1. Data we collect
1.1 Data you provide.
- Account data: email address, password (stored only as a salted hash), display name, and authentication data. If you sign in via a third-party identity provider, we receive a provider identifier.
- Profile and preferences: optional display name, bio/avatar, language, and content preferences — including your adult-content preference/affirmation, which indicates an interest in adult material.
- User Content: the prompts, character configurations, chat messages, and other inputs you submit, and the images and outputs generated for you ("Generated Content").
- Support and communications: messages you send us (e.g., support tickets), which may contain information you choose to include.
- Payment-related data: we use a third-party crypto payment provider (NOWPayments). We receive transaction status and references needed to credit your purchase. We do not collect or store your cryptocurrency wallet keys or card details.
1.2 Data collected automatically.
- Device/usage data: IP address, browser/device type, pages and features used, timestamps, and similar log data, used for security, abuse prevention, and reliability. Where we log IP for the age gate, we store it in hashed (pseudonymized) form, not in the clear.
- Local storage / cookies: language preference, age-affirmation, and authentication tokens. See our Cookie Policy and Section 7 below. Authentication tokens are stored in your browser's localStorage, not in cookies.
- Error and performance data: we operate self-hosted error-tracking and monitoring. Diagnostic events are masked to reduce personal data and are erased for a user upon account deletion (best effort).
- Account activity log: if you are signed in, we keep a first-party record of your page views and a small set of named in-product actions (for example, which page you viewed, that a checkout started, that an image finished generating) when they occur on the public, catalog, generator, or legal pages described in Section 1.3 below. It never includes chat messages, prompts, or generated content, is linked to your account, is retained for up to 90 days, and is visible only to authorized Charmloop staff through our internal admin tools — never to other users. See Section 3.
1.3 We do not sell your personal data, and we do not use third-party advertising trackers. We do use privacy-conscious analytics, and our two tools work differently:
- Microsoft Clarity — session-replay and heatmap analytics, limited to our public marketing, SEO, and legal pages. It records anonymous (logged-out) visitors only and stops recording immediately if you sign in.
- Umami — our self-hosted, cookieless analytics. Unlike Clarity, its underlying script is present on every page of the Service, including the signed-in app, and it records visits regardless of whether you are signed in. We only record a page view, however, for a defined set of public pages — our homepage, catalog (including individual listing pages), image generator, pricing, FAQ, guides/learn, styles, news, affiliate pages, and this legal section — never for chat, account, billing, or sign-in pages. We also record a small set of named, non-identifying product events (for example, that a checkout started, or that an image finished generating) from any page in the app; when one of those fires from a page outside the list above, the page address attached to it is replaced with a fixed placeholder so no account-specific or token-carrying address is ever sent to Umami. Umami's own records are never linked to your identity. If you are signed in, some of this same activity on the pages above is additionally kept — linked to your account — in the first-party activity log described in Section 1.2 above and Section 3 below.
See Section 2 (legal bases), Section 3 (sub-processors), and Section 7 (cookies) for detail.
2. How and why we use data; legal bases (GDPR Art. 6)
| Purpose | Examples | Legal basis (GDPR) |
|---|---|---|
| Provide the Service | Create your account, run AI chat and image generation, store your content, credit charms | Contract (Art. 6(1)(b)) |
| Process payments | Credit purchases via NOWPayments, prevent payment fraud | Contract; legal obligation for record-keeping |
| Security, abuse and content-policy enforcement | Rate limiting, age-gate logging (hashed IP), detecting prohibited content, moderation | Legitimate interests (Art. 6(1)(f)); legal obligation where reporting is required |
| Adult-content gating and preference | Honoring your adult-content access and preference settings | Consent for the preference/affirmation; contract to deliver the chosen experience |
| Communications | Transactional emails (verification, receipts, deletion notices) | Contract; legitimate interests |
| Improve and maintain the Service | Debugging, reliability, and cookieless product-usage analytics on our own infrastructure (self-hosted Umami, present site-wide); Umami's own database is never linked to your identity | Legitimate interests |
| Maintain a per-user activity log (signed-in users only) | Recording your page views and a small set of named actions on our public, catalog, generator, and legal pages while you are signed in, for support, security, and product-quality purposes; visible only to authorized staff in our admin tools | Legitimate interests |
| Website session-replay and heatmap analytics, public pages only | Microsoft Clarity records mouse movement, scrolling, and clicks on our public marketing, SEO, and legal pages, for anonymous (logged-out) visitors only; recording stops immediately if you sign in | Legitimate interests; Microsoft Clarity separately enforces its own consent requirement for EEA/UK/Swiss visitors, which may limit or block recording for those visitors (see Section 7) |
| Comply with law and respond to lawful requests | Responding to legal process, NCII/CSAM reporting obligations | Legal obligation |
Where we rely on consent, you may withdraw it at any time (this does not affect prior processing). Where we rely on legitimate interests, you may object (Section 6).
