Privacy Policy

What we collect, and why.

This page covers data collected through chameleon-data.com itself — the contact form, the signup flow, and site analytics. It does not cover data you process through a Chameleon instance you run yourself (self-serve) — that never reaches Chameleon at all; see the note on hosted instances below for the one case where it does.

Last updated July 20, 2026.


What we collect

Two forms, two purposes.

Contact form

Name, email, topic, and message. Sent by email so we can reply — not stored in a database beyond what our email provider retains in the normal course of delivering that email.

Signup form

Contact email, instance configuration (name, environment, region, warehouse type), and — depending on the path you pick — a GCP project ID/number (self-serve) or the email addresses of analysts you want granted BigQuery access (hosted). Stored so we can provision your instance and follow up on its status.

If you connect Snowflake, the signup form collects your account identifier, username, role, warehouse, database, and schema — never a password. Snowflake credentials are set directly in your own infrastructure's secret store after signup, not through this site.


Self-serve vs. hosted

This is the distinction that matters most.

Self-serve (BYOC): you run Chameleon in your own GCP project. Your actual data — whatever personal information your own product collects about your own users — never reaches Chameleon or this site. We only hold the signup metadata above.

Hosted:Chameleon provisions and operates a dedicated instance on your behalf. In this case Chameleon does process personal data on your behalf as part of running that instance — which is a materially bigger commitment than the self-serve case. We're flagging this plainly rather than overstating our current legal posture: formal data processing agreements for hosted customers are handled case by case as those engagements happen, not something this page can promise on its own. If you're evaluating hosted for a use case with real compliance requirements, say so when you sign up or contact us first.


Where it goes

Third parties we rely on.

Google Cloud Platform

Signup records are stored in Firestore in a Chameleon-owned GCP project. Hosted instances run in their own dedicated GCP project.

Resend

Delivers contact replies and signup emails (download links, status updates, credentials for hosted instances).

Vercel

Hosts this site. Vercel Analytics, used for basic traffic numbers, is cookieless — no persistent identifiers, no cross-site tracking, no consent banner required for it.


Retention and your rights

Ask, and we'll act on it.

We keep signup records for as long as needed to provision and support your instance. There's no automated deletion schedule for this data today — if you want your signup record deleted, email us and we'll remove it by hand.

You can ask to see what we hold about you, correct it, or have it deleted at any time by emailing brecht.bvb@gmail.com. We'll respond directly — there's no self-service portal for this yet.