Friendify’s AI chat and character service will end on 16 October 2026 at 21:59 Europe/London. Sign-in and registration stay open until then. This notice does not delete your data. Questions: [email protected]

Friendify flower logoFriendifyAI companions
DiscoverCreateToolsFeaturesPricing
Sign inStart chatting
Privacy PolicyTerms of ServiceCookie PolicyAge Assurance

Friendify legal

Privacy Policy

This Privacy Policy explains how FRIENDIFY LTD collects, uses, shares, stores, and protects personal data across Friendify's guest and account chat, group conversations, personas, AI photos, relationship features, marketplace, Discord, voice, creator tools, billing, and support workflows.

Effective
July 28, 2026
Controller
FRIENDIFY LTD
Privacy contact
[email protected]

Contents

ControllerFrameworksScopePersonal Data We ProcessSources Of Personal DataPurposes And Lawful BasesWhen Data Is RequiredAI Processing And Automated DecisionsProcessors And RecipientsInternational TransfersRetentionYour RightsData Protection ComplaintsCookies, Security, And Changes

Controller

Legal entity
FRIENDIFY LTD
Registration
Company number 16656938
Registered office
128 City Road, London, United Kingdom, EC1V 2NX
ICO
ICO registration reference ZC025171
Privacy contact
[email protected]
Data Protection Officer
Friendify has not appointed a Data Protection Officer at this stage. Privacy questions and rights requests should be sent to [email protected].
EU representative
Friendify does not currently list a separate EU representative. EU users may use the privacy contact above; if a representative is appointed, the details will be added to this policy.

Frameworks

  • UK GDPR
  • EU GDPR
  • Data Protection Act 2018
  • Data (Use and Access) Act 2025
  • PECR

Scope

This policy covers the current Friendify v2 product surface, including public pages, protected dashboards, API processing, optional integrations, and privacy tools.

  • Friendify web app, dashboard, account, privacy center, billing, public website, and API-owned sessions.
  • AI character chat, single and group conversations, user personas, memory, lorebook, Smart Chat Insights, relationship milestones and diary, collections, marketplace, creator profiles, reviews, reports, remix and referral attribution, notifications, and moderation workflows.
  • Optional Discord delivery, optional voice and call mode, optional spontaneous chat photos, optional character-initiated messages, optional relationship share cards, marketing preferences, and privacy request or complaint workflows.
  • Free, Spark, Bond, and Realm plan access, usage limits, Stripe-hosted Checkout, Stripe customer portal, invoices, and subscription status.
  • In-chat AI image generation of characters (SFW and NSFW), where a user can request a generated "selfie", screened before generation, stored as an owned asset (SFW on Vercel Blob, adult on a private EU-region Cloudflare R2 bucket), and metered per plan.
  • Real-time, turn-based voice calls, and one-time creator tips to creators via Stripe-hosted Checkout with a platform commission and manual or batch creator payouts.
  • Optional web search in chat, where a message that asks for current information can trigger a lookup with an external search provider before the character replies.
  • A limited youth-safe, SFW try-before-signup experience that creates a pseudonymous guest profile and session, stores the guest conversation temporarily, and can transfer that conversation to an account when the guest signs up.

Personal Data We Process

We process data that users provide directly, data generated when the service is used, and data received from selected providers such as Google OAuth, Discord, Stripe, Yoti, and model or voice processors. We do not sell personal data.

Account and authentication

Email address, display name, avatar, user ID, roles, Google OAuth profile data, Discord OAuth profile data, email magic links, login timestamps, hashed session tokens, the friendify_session cookie, and the friendify_last_auth_method cookie that remembers the last successful sign-in method for up to 365 days.

Guest trial chat

The try-before-signup flow creates a pseudonymous Guest user, a secure session, a one-way hash derived from the connection address for abuse prevention, Terms and Privacy Policy acceptance timestamps and policy version, conversation and message records, usage counters, and temporary milestone or notification records. It does not ask for or store the guest’s age or date of birth. Guest chats are limited to approved public SFW starter characters and use youth-safe settings. If you sign up in the same browser, the guest conversation and messages are transferred to the new account; abandoned guest data is deleted after at least 30 days, or later if the configured session lifetime is longer.

Characters, conversations, memory, and lorebook

Character profiles, visibility, chat and image model settings when enabled, appearance prompts, prompts, single or group messages and speaker attribution, conversation metadata, memory candidates, approved memory, rejected or deleted memory state, and lorebook/world knowledge.