Sensitive data note: Your use of adult features and your content preferences may reveal information about your sexual interests. Where this constitutes special-category data under applicable law, we rely on your explicit consent (manifested by affirming you wish to access adult content and setting your preferences) and on the necessity of processing to provide the service you requested. You can change your preference or delete your account at any time.
3. Sharing and sub-processors
We share personal data only with service providers that process it on our behalf under contract ("sub-processors"), and where required by law. Our sub-processors at launch are:
| Sub-processor | Purpose | Data categories | Location / notes |
|---|---|---|---|
| Anthropic | AI chat/text model provider | Prompts, chat content | United States — see provider terms |
| Google (Gemini) | AI model provider (chat/image) | Prompts, chat/image inputs | United States; may also be processed in other Google Cloud regions |
| xAI | AI model provider | Prompts, chat content | United States |
| Groq | AI model inference provider; speech-to-text transcription of voice messages | Prompts, chat content; voice recordings you send | United States |
| OpenRouter | AI model routing provider | Prompts, chat content | United States; requests may be routed onward to upstream model providers outside the United States |
| Featherless | AI chat/text model inference provider (adult-capable models) | Prompts, chat content | Processing region not publicly stated by the provider; assume processing outside the EEA/UK under the safeguards in Section 4 |
| ModelsLab | AI image generation provider | Image prompts/inputs | India |
| RunPod | GPU compute for image/video generation (Pro generator) | Image/video prompts/inputs | United States; GPU workloads may run in other RunPod data-centre regions |
| ElevenLabs | Text-to-speech synthesis for voice replies (where voice is enabled) | Assistant reply text derived from your conversation | United States |
| Bunny CDN (BunnyWay) | Media storage and content delivery | Generated images/media; separate SFW and NSFW storage zones | Slovenia (EU), with global edge delivery |
| NOWPayments | Cryptocurrency payment processing | Transaction data (no wallet keys/card data stored by us) | Processing region not publicly stated by the provider; assume processing outside the EEA/UK under the safeguards in Section 4 |
| SMTP2GO | Transactional email delivery | Email address, message content of transactional emails | New Zealand, with mail infrastructure in the United States and European Union |
| Google Firebase Cloud Messaging (FCM) | Web push notifications (where you opt in) | Device push token | United States — listed per platform design; confirm at launch |
| Microsoft (Clarity) | Session-replay and heatmap analytics, limited to our public marketing, SEO, and legal pages, for anonymous (logged-out) visitors only; recording stops immediately if you sign in | Page interaction/session-replay data (mouse movement, scrolling, clicks), device/browser metadata; text is masked per our Clarity project settings | United States — see provider terms |
| Self-hosted analytics (Umami, operated by us) | Cookieless traffic and product-usage analytics. The tracking script is present on every page of the Service (so that named product events can be recorded wherever they occur), but we record a page view only for our public marketing, SEO, catalog, image-generator, and legal pages; a named event fired outside those pages has its page address replaced with a fixed placeholder before Umami receives it. Umami runs regardless of your sign-in state, but its own database never links data to your identity | Page URL (or the fixed placeholder), referrer, screen size, general (non-precise) location derived from IP at request time (not stored), and the name and a small set of pre-approved, non-identifying parameters of any product event; no free text, no cookies, no local storage | Operator-controlled infrastructure |
| Account activity log (self-hosted, operated by us) | First-party, per-user activity timeline for signed-in users only. Mirrors the same public-page views and named product events described in the Umami row above, but links them to your account; used for customer support, security/abuse investigation, and product-quality purposes, and viewable by authorized Charmloop staff in our internal admin tools. Included in your data export and deleted when your account is deleted. Never includes chat messages, prompts, or generated content | Page URL, referrer, event name, and the same limited event parameters as the Umami row above, linked to your account; retained for up to 90 days | Operator-controlled infrastructure |
| Self-hosted error tracking & monitoring (GlitchTip/Grafana/Loki, operated by us) | Reliability, debugging, security | Masked diagnostic/log data | Operator-controlled infrastructure |
We may engage additional or replacement sub-processors; we will keep this list current. We do not permit sub-processors to use your data for their own purposes except as needed to provide their service to us or as required by law.
