Legal

Privacy Policy

How Chameleon processes, stores, and handles your data.

Effective date: 09/04/2026 Last updated: 09/04/2026

1. Scope

This Privacy Policy applies to the Chameleon desktop application and its local application services.

2. Information We Process

A. Information You Provide

Depending on how you use Chameleon, the application may process:

  • Prompts, instructions, and chat messages you enter.
  • Project names and other project information.
  • Source code, project files, and project structure that you create, open, edit, or provide to Chameleon.
  • Configuration information you enter into the application, including AI provider settings and API credentials.

B. Configuration and Technical Information

Chameleon may process and locally store technical information required to operate the application, including:

  • AI provider and endpoint configuration.
  • Ollama server address or URL.
  • Selected planning and coding models.
  • Provider settings.
  • System checks, such as whether Node.js and npm are installed and their versions.
  • Error, debugging, and operational logs generated while using the application.

Chameleon does not use this information for advertising or behavioral tracking.

C. Locally Stored Data

Chameleon stores certain information on your device, which may include:

  • Application configuration stored in a local SQLite database.
  • AI provider and model configuration.
  • API credentials or other authentication information required to connect to configured AI services.
  • Prompt template files.
  • Generated and edited project files.
  • Application logs and other files required for application functionality.

The exact location of these files depends on your operating system and Chameleon's installation.

3. How We Use Information

We process data to:

  • Set up and run your local development workspace.
  • Generate, modify, and debug code based on your prompts.
  • Show project trees, previews, visual editing controls, and logs.
  • Save your AI and prompt preferences.
  • Diagnose issues and improve application reliability.

Chameleon does not use your project files or prompts for advertising.

4. AI Processing and Third-Party Services

Chameleon allows you to configure the AI service or endpoint used for AI features.

Depending on your configuration, this may include a locally running AI service such as Ollama or a remote AI provider.

When an AI feature is used, Chameleon may send relevant prompts, project context, source code, project structure, or other information required to generate a response to the AI endpoint you have configured.

Local AI

If you configure Chameleon to use an AI service running locally on your device or local network, applicable AI requests may remain within your local environment and are not sent to Chameleon's developers.

Remote AI Services

If you configure a remote AI provider or server, information required for the requested AI operation is transmitted to that service.

Remote AI providers operate independently from Chameleon and may process information according to their own privacy policies, terms, and data-retention practices. You are responsible for reviewing the privacy practices of any third-party AI service you choose to use.

Chameleon does not control how an independently operated remote AI service processes information after it has been transmitted to that service.

5. Analytics, Advertising, and Tracking

Chameleon does not include built-in advertising SDKs.

Chameleon does not include built-in third-party analytics or behavioral tracking SDKs in the current implementation.

Chameleon does not sell personal information for advertising purposes.

6. Authentication and Accounts

Chameleon currently does not require an in-app user account for its core functionality and does not maintain an internal user account system.

Some AI providers or external services configured by the user may require their own accounts or authentication credentials. Those accounts are governed by the respective provider's policies.

API Keys and Credentials

When you configure an AI provider requiring an API key or other credential, Chameleon may store that credential locally on your device so that the application can make authorized requests.

Chameleon does not intentionally transmit stored credentials to the Chameleon developers.

You are responsible for protecting your device and for managing, rotating, or revoking credentials through the applicable AI provider when necessary.

7. Data Sharing

Chameleon does not sell your personal information.

Chameleon does not intentionally provide your project files, prompts, or locally stored application data to third parties controlled by Chameleon, except where necessary to operate a service you have explicitly configured or where required by law.

Information may be transmitted:

  • To the AI endpoint or provider you configure and use.
  • To a remote server you explicitly configure.
  • Where required by applicable law, regulation, legal process, or valid governmental request.
  • Where reasonably necessary to protect the rights, security, or safety of users, the application, or others.

8. Data Retention

Chameleon primarily stores application data locally on your device.

Data may remain on your device for as long as it is required for application functionality or until you delete it.

You can generally remove locally stored information by:

  • Deleting project files.
  • Removing Chameleon application data from your device.
  • Uninstalling Chameleon and removing remaining application data.

Data transmitted to a third-party AI provider may be retained by that provider according to its own policies and terms. Chameleon does not control the retention of data once it has been transmitted to an independently operated service.

9. Security

Chameleon uses reasonable technical measures intended to protect locally stored application information and credentials.

However, no method of storing or transmitting information is completely secure.

You are responsible for:

  • Securing your device.
  • Protecting your API keys and other credentials.
  • Securing any remote AI server you configure.
  • Reviewing the security and privacy practices of third-party services you use with Chameleon.

10. Your Choices and Controls

You can:

  • Choose whether to use a local or remote AI endpoint.
  • Select and change AI providers and models.
  • Change or remove AI configuration.
  • Edit or delete local project files.
  • Remove local application data from your device.
  • Revoke API keys through the applicable AI provider.

11. Children’s Privacy

Chameleon is not directed toward children under 13, or the equivalent minimum age in jurisdictions where a different minimum applies.

Chameleon does not knowingly collect personal information from children through an in-app account system.

12. International Data Transfers

If you configure a remote AI endpoint or third-party service located in another country, information processed through Chameleon may be transferred to and processed in that country.

The applicable third-party provider's privacy policy and terms determine how that provider handles such information.

13. Changes to This Policy

We may update this Privacy Policy from time to time.

If material changes are made, we will update the “Last updated” date and, where appropriate, provide additional notice.

14. Contact

For questions about this Privacy Policy or Chameleon, you can contact the developer through: