Legal
Privacy Policy
boyfrnd is a conversation product, so privacy isn't a footnote; it's most of the product. This draft explains what we collect, exactly how your conversations are processed, and the lines we won't cross.
Draft dated July 21, 2026 · Effective [EFFECTIVE DATE] · Not yet in effect
1. What this policy covers
This policy covers the boyfrnd mobile app and the boyfrnd website (together, the “Service”), operated by [LEGAL ENTITY NAME] (“we”, “us”), [REGISTERED MAILING ADDRESS]. boyfrnd is an AI companion service for adults 18 and over, offered in the United States. Questions go to support@boyfrnd.app.
2. Notice at collection
This is the summary California and other state laws require: the categories of personal information we collect, why, and how long we keep them. Details follow in the rest of the policy.
| Category | Examples | Why we collect it | How long we keep it |
|---|---|---|---|
| Identifiers | Email address, account ID, display name, device push token, IP address | Create and secure your account, deliver his messages, prevent abuse | While your account is active |
| Sensitive personal information | Birth date (age verification only); conversation content | Enforce the 18+ gate; generate replies and maintain character memory. Never used to infer characteristics about you or for advertising | While your account is active |
| Commercial information | Subscription plan, purchase history, Ember and ticket balances | Operate subscriptions and credits, apply plan limits, support | While active, plus up to 7 years for tax and accounting records |
| Internet or network activity | Daily message counts, feature usage, error and diagnostic logs | Apply limits, keep the Service working, debug failures | Logs up to 90 days; aggregate counters retained de-identified |
| Preferences you set | Tropes, pacing, timezone, quiet hours, heat level, notification toggles | Schedule proactive texts at humane times and shape the experience you asked for | While your account is active |
| Moderation and safety records | Rule category, response flow used, and a one-way hash of a short excerpt — not the readable text | Enforce content rules, run the crisis flow, produce aggregate SB 243 reporting | Up to 2 years for legal reporting and auditing; survives account deletion in hashed, de-identified form |
We collect this information directly from you, automatically as you use the Service, and from our payment processor and app stores for billing status. We do not buy personal information from data brokers, and we do not use advertising or cross-site tracking technologies in the app.
3. How we process your information
- Generating replies. When you send a message, relevant conversation context (recent messages, memories, your display name and preferences) is sent to our AI model providers to generate the character’s reply. These providers act as our service providers under contract and may not use your data for their own purposes, including model training.
- Memory. Facts you share and periodic summaries are stored so the character can remember you. You can view what he remembers and delete individual memories in the app; deleting your account permanently deletes all of them.
- Moderation. Every message, yours and the AI’s, is screened automatically against our content rules. When a rule triggers, we log a moderation event containing the category and a one-way hash of a short excerpt (not the readable text of your message).
- Safety. Messages are screened for self-harm and suicide signals. When a crisis flow runs, we log a safety event (signal category and which response flow was used). California law (SB 243) requires us to report aggregate statistics about these events annually; those reports never contain conversations or identities. See our safety page.
- Proactive texts. Your timezone and quiet hours are used to schedule his messages at humane times, within daily caps.
- Billing and support. To operate subscriptions and credits, respond to you, and keep the Service running.
Automated screening decides whether a message is deflected or whether the crisis flow runs. It does not produce decisions with legal or similarly significant effects about you. If repeated violations lead to account suspension, a person reviews it first, and you can contest it at support@boyfrnd.app.
4. What we never do
- We do not train AI models on your conversations. Your chats are used to generate replies to you, not as training data for our models or anyone else’s, and our contracts with model providers prohibit them from training on your data.
- We do not sell or share your personal information as those terms are defined by the CCPA/CPRA and comparable state laws, we have not done so in the preceding 12 months, and we do not use your conversation content for advertising or targeted advertising.
- We do not read your conversations except where strictly necessary: automated moderation and safety systems, aggregate analytics that do not expose content, a specific report you file that asks us to review a message, or a narrow investigation of fraud or a credible threat to someone’s safety.
5. Who we share information with
Service providers acting on our instructions and under contract: cloud hosting and database infrastructure, AI model providers (reply generation), Stripe (payments), app stores (in-app purchases), and push notification delivery. We may also disclose information if required by law or valid legal process, to protect safety, or as part of a merger, acquisition, or sale of assets — and we will tell you before your data becomes subject to a different privacy policy. SB 243 reports are aggregate and de-identified.
6. Retention
Retention periods by category are in the table in section 2. In general, account data, conversations, and memories are kept while your account is active; moderation and safety records are kept in hashed, de-identified form for legal reporting and auditing; billing records are kept as long as tax law requires. When you delete your account, personal data is removed as described below, and residual copies in encrypted backups are purged on a rolling basis within 30 days.
7. Deleting your data
Settings → Delete account (you’ll type DELETE to confirm) permanently removes your profile, relationships, conversations, memories, scheduled messages, credit balances, and push tokens, and cancels any active subscription. This is immediate and cannot be undone, and unused Embers and tickets are forfeited. You can also email support@boyfrnd.app from your account address and we’ll do it for you.
8. Your privacy rights
Depending on where you live, you have some or all of the following rights. We honour them for every US user regardless of state, because drawing a line by geography would be worse than just doing it for everyone.
- Know and access what personal information we collect, use, and disclose (this policy is that disclosure), and get a portable copy.
- Delete your personal information (see section 7).
- Correct inaccurate personal information — your profile is editable in-app; contact us for anything else.
- Opt out of sale, sharing, or targeted advertising — we do none of these, so there is nothing to opt out of, and we honour the right regardless.
- Limit use of sensitive personal information — we use your birth date only for age verification and your conversations only to operate the Service, which is already the narrowest permitted use.
- Opt out of profiling that produces legal or similarly significant effects — we do not do this.
- Appeal a decision we make about your request (required in Virginia, Colorado, Connecticut, and elsewhere): reply to our response and a different person will review it within 45 days.
- Non-discrimination for exercising any of these rights.
These rights are recognised under the California CCPA/CPRA, and under the comprehensive privacy laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states as they take effect.
How to exercise them. Use the in-app controls or email support@boyfrnd.app. We verify requests against your account email and respond within 45 days (extendable once by 45 more, with notice). Authorised agents may submit requests with proof of authorisation.
Global Privacy Control. We honour GPC and similar browser opt-out preference signals on our website. Because we do not sell or share personal information, the signal does not change how we treat your data — but we recognise it rather than ignoring it.
Shine the Light. California Civil Code §1798.83 lets residents request details about disclosures to third parties for their direct marketing. We make no such disclosures.
9. Age requirement
boyfrnd is for adults 18+. We do not knowingly collect information from anyone under 18; if we learn an account belongs to a minor, we delete the account and its data. If you believe a minor has created an account, tell us at support@boyfrnd.app.
10. Security
Data is encrypted in transit, access is scoped per-user at the database layer (row-level security), and conversation processing runs through service credentials that clients never hold. No system is perfectly secure; if a breach affects you, we will notify you as required by law.
11. Where your data is processed
The Service is operated in the United States, and your information is processed and stored there. If you access it from elsewhere, you are sending your information to the US.
12. Changes to this policy
We’ll post changes here and, for material changes, notify you in the app before they take effect. This document is a draft and will be finalised following legal review before launch.
13. Contact
[LEGAL ENTITY NAME]
[REGISTERED MAILING ADDRESS]
support@boyfrnd.app