privacy policy

Last updated: 7 October 2026.

The short version: we collect what we need to run the product, we encrypt the part that would hurt you most if it leaked, we do not sell it, we do not train models on your conversations, and there is no advertising or tracking of any kind in this app. The long version follows, and it names names.

1. What we collect

You give us:

  • an email address and a password — or a Google or Apple identity, if you sign in that way. With Google we store the claims Google's sign-in token carries (your email, name, given and family name, the URL of your Google profile picture, and Google's own id for you), and that picture URL becomes your avatar unless you change it. With Apple we store Apple's id for you, the email you chose to share — which may be one of Apple's private relay addresses — and a sealed Apple refresh token, kept for one purpose only: so we can revoke it when you delete your account. If you ever signed in with Discord, your account still carries Discord's id for you, the email it returned and the verified claim set behind it, username included — no app or website build we ship today offers that button,
  • a display name, and optionally a handle, a bio, an avatar and a cover image,
  • your timezone and your app language — the timezone is load-bearing, because "40 messages a day" means your day,
  • your messages, in one-to-one chats and in group rooms, and your personas, characters, scenes, lorebooks and pinned memories. A persona includes whatever you put in it: name, age, gender, appearance, likes and dislikes,
  • photos you upload: profile and cover pictures, persona and character portraits, and screenshots attached to a support ticket,
  • what you pick during onboarding — your taste selections and the interest channels you follow,
  • support tickets you send us, and your replies if we ever write to you — which reach the app only when the person answering records them onto the thread (§4),
  • the answer to the one optional question we ask when you delete your account, in the app or in the web app — what made you decide, picked from a short list, and one line of your own if you add one. It is stored without your account (§8),
  • an email address you typed into the waitlist form that used to be on our website — the form was removed in September 2026 and no page on this site collects one any more — with the code of whoever referred you there and a referral code of your own. Entries taken before then are still stored. That entry is not an account and never becomes one, even if you sign up later — which also means the deletion in §8 never reaches it.

The product generates:

  • structured Facts a character has extracted about you from your conversations — all of them visible to you, all editable, all deletable,
  • Moments, open loops, check-ins and bond levels — short pieces of writing and state a character keeps about your relationship,
  • generated images, stored with the prompt that made them, and voice clips of character lines,
  • story and game progress,
  • usage counts (messages, images, voice minutes) and your Sparks ledger, so we can apply your plan's limits,
  • purchases and subscriptions: what you bought, the amount and currency, and the store receipt identifier — Apple's transaction id or Google's order id — plus the webhook receipts a payment provider sends back to us, stored verbatim, exactly as they arrive. A web receipt carries whatever Razorpay put in it, which normally includes the email address, the phone number and the UPI handle you gave Razorpay at checkout. If you ask us to pay out creator earnings, we also keep the payout destination you give us and the KYC state it was paid under,
  • a record of each checkout attempt: every time you press a buy button, in the app or on the web — which pack or plan, on which platform and app version, the amount and currency when we know them, which screen you came from, and what became of it: whether it opened, was paid, was cancelled, failed or was refused, with the payment provider's own reason when it refused, shortened and with email addresses and long numbers taken out. It is kept while you have the account. It never holds a phone number, and we never ask you for one: when you buy Sparks on the web from outside India — in dollars or euros — Razorpay's own payment form asks for your phone number and card, you type them into Razorpay's fields, and they go to Razorpay, not to us. The one copy that reaches us is inside the receipt Razorpay sends back afterwards, as the line above says,
  • referral links,
  • product events: a fixed list of actions — a feed card appeared, a chat was opened, a notification was tapped, a character was published, and so on. Eighteen of them the app can send; three more it cannot — the first chat we open for you on the day you join, which our own server records, and the two share buttons that exist only on the website. Each row records the action, the surface it happened on — the feed, search, a rail, the character screen, a link, and a handful of others — the character it was about when it was about one, and the time. No message text,
  • promotion impressions and clicks: which of our own promotions you were shown, where, a session id the app mints itself, your app version and platform,
  • moderation and safety signals,
  • crisis-referral records (see §7).

