Legal
Privacy & Data Policy
1. Purposes for Which Customer Data Is Processed
Chimelab processes data for the following purposes only:
- Mail delivery detection — Ring vehicle motion events trigger on-server analysis of camera frames to detect when a vehicle stops at your MailDrop Zone, including a light-body color filter to reduce false positives from non-mail vehicles.
- Delivery history dashboard — confirmed deliveries are stored as records with timestamps, confidence scores, and up to nine snapshot thumbnails for your personal history.
- Ring account linking — your masked email address and Ring account ID are used to connect your Ring devices to yourChimelab account.
- Service operation — account IDs, device IDs, your timezone, and per-device settings (MailDrop Zone and detection sensitivity) route events to the correct user and tune detection.
- Security and fraud prevention — webhook signatures are verified to ensure motion events originate from Ring.
We do not process data for advertising, profiling, or any purpose not listed above. Chimelab does not send SMS, push, or email delivery alerts — delivery history is available in your dashboard only.
2. Use of Customer Data for AI Model Training
Chimelab does not use customer data to train, fine-tune, or improve any AI model.
Vehicle detection is performed by a local on-server model (YOLO11n ONNX) plus color heuristics. Camera frames are processed on our servers for inference only and are never sent to a third-party AI API.
The detection model weights are downloaded at application build time from a public open-source release — not from user data.
No snapshot images, video clips, or personally identifiable information are used as training data by Chimelab or any sub-processor.
3. Data Retention Periods
| Data Type | Retention Period |
|---|---|
| Delivery snapshot images (object storage) | Up to 9 most recent deliveries keep JPEG snapshots; older delivery rows (10–100) retain metadata only with snapshots automatically deleted |
| Delivery metadata (timestamps, confidence, detection stats) | Maximum 100 records per user; oldest records deleted on overflow |
| Recent motion debug records | Maximum 20 rows per user; older rows deleted automatically |
| Calibration preview image | Latest cached motion frame per device for MailDrop Zone setup in Settings (up to 20 recent-motion debug rows per user; preview blob overwritten when a new frame is stored) |
| Ring OAuth tokens | Encrypted at rest while linked. Removed when you delete your account or delete the Ring connection via the authenticated disconnect API. Uninstalling from the Ring App Store revokes access on Ring's side; token rows may remain until account deletion. |
| Webhook deduplication | PostgreSQL, 24-hour rolling window per request_id |
| Auth session cookie | 30 days maximum |
| User account data | Deleted immediately upon verified in-app account deletion (Settings → Delete Account) |
| Structured application logs | Written to hosting provider logs; app does not intentionally log PII, magic links, or OAuth tokens |
5. How to Exercise Your Privacy Rights (DSAR / Deletion)
You have the right to access, correct, export, or delete your personal data at any time. To submit a request:
- In-app deletion — go to Settings → Delete Account. Your account, Ring connection, delivery history, device settings, and stored snapshots are deleted immediately.
- Data export (DSAR) — email contactchimelab@gmail.com with the subject line “Data Access Request” from the email address on your account. We will respond within 30 days with a machine-readable export of all data associated with your account.
We do not charge a fee for privacy requests. We will verify your identity before fulfilling any request.
6. Available Opt-Out Mechanisms
- Disconnect Ring — uninstall or disconnect Chimelab from the Ring App Store. Ring stops sending motion webhooks and revokes OAuth access on Ring's side. Existing delivery records and encrypted token rows remain until you delete your account.
- Delivery watch hours — when your timezone is set in Settings, motion outside 6 AM–8 PM local time is not processed for delivery detection. Without a timezone, this gate is not applied.
- Delete account — permanently removes all data as described in Section 5.
- AI processing opt-out — because automated vehicle detection is the core function of the service, it cannot be disabled independently. Disconnecting your Ring account stops Ring media download and delivery detection.
- Ring privacy zones — you may configure privacy zones in the Ring app to mask areas of your camera view.
7. How Opting Out of Data Usage for Training Affects Your Service
Chimelab does not use customer data for AI training (see Section 2). There is therefore no opt-out required for training.
The detection model is a general-purpose open-source object detector. Its accuracy is not affected by any individual user's data.
8. Instances Where Humans May View Customer Data
Human access to customer data is strictly limited:
- Support requests — if you contact support, Chimelab support may view your delivery records (timestamps, confidence scores, detection metadata) to diagnose issues. Raw snapshot images are not viewed unless you explicitly share them or request help that requires it.
- Security incidents — in the event of a suspected security breach, authorized personnel may review structured logs to assess scope and remediate.
- Legal obligations — we may disclose data to law enforcement if required by a valid legal order.
- Calibration preview — the most recent motion frame used for MailDrop Zone setup is viewable by you in Settings; it is not routinely reviewed by operators.
No Chimelab personnel routinely views customer snapshot images or camera footage.
9. How Users Can Control and Review Their Data
- Delivery history — view logged deliveries, including snapshot thumbnails (up to nine most recent), timestamps, and confidence scores on the Dashboard.
- Device settings — configure MailDrop Zone, detection sensitivity, and timezone in Settings.
- Ring disconnect — uninstalling from the Ring App Store stops new webhooks and revokes OAuth on Ring's side. Delete your account to remove stored tokens and delivery history.
- Account deletion — permanently deletes all stored data immediately (see Section 5).
- Data export — request a full machine-readable export of your data at any time via email (see Section 5).
10. How We Inform Customers About Changes in AI Capabilities
We communicate detection capability changes through the following channels:
- This privacy page — the “Last updated” date at the top of this page is updated whenever AI processing practices change. Users are encouraged to review this page periodically.
- Email — for significant changes affecting data processing, we will send an email to the address on file at least 14 days before the change takes effect.
- Ring App Store listing — the app description and version release notes on the Ring App Store are updated to reflect new detection features.