Privacy policy
Last updated October 7, 2026
Draft: this page still needs review by a lawyer and isn’t final legal advice.
Chaos lets people create forms, quizzes, lessons, courses and flashcards (“creators”), lets anyone answer forms and quizzes (“respondents”), and lets people read and study published material (“learners”). This policy explains what we collect, why, and the choices you have. If something here is unclear, email khomod14@gmail.com.
The short version
- We don’t sell your data and we don’t show ads.
- We don’t use your content or answers to train AI models, and Chaos runs no AI itself. If you connect ChatGPT or Claude, they see only what you ask them to work with (see below).
- Answers belong to the creator of the form. The creator decides how long they are kept and can delete them at any time.
- You don’t need an account to answer a form unless its creator asks you to sign in.
Information we collect
If you create an account
- Account details: your name, email address, username and profile picture, handled by our sign-in provider, Clerk.
- Your content: the forms, quizzes, lessons, courses, flashcards, themes, templates, comments and settings you create, the source files you upload to lessons, and who you share them with.
- Copies: when you copy a public lesson or quiz, we record where it came from so the original author stays credited.
- Activity: records such as when a form was published or edited, so collaborators can see its history.
If you answer a form
- Your answers, including any files you upload, the language you used, and when you started and submitted.
- If the form requires sign-in, your account ID is linked to your answer, for example to allow one response per person.
- If the creator turns on unfinished answers, what you type may be saved before you submit. The form tells you when this is on.
- Basic technical signals used to prevent spam and abuse, such as how fast a form was completed and short-lived rate-limit counters.
If you learn on Chaos
- When you’re signed in, your progress through lessons and courses, your answers to attached quizzes, flashcard reviews and the weak areas worked out from them. These are private to you.
- Lessons you save, and any reports or comments you post. Comments on public lessons are visible to other readers.
- Highlights and notes are kept on your own device and are not shown to anyone else.
- Verification requests aren’t open yet; nothing is collected for them.
Stored on your own device
Chaos uses your browser’s local storage for your light/dark preference, whether sounds are on, and your progress on a form so you don’t lose answers if you close the page. Clerk uses cookies to keep you signed in. We don’t use advertising or cross-site tracking cookies.
Optional PostHog analytics runs only after you choose Allow analytics. You can reject it or withdraw consent through Cookie settings. Read our cookie and browser storage policy for storage details and controls.
How we use information
- To run Chaos: show forms, record answers, calculate quiz scores and show results to creators.
- To keep it safe: prevent spam, enforce limits and investigate abuse.
- To send in-app notifications to creators, for example when a response arrives.
- To connect with Max when a creator chooses to. Max receives only the form definitions the creator selects and permitted summary numbers, never individual answers.
- To work with ChatGPT, Claude or another assistant when you connect it (see below).
- To send webhook events to an address a creator sets up. Events say what happened (for example that a response arrived) and contain counts, not answers.
- To make a Google Wallet pass of your member card when you ask. The pass holds what your public card shows and is then handled by Google.
Who can see answers
The form’s owner and the collaborators they invite can see responses. Creators are responsible for how they use the answers they collect, and should tell respondents why they are asking. Small groups are hidden in summaries sent to Max so individuals can’t be singled out.
Using Chaos from ChatGPT or Claude
You can connect your Chaos account to ChatGPT, Claude or another assistant that supports MCP. You sign in with your Chaos account and approve the connection; you can disconnect it at any time in the assistant’s settings, or ask us to revoke it.
- The assistant can create, edit and publish forms, quizzes, lessons, courses and flashcards, and read your content, results and responses, only when you ask it to. New things it creates start as private drafts and are published only when you ask.
- What the assistant reads (for example a results summary or the answers you ask it to look at) is sent to its provider and handled under their policy, such as OpenAI’s or Anthropic’s. Only ask it to read individual answers when you are allowed to share them.
- Ask ChatGPT / Ask Claude buttons in lessons open the assistant with the lesson text or your selection. Nothing is sent until you choose to.
- Chaos never sends respondents’ answers to an assistant on its own, and assistants cannot delete forms or responses.
- Anything an assistant creates is marked in its history as made by a connected app.
Service providers
We use a small number of providers to run Chaos. They process data only on our behalf:
- Clerk for sign-in and account management.
- Convex for the database, file storage and server functions.
- Vercel for hosting the website.
- PostHog for optional product analytics when configured and you consent: which pages are visited (with links, names and codes removed from the address, so a form link is recorded only as “a form”), a few named events and errors, never answers. It keeps an anonymous id in your browser’s local storage, not a cookie. When you are signed in, these are linked to your account id (not your email or name); people answering forms stay anonymous.
- Vercel Speed Insights on chaos.fail, only after you allow analytics: page load speed (Core Web Vitals) with the page’s route pattern instead of its address. No cookies or browser storage.
How long we keep data
- Creators can set a retention period on each form; older responses are then deleted automatically.
- Deleting a form deletes its responses, uploads and history.
- Unfinished resume links expire after 30 days. Uploads that are never attached to a submitted answer are removed automatically.
- To request account closure or a copy of account data, email us from your account address. Requests are handled manually after identity and scope checks. Some records may need preservation for legal reasons or because published content references them; we will explain the scope before taking action.
Your choices and rights
Request a copy of account data · Request account closure. These links open an email request and do not delete data automatically. For answers to another person’s form, contact that creator first.
You can view, edit, export and delete your forms and responses from your dashboard. Depending on where you live, you may also have the right to access, correct, delete or receive a copy of your personal data, or to object to how it is used. If you answered someone else’s form, contact that creator first, since they control those answers; we will help if you can’t reach them. Email khomod14@gmail.com for any request.
Children
Accounts are for people old enough to agree to these terms where they live. Teachers and others who collect answers from children are responsible for getting any consent the law requires and for collecting no more than they need.
Security
Data is encrypted in transit. Private links (such as edit and resume links) and connection tokens are stored only as secure hashes. No system is perfectly secure, so please don’t collect sensitive information like passwords or payment card numbers in a form.
Changes
If we make significant changes to this policy we’ll update the date above and, where appropriate, let account holders know in the app.