Privacy Policy
Last updated: June 10, 2026
This Privacy Policy explains how ChatLMS ("we", "us") collects, uses, and protects personal information when you visit chatlms.ai, sign up for an account, or use the ChatLMS platform. For how we handle the training content and data your organization uploads to the platform, see our Data Privacy page.
Information we collect
- Account information: your name, work email address, password (stored only as a salted hash), and organization details you provide at signup.
- Billing information: handled by Stripe, our payment processor. We never receive or store your card number; we keep only non-sensitive billing status (e.g., whether a valid payment method is on file and its expiry month).
- Usage information: actions you take in the platform (logins, content views, assistant queries) recorded in your organization's audit and usage logs, along with technical data such as IP address and browser type.
- Contact and demo requests: name, work email, company, and team size when you submit our contact form or book a demo.
How we use it
- To provide, secure, and improve the service (authentication, support, abuse and fraud prevention, usage caps and billing).
- To send transactional email (verification, password reset, billing notices, assignment reminders) via Amazon SES.
- To respond to inquiries you send us.
- We do not sell personal information, and we do not use third-party advertising or tracking inside the application.
Who we share it with
We share personal information only with the service providers (subprocessors) needed to run ChatLMS, under contracts that limit their use of it: Amazon Web Services (hosting and email), Stripe (payments), and our AI providers, Anthropic and OpenAI, which process the text of assistant queries to generate answers and are contractually barred from training on it. We may also disclose information when required by law.
Data retention
Account information is kept while your organization's account is active. Operational logs are pruned on fixed schedules (e.g., security audit logs after about 13 months, session records after 90 days). When an organization is deleted, its data, including personal information, is permanently erased from our systems.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information. Organization administrators can export or erase their organization's data directly from the platform; individuals can contact us at privacy@chatlms.ai and we will respond within 30 days.
Security
Data is encrypted in transit and at rest, access is role-based and logged, and every organization's data is isolated at the database layer. Our Security page describes the program in more detail.
Children
ChatLMS is a business product and is not directed to children under 16. We do not knowingly collect personal information from children.
Changes to this policy
If we make material changes we will update this page and note the new effective date above.
Contact
Questions about this policy or your data: privacy@chatlms.ai.