Privacy Policy

Last updated: April 13, 2026 · Effective immediately

Chatelier LTD ("we", "us", "our"), Company № 16846652, registered in England & Wales, operates the Jess AI travel platform ("Service"). This Privacy Policy explains how we collect, use, and protect your information.

1. Information We Collect

a. Information You Provide

b. Automatically Collected

c. Third-Party Data

We may receive data from travel platforms (Duffel, Channex), payment networks (Base blockchain), and authentication providers (Google).

2. How We Use Your Information

PurposeLegal Basis (GDPR)
Provide travel search and booking servicesContract performance
Process payments via USDCContract performance
Personalize AI recommendationsLegitimate interest
Share passport data with airlines for bookingContract performance
Send booking confirmations and travel updatesContract performance
Improve the Service and Decision EngineLegitimate interest
Prevent fraud and ensure securityLegitimate interest
Comply with legal obligationsLegal obligation

3. Passport Data Protection

🔐 Your passport data is encrypted with AES-256-GCM before storage. It is only decrypted when needed to complete a flight booking with the airline. We never display full passport numbers in the UI. You can delete your passport data at any time from your profile.

4. Voice Data

If you use voice input:

5. AI Processing

Your queries are processed by OpenAI's API to generate responses. By using Jess:

6. Data Sharing

We share your data only as necessary:

RecipientPurposeData Shared
DuffelFlight search and bookingPassenger name, passport, dates
ChannexHotel bookingGuest name, email, dates
OpenAIAI processingChat messages (anonymized)
DeepgramSpeech-to-textAudio stream (not stored)
ElevenLabsText-to-speechResponse text only
Base NetworkPayment processingWallet address, amounts
BrevoEmail notificationsEmail, booking details

We do NOT sell your personal data. We do not share data with advertisers or data brokers.

7. Blockchain & Payment Data

Payments are processed on the Base blockchain (Layer 2 Ethereum). Please note:

8. Cookies & Tracking

We use minimal cookies:

We do not use third-party advertising cookies. We do not use Google Analytics or Facebook Pixel. You can disable cookies in your browser settings.

9. Data Retention

Data TypeRetention Period
Account informationUntil account deletion
Conversation history90 days, then auto-deleted
Passport data (encrypted)Until you delete it or 12 months after last booking
Booking records7 years (legal requirement)
Payment transactionsOn-chain permanently; off-chain records 7 years
Voice dataNot stored beyond active session

10. Your Rights

Under GDPR (UK/EU residents)

You have the right to:

To exercise these rights, contact us at info@chatelier.net. We will respond within 30 days.

Under CCPA (California residents)

You have the right to know what data we collect, request deletion, and opt out of data sales (we do not sell data). Contact us to exercise these rights.

11. Data Security

We implement industry-standard safeguards:

No system is 100% secure. We cannot guarantee absolute security but commit to promptly addressing any breaches.

12. International Transfers

Your data may be processed in:

Where data is transferred outside the UK/EU, we ensure appropriate safeguards are in place (Standard Contractual Clauses or adequacy decisions).

13. Children's Privacy

The Service is not intended for children under 13. We do not knowingly collect data from children under 13. If we become aware of such data, we will delete it promptly.

14. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via the Service or email. Continued use after changes constitutes acceptance. Previous versions are available upon request.

15. Data Protection Officer

For privacy inquiries or to exercise your rights:

If you are unsatisfied with our response, UK residents may contact the Information Commissioner's Office (ICO).