Draft requiring legal review before launch.

Privacy Policy

Version 1.0 · Effective 9 September 2026

1. Scope and important notice

Intimei is an AI-powered virtual companion service. Conversations may contain intimate, sexual, relationship, location or other sensitive personal information. We therefore treat conversation and memory data as privacy-sensitive information.

The production version of this policy must identify the legal controller/operator, registered contact details and representative or data-protection contact where required. Those operator-specific details have not yet been supplied in this repository.

2. Information the Service can process

  • Account data: email address, password hash, age, language, country, city and account status.
  • Profile data: display name, interests, preferences, avatar and onboarding responses.
  • Conversation data: messages, AI replies, conversation summaries, memories/facts and interaction state used for continuity.
  • Technical and security data: IP address, user agent, timestamps, authentication and audit records.
  • Location data: approximate or precise coordinates only when a feature actually requests and receives them.
  • Purchase data: packs, amounts, currencies, provider references, credit ledger and consent records. Card details should remain with the payment provider rather than the chat application.
  • Partner data: attribution, referral and affiliate information where applicable.

3. AI processing

Messages and selected conversational context may be sent to configured AI providers to generate replies, summaries or embeddings. The Service can also use Redis for short-term conversational context and PostgreSQL/pgvector for persistent data and retrieval.

Before launch, the operator must document the specific providers used, their roles, data locations, contractual safeguards, retention arrangements and any international transfers that apply.

4. Purposes and legal bases

Data may be processed to provide the requested virtual-companion service, authenticate accounts, maintain conversation continuity, prevent fraud and abuse, process purchases, comply with legal obligations and operate support/moderation functions.

Because adult conversations can reveal special-category or otherwise highly sensitive information, the operator must complete a jurisdiction-specific legal-basis assessment before launch, including whether explicit consent or other safeguards are required for particular processing.

5. Retention

Conversation records have a configured retention period. The application contains an automated cleanup process for expired conversations and corresponding short-term Redis buffers. Other records, such as payment, accounting, fraud, consent or audit records, may require different retention periods.

6. Your controls and rights

Depending on applicable law, you may have rights to access, correct, delete, restrict or obtain a copy of your personal data, object to certain processing, or withdraw consent where consent is the legal basis.

The application's data-export function is designed to include account/profile information, credit ledger, payments, consent records, conversations, messages and stored conversation summaries rather than excluding chat history.

7. Account deletion

Account deletion removes conversation/profile records covered by the deletion flow, clears corresponding short-term conversation buffers and anonymizes core account identifiers. Some records may need to be retained when legally required, for example accounting, fraud-prevention or dispute records.

8. Security

The application uses measures including password hashing, HttpOnly authentication cookies, authorization guards, rate limiting, audit controls and secret-management rules. No system can guarantee absolute security, and production deployment still requires operational controls such as key rotation, backups, monitoring and incident response.

9. Cookies and similar technologies

Authentication and referral features use cookies. See the Cookie Policy for further information. Non-essential analytics or advertising technologies should not be activated before the required consent mechanism is configured for the markets served.

10. Production legal review required

This page has been aligned with the actual technical design as a first hardening pass; it is not a substitute for jurisdiction-specific legal advice. Controller identity, contact information, processor list, international-transfer disclosures, legal bases and regulatory notices must be finalized before commercial launch.