This policy explains what information Enchant collects, how it is used to run your jobs, which companies are involved along the way, and the choices you have.
Last updated: July 27, 2026
01
Overview
This policy explains what information Conto Finance, Inc. ("we", "us") collects when you use the Enchant service at askenchant.com, how we use it, who we share it with, and the choices you have. Enchant is a product of Conto Finance, Inc., a Delaware corporation. The policy applies to the website, the guest trial, and automated access through the agent API, the hosted MCP endpoint, and OAuth-authorized clients.
The short version: we collect what we need to run your jobs, bill you accurately, and keep the service safe. Your job content goes to the tool that executes it. We do not sell your personal information, and we do not run third-party advertising.
02
Information we collect
Account information. Your email address when you sign up with a verification code. If you sign in with Google, we receive basic profile information from your Google account (your email address and account identifier). We never see your Google password.
Prompts and job content. The prompts and inputs you submit and the results that come back. Enchant keeps a local copy of chat history and settings in your browser. When you sign in, chat history and settings are also synchronized to our servers so they are available across sessions. We also store content you choose to save or share. Internal usage records keep a short preview and a hashed fingerprint of prompts for billing, support, and abuse prevention rather than a full transcript.
Payment information. Card payments are handled by Stripe. We do not store your card number; we keep transaction records such as amounts, timestamps, and your credit balance. If you top up with stablecoins, we record the wallet address and transaction details, and note that blockchain transactions are public by design.
Guest trial usage. If you try Enchant without an account, we generate a random identifier stored in your browser and count the prompts you have used against the free allowance. On our servers we store that identifier with usage counts, timestamps, and a one-way hash of your IP address (not the address itself) to enforce the limit and prevent abuse.
Referral information. If you follow or use a referral link or code, we record the code, the referring and referred account identifiers, attribution and reward status, relevant purchase references, and timestamps. Customer-facing referral reporting does not disclose the referred customer's email address to the referrer.
Usage and diagnostics. Server logs, aggregated page analytics through Vercel Analytics, and error and performance reports through Sentry. Our Sentry setup scrubs cookies and authorization headers and removes URL query strings and fragments before reports are sent.
03
How we use information
We use the information above to:
run your requests: select a service for each prompt and return the result;
show accurate prices, charge your credit balance, and process refunds for failed runs;
operate accounts, sign-in, and saved or shared content;
enforce guest limits, rate limits, and spending controls, and detect fraud and abuse;
respond to support requests;
monitor errors and performance and improve the service;
comply with legal obligations.
We do not sell your personal information, and we do not use your data for third-party advertising.
04
How job content is shared to run your jobs
This is the most important thing to understand about Enchant: when you run a job, the content of that job is sent to the third-party provider that executes it. That is how the work gets done.
The providers vary by job type. They include image, video, and voice generation services, web search and research tools, document and data extraction tools, and other paid APIs from the Enchant catalog.
Browser automation jobs run in cloud browser sessions provided by Browserbase, which visit websites at your direction. What you type into a browser job is visible to the websites the session visits.
Each provider processes job content under its own terms and privacy practices. The product shows which tool handled a job, so you can see where your content went.
A practical tip: do not put sensitive personal information into a prompt unless the job actually needs it.
05
Service providers we use
Beyond the job providers described above, we rely on a small set of companies to run the service itself:
Stripe: card payment processing and checkout.
Vercel: hosting and aggregated page analytics.
Neon: the Postgres database where account and transaction data lives.
Sentry: error and performance monitoring.
Resend: transactional email, such as sign-in verification codes.
Conto: the payment rails that move money between your credits and the tools that run your jobs.
Browserbase: cloud browser sessions for browser automation jobs.
These providers process data on our behalf to deliver their part of the service. We may also disclose information if required by law, to protect the rights and safety of users or the public, or as part of a corporate transaction such as a merger or acquisition, with notice where required.
06
Cookies and similar technologies
Enchant uses a deliberately small set of cookies and browser storage:
Session cookie. When you sign in, we set an essential, httpOnly session cookie that keeps you signed in for up to 7 days.