Personas and relationship journey

Private user persona names, descriptions, traits, default status, moderation status, and the persona selected for a conversation; relationship labels, milestone kind and label, message-count or anniversary values, achieved dates, AI-generated diary text or milestone excerpts, and character-initiated message state. When you create a relationship share card, Friendify signs a token containing only user and conversation IDs and re-derives a restricted view containing journey aggregates; the public card never includes messages, persona text, diary text, or your identity.

Marketplace and creator features

Creator profiles, display names, bios, marketplace listings, collections, follows, reviews, reports, remix source and derivative relationships, share and referral-attribution events (including the referring user ID), install and discovery events, in-app notifications, optional notification email status, uploaded character or marketplace visual assets, asset moderation status, moderation notes, mature-content gates, self-declaration status where allowed, and Yoti age verification status where required.

Mature access checks

IP-derived coarse region is used to decide whether mature/NSFW access requires self-declaration, Yoti age assurance, or no mature access. Friendify does not store raw IP for age policy decisions unless separately needed in security logs. Self-declaration stores selfDeclaredAdultAt, selfDeclarationPolicyVersion, and selfDeclarationRegion only.

Discord integration

Linked Discord account data, Discord user IDs, usernames, avatars, server/guild and channel IDs, bot installation metadata, quotas, usage events, and server-side bot token handling.

Voice features

Voice consent state, short microphone audio inputs captured when voice or a real-time, turn-based voice call is enabled (voice activity detection auto-loops turns), speech-to-text transcripts, text-to-speech generation requests, voice usage counters, and processor status for ElevenLabs. ElevenLabs is used for both speech-to-text and text-to-speech. Your microphone audio is sent to ElevenLabs, which processes it in the United States, to produce a transcript and to generate spoken replies. On Friendify's current ElevenLabs plan, voice requests are not processed in zero-retention mode, so ElevenLabs may retain the submitted audio and transcript under its own privacy policy and retention schedule. Friendify has opted out of allowing ElevenLabs to use your voice inputs to train or improve its models.

Billing and commercial data

Stripe customer ID, subscription ID, checkout session ID, plan key, entitlement status, invoices, tax metadata where required, refund and cancellation status. Friendify does not collect card numbers, CVC/CVV, expiry, or raw payment method details.

Support, safety, and operations

Support messages, privacy request records, consent audit records, security logs, abuse reports, admin audit events, redacted diagnostics, IP-derived security metadata, and service reliability metrics.

Preferences and communications

Privacy preferences for marketing, analytics, advertising, aiProcessing, memory, discord, voice, webSearch (web lookups in chat), chatPhotos (spontaneous character photos), proactiveMessages (character-initiated messages), migration, and smartChatInsights; per-conversation proactive mute state; service emails, security notices, legal notices, in-app notifications, and optional marketing messages.

AI-generated chat images

When you request an AI-generated image of a character in a chat (a "selfie"), Friendify stores the result as an owned asset (kind chatImage, source generated) with a storage key, isNsfw flag, and moderation status, linked to the conversation. SFW images are kept in the Vercel Blob store used for uploads; adult (NSFW) images are stored in a separate private, EU-region bucket (Cloudflare R2) and are served only to you through an authenticated, mature-gated proxy. Your optional free-text instruction, the conversation context, and the character's stored appearance prompt are used to generate the image (through OpenRouter for SFW models or ModelsLab for uncensored adult models) and every result is screened by moderation before it is stored. If you enable the optional "Spontaneous photos" (chatPhotos) permission in Privacy settings, a character may also send you a photo without a button press: after a reply, an automated routing step reviews the recent conversation to decide whether a photo fits the moment and what it should show. These automatic photos use the same generation providers, moderation screening, storage rules, and per-plan image quota as requested images, never run once your image quota is spent, and stop as soon as you withdraw the permission. Image generation is included on every plan and metered per plan (free 3 per 24h; spark 30, bond 150, realm 500 per billing period); the Pricing and Billing pages show the current allowance.

