VERSION 2026-09-27-beta-3 · 27 SEPTEMBER 2026
Privacy notice
CHUMA team authors can translate their community post text using OpenRouter and the Novita Ling endpoint. Only the entered post text is sent on request or when publishing without translations. Project files and support messages are not included. Members can also request a translation of a visible community comment into English, Russian or Danish using the same provider. Only that comment text is sent; a notice appears next to the comments. Comment translations are cached and can contain errors. Saved translations are shown according to the reader’s selected language; the English original remains available.
Community and support (updated 29 September 2026)
The optional community is shared by signed-in members. Names chosen for posts and comments, messages, posted images and videos, replies and reaction counts are visible to those members. Your archive is not published to the community. Participation is optional and supports the requested community service. Video recording requests camera and microphone access only when you choose to record. Recordings stay on your device until you publish; uploaded drafts are removed after 24 hours if not published. Published videos are stored in private Cloudflare R2 and available to signed-in members. Our legitimate interest in preventing abuse also supports moderation. Do not share confidential project information or another person's personal details without an appropriate basis. Authors can hide their comments; the CHUMA team can moderate posts and comments. Hidden material is retained for moderation but is no longer shown to members. Contact us to request correction or permanent removal, including when closing your account.
The support form sends your reply email, subject, message and optional reduced screenshot through Cloudflare to our Gmail support mailbox, chumastudiobyelena@gmail.com. We use these records to respond to your request. Google processes the mailbox and replies. Other members cannot view your support requests. Application copies are deleted after 180 days; mailbox correspondence is handled separately and reviewed when a request is resolved or an erasure request is received. No automatic mailbox deletion is configured. Existing international processing and rights information below also applies to these functions.
Optional link imports
When you submit a public Google Drive or Yandex Disk link, we contact that provider to list and copy the selected files into your workspace. We retain the source identifiers, file paths and transfer status to run the import and report errors. Inactive import records are removed after seven days; imported files follow the normal project retention rules. Link discovery and transfer do not send file contents to an AI provider. Cloud providers may record these download requests under their own policies.
Who is responsible
Olga Aleksandrovna Sukhova, Denmark. Email: chumastudiobyelena@gmail.com. The operator is the controller for account administration, service security and support records. A studio normally controls personal data in its project content; for that content we act on its instructions as a processor under our data processing terms. If you are depicted or named in a studio's material, contact that studio or contact us and we will help route the request.
Data, purposes and legal bases
We collect your name, studio name, contact email and accepted document version to create and administer the account. For an individual customer this is necessary to perform the service contract (GDPR Article 6(1)(b)). For a studio representative, our legitimate interest is administering the studio's requested service (Article 6(1)(f)). Required registration fields are needed to open an account.
Access key and session hashes, expiry times, short lived IP based rate limit hashes, request metadata and support audit records protect accounts, prevent abuse and help investigate incidents. We rely on the legitimate interests of operating a secure service and resolving problems, with restricted access and limited retention. For a binding legal obligation we rely on Article 6(1)(c). We do not rely on a blanket consent to the privacy notice.
Project data includes uploaded images, documents, drawings, tables, 3D files, textures and any embedded metadata, filenames, credits, location, descriptions, year and memorable details entered by the studio. Do not include unnecessary personal information in files or their metadata. We use project content to provide the functions requested by the studio, not for advertising. There is no advertising profiling, sale of personal data, or solely automated decision with legal or similarly significant effects. AI provides editable suggestions only.
Administrative access
Authorized administrators may access a workspace where necessary to investigate a reported problem, correct project metadata, restore a project from Trash, or address a security incident. This is part of providing support; a separate access permission button is not required. Administrators must record a specific reason and limit access to the affected data. The support interface permits previews and metadata corrections but blocks original and ZIP downloads, uploads, AI requests and permanent deletion. Support actions are logged. Access for curiosity, marketing, portfolio use, sale or model training is prohibited. Viewing a preview necessarily transmits that preview to the administrator's browser. Infrastructure administrators retain technical access beyond these interface controls and are subject to the same purpose and confidentiality restrictions.
Providers and international processing
Cloudflare, Inc. supplies hosting, Workers, the D1 database and R2 storage, including request delivery and security. Optional AI uses OpenRouter, Inc. and the selected Google Gemini or Gemma model endpoint. In the CHUMA operator workspace only, an explicitly selected experimental Ling model is also processed by Novita through OpenRouter. This additional provider is not enabled for other studio workspaces. For description drafting, only submitted text and up to 80 filenames are sent. If you request room labels in the CHUMA pilot, reduced image previews are also sent through OpenRouter to Google Gemini with the same provider privacy controls; original images are not sent. Our application records request time, status and cost, not a separate history of prompt text.
Requests use settings that prohibit provider data collection and require a provider endpoint marked as having zero data retention. This is a routing restriction, not a guarantee that no legal, security or usage metadata exists anywhere. If no eligible endpoint is available, the AI request fails rather than relaxing the restriction.
These suppliers operate internationally, including in the United States. The current deployment does not promise exclusive EU or EEA storage or processing. The published Cloudflare and OpenRouter processing agreements describe contractual safeguards, including EU standard contractual clauses where applicable. The operator must ensure the correct contracting party, applicable transfer module and any necessary supplementary measures are in place; publishing this notice is not evidence that those checks have been completed. Contact us for the applicable safeguards and relevant copies, with unrelated confidential details removed.
Retention
Login sessions expire after at most 7 days; signing out invalidates the session. Rate limit records expire within 2 hours and are removed by the hourly cleanup. Support audit entries are kept for up to 90 days. AI request status and cost records are retained for the duration of the limited AI pilot to enforce its total request cap, then removed within 30 days of its closure.
Account details and active projects remain while your account is open. Trash has a 30 day recovery period. On verified account closure, live account and project data will normally be removed within 30 days, unless you request an agreed retrieval period or a specific legal obligation requires retention. We will explain any exception and its scope. Restricted operational backups may temporarily retain data; support will identify affected copies and confirm their deletion schedule in its response. We do not promise instant erasure from all historical copies. Older CHUMA import previews may also exist in prior deployment packages and require manual cleanup.
Your rights
You may request access, correction, erasure, restriction and, where applicable, a portable copy of personal data. You may object to processing based on legitimate interests. If a separate optional activity relies on consent, you can withdraw that consent without affecting earlier lawful processing. Email the operator. Requests are normally free; we may ask for proportionate information to verify your identity, rather than routinely asking for identity documents.
We respond without undue delay and normally within one month. If an extension is legally allowed because of complexity or volume, we will explain it within the first month. You can complain to Datatilsynet, Denmark's data protection authority, or another competent supervisory authority, including where you live or work in the EEA. You do not have to contact us before complaining.
Security and updates
We use HTTPS, private storage, workspace access checks, hashed access keys and secure session cookies. Support access is restricted and logged. This is not end to end encryption: the operator can technically access content. No security certification or guarantee of absolute security is claimed. We will handle personal data breaches, notify affected studios and, where required, authorities and individuals. Material changes to this notice will be communicated through the service or your contact email.