Controller
- Legal entity
- FRIENDIFY LTD
- Registration
- Company number 16656938
- Registered office
- 128 City Road, London, United Kingdom, EC1V 2NX
- ICO
- ICO registration reference ZC025171
- Privacy contact
- [email protected]
- Data Protection Officer
- Friendify has not appointed a Data Protection Officer at this stage. Privacy questions and rights requests should be sent to [email protected].
- EU representative
- Friendify does not currently list a separate EU representative. EU users may use the privacy contact above; if a representative is appointed, the details will be added to this policy.
Frameworks
- UK GDPR
- EU GDPR
- Data Protection Act 2018
- Data (Use and Access) Act 2025
- PECR
Scope
This policy covers the current Friendify v2 product surface, including public pages, protected dashboards, API processing, optional integrations, and privacy tools.
- Friendify web app, dashboard, account, privacy center, billing, public website, and API-owned sessions.
- AI character chat, single and group conversations, user personas, memory, lorebook, Smart Chat Insights, relationship milestones and diary, collections, marketplace, creator profiles, reviews, reports, remix and referral attribution, notifications, and moderation workflows.
- Optional Discord delivery, optional voice and call mode, optional spontaneous chat photos, optional character-initiated messages, optional relationship share cards, marketing preferences, and privacy request or complaint workflows.
- Free, Spark, Bond, and Realm plan access, usage limits, Stripe-hosted Checkout, Stripe customer portal, invoices, and subscription status.
- In-chat AI image generation of characters (SFW and NSFW), where a user can request a generated "selfie", screened before generation, stored as an owned asset (SFW on Vercel Blob, adult on a private EU-region Cloudflare R2 bucket), and metered per plan.
- Real-time, turn-based voice calls, and one-time creator tips to creators via Stripe-hosted Checkout with a platform commission and manual or batch creator payouts.
- Optional web search in chat, where a message that asks for current information can trigger a lookup with an external search provider before the character replies.
- A limited youth-safe, SFW try-before-signup experience that creates a pseudonymous guest profile and session, stores the guest conversation temporarily, and can transfer that conversation to an account when the guest signs up.
Personal Data We Process
We process data that users provide directly, data generated when the service is used, and data received from selected providers such as Google OAuth, Discord, Stripe, Yoti, and model or voice processors. We do not sell personal data.
Account and authentication
Guest trial chat
Characters, conversations, memory, and lorebook
Personas and relationship journey
Marketplace and creator features
Mature access checks
Discord integration
Voice features
Billing and commercial data
Support, safety, and operations
Preferences and communications
AI-generated chat images
Web search in chat (consent-based)
Chat safety screening
Sensitive (special category) information you share in chat
Usage analytics and ad measurement (consent-based)
Creator tips and contributions
Browser-resident character assistant data
Sources Of Personal Data
Most data comes directly from you or from your use of Friendify. Some data is received from connected providers or from other users who interact with public or shared areas.
You
Your use of Friendify
Connected providers
Other users or public areas
Purposes And Lawful Bases
Friendify uses personal data only for defined purposes. The lawful basis may differ by feature, jurisdiction, and whether you enable optional features in Privacy settings.
Contract
Consent
Legitimate interests
Legal obligation
When Data Is Required
Some personal data is required to provide a requested service or comply with legal obligations. Other data is optional and controls whether a feature can be enabled.
Required for an account
Required for paid plans and tips
Optional feature data
Required by law or safety
AI Processing And Automated Decisions
Friendify uses AI to generate single and group-chat character replies, provide character-editor suggestions, generate selfie-style character images in chat when you request them or — only when you enable the optional Spontaneous photos (chatPhotos) permission — when an automated routing step decides, from the recent conversation, that the character would naturally send a photo of the current moment, transcribe voice input to text and synthesize character speech, summarize or prepare memory candidates, support smartChatInsights and its relationship diary when enabled, prepare optional character-initiated messages after quiet periods, classify uploaded visual assets for adult-content moderation, and help moderate marketplace activity. This means message content and speaker attribution, character instructions, a selected user persona, relationship context, character-assistant history and draft fields, character appearance prompts, memory, lorebook, optional image instructions, generated images, voice audio and transcripts, visual assets selected for upload, and safety metadata may be sent to OpenRouter, ModelsLab (for uncensored adult images), OpenAI, ElevenLabs, or compatible providers when needed to provide and protect the service. Before an image is generated your instruction is screened by content moderation; illegal or exploitative requests are rejected and the image quota is refunded, SFW characters require a clean result, and NSFW images are produced only for NSFW characters accessed under a valid mature gate. This screening blocks a request but is not a solely automated decision producing legal or similarly significant effects. The spontaneous-photo routing step is likewise a feature-delivery decision only: it can only skip or send an in-chat photo you have opted into, consumes your normal image quota, never runs once that quota is spent, and stops as soon as you turn the permission off in Privacy settings. SFW generated images are stored in our Vercel Blob store; adult (NSFW) generated images are stored in a private, EU-region Cloudflare R2 bucket and served only to their owner through an authenticated, mature-gated proxy. Each carries an NSFW flag and moderation status and is associated with the conversation.