Sign-in flow cookies. Google sign-in uses short-lived cookies to protect the sign-in handshake.
Browser storage.Your chat history, settings, guest trial identifier, and a pending referral code are stored in your browser's local storage. Pending referral attribution expires after 30 days. Clearing site data removes these local values sooner. If you are signed in, clearing browser storage does not by itself delete the synchronized server copy of your chat history or settings.
Analytics. Page analytics run through Vercel Analytics, which is designed to work without cross-site tracking cookies. We do not use advertising cookies or third-party trackers.
07
Data retention
Account information is kept for the life of your account. When your account is deleted, we remove user-authored content and operational credentials, retain a pseudonymous account tombstone and salted email hash for security, and purge the prior plaintext email after 90 days. Residual backup copies can persist for up to 90 days.
Transaction and billing records are kept for up to 7 years, as required for tax and accounting purposes.
Synchronized server chat history and settings are kept until you delete them or your account is deleted. Copies stored in your browser stay there until you clear them; we do not control that local copy.
Saved prompts, session memory, and shared results are kept until you delete them or your account is deleted.
Guest trial records, including the guest identifier, usage counts, and hashed IP addresses, are kept for up to 12 months and then deleted or aggregated.
Internal server diagnostics, audit logs, rate-limit records, and telemetry are kept for up to 13 months and then deleted or aggregated. Monitoring providers may retain de-identified aggregate metrics after the underlying event expires.
08
Security
We take reasonable technical and organizational measures to protect your information, including encryption in transit, httpOnly session cookies, hashed rather than raw IP addresses for guest tracking, scrubbing of credentials from error reports, and access controls on production systems. No online service can promise perfect security, so please use a unique email setup you control and contact us right away if you suspect a problem with your account.
09
Your rights and choices
Wherever you live, we want you to be able to see and control your information. You can:
ask for a copy of the personal information we hold about you;
ask for that copy in a portable, machine-readable format;
ask us to correct inaccurate information;
ask us to delete your account and associated personal information;
object to or ask us to restrict certain processing;
clear your local chat history and guest identifier from your browser at any time.
These rights are available to everyone who uses Enchant, wherever you live. To exercise them, use the support form in the product or contact support@conto.finance. We may need to verify that a request comes from you before acting on it.
10
For users in Europe (GDPR and UK GDPR)
If you are in the European Economic Area or the United Kingdom, Conto Finance, Inc. is the controller of your personal data, and we process it on these legal bases:
Contract: running your jobs, managing your account, and processing payments.
Legitimate interests: keeping the service secure, preventing abuse of the guest trial, and improving the product.
Legal obligation: tax and accounting records.
Consent: where we ask for it, which you can withdraw at any time.
You also have the rights to object to or restrict processing and to data portability, described in Section 9, and you can lodge a complaint with the supervisory authority where you live. To exercise any of these rights, contact us as described in Section 9.
11
For California residents (CCPA and CPRA)
If you are a California resident, you have the right to know what personal information we collect (described in Section 2: identifiers such as your email address, commercial information such as transactions, and internet activity such as usage records), to delete it, to correct it, and to not be discriminated against for exercising those rights.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
To exercise your rights, use the support form or contact support@conto.finance. An authorized agent may submit a request on your behalf with proof of authorization.
12
International transfers
Enchant and most of its service providers operate in the United States, so your information is processed there and in other countries where our providers run infrastructure. Where data moves from the EEA or UK to countries without an adequacy decision, we rely on appropriate safeguards, such as standard contractual clauses, where they are required.
13
Children
Enchant is not directed at anyone under 18, and we do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us personal information, contact us and we will delete it.
14
Changes to this policy
We may update this policy as the service evolves. If we make material changes, we will take reasonable steps to notify you, for example by email or by an in-product notice, before the changes take effect. The date at the top of this page shows when the current version took effect.
15
Contact
Questions about privacy are welcome. Use the support form in the product, or reach us at: