Data we process
We process account identifiers, transaction records, prompts, uploads, generated outputs, security logs, and technical request data needed to operate the service.
Purpose
Data is used to authenticate users, process generation and payment requests, deliver outputs, prevent abuse, troubleshoot failures, and meet legal obligations.
Service analytics
When product analytics is enabled for Chimera, we measure page usage and limited product events such as generation, checkout, account sign-up, and confirmed purchase. We do not send prompts, uploads, generated outputs, account, Clerk, Stripe, card, task, or payment-capability identifiers, or checkout URLs to analytics. Analytics providers may process technical data such as cookie or device identifiers and page information under their own terms. We use these measurements to understand service usage and improve reliability.
Advertising attribution
When you arrive through a supported advertising partner, we may retain the partner’s pseudonymous click identifier in your browser. After a confirmed purchase, we may send that click identifier and the purchase value to the same partner so the campaign can be measured. We do not send prompts, uploads, generated outputs, account identifiers, email addresses, card details, or payment-capability identifiers for advertising attribution.
Storage and providers
Input uploads expire 24 hours after upload once processing no longer needs them. Generated media remains available through your account library for 16 days after creation and is then removed. Account, transaction, and security records may be retained longer where operational, fraud-prevention, or legal requirements apply.
Your choices
You may request access, correction, or deletion where applicable. Some transaction and security records must be retained by law or for fraud prevention.
Contact
Send privacy questions through the contact page. Do not include sensitive images in an initial inquiry.
Last updated: August 14, 2026