Web search in chat (consent-based)

If you allow the Web search permission in Privacy settings, a message that asks for current information — a news event, a price, something "latest" or "today", or a link — can trigger a web lookup before the character replies, and the results are shown as sources under the reply. The search runs with Brave Search, and what is sent is a short search query derived from your message, capped at 50 words. Before it is sent, Friendify removes email addresses, phone numbers, API keys and long tokens from the query, and refuses the lookup entirely if the message contains a password, secret or key. No account identifier, conversation identifier or IP address is sent with the query, so Brave receives the query and Friendify's API key, not your identity. Brave processes the query in the United States and keeps a record of queries made through its search API for up to 90 days for billing and troubleshooting. Brave's position is that search queries sent through its API are not personal data and that it does not act as Friendify's processor for them; Friendify treats them as your personal data regardless, because Friendify can link a query to your account. Web search never runs when the permission is off, never runs for a character whose owner has disabled it, and ordinary conversation that does not ask for current information is never sent.

Chat safety screening

To protect people — especially under-18s — from serious harm, Friendify screens chat messages for a small set of safety signals: suicide and self-harm, eating-disorder encouragement, grooming and sexual content involving minors, and threats, bullying or hate. This screening runs on Friendify's own servers. Your message text is not sent to any third party for it, and it is not used to train any model. What is stored alongside the message is the verdict, not a copy of the text: a category, a risk level, and the version of the safety rules that produced it. Friendify may also run the screening in an observe-only mode where the verdict is recorded but nothing you see changes. Where screening is enforced and a message raises a serious signal, the character's reply may be replaced with an out-of-character message: for suicide, self-harm or eating-disorder signals this offers UK support lines, and for grooming or sexual content involving a minor it stops that exchange. A safety response is not an accusation and does not by itself restrict your account. The lawful basis is Friendify's legitimate interest in keeping users safe and meeting its Online Safety Act duties, and, where a message indicates a risk to life, the vital interests of the person concerned. You can ask about, or object to, this processing through the Privacy centre.

Sensitive (special category) information you share in chat

Conversations with characters are free-form, so you may choose to share information UK data-protection law treats as special category data: health (including mental health), sex life or sexual orientation, and religious, philosophical or political beliefs. Friendify processes that information only to run your chats (including the optional memory and insights features you separately control) and to keep you safe through the chat safety screening described above. The lawful basis is your explicit consent (UK GDPR Article 9(2)(a)), which Friendify asks for in a separate consent step before your first chat — for guests, in the guest consent step. Sensitive information is never used for advertising and never used to train AI models. You can withdraw this consent at any time in the Privacy centre; withdrawal pauses chat until it is granted again, does not affect processing that already happened, and you can delete your conversations at any time. Safety screening of a message that indicates a risk to life additionally relies on the safeguarding and vital-interests provisions described in the screening section.

Usage analytics and ad measurement (consent-based)

When you allow analytics cookies, Google Analytics 4 collects pseudonymous usage events for Friendify's web pages: pages viewed, referrer, session and device or browser metadata, approximate location derived by Google, and the _ga cookie identifiers. When you separately allow advertising cookies, Google Ads records conversion measurement data (the _gcl_au and related cookies, ad click identifiers, and conversion events) so Friendify can tell whether its ad campaigns work. Neither product receives your email address, display name, chat messages, character content, or memory data, and neither runs at all until you allow its category. Google Consent Mode signals communicate your per-category choice to Google. Your allow-or-decline choices are stored in the friendify_analytics_consent and friendify_ads_consent cookies and, for signed-in changes made in Privacy settings, in your consent audit records.

Creator tips and contributions

One-time supporter tips sent to a creator through Stripe-hosted Checkout in payment mode. A CreatorTip record stores the sending user ID, recipient creator user ID, creator handle, amount in cents, currency, platform fee in cents, status (pending, succeeded, failed, or refunded), Stripe checkout session ID, Stripe payment intent ID, an optional message up to 280 characters, and the paid-at time. Friendify does not collect card numbers, CVC/CVV, expiry, or raw payment method details.

Browser-resident character assistant data

The character editor uses an IndexedDB database named friendify-character-assistant to keep up to 40 recent assistant history messages per character draft and the selected assistant model for SFW or NSFW editing. This data stays in that browser, is sent to Friendify only when you use the character assistant, and remains until you clear the assistant history, clear site data, or remove it through browser controls. The theme preference is separately stored in local storage.

Sources Of Personal Data

Most data comes directly from you or from your use of Friendify. Some data is received from connected providers or from other users who interact with public or shared areas.

You

Account registration, profile edits, characters, messages, prompts, marketplace listings, reviews, reports, support requests, consent choices, privacy requests, and billing actions.