Character-initiated messages are optional. When the global proactiveMessages permission and operator configuration are both on, a worker may select an eligible active web conversation after a quiet period, use recent messages, the character profile, and the selected persona to generate one in-character check-in, and create an in-app notification. Cooldowns, an atomic claim, unread notification anti-stacking, and a per-conversation mute reduce repeated contact. Turning off the permission stops future check-ins; existing messages remain until the conversation or account is deleted.
Relationship milestones use message-count thresholds, anniversaries, and forward changes in the Smart Chat Insights relationship label. The optional public journey card is created only when you request it. Its signed token carries identifiers rather than chat content, and the view is rebuilt behind SFW and safety gates from a small allowlist of journey aggregates. It never publishes messages, persona content, diary text, or your identity.
Friendify does not use solely automated decision-making that produces legal or similarly significant effects. Age-gated mature content may require self-declaration or age assurance depending on apparent region and applicable law. Automated visual classification may mark an uploaded asset as mature, keep it in review, or support public-display gating, but marketplace and asset moderation may still involve manual review, appeal, or support routes where appropriate.
Friendify uses IP-derived coarse region for mature-access compliance and does not store raw IP for age policy decisions unless separately needed for security logs. Self-declaration stores only selfDeclaredAdultAt, policy version, and coarse region. Yoti handles provider verification data where stronger assurance is required, and Friendify stores only the adult result, reference, method, timestamp, and minimal metadata needed for mature access.
Processors And Recipients
We share data with service providers only when needed for the service, safety, payments, support, legal compliance, or user-requested integrations.
| Provider | Purpose | Data |
|---|---|---|
| Stripe | Stripe-hosted Checkout, customer portal, subscriptions, one-time creator tips in payment mode, invoices, fraud controls, taxes, refunds, and payment records. Friendify is the merchant of record and does not use Stripe Connect. | Billing identifiers, plan and subscription metadata, one-time tip amount, currency, platform commission, checkout session and payment intent IDs, tip and payment status, customer contact details, invoices, and fraud signals handled by Stripe. |
| OpenRouter | Routing AI requests to OpenRouter or OpenAI-compatible model providers for character replies, group-chat turns, character-assistant suggestions, Smart Chat Insights and diary generation, memory-related processing, character-initiated messages, spontaneous-photo routing, and in-chat image generation (OpenRouterImageAdapter, /chat/completions with the image modality). | Conversation context, speaker attribution, prompts, character instructions, selected user persona, relationship context, stored character appearance prompts, optional user image instructions, character-assistant history and draft fields, safety metadata, and technical request metadata needed to generate replies, insights, suggestions, and images. |
| ModelsLab | Generating uncensored adult (NSFW) in-chat character images for mature characters accessed under a valid age gate, when the operator has enabled ModelsLab image routing. Runs with the provider safety checker off; Friendify's own moderation scan screens every result before it is stored. | The assembled image prompt (character appearance and scene description derived from the conversation) and technical request metadata needed to generate the image. No account identifiers or raw chat transcripts are sent. |
| OpenAI | Automatic safety classification of uploaded visual assets, including adult-content detection for mature marketplace and asset moderation workflows where enabled. | Uploaded image bytes or data URLs, content type, safety classification output, and technical request metadata needed to classify visual assets. |
| ElevenLabs | Optional voice processing where enabled, including speech-to-text transcription, text-to-speech generation, and a real-time, turn-based voice call mode. Processing occurs in the United States under Standard Contractual Clauses, the UK International Data Transfer Addendum, and ElevenLabs' Data Privacy Framework certification. Zero-retention mode is not available on Friendify's current plan, so ElevenLabs may retain request data under its own privacy policy; Friendify has opted out of ElevenLabs using its voice inputs for model training. | Short microphone audio captured for transcription, text for speech generation, speech-to-text transcripts, generated audio and audio metadata, voice usage counters, and processor response metadata. ElevenLabs may retain this request data under its own retention schedule, which Friendify does not control. |
| Brave Search | Optional web search in chat, where enabled and where you have allowed the Web search permission. A lookup runs only when a message asks for current information; the reply then cites the sources returned. Processing occurs in the United States. Brave states that search queries submitted through its search API are not personal data and that it is not a processor, service provider or third party in respect of them; Friendify treats those queries as your personal data because Friendify can link them to your account, and records that difference of position in its internal sub-processor register. | A short search query derived from your message and capped at 50 words, with email addresses, phone numbers, API keys and long tokens stripped out beforehand, plus Friendify's own API key. No account identifier, conversation identifier, character identifier or IP address is sent. Brave retains a record of queries made through the search API for up to 90 days for billing and troubleshooting. |
| Yoti | Age assurance for mature marketplace content, NSFW chat, or other age-gated experiences where stronger assurance is required by apparent region. | Yoti stores or handles provider verification data in its flow. Friendify stores only adult status, verification reference, method, timestamp, coarse region, and minimal metadata needed to confirm eligibility. |
