Skip to policy
🗿Chad Analytics
Privacy Terms Support Back to Chad

The plain-English version

Privacy without the fog.

Chad measures website traffic and delivers reports in Slack or Microsoft Teams. This policy explains exactly what data moves through the product, why we need it, and how you stay in control.

Effective and last updated: July 19, 2026

✓ Cookieless analyticsThe Chad snippet does not set cookies or build profiles across unrelated websites. It uses first-party browser storage, explained below.
✓ No data salesWe do not sell personal information or use it for cross-context behavioral advertising.
✓ Your callYou can request access, correction, export, or deletion by emailing us.

On this page

1. Scope 2. What we collect 3. How we use it 4. Cookieless analytics 5. Slack, Teams, and MCP 6. Watched installation 7. AI processing 8. When we share data 9. Retention 10. Your choices and rights 11. Security 12. International transfers 13. Children 14. Changes 15. Contact

1. Scope and who operates Chad

This Privacy Policy applies to the Chad Analytics website, tracking snippet, Slack app, Microsoft Teams app, reports, support, billing, and the optional “Do it for me, Chad” browser installer (together, the “Service”). “Chad,” “we,” “us,” and “our” mean Chad Analytics.

For the analytics data collected from a customer’s website, that customer decides why the website is measured and is generally the controller or business. Chad processes that data for the customer. For account, billing, product-security, and our own website data, Chad may act as the controller or business.

2. What we collect

CategoryExamples
Website analyticsSite domain, page path, referring URL, detected AI referral source, UTM campaign fields, detected crawler name, event time, random first-party visitor and session identifiers, language, screen width, and coarse country, region, city, device, browser, and operating-system categories.
Goals, identity, and journeysGoal name and time; optional value, currency, and limited custom properties; anonymous page and session sequences; and, only when a customer calls Chad’s identify API, a one-way hashed customer identifier and limited traits supplied by that customer.
Revenue and connected commerce accountsWhen a customer connects a supported commerce or payment provider: provider and account identifiers, OAuth scopes and tokens, payment or order identifiers, status, amount, currency, time, limited product metadata, and first- or last-touch attribution. Full card numbers are not sent to Chad.
Account and configurationWorkspace or organization name, site ID, website domain and detected platform, time zone, report schedule, plan, and installation status.
Slack and Teams connection dataWorkspace, tenant, channel, conversation, and installer identifiers; channel name; OAuth bot token, webhook URL, or Bot Framework connection details; commands, @mentions, and follow-up messages sent inside active Chad threads.
Automatic-install session dataWebsite platform, target site, remote session ID, task progress, actions taken, screenshots or page representations used by the agent, live-view data, and—when recording is enabled—a recording of the remote browser session.
Billing dataPlan, subscription status, and Stripe customer and transaction identifiers. Stripe—not Chad—collects full payment-card details.
Support and technical dataMessages you send us, diagnostics, request timestamps, IP-derived security information, device/browser information, and error logs needed to secure and operate the Service.

We receive data directly from you, from your website when the snippet or server package runs, from Slack or Microsoft when you connect an integration, from Stripe for Chad’s own billing, from a commerce or payment provider you choose to connect for revenue attribution, and from the providers that operate parts of the Service.

3. How we use information

  • Measure visits, sessions, bounce rate, pages, referrers, campaigns, coarse location and device categories, AI referral traffic, and crawler activity.
  • Measure customer-defined goals, anonymous journeys, funnels and drop-off, and—when configured—revenue attribution.
  • Send scheduled reports, first-visitor notifications, and answers to questions in Slack or Teams.
  • Detect a site’s publishing platform and help install, verify, and publish the Chad snippet when authorized.
  • Create and maintain accounts, integrations, plans, and billing.
  • Provide support; diagnose failures; prevent fraud, misuse, and security incidents; and comply with law.
  • Improve product reliability and features using aggregate or de-identified information.

Where a law requires a legal basis, we rely on performing our contract, legitimate interests in operating and securing the Service, consent where requested, and compliance with legal obligations.

