1. Introduction
dymi ("dymi", "we", "us") is an AI companion product. This Privacy Policy explains what personal data we collect when you use our website, applications, and related services (the "Services"), why we collect it, how long we keep it, who processes it on our behalf, and the rights you have. This Policy is effective as of July 18, 2026.
Please note: as an AI companion service, the data we process includes the content of your conversations with AI characters, which may reveal sensitive information about you (such as your feelings and relationships, or — if you choose to enable mature features — intimate preferences). We treat conversation content as confidential and protect it as described in this Policy.
2. Data We Collect
Account data: your email address, password (stored only as a cryptographic hash — we never store plaintext passwords), optional display name, user ID (UID), and your age-confirmation timestamp.
Conversation content: messages you exchange with AI characters, relationship state (affection, relationship stages, milestones), and life events generated for your characters while you are away.
Memory data: long-term memories the service derives from your conversations (preferences, facts, boundaries, habits), per-character memory summaries, and vector embeddings used to retrieve relevant memories.
Payment and order data: items purchased, order/transaction identifiers, amounts and currency, payment channel, and fulfillment status. Payments are processed by third-party processors (DogPay and AllScale for cryptocurrency payments; Stripe where card payments are offered). We never see or store your full card number or crypto wallet private keys.
Device and log data: IP address, browser type, device language, approximate region derived from IP, access times, pages visited, and security/anti-abuse logs.
Cookies and growth events: a small set of cookies/local storage used for sign-in and preferences, plus pseudonymous growth and attribution events (e.g. sign-up, purchase) that may be shared with advertising platforms (such as Meta) through server-side conversion APIs to measure campaign performance. A pseudonymous client ID is stored on your device.
Support and feedback messages you send us.
3. Purposes and Legal Bases
We use the data above to: provide the conversation service (generating character replies, maintaining long-term memory and relationship progression); operate subscriptions, credits, and payments and prevent fraud; ensure security, prevent abuse, and perform content-safety moderation (automated classifiers may scan conversations to block illegal content, such as sexual content involving minors); analyze and improve the product; measure advertising performance; and comply with legal obligations such as tax and accounting.
Under the GDPR, our legal bases are: performance of a contract (providing the service you request); legitimate interests (security, abuse prevention, product improvement); your consent (mature mode, and marketing attribution where required by law); and legal obligations (retention of financial records).
4. AI Model Providers and Other Processors
To generate character replies, your conversation content and relevant memories are sent to third-party large language model APIs (including Anthropic) for processing. These providers process data on our behalf under their own data processing terms; under their API policies, API inputs are not used to train their models by default. We transmit only the data needed to generate a reply.
Other processors include: cloud database and hosting providers (which store data on our behalf), the payment processors listed above, and email delivery providers that send verification codes and notices. These providers may not use your data for their own purposes.
5. Storage Location and Retention
Data is stored on cloud infrastructure that may be located outside your country (including the United States and other regions where our providers operate).
Account data, conversations, and memories are kept while your account is active. When you delete your account, we immediately anonymize your account record and delete your conversations, memories, and related personal content; residual copies in backups expire within 30 days.
Financial records (orders and ledger entries) are retained for up to 7 years after a transaction as required by tax and accounting laws, linked only to an anonymized account identifier.
Server and security logs are retained for 90 days. Mature-mode private sessions are excluded from long-term memory by design and are no longer displayed after 24 hours.
6. No Sale of Data; Sharing
We do not sell your personal data, and we do not share it with third parties for their own marketing. We share data only with the processors described above, when required by law, or as part of a business transfer (with prior notice).
For purposes of the CCPA/CPRA, we do not "sell" personal information; advertising measurement via conversion APIs may be considered "sharing" under California law, and you may opt out by contacting us using the details at the end of this page.
7. Your Rights (GDPR)
If you are in the European Economic Area, the United Kingdom, or another applicable region, you have the right to: access (obtain a copy of the data we hold about you); rectification; erasure (the "right to be forgotten"); data portability (receive your data in a structured, machine-readable format); restriction of and objection to processing; withdrawal of consent (without affecting processing based on consent before withdrawal); and lodging a complaint with your local data protection authority.
How to exercise them: you can export all of your data or delete your account directly in the app under Profile → Privacy & Data, or email privacy@dymi.ai. We may verify your identity before acting on a request and will respond within 30 days.
8. California Residents (CCPA/CPRA)
California residents have the right to: know (the categories and sources of personal information we collect and use); delete; correct; opt out of the sale/sharing of personal information (as noted in Section 6, we do not sell your information); and not be discriminated against for exercising these rights.
You may submit a request via privacy@dymi.ai, or through an authorized agent (we will need to verify the agent's authority). We will verify and respond within the time required by law.
9. Cookies and Similar Technologies
We use: strictly necessary cookies (sign-in session, security); preference cookies (such as language); and analytics/attribution identifiers (a pseudonymous client ID and conversion events).
You can manage or clear cookies in your browser settings, but disabling necessary cookies will prevent sign-in.
10. Minors
The Services are intended only for users aged 18 or older, and age confirmation is required at registration. We do not knowingly collect personal information from anyone under 18; if we discover that we have, we will promptly delete the account and its data.
11. International Data Transfers
Our processors may be located outside your jurisdiction. For transfers of data originating in the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) where required by law.
12. Changes and Contact
We may update this Policy from time to time. The updated version will be posted on this page with a new effective date; material changes will be announced in advance via in-app notice or email.
For any questions, requests, or complaints about this Policy or our privacy practices, contact: privacy@dymi.ai.