We collect automatically:

  • your IP address and user agent, stored against every login session so that you and we can see where an account is signed in. You can view and revoke those sessions in the app,
  • your IP address, user agent and the address of each request in our server logs, including the query string — so a search you typed can appear in a log line,
  • a country, read from your IP address at our edge. We do not keep the country itself. We map it to one of three pricing regions — India, US or EU — and that region is pinned to the account. Earlier versions of this policy said you gave us your region. You did not; we derived it,
  • your push token and a device record — platform, app version, language, last seen, and what your phone last told the app about notifications (allowed, refused or not asked yet), with the date that answer last changed. The record is made whether or not you allow notifications, because the phone has a push token either way,
  • where your account came from, written once when you sign up and never changed: the platform and app version you signed up on, and what the link that brought you said about itself — a campaign tag, the host of the site you came from (never its full address), the first page you landed on without its query, which of our buttons you pressed, and on Android the Play install referrer, with any ad click id replaced by a placeholder. On our website and in the web app that trail is held in your browser tab, and it leaves the tab only in the link you follow to the web app or to Google Play, or with your sign-up. It never holds your IP address, your user agent or an email address,
  • your app version and OS version, which the app puts in its user agent.

We do not collect precise location, your contacts, microphone audio, your browsing history in other apps, photos you did not upload, health data from your phone, or an advertising identifier. Photos you do upload are re-encoded before we store them, so the GPS coordinates a camera writes into an image file are not kept.

Voice input. When you tap the microphone in the chat composer, your device's own speech-recognition service turns what you say into text in the message field — Apple's on iPhone and in Safari, Google's on Android and in Chrome and Edge. That service may process the audio on your device or on Apple's or Google's servers, under their terms. It is the only reason the app asks for microphone access, and the microphone is open only while you are dictating. We receive no audio: only the text, and only when you send it.

2. Your messages are encrypted at rest, and here is where the plaintext goes

Message bodies and their variants, chat and group summaries, group messages, the values of memory Facts, your diary Moments and the replies under them, the daily question and your answer to it, the one-line notes a character keeps about an unfinished thread and about your bond, the standing directions you write about how a character should be played, and the asides characters trade about you in group rooms are all encrypted in our database (AES-256-GCM), with a key that is not in the database.

This is a deliberate defence against one specific, real disaster: in 2024 the AI-companion service Muah.ai was breached, and the leak paired 1.9 million email addresses with the prompts those people had written. Those pairs were then used for extortion. In this category, the linkage is the harm.

There is no console query, no dashboard, no report and no analytics job anywhere in our stack that returns message text in bulk, and there is no batch decryption endpoint — by design, and we intend to keep it that way. But an earlier version of this policy said there was exactly one path to a plaintext message. That was not true. What follows is every path we have found, named as specifically as we can — we have had to lengthen it twice, so read it as the current state of an audit we keep running rather than as a closed set, and tell us if you find one we have missed.

Before any of it, the ordinary one: showing you your own writing. The server opens what you wrote to render your chat, your diary and your pinned memories back to your own app, over an encrypted connection. Everything below is plaintext going somewhere other than back to you.