4. How Chad’s cookieless analytics works

The Chad website snippet does not set cookies. It creates a random anonymous visitor identifier in the website’s own localStorage and a random session identifier that renews after 30 minutes of inactivity. Browser storage is scoped to that website’s origin, so Chad does not use these identifiers to follow a visitor across unrelated websites. A visitor can reset them by clearing that website’s stored data.

For requests without the browser identifier, our server can estimate a daily unique visitor by briefly using the request’s IP address and user-agent with the site ID and a randomly generated daily salt. It immediately hashes those values and stores only a shortened daily hash. Chad does not store the raw IP address or raw user-agent in the analytics event table. The user-agent is reduced to coarse device, browser, and operating-system categories; available hosting headers are reduced to coarse country, region, and city fields.

Customers can record named goals with limited scalar properties and can call an identify API. Chad one-way hashes the supplied customer identifier before storage; customers should use an internal, non-sensitive ID rather than an email address or other directly identifying value. Anonymous identifiers, session identifiers, identified IDs, and timestamps let Chad calculate sessions and customer-configured journeys, funnels, and attribution.

Page paths, referrers, campaign parameters, goal properties, and identity traits can still contain information a website owner or visitor supplies. Customers must not put sensitive information or unnecessary personal information in those fields.

Important distinction: “Cookieless” means Chad’s snippet does not set browser cookies; it does use the first-party localStorage described above. The customer’s website, Slack, Teams, Stripe, Shopify, Browser Use, and other third-party services may use their own cookies or browser storage under their own policies.

5. Slack, Microsoft Teams, and MCP data

Chad uses the minimum practical workspace data needed to install the app, post reports, create or use the selected reporting channel, and answer commands, @mentions, and follow-up replies. In Slack, Chad requests public-channel message history so a person can mention Chad once and then continue naturally inside the same thread. Chad immediately ignores ordinary channel messages, bot messages, and replies in threads where Chad has not already responded. It does not request private-channel, direct-message, or file-reading access and does not export or back up Slack messages.

We process the command, mention, or qualifying thread-reply text and the identifiers included in the corresponding Slack or Teams request to generate and deliver the requested response. Chad stores only the workspace, channel, and thread identifiers needed to recognize an active Chad thread; it does not intentionally persist the message text in its product database after responding. The message and Chad’s reply may remain in Slack or Teams according to the customer’s retention settings.

OAuth tokens, webhook URLs, and bot connection details are treated as server-side secrets. They are used only to provide the integration and are not exposed in the tracking snippet or to other customers.

If you create a Chad MCP credential and configure an AI or coding client, that client can request the read-only analytics available to the connected Chad account. Chad returns data only after authenticating the credential and applying its tenant and site limits. The client stores the credential under its own configuration and receives the analytics answers you request, so its provider’s terms and privacy policy also apply. Revoke or rotate the credential if it is exposed.

6. “Do it for me, Chad” browser sessions

If you choose automatic installation, Chad creates a private remote browser using Browser Use. You open the live view, enter your credentials directly into the website manager, and complete any multifactor or human-verification steps. Once you hand control to Chad, the agent can navigate the selected account, add the snippet, save changes, and publish the selected site while you watch.

What that means for privacy: remote-browser activity can include page content, screenshots, actions, cookies, temporary authenticated session state, and a session recording. Chad’s application does not ask for or store your website password in its account database, but the target website and Browser Use necessarily process browser-session data to operate the session. Do not type unrelated secrets into the remote browser.

Chad keeps the remote session ID and public task progress only as needed to run and monitor the installation. Recordings are enabled for transparency, troubleshooting, and security review and are retained under our Browser Use account’s configured retention. You may ask us to delete a recording or related session data.

7. AI processing

Chad uses Anthropic models to answer some free-form analytics questions, generate short report insights, and power parts of browser automation. We send only the question, the analytics context needed to answer it, and instructions for the task. AI outputs can be wrong, so they should not be treated as legal, financial, medical, or other professional advice.

We do not use Slack data, Teams data, customer content, or analytics events to train our own models. We also do not authorize our model providers to use customer content to train general-purpose models. Providers process data under their commercial terms and our account configuration.

