Privacy Policy
Effective date: July 8, 2026 · Part of the Velvet.AI legal centre
This Privacy Policy explains, in plain terms, what data we process when you use Velvet.AI (the "Service"), why we process it, and the rights you have over it. The Service is for adults only (18+).
1. Who we are
Velvet.AI is operated by the entity identified below ("we", "us"), which is responsible for the personal data processed through the Service.
- Operator: Emil Svensson
- Registered/postal address: [c/o postal address — to be completed before publishing]
- Privacy contact: privacy@velvetapp.ai
2. Personal data we collect
We collect and process the following categories of data:
- Account identity: email address and username/display name. If you sign in through a third-party login provider (Google, GitHub, Microsoft, or Apple), we receive the identity information that provider returns.
- Authentication data: your sign-in credentials are handled by our authentication provider. If you enable two-factor authentication, we process your enrolment data.
- Chat content and AI memory: your conversations and messages with AI characters, together with derived "memory" records such as remembered facts, relationship state, session summaries, and significant events used to personalise your chats.
- Characters you create: the fields of any character you make (name, description, tagline, backstory, personality traits, tags, visual prompt, and similar), which become public if you publish them.
- Roleplay persona: your roleplay name and backstory used in prompts.
- Social and community data: comments you post and your follow/creator relationships.
- Wallet and tier data: your in-app credit ("gems") balance, transaction/ledger records, and subscription tier.
- Reports and moderation records: if you file a report, the reason, your free-text description, and your user ID and email; moderation audit records may include the reason and a sample of the content concerned.
- Age-gate status: a flag and timestamp recording that you confirmed you are 18 or over.
- Anti-bot data: an anti-bot risk token and score processed during the age gate to distinguish humans from automated abuse.
- Optional API key (BYOK): if you bring your own model-provider key, it is stored only on our server side and never returned to your browser; we retain only the provider name and the last four characters as a hint.
- Preferences: theme, accent, font size, layout, language, and content-filter settings.
We also compute some signals at runtime that we do not store, including content classification of message text and mood detection, used only to route messages. Our minor-safety scan also runs at runtime; however, when content is blocked or reported, the outcome plus a sample of the content concerned is retained in our moderation/audit records (described above under "Reports and moderation records").
Adult and sensitive content. The Service is designed for adult roleplay, which is likely to involve intimate or sexual themes and may reveal sensitive information about you (for example, information about your sex life or sexual orientation). Because this is a core purpose of the Service, we ask for your explicit, affirmative consent to process this sensitive content when you start using the Service, separately from your general acceptance of these terms. We process this content only to operate, secure, and moderate the Service. You can withdraw this consent at any time by ceasing to use the chat features or by closing your account; withdrawal does not affect processing already carried out. Where you choose to publish a character or comment containing such content, you are making that content public yourself.
3. Why we process your data and the basis for it
| Purpose | Basis |
|---|---|
| Creating your account and authenticating you | To provide the service you asked for |
| Providing the chat/roleplay service, including routing your prompts to third-party AI providers | To provide the service you asked for |
| Generating voice audio when you use the voice feature (text sent to our text-to-speech provider) | To provide the service you asked for |
| Publishing and hosting characters, comments, and follows you choose to make public | To provide the service you asked for |
| Operating the credits/wallet and subscription tiers | To provide the service you asked for |
| Age-gating (18+), the automated minor-safety filter, anti-bot checks, abuse reporting, and moderation | Our legitimate interest in keeping the Service lawful and safe, and any legal obligation that applies |
| Security, fraud and abuse prevention, and defending legal claims | Our legitimate interest in protecting the Service and our users |
| Processing sensitive/adult content in your chats | Your explicit consent (for content you publish, content you have made public yourself) |
| Keeping records required by law (for example, accounting) and responding to lawful requests | A legal obligation we must meet |
| Any non-essential cookies/storage or optional analytics | Your consent |
Providing account and chat data is necessary to use the Service: without it you cannot create an account or chat. Where we rely on our legitimate interests, you may object (see Section 8).
4. Recipients and processors
We share personal data only with the providers needed to run the Service:
- Our cloud and authentication provider (Google Firebase) — sign-in, database, and serverless functions that power and proxy all AI calls.
