Privacy Policy
Last updated: 4 August 2026
This policy explains what personal data Velvet Line collects, why, how long we keep it and what rights you have. The controller is TODO — registered legal entity name (TODO — company number and jurisdiction), TODO — street, TODO — city, postcode, TODO — country. Privacy enquiries: privacy@example.com.
1. What we collect
| Data | Why | Lawful basis |
|---|---|---|
| Email address and password hash | To create and secure your account | Contract |
| Date of birth | To confirm you are old enough to use an adult service | Legal obligation |
| Gender and display name | So characters address you correctly | Contract |
| Google account id, name, avatar (if you sign in with Google) | To sign you in | Contract |
| Conversation transcripts and call summaries | To give characters memory of what you have discussed | Contract |
| Usage records (call length, characters used, credits consumed) | Billing, fraud prevention, capacity planning | Contract, legitimate interests |
| Subscription and payment records | To provide and account for what you bought | Contract, legal obligation |
| IP address and browser information | Security, abuse prevention, fraud screening | Legitimate interests |
2. What we never see
We do not receive or store your card number. Card details are entered directly into our payment provider CCBill and never reach our servers. We receive only a token, the result of the charge and your subscription status. See Billing Support.
3. Conversations — please read this
Voice calls are converted to text so a character can respond and remember. Those transcripts are stored on our servers, together with short summaries of each call, and are linked to your account.
Being direct about the current state: transcripts are stored without field-level encryption, and we do not yet operate an automatic retention limit — they are kept until you ask us to delete them or you close your account. Improving this is on our roadmap. Until it is done, please do not share information in a call that you would not want stored, including real names, addresses, financial details or health information.
Audio itself is not recorded or retained. Images generated during a call exist only in your browser for the length of that call and are not stored by us.
4. Automated processing
Your messages are sent to third-party AI providers to produce speech recognition, replies, synthesised voice and images. This processing is automated. It does not produce decisions with legal or similarly significant effects about you.
5. Who we share data with
- CCBill — payment processing, subscription management and fraud screening.
- Venice AI — language, voice synthesis and image generation.
- Deepgram — speech recognition.
- LiveKit — real-time audio transport.
- Turso — database hosting.
- Google — only if you choose to sign in with Google.
- Law enforcement or regulators, where we are legally required to.
We do not sell personal data and we do not use it for third-party advertising.
6. International transfers
Our providers operate in the United States and elsewhere. Where data leaves the UK or EEA we rely on the appropriate safeguards, such as Standard Contractual Clauses.
7. How long we keep data
- Account records: for as long as your account exists.
- Transcripts and call summaries: until you delete them or close your account (see section 3 — there is no automatic limit yet).
- Payment and billing records: as required by tax and financial rules, normally six to seven years, even after your account closes.
- Records relating to age assurance and content complaints: as required by our payment providers and applicable law.
8. Your rights
Subject to where you live, you may have the right to access your data, correct it, delete it, restrict or object to processing, receive a portable copy, and withdraw consent. To exercise any of these, write to privacy@example.com. We will respond within one month.
Deleting your account deletes your profile, transcripts and memories. Billing records are retained where the law requires it.
You may also complain to your local data protection authority. In the UK that is the Information Commissioner’s Office.
9. Cookies
We use only what the service needs to function:
- a session cookie, so you stay signed in;
- an age-confirmation cookie, so the entry notice is not shown on every page;
- a guest identifier, so a character remembers a trial conversation.
We do not use advertising or third-party tracking cookies.
10. Security
Passwords are stored hashed with bcrypt. Traffic is encrypted in transit. Access to production data is limited to staff who need it. No system is perfectly secure, and section 3 describes an area we know is not yet where it should be.
11. Children
This service is strictly for adults. We do not knowingly collect data from anyone under 18. If we learn that we have, we delete the account and its data immediately.
12. Changes
We will update the date at the top when this policy changes, and notify you by email of material changes.