  1. Anything you ask for in the moment. To answer you we decrypt the relevant part of the conversation and send it to an AI provider (§3) — and so do the other things you can ask for in the moment, each of which decrypts your own writing: your recent turns for a picture taken inside a chat, the one message you asked to illustrate for a scene picture, the diary page plus the replies under it for a reply to a Moment, and your recent turns again for the three tap-to-send replies the chat offers you. This is the main one, and it is the whole point of the product.
  2. The work that runs when you are not there. Background work opens something of yours with no request from you in flight: the nightly message a character sends you, the asides in your group rooms, the memories we extract, the summaries we fold them into, your diary Moments, your daily question, the open threads a character keeps track of, and a story's quiet pass between chapters. Each one decrypts what it needs — your recent turns, the Facts a character has stored, the paraphrase of an unfinished thread — and sends it to an AI provider, and each one checks your permission every time it runs, before anything is opened (§3).
  3. Reading a line aloud. A character's reply is sent as text to a voice provider to be spoken — usually to our own voice server, which is a separate machine and is reached over an unencrypted connection (§3). A reply is not the only thing read aloud: the opening sentences of a diary Moment, and the daily question a character asked you, are spoken from the same decrypted text. Those two go only to our own voice server, never to an outside voice company.
  4. Notifications. If character-message notifications are on, a reply is previewed verbatim on your lock screen, which means it passes through Google's and Apple's push services.
  5. Your own export. When you export your data we decrypt your chats, write them to a file in our storage, and email you a signed link that expires after 72 hours. The link expires; the file does not. Nothing deletes an export bundle automatically, and no database row points at one — the only thing that can reclaim it is the same by-hand console in §8.
  6. One audited admin read of a single message. It requires a super-admin, it decrypts one message per request, a written reason is mandatory, and it writes an audit row naming the admin, the message and the reason. There is no bulk version.
  7. Two audited admin reads of open loops — the short paraphrases a character keeps of unfinished threads. One shows a named person's threads; the other is the dry run for the nightly message, which decrypts one thread each for a page of candidates, up to two hundred. Both are super-admin only, and both write an audit row naming the admin and the person read. Neither copies what the threads said into that row.
  8. Fields that were never encrypted in the first place. Of the things you write, the sealed ones are those named at the top of this section; the rest are stored in the clear, and these are the ones worth saying out loud: chat titles, the label of a memory Fact (the value is encrypted), image prompts — including the prompt an in-chat image builds from the conversation — the note you write on a pinned message, the muted words you asked us never to show you, your bio, the title and body of every notification sitting in your in-app inbox (they are written out of your own worlds and conversations: "Luna left something for you", with the world's own title in it), the character, persona, scene and lorebook text you wrote, review bodies, support tickets and every message written on them, your replies to an email we sent you, and the details you write when you report something.

3. Who processes your data, and what they get

We ask your explicit permission before we send anything to a third-party AI provider, at signup. Until you give it, the server refuses every AI request — no chat, no images, no voice. You can withdraw it at any time in Settings, and chat stops working again, because there is nothing left to send. Withdrawing it does not delete your account or anything in it.

Withdrawing it stops the background work as well as the conversation. The nightly message a character would have sent you, the asides characters exchange about your group rooms, the memories we extract from your conversations, the summaries we fold them into, your diary and your daily question, the open threads we keep track of, and a story's quiet passes between chapters each check your permission every time they run — before anything of yours is opened, not only when you press send. If you withdraw it, they stop; they do not queue up and run later. It binds us too: if we write to you personally (§4) and you have not given that permission, nobody here can ask a model to help draft it — not the first email, and not a reply to what you wrote back. A person writes it.

AI that writes — the lanes running today: replies and the messages a character starts on its own, chat titles, suggested replies, conversation and group summaries, memory extraction and consolidation, your diary Moments, your daily question, open threads, group asides, a story's beats and its ambient passes, translation, image prompts, tag suggestions, the clean-up of a character card you import, the content-moderation pass, the crisis classifier, and the draft of an email we send you. A lane we add later is added to this list, and it is gated by the same permission as the rest. These receive the conversation text, your persona (including its age, gender, appearance, likes and dislikes) and the Facts a character remembers about you. They do not receive your account id or your email address; the name in the prompt is your persona's name, which the app offers to prefill from your display name — except in that email draft, which carries your display name, because the mail is addressed to you.

  • DeepSeek — first in line for chat replies today, and for translation.
  • Anthropic — next in line for chat, and first for the crisis classifier, memory extraction and input moderation.
  • OpenAI — next.
  • Google (Gemini) — next.
  • xAI (Grok) — wired into the same gateway and reachable from the same routing table, so a lane pointed at it receives what the four above receive.

