Privacy Policy

Effective date: [EFFECTIVE DATE]

This policy explains how [COMPANY LEGAL NAME] ("we", "us") handles personal information when you use [SITE NAME] (the "Service"). The Service is for adults only; we do not knowingly collect information from anyone under 18, and we delete it if we learn we have.

1. What we collect

InformationWhere it comes from and why
AccountCreated when you confirm you are 18+: an account code, the time you confirmed your age, and a random device id (stored hashed). Your recovery key is stored only as a hash. We use these to keep your account and call time, and to keep you signed in.
Email address and password (optional)Only if you add them. We store the email and a hash of your password (never the password itself), and use the email to send verification codes, receipts, support replies and legally required notices. We do not send marketing email unless you opt in.
Call-time balance and purchase historyCreated when you buy call time and make calls: product, price, order number, payment status, time, and seconds added or used. Needed for billing, refunds, fraud prevention, tax and accounting.
Payment detailsEntered on the hosted checkout of our payment processor, [PAYMENT PROCESSOR NAME]. We never receive or store your full card number. The processor sends us the payment result and may share limited data (such as card brand, last four digits, country, and fraud-check results). The processor's own privacy policy applies to the data it collects.
Call metadataWhich character you called, call start and end times, minutes charged, connection status and errors. Used to bill you, run and troubleshoot calls, and prevent abuse.
Chat textMessages you type, and speech you dictate after your browser turns it into text, are sent to AI models to generate the character's replies. We keep conversation text and short notes derived from it (for example, the name you give) as "conversation memory", linked to your account, so a character can remember earlier talks with you.
VoiceWhen you turn on the mic, speech recognition runs in your browser; depending on your browser, the browser maker (for example Google or Apple) may process the audio under its own policy. Your raw audio is not sent to the character's video stream and we do not store recordings of your voice.
Images you uploadIf you use an optional feature that takes a reference picture, the image is sent to an AI image provider to create the scene and stored so the result can be shown. Only upload images you have the right to use and that do not show a real person without consent or anyone under 18.
Device and technical dataIP address, browser type (user agent), and request logs, collected automatically by our servers and network providers. Used for security, rate limiting, fraud prevention and debugging.
Advertising and campaign dataIf you arrive from an ad, the campaign tags in the link (such as utm_source or ad id) and the Meta click id (fbclid), kept in your browser for up to 90 days and with your account. Used to know which ads bring visitors and to measure them; see section 3.

We do not sell your personal information for money. We do not run third-party advertising or analytics scripts in your browser. We do not use your data to train our own AI models. [CONFIRM WITH AI PROVIDERS' TERMS WHETHER THEY MAY USE INPUTS FOR TRAINING]

2. Sensitive information

Using an adult service, and what you say in a chat, can reveal information about your sex life or sexual orientation, which some state laws treat as sensitive personal information. We use it only to provide the Service you asked for, as described here, and not to profile you or infer characteristics about you.

3. Who we share it with

We share personal information only with service providers that process it for us under contract, and only as needed:

Advertising measurement (Meta)

We advertise on Meta (Facebook and Instagram). To measure those ads, our server (not a script in your browser) may send Meta's Conversions API a limited set of events: page view, viewing a room, your first call, starting checkout, and a completed purchase (with its amount and currency). Each event carries a hashed account id, your hashed email if you verified one, your IP address and browser user agent, the Meta click id and campaign tags if you came from a Meta ad, and the page address without any query string. We never send chat text, character names, recovery keys or card details. Meta processes this data under its own terms and may use it for ad measurement and targeting. Under some state laws this counts as "sharing" for targeted advertising; you can opt out as described in section 6.

Current list of subprocessors and their locations: [SUBPROCESSOR LIST]. Some of these providers may process data outside the United States. We also disclose information when required by law, to protect people from harm, to enforce our Terms, and in connection with a merger or sale of the business (with notice to you). We report apparent child sexual abuse material to NCMEC as required by 18 U.S.C. 2258A.

4. How long we keep it

DataKept for
Account (account code, email, balance)While your account is open. When you delete it in the app (section 5) your email, password and recovery keys are erased at once; an emailed request is completed within 45 days.
Purchase and billing records[BILLING RECORD RETENTION PERIOD, e.g. 7 years] to meet tax, accounting and card-network rules, even after account deletion (then no longer linked to your email or account code).
Conversation memory and chat textConversation memory: 90 days after your last visit, then deleted automatically, or at once when you delete your account. The text of a single call is deleted when the call ends, and in any case within 24 hours of its last message.
Uploaded images[IMAGE RETENTION PERIOD].
Server and security logs[LOG RETENTION PERIOD, e.g. 90 days].
Sign-ins, email codes and recovery keysA sign-in session until it expires (30 days after you last use it) or you sign out; email verification codes 1 day after they expire; a replaced recovery key 30 days after it was replaced.
Advertising events and campaign data90 days, then deleted automatically, or at once when you delete your account. Meta keeps what it receives under its own policy.

5. Deleting your data

In the app, open My account and choose Delete my account. It takes effect at once: we erase your email, password hash, recovery keys, sign-in sessions, email codes, conversation memory, campaign data and advertising events, sign you out everywhere, and cancel any checkout still open. Your orders, payments, call records and call-time history are kept for tax, accounting, refunds and chargebacks, but no longer linked to an email or account code.

You can also email [PRIVACY EMAIL] from the address on your account, or include your account code, and ask us to delete your account, your conversation memory, or both. For a guest account we may ask you to prove it is yours with your recovery key or by a step in the app. We confirm the request and complete it within 45 days. Clearing your browser's site data signs you out and removes the saved recovery card, device id and campaign data from that device, but does not delete your account. We keep billing records we are legally required to keep. Deleting your account forfeits any remaining call time unless you ask for a refund first (see the Refund Policy).

6. Your privacy rights (California and other US states)

Depending on where you live (including California under the CCPA/CPRA, and Virginia, Colorado, Connecticut, Utah, Texas, Oregon and other states with comprehensive privacy laws), you may have the right to:

To use a right, email [PRIVACY EMAIL]. We verify requests by sending a code to your account email. An authorized agent may act for you with your signed permission. We answer within 45 days (extendable once by 45 days where the law allows). If your appeal is denied you may contact your state attorney general.

Your privacy choices — Do Not Sell or Share My Personal Information: turn on the Do Not Sell or Share My Personal Information switch in My account (also linked at the bottom of the main page). It takes effect at once: we stop recording your events for Meta and never send the ones still waiting. You can also email [PRIVACY EMAIL] with the subject "Do Not Share" and your account code or email; we act on an emailed request within 15 business days. If your browser sends a Global Privacy Control (GPC) signal, we treat it as an opt-out and save it on your account; while your browser sends it, the switch stays on.

In the last 12 months we collected the categories listed in section 1: identifiers (account code, email, IP address, device id, Meta click id), commercial information (purchases), internet activity (logs, call metadata), audio-derived text, user-provided images, inferences only as needed to run conversations, and sensitive information as described in section 2. We disclosed them for business purposes to the service providers in section 3, and shared identifiers, commercial information and internet activity with Meta for advertising measurement as described there. We did not sell them for money.

7. Security

We use HTTPS, HttpOnly session cookies, hashed passwords and recovery keys, access controls and limited data collection. No system is perfectly secure; if a breach affects your personal information we will notify you as the law requires.

8. Children

The Service is not for anyone under 18. Report a suspected minor user to [SUPPORT EMAIL].

9. Changes and contact

We will post changes here and update the effective date. Questions: [COMPANY LEGAL NAME], [ADDRESS], [PRIVACY EMAIL].