Velvet.AI
Operated by Emil Svensson · Contact: legal@velvetapp.ai · Adults only (18+)

Privacy Policy

Effective date: July 8, 2026 · Part of the Velvet.AI legal centre

This Privacy Policy explains, in plain terms, what data we process when you use Velvet.AI (the "Service"), why we process it, and the rights you have over it. The Service is for adults only (18+).

1. Who we are

Velvet.AI is operated by the entity identified below ("we", "us"), which is responsible for the personal data processed through the Service.

2. Personal data we collect

We collect and process the following categories of data:

We also compute some signals at runtime that we do not store, including content classification of message text and mood detection, used only to route messages. Our minor-safety scan also runs at runtime; however, when content is blocked or reported, the outcome plus a sample of the content concerned is retained in our moderation/audit records (described above under "Reports and moderation records").

Adult and sensitive content. The Service is designed for adult roleplay, which is likely to involve intimate or sexual themes and may reveal sensitive information about you (for example, information about your sex life or sexual orientation). Because this is a core purpose of the Service, we ask for your explicit, affirmative consent to process this sensitive content when you start using the Service, separately from your general acceptance of these terms. We process this content only to operate, secure, and moderate the Service. You can withdraw this consent at any time by ceasing to use the chat features or by closing your account; withdrawal does not affect processing already carried out. Where you choose to publish a character or comment containing such content, you are making that content public yourself.

3. Why we process your data and the basis for it

PurposeBasis
Creating your account and authenticating youTo provide the service you asked for
Providing the chat/roleplay service, including routing your prompts to third-party AI providersTo provide the service you asked for
Generating voice audio when you use the voice feature (text sent to our text-to-speech provider)To provide the service you asked for
Publishing and hosting characters, comments, and follows you choose to make publicTo provide the service you asked for
Operating the credits/wallet and subscription tiersTo provide the service you asked for
Age-gating (18+), the automated minor-safety filter, anti-bot checks, abuse reporting, and moderationOur legitimate interest in keeping the Service lawful and safe, and any legal obligation that applies
Security, fraud and abuse prevention, and defending legal claimsOur legitimate interest in protecting the Service and our users
Processing sensitive/adult content in your chatsYour explicit consent (for content you publish, content you have made public yourself)
Keeping records required by law (for example, accounting) and responding to lawful requestsA legal obligation we must meet
Any non-essential cookies/storage or optional analyticsYour consent

Providing account and chat data is necessary to use the Service: without it you cannot create an account or chat. Where we rely on our legitimate interests, you may object (see Section 8).

4. Recipients and processors

We share personal data only with the providers needed to run the Service:

We do not sell your personal data. We may disclose data to authorities where legally required.

Payments: payment processing is not currently live. The Service does not collect or process real card or banking data at this time. If we activate a payment provider in the future, we will update this Policy first.

Analytics: no non-essential analytics are currently used. Analytics code is present in the application but is not active and is never initialised, so no analytics data is collected. We will not enable any analytics until we have first shipped a consent banner that lets you accept or reject it and withdraw consent, and we will update this Policy beforehand.

5. International data transfers

To run the Service, your personal data — including the prompts and messages you send to AI characters — is transferred to and processed by our providers in other countries, which may not provide the same level of data protection as where you live. In particular:

You may request a copy of the specific safeguards we use for a given transfer by contacting us at privacy@velvetapp.ai.

6. How long we keep your data

Where no fixed period is given, we keep data only as long as necessary for the purpose it was collected for, then delete or anonymise it.

7. Cookies, local storage, and similar technologies

We use the following client-side storage:

Your sign-in session and tokens are managed by our authentication provider's software, which stores them client-side in its own storage. The only cookies on the Service are those set by third parties — our authentication provider (Google Firebase, for session/security) and the anti-bot provider (Google reCAPTCHA). These are strictly necessary to keep you signed in and to prevent abuse, and require no consent, but we describe them here for transparency. We do not write first-party app cookies, and the Service ships no tracking service worker. No analytics cookies are set while analytics is dormant. Any non-essential cookies or analytics will only be used after we ship a consent banner and obtain your prior consent, which you will be able to withdraw at any time.

8. Your rights

You have the right to:

To exercise any right, contact privacy@velvetapp.ai. We aim to respond within one month; for complex or numerous requests we may extend this by up to two further months, and will tell you if we do. If you believe we have mishandled your data, you may also complain to the data-protection regulator that has authority over you, where one exists.

9. Automated systems and safety filters

We use automated systems to keep the Service lawful and safe. In particular, an automated minor-safety filter scans character fields, comments, and chat messages and looks for the co-occurrence of minor-indicative and sexual signals (including normalising attempts to disguise words), and automated abuse detection looks for abuse patterns. These systems may automatically block content or, in serious cases, restrict or suspend an account.

Where a decision producing a significant effect on you is taken solely by these automated means, you may request human review, express your view, and contest the decision by contacting us. Reports and serious cases are reviewed by a human moderator. See the Content & Conduct Policy for how we communicate reasons for removals and how to appeal.

Child-safety reporting. If our systems identify suspected child sexual abuse material or conduct indicating a risk to a child, we quarantine the material in an encrypted, access-restricted store, and report it to the Swedish Police Authority (Polisen) and, where there is a connection to the United States or where it is necessary to protect a child, to the U.S. National Center for Missing & Exploited Children (NCMEC), a non-profit clearinghouse that forwards reports to law enforcement worldwide. A report contains only what is needed: the flagged content, account identifiers, and technical metadata such as IP addresses and timestamps. The legal bases are our legitimate interest in preventing the service from being used for child sexual abuse and in reporting suspected crime (Article 6(1)(f) GDPR), our legal obligations to notify authorities where a person's life or safety is threatened (Article 6(1)(c) GDPR), and — for the transfer of a report to NCMEC in the United States — important reasons of public interest recognised in EU law (Article 49(1)(d) GDPR) or the protection of a child's vital interests (Article 49(1)(f) GDPR). Evidence connected to a report is kept for 90 days (12 months for reports made to NCMEC, or longer under a law-enforcement preservation order) and is then irretrievably deleted; only a cryptographic hash is retained to block re-upload. This processing is never used for any other purpose.

10. Adults only — no data from under-18s

The Service is intended solely for adults aged 18 or over and is not directed to anyone under 18. We do not knowingly collect or process personal data from anyone under 18. Access is protected by an age gate combining your self-declaration of being 18 or over and an anti-bot check (which confirms you are likely a real person but does not by itself determine your age), supported by our minor-safety content filter and user reporting. If we learn that a user is under 18, we will close the account and delete the associated data. If you believe a minor is using the Service, contact privacy@velvetapp.ai.

11. Source of data

Most data comes directly from you. Where you sign in through a third-party login provider, we receive identity information from that provider. Where you publish a character or comment, other users' activity (such as following you or commenting) may also generate data relating to you within the Service.

12. Security

We use technical and organisational measures appropriate to the risk to protect your data, including server-side-only storage of any BYOK key, access controls, input sanitisation, and rate limiting. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

13. Changes to this Policy

We may update this Policy from time to time. We will post the updated version here with a new effective date and, where changes are significant, take reasonable steps to notify you. Your continued use of the Service after an update means you accept the revised Policy.

14. Contact

For any privacy question or to exercise your rights, contact us at privacy@velvetapp.ai.

This Policy is provided for transparency and is not legal advice.