AI that draws. Image prompts go to five providers: Tensor.Art, Sogni, OpenAI, Google (Gemini) and NovelAI. Which one draws a given picture is the character's own art-direction setting, with the others behind it as fallbacks, in an order we can change from our own console without shipping a new build.

Image scanning. Every generated image, and every photo you upload — profile and cover pictures, persona and character portraits — is scanned by Google Cloud Vision for content we do not allow. Images the scanner rejects can get a second look from Google (Gemini). There is one exception, and it is deliberate: a screenshot attached to a support ticket is re-encoded and stored for the person handling your ticket to look at, and it is not sent to the scanner.

AI that speaks. Most voice clips are produced on a voice server we run ourselves. It is a second machine we rent, at its own public address, shared with an unrelated product — so the line of dialogue to be spoken is decrypted here and sent to it across the internet. That request carries a secret token and the machine's firewall accepts it from our application server and nothing else, but the connection itself is not encrypted in transit, and we would rather say so than let you assume otherwise. The rest of the clips go to Google Cloud Text-to-Speech or Google (Gemini), which receive the same line of dialogue over HTTPS. Two more voice companies are built into the product, and both are dark today. Cartesia we can switch on from our own console, without a new build. ElevenLabs — the paid voice path this feature was designed around — we cannot: it reads its key from the server's own environment, so turning it on takes a deploy, and a key typed into the console for it does nothing. A backend with no key in place is dark, and a character pointed at it falls back to the free voice on our own server; when a key is in place, that company receives the decrypted line exactly as the two above do. We name all four of those companies rather than list only the ones a given day happens to route to.

Push notifications. Google Firebase Cloud Messaging, and Apple's push service (APNs) for iPhones. They receive your device token and the text of the notification — which, for a character reply, is the reply. Firebase's messaging library also registers an installation id with Google and reports delivery diagnostics; that is what sending push through Firebase costs. Neither Firebase Analytics nor Crashlytics is in this app.

Error tracking. Sentry, for server errors only, and only when the server itself failed (a 5xx). What our own code sends is the exception itself — its message and stack — plus an error code and an HTTP status. It is never given a request body, and we never attach your identity to a report. On top of that we have not switched off the context Sentry's own library collects by default — which machine and process the error happened on, and recent lines from our server log — so assume that rides along with it. Sentry's option for sending personal data is left off, so it is not given your IP address. There is no crash-reporting or analytics SDK inside the app. What the app does send is its own crash reports, to our own server and to nobody else. When the released app on a phone meets an error it did not expect, or stops while it is open on screen, it sends the kind of error and its message with addresses, links, ids and long numbers removed, the lines of the app's code it happened in, the route pattern of the screen (never an address with an id in it), the app version, platform, OS version and language, and a daily code the phone makes from a random secret it never sends — so one phone can be counted within a day and not followed from one day to the next. A report is sent without your sign-in and carries no account, no device id and no message text. Each day's count is kept 90 days, and the error itself until 90 days after anyone last reported it.

Email. Hostinger is our mail host and handles every message in both directions: verification codes, password resets, your export link, deletion notices and any support conversation.

Storage, delivery and hosting. Cloudflare sits in front of every request, so it sees your IP address and supplies the country we derive your region from; its object storage holds your images, voice clips, avatars, support attachments, export files and our nightly database backups. Hostinger rents us the servers that run the application, the database and the cache, and hosts our mailbox; the voice server above is a separate rented machine, and we name it here rather than let this paragraph read as the whole estate.

Payments. On iPhone, Apple; on Android, Google Play. We never see your card. We receive a receipt identifier and verify it with Apple's and Google's servers, and we send Apple an opaque account token so a purchase lands on the right account. On the web, Razorpay takes the payment; it receives your email address, your plan and your account id so it can attach the subscription correctly, and the receipts it sends back to us are stored verbatim, unredacted — which means the copy we keep carries the email address, phone number and UPI handle you gave Razorpay. See §8 for how long that lasts, because the honest answer is "indefinitely".

Sign-in. Apple, when you use Sign in with Apple — we exchange a code with Apple and hold the resulting refresh token sealed, so we can revoke it on deletion. With Google, our servers send Google nothing: we verify Google's token locally against Google's published keys. The sign-in itself happens between you and Google, as it has to, so Google knows you signed in here — and the profile picture it hands us stays a Google address that your app loads from Google until you change your avatar.

We require each of these companies, by contract, to protect your data to the same standard this policy sets, to use it only to do the job we sent it for, and not to train their models on it. None of them may sell it, share it onward or reuse it for their own purposes. We do not pad this list, and where a provider is wired but is not serving you today we say so rather than leave it off. It is the set as of the date at the top of this page; when a company joins it or leaves it, this section is where that is written down.

4. Promotions, and what we do not do

We promote our own product inside our own app. You will see our offers as a card when you open the app, as cards braided into Discover, and as a screen when you hit a limit. They are all ours: oomfy ai plans, Sparks and our own characters. We decide which one you see using your app language and your pricing region, and we record that you saw it and whether you tapped it — the campaign, where it appeared, the app-minted session id, your app version and platform. Those records exist to cap how often you are interrupted and to tell us whether a promotion was worth running.

We send product news — a feature shipped, a policy changed, maintenance — by push and sometimes by email. It is on by default, and Settings → Notifications turns it off. We also sometimes write personally to someone who signed up and never came back, to ask why. If you reply, it arrives in a human mailbox: nothing in the app captures replies automatically today, so your answer reaches the thread only when the person handling it pastes it in, and then it is kept there until you delete your account. Whoever answers may ask a model to draft what we send back — it is given the last few messages on the thread, including your own words, plus your name and your language. That happens only if you have given the AI permission in §3; without it the drafter refuses and the mail is written by hand.

Discover is personalized. We rank characters for you from what you chat with, like, review and follow, and from the channels you picked. It is built from that behaviour, not from the text of your messages.

There is no third-party advertising anywhere in this product. No ad network, no advertising SDK, no ad identifier — no IDFA, and therefore no App Tracking Transparency prompt, because there is nothing to ask you for. No pixel, no third-party attribution tool, no third-party analytics: where your account came from (§1) is recorded by our own server, once, and is given to nobody. Nothing you do here is shared with anyone for advertising, and nothing you do here is combined with what you do in other companies' apps or on other companies' websites. We do not track you, in Apple's sense of the word or in any other.

And, as before:

  • We do not sell your data. Not to advertisers, not to data brokers, not to anyone.
  • We do not train models on your conversations, and we do not let anyone else.
  • We do not build a profile of you for anybody but you.

5. Why we are allowed to process it (GDPR Art. 6)

  • Contract — to give you the service you signed up for: your account, your chats, your memory, your purchases.
  • Legal obligation — safety reporting, tax records, and the SB 243 crisis-referral count.
  • Legitimate interests — security, fraud prevention, abuse detection, keeping the service running, personalizing what we recommend, and promoting our own product to our own users. We have balanced these against your rights and documented it. You can object, and you can switch product news off without leaving.
  • Consent — for sending your content to a third-party AI provider, in the conversation and in the background work behind it. You can withdraw it at any time (§3).

6. Your rights, and how to actually use them

You can, without asking permission and without talking to anyone:

  • See every Fact a character has stored about you, and edit or delete any of them, in the app.
  • See every signed-in session, with the IP address and device it was created from, and revoke any of them.
  • Withdraw your AI consent, in Settings.
  • Turn off product news and character notifications, in Settings.
  • Export your data — your account record, your one-to-one chats and every message in them (group rooms are not in the bundle today), your memory Facts, every character you made with its lorebook, your own lorebooks, your personas, your Sparks ledger and your subscriptions, as one JSON file — from Settings, or via GET /me/export. We email you a signed download link.
  • Delete your account, in the app.

