The Chameleon Privacy Promise: Zero Knowledge by Design
Chameleon does not maintain user databases, does not track your online navigation, does not record keystrokes, and does not operate any intermediate proxy servers that intercept your browsing sessions, screen captures, or AI queries. What happens on your screen stays on your device.
Architectural Privacy Guarantee
Chameleon Labs (“we”, “us”, or “our”) is committed to uncompromising privacy standards. This Privacy Policy discloses our information practices for the Chameleon desktop application (macOS and Windows), our website, and related services (collectively, the “Software”).
Unlike traditional software companies that aggregate user data to train proprietary algorithms or monetize via telemetry brokers, Chameleon is intentionally engineered as an air-gapped, client-side utility. Our servers have neither the capability nor the architectural permission to observe what you view, read, capture, or type inside the application.
What We Never Collect
To eliminate any ambiguity, Chameleon maintains a strict non-collection policy for all operational and sensitive user data:
We never monitor, log, or record URLs visited, search queries entered, bookmarks, or web session cache.
We never stream, capture, upload, or inspect display buffers, screen shares, or video conferencing feeds.
We never keylog, monitor typing speeds, inspect clipboard buffers, or record shortcut keystrokes.
We never record, listen to, process, or store microphone audio, system sound, or call audio.
Local Execution & Display APIs
Chameleon achieves its screen-share invisibility by directly calling low-level operating system window compositor flags on your local machine:
- On macOS: Chameleon interacts with the local Quartz Window Server and ScreenCaptureKit frameworks (
kCGWindowSharingNone) entirely within your machine’s memory space. - On Windows: Chameleon invokes the Desktop Window Manager (
SetWindowDisplayAffinitywithWDA_EXCLUDEFROMCAPTURE) locally.
None of these operating system calls produce remote network telemetry or transmit your display state across the internet.
AI Vision & Third-Party Services
Chameleon features a “1-Click Screenshot to AI” shortcut allowing you to snip your desktop and provide visual context to your chosen artificial intelligence assistant (such as OpenAI ChatGPT, Google Gemini, Anthropic Claude, xAI Grok, or DeepSeek).
- The screen capture is created locally and stored temporarily in your computer’s volatile system RAM.
- When you submit the prompt, the image and text are dispatched directly from your computer to the official endpoint of the AI provider via secure TLS 1.3 encryption.
- Chameleon does NOT route this payload through any intermediary proxy or proxy server operated by Chameleon Labs. We never inspect, store, or cache your screenshots or prompts.
- Your interactions with third-party AI models are governed exclusively by each respective provider’s privacy terms (e.g. OpenAI Privacy Policy, Google Privacy Policy, Anthropic Privacy Policy).
License Checks & Update Manifests
To prevent unauthorized piracy and ensure you have access to critical security patches, the Software performs minimal, privacy-preserving client checks:
- Cryptographic License Verification: When you enter a license key, the application sends a one-way hashed activation token, cryptographic signature, and license key string to verify entitlement. This check contains no personal browsing or system activity data.
- Version Update Checks: Periodically, Chameleon queries our static HTTPS release manifest to check if a newer build is available. This request sends only the current application version number and your general operating system family (e.g., macOS Sonoma or Windows 11).
Payment & Billing Data
When you purchase a Chameleon license, all financial transactions are processed directly by certified, PCI-DSS Level 1 compliant third-party payment gateways (such as Stripe, LemonSqueezy, or Paddle).
Chameleon Labs and its creators never receive, process, or store full credit card numbers, debit card details, or CVV security codes. We receive only non-sensitive transactional tokens (e.g., payment status, order ID, and the email address you provided for license delivery).
Website Analytics & Cookies
When visiting our marketing website, standard technical web server logs (including your IP address, browser user agent, referring URL, and timestamp) are processed temporarily to mitigate distributed denial-of-service (DDoS) attacks, detect security anomalies, and ensure CDN edge routing efficiency.
We do not deploy intrusive cross-site tracking pixels, third-party advertising cookies, or behavioral profiling scripts. We do not sell, rent, or trade your website visitation data to any data brokers or advertisers.
Global Regulatory Compliance (GDPR & CCPA)
8.1 European Union & UK General Data Protection Regulation (GDPR): Under the GDPR, Chameleon functions primarily as a decentralized software provider. Because we do not store personal operational data on our servers, our data minimization is absolute. For billing records, our lawful basis for processing is contractual necessity and compliance with statutory financial retention obligations. You have the right to request access to or deletion of your billing email record by contacting us.
8.2 California Consumer Privacy Act (CCPA / CPRA): We do NOT “sell” or “share” personal consumer information as defined under California law. We do not use sensitive personal information for inferring characteristics about consumers.
Protection of Children (COPPA)
The Software and website are intended strictly for adult professionals, developers, and individuals of legal majority. We do not knowingly collect, solicit, or maintain personal information from children under the age of thirteen (13), or under the age of sixteen (16) in the European Union and United Kingdom. If you become aware that a child has provided us with personal information, please notify us immediately so we may purge such records.
Local Data Security
Any user preferences, saved bookmarks, or API keys configured inside the Chameleon desktop application are stored locally on your physical device using your operating system’s secure credential storage facilities (such as Apple macOS Keychain or Windows Credential Manager) and standard sandboxed application support directories. Chameleon Labs has no remote access or decryption keys for this data.
Policy Changes & Privacy Inquiries
We may update this Privacy Policy from time to time to reflect operational, legal, or technical changes. Any revisions will be published on this page with an updated “Effective Date”.
If you have any questions, concerns, or data protection inquiries regarding this Privacy Policy, our local-first architecture, or your privacy rights, please reach out directly to our Data Protection Officer at: