API Privacy Policy

Last updated: August 28, 2026

This policy explains what information Chroma Golem Inc. collects when you use our AI API and the developer dashboard at chromagolem.com, why we collect it, and who we share it with. It covers two different kinds of data: information about you as our customer, and information your game sends us on behalf of your players. Those are treated differently, and the sections below say which is which.

If you are a player of one of our own games rather than a developer, the games privacy policy is the one that applies to you.

Your account data

When you sign up we collect your email address and a securely hashed password. If you create or join an organization, we store its name and your membership in it, along with any invitations you send or receive. We also store the API keys you generate, their names and versions, and the model preferences you set for each one.

When you buy credits, our payment processor Stripe handles the transaction. We never see or store your card number — we keep a Stripe customer reference, the amount, the date, and the credits purchased, so we can maintain your balance and your billing history.

API request data

Every call to our API is logged so we can meter usage, bill accurately, show you analytics, and keep the service running. For each request we record which API key was used, the model requested and the model actually used, token counts, response time, cost, timestamps, and any client_id or prompt_id you supply.

We may also retain the content of your requests and the responses we return — the prompts, messages, and generated text or images that pass through the API. We use this to operate and debug the service, investigate abuse and errors, and improve the quality and reliability of what we offer. We do not sell this content, and we do not use it to train our own models.

Requests that fail authentication are logged separately, including the API key that was presented, so we can detect credential misuse and help you troubleshoot broken integrations.

Your players' data, and who is responsible for it

When your game calls our API, whatever your players type may reach us inside your prompts. For that data, you are the data controller and we are your processor: we handle it on your instructions, to provide the API to you, and for the operational purposes described above. We don't use it for our own independent purposes, and we don't contact your players.

That division of responsibility means a few practical things are on you:

  • Having your own privacy policy that tells your players what your game collects and that AI-generated features send their input to a third party.
  • Having a lawful basis to send us their data, and obtaining consent where the law you operate under requires it.
  • Passing us a pseudonymous client_id. It exists to separate one player's usage from another's in your analytics, so use a random or hashed value — not an email address, a real name, or a platform account ID.
  • Not sending us special category data (health, biometric, precise location, government identifiers, and the like). Our API is not designed to receive it.
  • Handling requests from your own players. If one of your players asks us directly to access or delete their data, we will refer them to you, because we have no way to identify them.

If you need a signed data processing agreement, email info@chromagolem.com and we'll work through it with you.

Who we share data with

We do not sell your data or your players' data, and we don't share it with anyone for their own advertising or marketing. We rely on the following service providers, each processing data on our behalf under contract:

  • AI providers — Microsoft Azure OpenAI Service and OpenAI receive the prompts we route to them and return the generated result. Under our agreements with them, they do not use that content to train their own models. Some image generation runs on models we host ourselves, in which case the content never leaves our infrastructure.
  • Stripe — processes payments and holds the card details we never see.
  • Sentry — receives error and performance reports, which can include request details and the IP address the request came from, so we can diagnose failures.
  • Hosting and infrastructure providers — the services that run our servers, store our data, and deliver our email.

We may also disclose data if we're legally required to, or where it's necessary to enforce our terms, investigate abuse, or protect the rights and safety of our users or the public. If we're ever compelled to hand over your data, we'll tell you unless we're legally prohibited from doing so.

Where your data goes

Chroma Golem is based in the United States, and the providers above may process data in the United States and other countries. If you or your players are located elsewhere, data may be transferred to and stored in countries whose data protection laws differ from your own.

Cookies and the dashboard

Our website uses a session cookie to keep you signed in, and a cookie to protect forms against cross-site request forgery. Both are strictly necessary to operate the site. We do not run third-party advertising, tracking, or web analytics on chromagolem.com, so there is no tracking to opt out of.

Email we send you

We send transactional email you can't opt out of while you have an account: password resets, organization invitations, and alerts when your credit balance runs low. We may occasionally send product updates about new models or features — you can opt out of those at any time by emailing us or using the unsubscribe link, and doing so won't affect your service.

How long we keep it, and closing your account

We keep your account data for as long as your account is open. Usage and request logs are retained for as long as they're useful for billing, analytics, and abuse monitoring, and are deleted or aggregated after that.

If you close your account, we delete your account details and API keys, and delete or anonymize the associated usage logs. We keep payment and invoice records for as long as tax and accounting law requires us to, even after your account is gone. To close your account, email info@chromagolem.com.

Your rights

Depending on where you live — including under the GDPR in Europe and the UK, and the CCPA/CPRA in California — you may have the right to access the personal data we hold about you, correct it, delete it, receive a copy of it, or object to how we use it. California residents also have the right to know that we do not sell or share personal information as the CCPA defines those terms, and we will never discriminate against you for exercising any of these rights.

Email info@chromagolem.com from your account address to make a request. These rights cover your own data as our customer. For data belonging to your players, the request goes to you as the controller, and we'll support you in answering it.

Security

We encrypt data in transit, hash passwords, and restrict internal access to production data to the people who need it. Your API keys are credentials: treat them like passwords, keep them out of client-side code and public repositories, and rotate them if you think one has been exposed. You can create, version, and retire keys from your dashboard at any time. If you believe you've found a security issue, please tell us at info@chromagolem.com rather than disclosing it publicly.

Children

The API and dashboard are business tools for developers, not services for children, and you must be at least 18 to hold an account. If your own game is directed to children, complying with laws like COPPA and the GDPR's rules on children's data is your responsibility as the controller, including deciding what you send us.

Changes to this policy

We'll update this page as our service and our providers change, and we'll update the date at the top when we do. If a change materially affects how we handle your data, we'll notify account holders by email before it takes effect.

Contact us

Questions about this policy, your data, or a data processing agreement? Email info@chromagolem.com.

Chroma Golem Inc.