Privacy Policy
Last updated: September 19, 2026
1. Who we are and what this policy covers
MolChart (molchart.com) is a web-based chemical structure editor operated by its developer, Xiangyang Wang. You can reach us at admin@walzone.com. This policy covers the molchart.com website and editor, its built-in AI assistant, and the MolChart app for ChatGPT (the "ChatGPT plugin"), which talks to the same server.
2. What we collect
We collect only what is needed to run the service. By category:
- Account data (only if you create an account): email address, username, a salted hash of your password (never the password itself), and, if you sign in with Google, the email address Google returns to us. We also store whether your address is verified and the plan you are on.
- Your content: the chemical structures, reactions, text labels and notes you draw or import, saved as documents so you can come back to them.
- AI assistant conversations: the messages you send the assistant, its replies, the editing commands it issued, and the structure on your canvas at the time (as SMILES), together with a random per-browser visitor id and a per-tab session id. Please do not paste confidential or personal information into the assistant.
- ChatGPT plugin data: when you use MolChart inside ChatGPT, ChatGPT sends our server the tool calls its model derives from your conversation (for example a SMILES string, a compound name, or a document id). We do not receive your ChatGPT account identity and the plugin needs no MolChart sign-in. The structures you create are stored as guest documents under a random document id. Our tool responses contain only chemistry data, document ids and status messages.
- Usage and technical data: for each page view and API request we log the page or endpoint, time, response status and duration, your IP address, approximate location (country and city, derived from the IP address), browser user agent, referring page, and any advertising click id (gclid / msclkid) present in the landing URL. Our web server also keeps standard access logs.
- Billing data (paid membership only): payments are handled by Stripe. We store your Stripe customer and subscription ids, plan and renewal date. We never see or store card numbers.
- Support correspondence: what you send us by email.
3. How we use it
- To provide the editor: save, sync and display your documents; run the AI assistant; answer ChatGPT plugin requests.
- To operate accounts: sign-in, email verification, password reset, membership billing and usage quotas.
- To keep the service working and secure: diagnose errors, detect abuse, and understand which features are used. AI conversation logs are read only to debug incorrect edits and improve the assistant's instructions.
- To measure our own advertising: whether a visit came from a Google or Microsoft search ad and whether it led to using the editor.
- To contact you about your account or important service changes. We do not send marketing email.
Where the GDPR applies, we rely on performance of a contract (providing the service you asked for), our legitimate interests (security, debugging, measuring our own ads), and your consent where the law requires it (advertising tags).
4. Who receives your data
We do not sell personal data and do not share it for third-party marketing. Data is shared only with the processors and services below, each for the purpose stated:
- OpenAI (API) — receives your AI assistant messages and the current canvas so the assistant can answer. Under OpenAI's API terms this data is not used to train their models. When you use the ChatGPT plugin, OpenAI is the platform you are talking to; its own privacy policy governs your conversation there.
- PubChem (US National Library of Medicine) — receives the structure, SMILES, name or compound id you search for, when you use a PubChem search feature.
- ip-api.com — receives visitor IP addresses to derive the approximate country and city stored with page views.
- Google — Google Ads conversion tag (measures visits from our search ads), Google Fonts (loads typefaces), and Google Sign-In if you choose it.
- Microsoft Advertising — UET tag, measures visits from our Bing ads.
- Stripe — payment processing for memberships.
- IONOS — hosts our servers and database in the United States.
- Our email provider (walzone.com mail server) — delivers account verification and password-reset messages.
Our servers are in the United States; if you use MolChart from elsewhere your data is transferred there. We may also disclose data when the law requires it.
5. How long we keep it
| Data | Kept for |
|---|---|
| Account data | Until you delete your account (see section 6) |
| Documents in your account | Until you delete them or your account |
| ChatGPT guest documents | 30 days after the last change, then deleted automatically |
| ChatGPT plugin tool-call log | 30 days, then deleted automatically |
| AI assistant conversation logs | 24 months |
| Page views and API usage logs (incl. IP address, location) | 24 months |
| Web server access logs | 14 days |
| Email verification / password-reset tokens | 24 hours / 1 hour |
| Billing records | As long as required for tax and accounting law; Stripe keeps its own records |
6. Your controls and rights
- Your documents: view, edit, export and delete them at any time in the editor. In ChatGPT, ask MolChart to delete a document, or simply wait: guest documents are deleted 30 days after their last change.
- Your account: change your password and email in the editor. To delete your account and all data linked to it, email admin@walzone.com from your account address; we complete deletion within 30 days.
- Access, correction, portability, objection: email us and we will provide a copy of your data, correct it, or stop a processing you object to, within 30 days.
- Advertising tags: the Google and Microsoft tags load only on molchart.com pages; you can block them with your browser's tracking-protection or an ad blocker without losing any functionality. The ChatGPT widget loads no advertising or analytics tags.
- If you are in the EU/UK you can also complain to your data-protection authority.
7. Cookies and local storage
MolChart itself sets no tracking cookies. Your browser keeps a sign-in token (so you stay logged in) and a random visitor id (used for the free AI allowance and to group your own assistant conversations); both are in the browser's local storage and are removed when you clear site data. The Google Ads and Microsoft UET tags may set their own cookies as described in their policies.
8. Security
All traffic is encrypted with TLS, passwords are stored only as salted hashes, and access to the production database is limited to the operator. No system is perfectly secure; if we learn of a breach affecting you we will notify you as the law requires.
9. Children
MolChart is not directed at children under 13 and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
10. Changes to this policy
We will post changes on this page and update the date above. For significant changes we will notify account holders by email or a notice in the application.
11. Contact
Questions or requests about this policy: admin@walzone.com.
← Back to MolChart