| Google Analytics | Consent-based aggregate usage measurement (Google Analytics 4) that runs only after you allow analytics cookies through the consent banner, the cookie preferences dialog, or the Analytics permission in Privacy settings. Google Analytics 4 does not log or store individual IP addresses. Processing may occur in the United States under Google's Data Privacy Framework certification and Standard Contractual Clauses. | Pseudonymous cookie identifiers (_ga and _ga_*), pages viewed, referrer, approximate location derived by Google, device and browser metadata, and usage events. No account email, display name, chat content, or message text is sent to Google Analytics. |
| Google Ads | Consent-based advertising conversion measurement that runs only after you allow advertising cookies through the consent banner, the cookie preferences dialog, or the Advertising permission in Privacy settings. Google Consent Mode signals limit Google Ads to the categories you allowed. Processing may occur in the United States under Google's Data Privacy Framework certification and Standard Contractual Clauses. | Advertising cookie identifiers (_gcl_au and related _gcl_*/_gac_* cookies), ad click identifiers, conversion events, pages viewed, and device and browser metadata. No account email, display name, chat content, or message text is sent to Google Ads. |
| Discord | Discord OAuth, optional account linking, bot delivery, server/channel setup, and bot usage events. | Discord account profile data, Discord IDs, server/channel IDs, bot installation metadata, and message routing metadata. |
| Google OAuth | Google sign-in and account identity verification when selected by the user. | Google account ID, email, verified email status, display name, and avatar URL. |
| Email and hosting providers | Email magic links, service notices, legal notices, infrastructure hosting, database, queueing, and observability. | Email addresses, delivery events, application data, logs, encrypted records, and redacted diagnostics. |
| Vercel (hosting and Blob storage) | Application hosting and Blob object storage for uploaded assets and SFW AI-generated chat images. | Application requests, uploaded and SFW generated image bytes, storage keys, URLs, content type, isNsfw flag, moderation status, and technical metadata. Processing may occur in the United States and other Vercel regions. |
| Cloudflare R2 | Private, EU-region object storage for adult (NSFW) AI-generated chat images, served only through Friendify's authenticated, owner-only proxy and never a public URL or CDN. | Adult generated image bytes, storage keys, content type, and technical metadata, stored in an Eastern-Europe region for EU data residency. |
International Transfers
Friendify is a UK company and may process data in the UK, EEA, United States, and other locations used by our providers. Our international transfers rely on adequacy regulations, standard contractual clauses, the UK international data transfer addendum, processor contracts, and technical safeguards where required.
If a provider changes processing location or introduces a new transfer that materially affects users, we update this policy and relevant in-product notices before starting the new processing where required.
Retention
We keep personal data only as long as necessary for the service, safety, legal obligations, disputes, accounting, and user-controlled privacy requests.
Sessions
Guest trial data
Privacy requests
Account deletion
Exports
Deleted conversations and memory candidates
Voice audio and transcripts
Web search queries and sources
Audit records
Billing records
Generated chat images
Personas, milestones, diary, notifications, and share cards
Character assistant browser data
Tip and commission records
Your Rights
Depending on where you live and the processing involved, you may have the following rights under UK GDPR, EU GDPR, and the Data Protection Act 2018.
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction
- Right to data portability
- Right to object
- right to withdraw consent
You can use the Privacy center for consent controls, export requests, deletion requests, memory deletion, conversation deletion, and Discord unlink requests, or contact [email protected]. You also have the right to complain to the Information Commissioner's Office or your local supervisory authority.
Data Protection Complaints
You can make a data protection complaint by emailing [email protected] and stating that your message is a data protection complaint. You do not need to quote a law. Include enough information for us to identify the account or processing and understand what you believe went wrong, but do not send passwords, identity documents, payment card data, or unrelated sensitive content.
We will acknowledge a data protection complaint within 30 days, take appropriate steps to investigate without undue delay, keep you informed where an investigation remains open, and communicate the outcome without undue delay. This process does not remove your right to complain to the Information Commissioner's Office or another competent supervisory authority.
Cookies, Security, And Changes
Friendify uses strictly necessary cookies and limited local storage as described in the Cookie Policy. Optional Google Analytics cookies and optional Google Ads conversion-measurement cookies are set only after you allow them through the cookie consent banner, the cookie preferences dialog available from the Cookie settings link on every page, or the Analytics and Advertising permissions in Privacy settings, and you can withdraw each choice at any time through the same controls. Any further non-essential analytics or advertising storage must not be introduced without the required notice and consent flow.
We use security measures such as HttpOnly session cookies, server-side session handling, redaction of sensitive audit metadata, access controls, encryption in transit, and encryption at rest where supported. No system is perfect, so users should keep OAuth accounts secure and contact us quickly about suspected abuse.
We may update this policy when the service, law, providers, or processing changes. Material changes will be communicated in a way appropriate to the change before the new processing begins where required.