Trust & Compliance

Last updated: June 17, 2026

CHYNJ builds local-first software. Product content stays on the user's device by default: Kaptain project work stays on the Kaptain machine, Konnect leads stay on the phone unless exported by the user, and Konvertex scripts/audio stay on the laptop unless the user selects an online rendering path. CHYNJ does not use product content for marketing, analytics, model training, profiling, or resale. The data CHYNJ stores centrally is limited to account, licensing, billing, support, download, and device-certification metadata needed to operate the service. This page is the single place to understand how we handle that data, who our sub-processors are, and where we stand on formal frameworks.

Privacy rights and regulatory posture

This is an operating posture and standardization effort, not a statement that CHYNJ has completed a formal legal review, external certification, or audit. For audited frameworks, see the roadmap below.

Compliance standardization & audit roadmap

Sub-processors

We use a deliberately short list of established providers. Each operates under a signed Data Processing Agreement.

User-directed exports and third-party connections are controlled by the user and governed by the connected provider's terms. They are not used by CHYNJ for marketing, analytics, model training, profiling, or resale. We use no ad-tech, marketing-automation, or session-replay sub-processors. We notify subscribers by email before adding a new CHYNJ-operated sub-processor.

Data residency & what we hold

Local content stays on the device unless the user explicitly exports it or chooses a product path that requires an outside service, such as Konvertex online voice rendering. The personal data CHYNJ holds by default is the minimum needed to run accounts, subscriptions, licensing, support, and downloads: your checkout/account email, country, subscription lifecycle events, the last 4 digits / brand of your card as provided by Stripe, issued license keys, connected-device metadata such as hashed device fingerprints or certificate status, and transactional email records. These live in Cloudflare D1 or the listed providers' systems, protected in transit and at rest by those services.

Your data rights

To access, export, correct, or delete your data, email privacy@chynj.ca. We respond within 30 days. Because we collect so little, most requests resolve quickly. Full detail of your rights is in the Privacy Policy.

Security

Data in transit is protected with HTTPS; subscriber and license records are encrypted at rest. We publish a security.txt and welcome coordinated disclosure. Report vulnerabilities to security@chynj.ca.

Contact