The web form at oomfyapp.com/delete-account is the exception to that heading, and we would rather say so than let it look like a second button. It exists for someone who cannot get into the app, and it is a request a person fulfils: it files a support ticket, and we confirm by email that the request came from you before anything is destroyed — because a stranger who knows your address must not be able to erase your account from a public form. Two consequences worth knowing. It is slower, and it involves talking to someone. And because you are logged out when you send it, the address you type is stored on that support ticket, which the deletion scrub can never reach, because it was never attached to an account. Deleting from inside the app avoids both.

You also have the right to rectification, restriction, objection, and to complain to your data-protection authority. Write to [email protected] and we will answer within 30 days.

7. Crisis referrals

If our classifier detects a crisis in a message you send, the character breaks character immediately and we show you real, human crisis resources (full protocol here). The message that triggers this is classified by an AI provider, on the same basis as everything else in §3.

We keep a record of the referral. California SB 243 requires operators to report the number of crisis referrals issued to the Office of Suicide Prevention from July 2027, and we cannot report a count we did not keep.

An earlier version of this policy described that record as "a timestamp and a counter". It is more than that, and we would rather correct it than let you find out. The record holds: when it happened, which classifier model made the call and how confident it was, what we did, which resources we showed you, whether you tapped through the card, your region at the time, the reporting year, and references to your account, the chat and the message. It contains no message text. Unlike almost everything else, it survives account deletion — with the references to your account, your chat and your message removed from it, so what is left is the event and not you, because a count we destroyed is a count we cannot report.