- AI model providers — Anthropic and OpenRouter, which receive the parts of your chat and character content needed to generate responses server-side. Where a DeepSeek-developed model is used for our built-in service, it is served through OpenRouter by inference hosts in the United States or Europe that are contractually barred from retaining or training on your prompts — never by DeepSeek's own China-located service. If you use your own key (BYOK) for DeepSeek, OpenRouter, or OpenAI, your requests (including prompts and messages) are transmitted to that provider and billed to you by them; for DeepSeek BYOK this means a transfer to China that happens only with your explicit consent (see Section 5).
- A text-to-speech provider (ElevenLabs) — used server-side only when you use the voice feature, which receives the text to be voiced.
- An anti-bot provider (Google reCAPTCHA) — for the human check at the age gate.
- Third-party login providers — Google, GitHub, Microsoft, and Apple, if you choose to sign in with them.
- Our hosting/CDN provider (Vercel) — which serves the application.
- Google Fonts — a web-font content-delivery network; loading fonts may expose your IP address to Google, but we do not send other personal data to it.
We do not sell your personal data. We may disclose data to authorities where legally required.
Payments: payment processing is not currently live. The Service does not collect or process real card or banking data at this time. If we activate a payment provider in the future, we will update this Policy first.
Analytics: no non-essential analytics are currently used. Analytics code is present in the application but is not active and is never initialised, so no analytics data is collected. We will not enable any analytics until we have first shipped a consent banner that lets you accept or reject it and withdraw consent, and we will update this Policy beforehand.
5. International data transfers
To run the Service, your personal data — including the prompts and messages you send to AI characters — is transferred to and processed by our providers in other countries, which may not provide the same level of data protection as where you live. In particular:
- United States: Google (Firebase, reCAPTCHA, Fonts, and OAuth sign-in), Anthropic, OpenRouter, ElevenLabs, Vercel, and OpenAI (only if you use an OpenAI BYOK key) are based in or process data in the United States. The anti-bot token from the age gate and your chat content (where the relevant provider is used) reach providers in this country. For these transfers we rely on recognised data-transfer safeguards, including data-protection framework certification where the provider is certified, and standard contractual clauses otherwise.
- China (only if you bring your own DeepSeek key): our built-in service never sends your data to China — all platform AI requests that use DeepSeek-developed models are processed via OpenRouter (a US-based routing service) exclusively on a fixed allowlist of inference hosts based in the United States or Europe, with zero data retention required for every request (the hosts we allow may not store your prompts or use them for training), and if no such host is available your request fails rather than being sent anywhere else. The only way your data reaches China is if you yourself add a DeepSeek API key in the optional bring-your-own-key feature: your own requests are then sent to DeepSeek's service in China, a country with no EU adequacy decision, where authorities have broad legal access to data held by companies and where your EU data-protection rights may not be enforceable. That transfer happens only with your explicit consent (Article 49(1)(a) GDPR), which you give when you save the key after being shown this warning, and you can end it at any time by removing your key.
You may request a copy of the specific safeguards we use for a given transfer by contacting us at privacy@velvetapp.ai.
6. How long we keep your data
- Account and profile data: for as long as your account is active. After you close your account, we delete it within 30 days, subject to the backup-rotation maximum below.
- Chat content and AI memory: until you delete the relevant content or close your account; residual copies are removed within the backup-rotation maximum below.
- Published characters, comments, and follows: until you remove them or your account is closed; other users may retain copies they were permitted to make.
- Wallet and transaction records: for as long as accounting and tax law require us to keep them (typically several years), then deleted.
- Reports and moderation records (including minor-safety audit records and any content sample): for up to 2 years for safety, audit, and legal-defence purposes, or longer where we are legally required to retain or report them.
- BYOK key: until you remove it or close your account.
- Backups: our backups rotate and any residual copies are overwritten within 90 days.
Where no fixed period is given, we keep data only as long as necessary for the purpose it was collected for, then delete or anonymise it.
7. Cookies, local storage, and similar technologies
We use the following client-side storage:
- Local storage for essential preferences and UX flags, specifically: an age-check flag, app version, theme, accent, font size, layout (compact) setting, language, content-filter preference, and a flag recording that you dismissed the install prompt.
