to populate your Aisha Social Engagement Center and generate on-profile draft replies. All such DM content is held in an encrypted format accessible and readable only by authenticated users within your Aisha Social workspace. Chromatics administrators and system operators have no technical ability to decrypt or access this content.
D. What We Do Not Collect
We explicitly do not collect, ingest, or retain:
- Payment card details, CVV codes, or billing addresses (handled by Stripe).
- Follower lists or audience demographic data.
- Historical post content, comment threads, or private messaging history prior to your profile connection or beyond what is actively managed in your workspace.
- Onboarding questionnaires, profile descriptions, or custom voice guidelines as standalone unencrypted, public-facing records.
4. Cookies and Tracking
No product analytics or profiling. Aisha Social runs no product-analytics platform, no advertising or marketing pixels, no session recording or replay, and no cross-site tracking. We do not sell or share your data with data brokers, and we do not profile you for advertising.
Storage we set ourselves. The only information we store on your device is what the Service needs to work: a session token so you stay signed in, short-lived security tokens used while you connect a social account, a 24-hour record of any address you submit through our contact form so the same message is not sent twice, and local state such as your theme, drafts you have not saved yet, and where you left off in a setup flow. None of this is used to track you or to build a profile, none of it is shared with anyone, and it is exempt from consent requirements because the Service cannot function without it.
Aggregate traffic measurement. Our hosting provider, Cloudflare, measures page traffic at the network edge. It uses no cookies, stores nothing on your device, and does not fingerprint or identify individual visitors - it counts requests.
Third-party services you invoke. Some features load code from the provider that powers them, and those providers may set their own cookies when they do. This happens only on the pages and actions concerned, never site-wide: Google (Sign in with Google, and reCAPTCHA Enterprise, which protects account signup from automated abuse), Meta, TikTok, LinkedIn, X and Pinterest (connecting your social accounts), and Adobe (the optional in-app image editor). We use none of them for analytics or advertising.
5. Encryption-First Data Model
To protect your profile's sensitive assets and private communications, Aisha Social operates under a strict, encryption-first model. All sensitive user data - including access tokens, direct messages, and chat sessions - is encrypted end-to-end. No Chromatics employee, system administrator, or third-party infrastructure partner has the technical ability to read, access, or decrypt your data. Encryption keys are structured such that decryption is only possible within your authenticated workspace session.
- Encryption at Rest: Your OAuth access tokens, API credentials, and direct message data are encrypted using industry-standard AES-256 encryption when not in active use.
- Zero Admin Access: Only authenticated users within your specific Aisha Social workspace can trigger decryption. Chromatics developers, system administrators, and hosting partners have no manual visibility or technical ability to access your decrypted tokens, messages, or session content.
- Programmatic Decryption Only: Decryption of your access tokens occurs programmatically and solely in temporary, secure system memory for the duration necessary to execute a specific action - publishing, syncing analytics, or generating AI-assisted drafts - only when initiated by you.
- Breach Protection: In the event of an unauthorized external breach, only unreadable ciphertext is exposed. Without the corresponding workspace-scoped encryption keys, this data cannot be decrypted by any party.
6. AI Model Training Policy
ChromaticsAI LLC uses only publicly available social media information to calibrate AI outputs within your workspace. Your private data is never used for any AI training purpose.
What May Be Used: Publicly accessible content associated with your connected social profiles (e.g., publicly posted captions, public profile metadata) may be used to calibrate voice and improve generation quality within your own workspace.
What Is Never Used: Your personal data - including your email address, billing records, private direct messages, encrypted access tokens, Aisha Social chat session content, and any non-public account information - is never used to develop, fine-tune, or improve any proprietary or third-party generative AI model.
Subprocessors: Aisha Social processes generative AI requests through the official APIs of trusted subprocessors, including OpenAI and Seedance (for video generation). All integrations operate under commercial developer contracts that legally prohibit these providers from retaining or using Aisha Social's API data payloads for model training.