4. International transfers
We and our sub-processors may process data in countries outside your own, including outside the EEA/UK. Where we transfer personal data internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum / IDTA where applicable) or an adequacy decision. You may request information about the safeguards used by contacting privacy@charmloop.ai.
5. Retention
5.1 We keep your account and associated data until you delete your account. When you request deletion, a 30-day grace period begins, during which you can cancel the request and recover your account. After the grace period expires, we permanently anonymize or erase your personal data as described below.
5.2 What deletion does. On completion we anonymize your user record (we remove or replace your email, username, password hash, display name, avatar, bio, and third-party provider identifier), zero your charm balance, and delete your support tickets and messages. Images and other content you generated are removed from active service per our deletion process. Diagnostic/error events and account activity log entries (Section 1.2) associated with you are erased; diagnostic/error events on a best-effort basis, activity log entries deleted outright.
5.3 What we retain, and why. We may retain (a) limited records required for legal, tax, accounting, fraud-prevention, and security-audit purposes (including immutable security/audit logs of staff actions and abuse handling), and (b) content we are legally required to preserve or report. Public content you chose to publish (for example, a public AI Companion you created) may remain available with your authorship shown as "Deleted User"; private content is removed.
5.4 Data export. Before deleting, you can request a copy of your data; we generate an export file, and the download link is available for a limited time before it expires.
5.5 Backups are rotated on a normal cycle; residual copies in backups are overwritten in the ordinary course.
6. Your rights
Depending on where you live, you may have the right to: access your data; rectify inaccurate data; erase your data ("right to be forgotten"); restrict or object to processing; data portability; and to withdraw consent. Charmloop provides self-service data export and account deletion in your account settings; you can also exercise rights by contacting privacy@charmloop.ai.
- EU/EEA/UK (GDPR/UK GDPR): the rights above, plus the right to lodge a complaint with a supervisory authority — the data-protection authority of your country of habitual residence, of your place of work, or of the place where the alleged infringement occurred.
- California (CCPA/CPRA): rights to know, delete, correct, and opt out of "sale"/"sharing" (we do not sell or share personal data as defined), and the right not to be discriminated against for exercising your rights. We do not knowingly process data of consumers we know to be under 18.
- Other jurisdictions: we honor applicable local rights.
We will verify your identity before acting on a request and respond within the time required by law. We will not charge a fee except where permitted.
7. Cookies and local storage
We use a minimal set of strictly-necessary and functional cookies/local-storage items — a language preference (NEXT_LOCALE), an age-affirmation token (cl_age_18), and authentication tokens in localStorage — together with cookies set by Microsoft Clarity (session-replay and heatmap analytics, public marketing and legal pages only, anonymous visitors only) and our self-hosted Umami analytics, which is cookieless and sets no local-storage item. We do not use third-party advertising cookies. Full detail, including durations, is in our Cookie Policy at charmloop.ai/cookies.
8. Security
We use technical and organizational measures to protect personal data, including encryption in transit, hashed passwords, access controls, pseudonymization of certain logs, and separation of adult and non-adult media storage. No system is perfectly secure; we cannot guarantee absolute security. Tell us about any suspected vulnerability at support@charmloop.ai.
9. Children / 18+ only
The Service is strictly for adults 18+ and is not directed to children. We do not knowingly collect personal data from anyone under 18. If we learn that we have collected data from a person under 18, we will delete it and terminate the account. If you believe a minor is using the Service, contact abuse@charmloop.ai.
10. Changes
We may update this Policy. Material changes will be signaled by an updated "Last updated" date and, where appropriate, additional notice. Continued use after changes take effect constitutes acceptance where permitted by law.
11. Contact
Privacy / data protection: privacy@charmloop.ai. Controller: the operator of Charmloop (charmloop.ai). Address all data-protection questions, rights requests, and questions about our international-transfer safeguards to privacy@charmloop.ai; that address reaches the people responsible for data protection.