8. Retention

  • Active account: we keep your data while you have an account.
  • Deactivated: 30 days, then treated as deleted. Logging back in restores it.
  • Deleted: your account is unreachable immediately, and your email and handle are replaced the same day on the account row itself — with an exception we would rather name than have you find (the other places a copy of it can survive are below): if a moderator ever took an action on your account, the admin audit trail holds a copy of how that account read at the time, address included, and nothing scrubs it (below). Thirty days later a scrub runs, and it destroys the rows rather than flagging them: your chats and messages and everything written out of them — summaries, memory Facts, Moments and the replies under them, the daily question and your answer, open threads, bond notes — your group rooms and the asides in them, your personas and lorebooks, image and voice records, your story and game progress, devices and push tokens, notifications and notification settings, your browse channels and muted words, sign-in identities, sessions, your check-in streak, likes, reviews, follows, the blocks you made, your product events and the promotions you were shown, your per-day usage counts, your Sparks balance, coupon redemptions, the invites you sent, the record of any character submission we refused, the quiet safety signals that only said you seemed distressed on a date, and any outreach thread we started with you. The same scrub deletes the record of where your account came from (§1) and your checkout attempts.
  • The honest exceptions inside that scrub. Characters you made — every one of them, not only the ones you published — are made private and switched off rather than destroyed, because other people are mid-conversation with the published ones. Your pictures — your avatar and cover, your personas' faces, and every image you generated or uploaded — are deleted from storage by the scrub itself, once its database changes have committed. Three kinds of file are not: a portrait or cover that a surviving character or scene of yours still uses, because other people are still looking at it; an image our safety scan refused, which we keep as moderation evidence; and voice clips, which are shared by everyone who heard the same line, so the scrub only unreferences them. Those are reclaimed by hand, from an admin console that lists unreferenced objects for a human to review before anything is deleted — there is no automatic sweep and no fixed window for them, so they can outlive the rows that pointed at them indefinitely. (Free voice clips are the one exception inside the exception: the audio our own voice server produces is deleted from storage once the link to it has expired, by the same code that made it.) And an export bundle we built for you sits on that same manual footing — the link we mailed you stops working after 72 hours, and nothing deletes the file automatically.
  • What survives on purpose, because it is our record. These are the survivors we know of, and the list has got longer every time we have gone looking, so take it as the honest state of it rather than as a promise that it is the last word: financial records, for as long as tax law requires — purchases, subscriptions, creator earnings, and creator payouts, which name the payout destination you gave us, the KYC state it was paid under, any note from that review, and the anti-fraud assessment the payout was approved against, which scores the accounts that chatted with that creator and names them by account id, so your id can sit in somebody else's payout row after you have gone — and your Sparks ledger; store-receipt claims (an opaque receipt id, not a person — otherwise "buy, delete, re-register, replay" would be a working exploit); the webhook receipts our payment provider sends us, kept verbatim and unredacted — for a web payment that means the email address, phone number and UPI handle you gave the payment provider, and neither the scrub nor any retention window can reach it, because the row is not attached to your account and nothing in the product deletes one; the crisis-referral record in §7, with its account, chat and message references removed; the whole of a support ticket you filed — the subject, your first message, everything you wrote back on the thread afterwards, and any screenshot you sent us, the stored image file as well as the row, because nothing sweeps it automatically — with your account detached from it, and with an email address on it only in one case: a ticket filed while you were signed in never carried one by design, but one filed from the logged-out web form keeps the address you typed and nothing removes it; reports you filed about someone else's content, with your account detached but the text you wrote left on them; strikes and enforcement decisions taken on your account, with the reason recorded at the time; moderation records of actions we took; the admin audit trail — every action an admin took, on whom and why — which, where one was ever taken on your account, holds that account as it read at that moment, including the email address, handle, display name and bio it had then, with no scrub and no window on it; AI cost and token-count rows with no account attached to them; any prompt version you authored or promoted through our console, with your name removed; and a stripped account row that keeps your region, timezone, language, the dates you accepted these terms, the dates the account was created and deleted, and a store account token. One more is ours alone. If your account was one we marked as belonging to our own team, a tester or an app-store reviewer, that mark is kept, so that the account stays out of our usage statistics.
  • What survives because it is somebody else's: scenes you published stay published and playable, with your name on them replaced by "Deleted user", because other people are part-way through them; a per-month count of how many messages you exchanged with each character stays with that character's creator statistics, attached to your deleted account id and to nothing else about you; an invite you accepted stays on the account of the person who invited you — it is their record of an invite that paid them — and by then it names your deleted account and nothing else about you; and blocks other people made against you stay, because they are their decision and not yours.
  • Kept without your account: every deletion and every deactivation you make yourself, in the app or the web app, writes one row that names nobody — which of the two it was, whether the closing question was shown, the answer if you gave one, the platform, app version and app language, how old the account was and how many messages it had sent (in bands, never the figures), and the week it happened in. It holds no account id, no other id and no time of day. Text you typed has addresses, links, handles and long numbers taken out before it is stored, and is erased after 26 weeks; nothing can take out a name you type, so please leave names out. The rest of the row has no window.
  • The fixed windows we keep, whether or not you ever leave: login sessions and their IP addresses, 60 days — a nightly sweep deletes the session rows themselves, so the IP address and device a login recorded do not outlive the session that recorded them; product events, 180 days; your notification inbox, 90 days and at most the newest 200; safety signals, 90 days; web-server request logs, about 14 days; application logs rotate by size, not by date; database backups, about 7 days. Where this policy names no window, read that as there being none, not as a quiet one we left out.
  • No window at all: an address typed into the waitlist form that used to be on our website. The form is gone; the entries it took are not. It is attached to no account, no sweep touches it and nothing in the product deletes one — write to us and we will remove it by hand. We would rather name that gap than defend it.

9. Children

oomfy ai is 18+ and there is no minor experience at all. We do not knowingly collect data from anyone under 18, and if we discover that we have, we delete it and terminate the account. See Child Safety Standards.

10. International transfers

We operate globally, and so do the companies in §3. Your data may be processed in India, the European Union, the United States, and — because DeepSeek is a China-based company and handles most chat replies today — in China, and in whatever other country a company named in §3 serves you from. Transfers out of the EEA/UK rely on Standard Contractual Clauses.

If you would rather your conversations did not leave for a third-party AI provider at all, withdrawing your AI consent (§3) is the switch that stops it.

11. Contact