7. How We Use Your Information
We use the limited data described in Section 3 solely to provide the Service features you explicitly trigger, including:
- Authenticating your account and maintaining secure session access.
- Processing subscription billing and issuing invoices via Stripe.
- Authenticating API calls to your connected social platforms using your encrypted access token.
- Displaying your connected profile name and logo within the Aisha Social interface.
- Calibrating AI-generated content using publicly available social profile information.
- Maintaining and displaying page analytics for your connected accounts.
- Scheduling and publishing Campaigns - multiple generated posts across a user-defined timeline, with blackout days excluded.
- Triage and Inbox Management: Fetching public comments and private direct messages (where explicitly authorized by you) into your Aisha Social Engagement Center, and generating draft replies in your established voice.
- Defending against billing disputes by providing proof-of-service records to Stripe and card networks.
Platform Data Limitation: Data obtained from third-party social APIs is used solely to provide organic content management, messaging, and analytics features. We never sell, rent, or share platform data, and we do not use platform data for advertising, profiling, or cross-user tracking. Aisha Social does not access or process data related to paid social media ad campaigns.
8. Data Retention and Deletion
Page Analytics: Performance analytics for your connected social pages are retained for the lifetime of your account and permanently deleted when you delete your account.
Direct Messages (DMs): Direct message data pulled into your Aisha Social inbox is held in encrypted form only as long as necessary to facilitate your engagement workflows. You may delete individual message threads, single messages, or your entire message archive at any time from within Aisha Social.
Chat Sessions: Aisha Social chat history is retained for the lifetime of your account unless you delete individual sessions manually. All remaining sessions are permanently deleted upon account deletion.
Account Deletion: Upon account deletion, all account metadata, page analytics, chat sessions, direct message archives, encrypted access tokens, and associated data are permanently deleted or anonymized within 30 days. Deletion immediately revokes and destroys our copy of the workspace encryption key, rendering any remaining encrypted data permanently irrecoverable - by anyone, including Chromatics.
Note: We may retain Stripe Customer IDs and invoice records where required by law or for fraud-prevention audits (e.g., resolving outstanding balances or tax obligations).
9. Your Privacy Rights (GDPR & CCPA/CPRA)
Whether you are located in the United States, the European Union, or other global jurisdictions, Chromatics honors your fundamental data rights:
- Right to Know/Access: You can request a summary of the data held about your account at any time.
- Right to Portability/Export: You can request an export of your page analytics, message history, and chat session data (processed within 72 hours).
- Right to Rectify: You can update your account details and connected profile information directly in your Account Settings.
- Right to Erase (Deletion): You can request the permanent erasure of your account, message data, and connected social data.
To exercise these rights, email us at support@chromatics.ai or navigate to Account → Privacy in the Aisha Social app.
10. Content Safety and Prohibited Uses
Our Service enforces strict content safety standards aligned with US federal law and the EU AI Act. Aisha Social will refuse to generate, and our systems will immediately block, any content relating to:
- Child Sexual Abuse Material (CSAM) or minor exploitation.
- Targeted harassment, bullying, or incitement of violence against any individual or group.
- Impersonation of a real person or public figure, or the generation of fabricated customer testimonials or reviews.
11. Compliance and Jurisdictional Notes
EU AI Act (August 2024): Aisha Social is classified as a General-Purpose AI (GPAI) system. In compliance with the Act, we maintain technical documentation of our model interactions, adhere to EU copyright policies, and restrict AI calibration to publicly available social content only - never personal user data or private messages (Article 10).
California SB 942 (effective Jan 2026): Aisha Social provides easy-to-use in-app tags (such as #AIAssisted) so users can remain compliant with California's AI-generated content disclosure laws.
Third-Party Webhooks: We verify the digital signatures of all incoming webhook events (including Meta integrations) to prevent unauthorized spoofing.