- IndexedDB to cache character and generated images and to enable offline access to your data.
Your sign-in session and tokens are managed by our authentication provider's software, which stores them client-side in its own storage. The only cookies on the Service are those set by third parties — our authentication provider (Google Firebase, for session/security) and the anti-bot provider (Google reCAPTCHA). These are strictly necessary to keep you signed in and to prevent abuse, and require no consent, but we describe them here for transparency. We do not write first-party app cookies, and the Service ships no tracking service worker. No analytics cookies are set while analytics is dormant. Any non-essential cookies or analytics will only be used after we ship a consent banner and obtain your prior consent, which you will be able to withdraw at any time.
8. Your rights
You have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data.
- Restrict processing in certain cases.
- Portability — receive your data in a portable format.
- Object to processing based on our legitimate interests.
- Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
To exercise any right, contact privacy@velvetapp.ai. We aim to respond within one month; for complex or numerous requests we may extend this by up to two further months, and will tell you if we do. If you believe we have mishandled your data, you may also complain to the data-protection regulator that has authority over you, where one exists.
9. Automated systems and safety filters
We use automated systems to keep the Service lawful and safe. In particular, an automated minor-safety filter scans character fields, comments, and chat messages and looks for the co-occurrence of minor-indicative and sexual signals (including normalising attempts to disguise words), and automated abuse detection looks for abuse patterns. These systems may automatically block content or, in serious cases, restrict or suspend an account.
Where a decision producing a significant effect on you is taken solely by these automated means, you may request human review, express your view, and contest the decision by contacting us. Reports and serious cases are reviewed by a human moderator. See the Content & Conduct Policy for how we communicate reasons for removals and how to appeal.
Child-safety reporting. If our systems identify suspected child sexual abuse material or conduct indicating a risk to a child, we quarantine the material in an encrypted, access-restricted store, and report it to the Swedish Police Authority (Polisen) and, where there is a connection to the United States or where it is necessary to protect a child, to the U.S. National Center for Missing & Exploited Children (NCMEC), a non-profit clearinghouse that forwards reports to law enforcement worldwide. A report contains only what is needed: the flagged content, account identifiers, and technical metadata such as IP addresses and timestamps. The legal bases are our legitimate interest in preventing the service from being used for child sexual abuse and in reporting suspected crime (Article 6(1)(f) GDPR), our legal obligations to notify authorities where a person's life or safety is threatened (Article 6(1)(c) GDPR), and — for the transfer of a report to NCMEC in the United States — important reasons of public interest recognised in EU law (Article 49(1)(d) GDPR) or the protection of a child's vital interests (Article 49(1)(f) GDPR). Evidence connected to a report is kept for 90 days (12 months for reports made to NCMEC, or longer under a law-enforcement preservation order) and is then irretrievably deleted; only a cryptographic hash is retained to block re-upload. This processing is never used for any other purpose.
10. Adults only — no data from under-18s
The Service is intended solely for adults aged 18 or over and is not directed to anyone under 18. We do not knowingly collect or process personal data from anyone under 18. Access is protected by an age gate combining your self-declaration of being 18 or over and an anti-bot check (which confirms you are likely a real person but does not by itself determine your age), supported by our minor-safety content filter and user reporting. If we learn that a user is under 18, we will close the account and delete the associated data. If you believe a minor is using the Service, contact privacy@velvetapp.ai.
11. Source of data
Most data comes directly from you. Where you sign in through a third-party login provider, we receive identity information from that provider. Where you publish a character or comment, other users' activity (such as following you or commenting) may also generate data relating to you within the Service.
12. Security
We use technical and organisational measures appropriate to the risk to protect your data, including server-side-only storage of any BYOK key, access controls, input sanitisation, and rate limiting. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
13. Changes to this Policy
We may update this Policy from time to time. We will post the updated version here with a new effective date and, where changes are significant, take reasonable steps to notify you. Your continued use of the Service after an update means you accept the revised Policy.
14. Contact
For any privacy question or to exercise your rights, contact us at privacy@velvetapp.ai.
This Policy is provided for transparency and is not legal advice.