Privacy policy
Last updated: September 19, 2026
This policy explains what data we process when you use 4thechase.com, why, and what your rights are. It is written to be read, not to be long. It complies with the Swiss Federal Act on Data Protection (nFADP) and the EU General Data Protection Regulation (GDPR).
1. Who is responsible
4TheChase is an independent project based in Lausanne, Switzerland. For any request, including the publisher's full identity, write to contact@4thechase.com: we answer within 30 days.
For any data-related question: contact@4thechase.com.
2. What this policy covers
The 4thechase.com website and its early-access list. The mobile app is not published yet: this policy will be completed at launch, and you will be notified.
The app's guiding principle, worth knowing now: your cards are stored on your phone. If you create an account (optional), they are copied to our server hosted by Supabase in Zurich (Switzerland), under your identifier, so they can be found on another device; deleting the account, from inside the app, erases that copy. Without an account, the only data that leaves your device is what you give the assistant to read: the text of a card when you ask a question, a screenshot or a voice note when you hand one over. That content passes through our server, which relays it to Google Gemini without storing it, and serves no other purpose.
3. Data we process
- Early access: your email address, your first name if you give it (it is optional, and it only serves to personalise the launch email), the language of the site and the date you signed up. Nothing else: no last name, no age, no password, no account. There is nothing to sign in to.
- Technical data: IP address and server logs, kept by our hosting provider for security and operations (30 days maximum).
- Audience measurement: aggregated, anonymous statistics (page views, country, device type) via Vercel Analytics, without cookies or personal identifiers.
- Live demo: if you ask the demo chat a question, its text is sent to our server and then to the Google Gemini API to generate the answer. We do not store it. Our calls come from an account established in Switzerland, where Google's terms apply its most protective regime, excluding human review and model training. We still ask you not to put personal data in it: this is a public demo.
We collect no data about anyone other than you through the website. The cards you create in the app describe third parties: they stay on your device, under your sole responsibility. With an account, the copy on our server is never browsed for its own sake: only a documented request from someone who appears in it (access or erasure) can lead us to look for a card there.
4. Purposes and legal bases
- Writing to you when the app launches: your consent, given on the form and timestamped, which you can withdraw at any time (GDPR art. 6(1)(a)). That is the only reason we keep your address.
- Sending you launch news: your consent, which you can withdraw at any time (art. 6(1)(a)).
- Securing the site and preventing abuse: legitimate interest (art. 6(1)(f)).
- Asking the assistant a question, generating a brief, having a screenshot or a voice note read: your consent, asked for inside the app before the first send and timestamped (GDPR art. 6(1)(a)). That content passes through our server, which relays it to the Google Gemini API. We neither store nor read it: the relay carries and keeps nothing. It exists so the access key is not embedded in the app, where it would be extractable. Google's terms exclude human review and using this data to train its models; it keeps that content for at most 55 days, solely to detect and prevent abuse, then deletes it.
You can withdraw this permission at any time, from inside the app: Settings, Permission section, the "Let Noa read your cards" switch. It takes effect immediately and asks for no confirmation. Everything else keeps working without it: cards, timeline and search send nothing to anyone.
5. Where your data is, and who can access it
- Early access list: Supabase, database hosted in Zurich, Switzerland.
- Website: Vercel Inc. (United States), global delivery network. Vercel acts as a processor under standard contractual clauses.
- Relay to the AI: Vercel Inc. (United States), which hosts the server that content passes through without being stored. - Answer generation: Google LLC (Gemini API), established in the United States. ⚠️ Google commits to no region: it may process that content in any country where it operates facilities. Transfers covered by the Data Privacy Framework and standard contractual clauses.
We never sell or rent data. No third party receives your data for advertising purposes.
6. Retention
Your address is kept until the app launches, or until you ask us to erase it. Technical logs are erased after 30 days at most. Audience statistics are anonymous from the moment they are collected.
What you give the assistant to read: nothing on our side, the relay keeps nothing. At Google, 55 days at most, solely to detect and prevent abuse.
Your permission to send to the AI: the date and the version of the text you accepted stay on your phone for as long as the permission is active. Withdrawing it erases them.
7. Your rights
At any time you can: access your data, correct it, delete it, request a portable copy, object to processing based on legitimate interest, and withdraw consent.
To erase your address, withdraw that consent or exercise any other right, write to contact@4thechase.com: we answer within 30 days.
The permission to send to the AI is withdrawn from inside the app, without writing to us: Settings, Permission section, the "Let Noa read your cards" switch. Your cards are handled from the app too, Data section: "Export my data" produces a ZIP file with your cards, memories, meetings, conversations with the assistant and photos, as JSON and as readable text (that is your portable copy, GDPR art. 20 and FADP art. 28); "Erase all data" deletes everything from the phone and, when an account is signed in, the copy on our server.
You can also lodge a complaint with a supervisory authority: in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EU, the authority of your country of residence.
8. Cookies
The site uses no tracking or advertising cookies, which is why it shows no banner. There is no session cookie either, since there is nothing to sign in to. Audience measurement works without cookies.
9. Security
End-to-end TLS encryption, database-level access rules (row level security) that make the early-access list unreadable from the browser, administrator access limited to what is strictly necessary, strict security headers on the site. No system is infallible: if an incident affects your data, we will inform you without undue delay.
10. Minimum age
4TheChase is for adults. We do not knowingly add minors to the early-access list.
11. Changes
If this policy changes substantially, in particular at the app launch, you will be informed by email or in the app before the change takes effect.