8. When we share information

We do not sell personal information, rent customer data, or share it for cross-context behavioral advertising. We disclose information only as needed:

  • Service providers: hosting and infrastructure (Railway), database services (Supabase), messaging platforms (Slack and Microsoft), AI processing (Anthropic and the model providers used by Browser Use), browser automation (Browser Use), and billing (Stripe).
  • At your direction: when you connect an integration, publish a site change, ask Chad to post a report, configure an MCP client, or connect a commerce or payment provider such as Stripe or Shopify.
  • Legal and safety: when reasonably necessary to comply with law, enforce our terms, or protect users, the public, or the Service.
  • Business transfer: as part of a financing, acquisition, reorganization, or sale, subject to appropriate confidentiality and notice where required.

Providers may process data only to provide their contracted services and are subject to their own legal terms and privacy obligations.

9. How long we keep information

InformationTypical retention
Analytics events, goals, identities, journeys, funnels, attributed payments, and reportsWhile the account is active and historical data is needed to provide the reporting service. After a verified account-deletion request, we delete active-system data within 30 days unless law requires longer retention.
Site, workspace, and integration recordsWhile the site or integration is connected. Tokens and connection secrets are deleted or made unusable after a verified deletion request; revoking an integration at Slack, Microsoft, or the source platform also prevents further use.
Commands, @mentions, and active-thread repliesMessage text is processed to answer the request and not intentionally stored in Chad’s product database. Workspace, channel, and thread identifiers are kept while the integration is connected so follow-up replies work. Operational logs, if any, are generally retained for no more than 30 days. Copies in Slack or Teams follow that customer’s settings.
Remote browser data and recordingsChad’s in-memory session state expires after the installation session. Browser Use retains session artifacts and recordings according to the configured provider retention; we use them only for transparency, security, and troubleshooting and will process verified deletion requests.
Billing and legal recordsFor the period required for tax, accounting, fraud-prevention, dispute, and legal obligations.

Encrypted backups and disaster-recovery copies may persist for up to 90 additional days before being overwritten. We may keep de-identified aggregate statistics that can no longer reasonably identify a person, site visitor, or workspace.

10. Your choices and privacy rights

Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to processing; withdraw consent; and appeal a denied request. You may also complain to your local data-protection authority.

  • Remove the tracking snippet to stop new website analytics events, and clear the website’s stored browser data to remove its local anonymous and session identifiers from that browser.
  • Revoke Chad in Slack, Microsoft Teams, or the connected website platform.
  • Disconnect a commerce or payment integration and rotate or revoke an MCP credential you no longer use.
  • Email hello@chadanalytics.com to request access, transfer, correction, or deletion.

Tell us the website domain and connected workspace so we can locate the right account. We may need to verify that you control the account before fulfilling a request. We aim to respond within 30 days or the period required by applicable law.

Website visitors should usually direct requests to the customer whose website they visited. We will assist our customer with verified requests when Chad acts as its processor.

11. Security

We use reasonable administrative, technical, and organizational safeguards, including encrypted HTTPS transport, server-side secret storage, access controls, request-signature verification for Slack and Teams, and tenant separation. No internet service is perfectly secure, and we cannot guarantee absolute security.

If you believe you found a security issue, contact hello@chadanalytics.com and avoid including credentials or sensitive customer data in the first message.

12. International data transfers

Chad and its providers may process information in the United States and other countries where they operate. Where required, we rely on recognized transfer mechanisms and contractual protections. Local privacy laws may differ from those in your country.

13. Children

The Service is for businesses and is not directed to children under 13—or a higher minimum age where local law requires it. We do not knowingly create accounts for children. Contact us if you believe a child provided account information.

14. Changes to this policy

We may update this policy as the Service changes. We will change the date at the top and provide additional notice in the Service or connected workspace when a change materially affects your rights.

15. Contact us

Questions, support requests, and privacy-rights requests can all go to the same place.

Chad Analytics

Privacy and data requests

hello@chadanalytics.com
© 2026 Chad Analytics · Made with ☕️ and 🗿
HomeTermsSupport