Your use of Friendify

Session metadata, usage counters, plan entitlement checks, coarse region for mature-access compliance, Discord setup activity, voice usage, memory review actions, persona selection, relationship milestones, marketplace and referral events, notification state, safety events, diagnostics, and audit events generated while the service operates.

Connected providers

Google OAuth, Discord, Stripe, Yoti, OpenRouter, ElevenLabs, Brave Search, email providers, hosting providers, and similar processors may return identifiers, status, usage, delivery, verification, or processor metadata.

Other users or public areas

Marketplace reviews, reports, creator interactions, follows, collections, moderation submissions, and public or shared content may identify users or content connected with an account.

Purposes And Lawful Bases

Friendify uses personal data only for defined purposes. The lawful basis may differ by feature, jurisdiction, and whether you enable optional features in Privacy settings.

Contract

Creating or temporarily operating guest sessions, keeping users signed in, transferring a guest chat on signup, delivering single or group web chat and requested in-chat image generation, maintaining characters, personas and relationship journey data, creating a share card at your request, applying Free, Spark, Bond, and Realm limits and image or voice quotas, opening Stripe-hosted Checkout and portal flows, processing one-time creator tips you choose to send, and providing requested Discord or voice features.

Consent

Optional marketing, optional Google Analytics measurement after you allow analytics cookies, optional Google Ads conversion measurement after you allow advertising cookies, optional memory, optional Discord features, optional voice processing, optional web search in chat (webSearch), optional spontaneous chat photos (chatPhotos), optional character-initiated messages (proactiveMessages), smartChatInsights including its diary output, migration choices, and any non-essential cookies or browser storage that require consent.

Legitimate interests

Keeping the service secure, using a one-way address hash and rate limits to prevent guest abuse, preventing fraud, debugging errors with redaction, measuring aggregate service reliability, recording marketplace event and referral attribution, delivering event-based service notifications, enforcing account and marketplace safety, and improving the product without overriding user rights.

Legal obligation

Tax and accounting records for subscriptions and creator tips, consumer-law obligations, mature-access compliance where applicable, sanctions or abuse response where required, privacy rights handling, security incident records, and lawful requests from courts, regulators, or competent authorities.

When Data Is Required

Some personal data is required to provide a requested service or comply with legal obligations. Other data is optional and controls whether a feature can be enabled.

Required for an account

An email, OAuth identity, session data, and basic account metadata are needed to create an account, sign in, secure the service, and provide protected dashboards.

Required for paid plans and tips

Stripe billing identifiers, subscription status, invoice metadata, and tax or accounting data are needed to provide paid Free, Spark, Bond, and Realm upgrades where applicable. Sending a one-time creator tip requires the tip amount, currency, the recipient creator, Stripe checkout and payment identifiers, and any optional message you add.

Optional feature data

Memory, personas, relationship sharing, Discord, voice, in-chat image generation, spontaneous photos, character-initiated messages, creator tips, smartChatInsights and its diary, marketplace participation, mature-content age checks, marketing, analytics, and advertising are optional or feature-specific. Mature self-declaration stores only adult declaration timestamp, policy version, and coarse region; Yoti handles provider verification data where stronger assurance is required. Image generation and voice are metered by plan, and creator tips are voluntary one-time payments. If you do not provide the data or withdraw consent, those features may not work.

Required by law or safety

Some fraud, security, tax, consumer, privacy request, dispute, abuse-report, and audit records may be required even if an account is later closed.

AI Processing And Automated Decisions

Friendify uses AI to generate single and group-chat character replies, provide character-editor suggestions, generate selfie-style character images in chat when you request them or — only when you enable the optional Spontaneous photos (chatPhotos) permission — when an automated routing step decides, from the recent conversation, that the character would naturally send a photo of the current moment, transcribe voice input to text and synthesize character speech, summarize or prepare memory candidates, support smartChatInsights and its relationship diary when enabled, prepare optional character-initiated messages after quiet periods, classify uploaded visual assets for adult-content moderation, and help moderate marketplace activity. This means message content and speaker attribution, character instructions, a selected user persona, relationship context, character-assistant history and draft fields, character appearance prompts, memory, lorebook, optional image instructions, generated images, voice audio and transcripts, visual assets selected for upload, and safety metadata may be sent to OpenRouter, ModelsLab (for uncensored adult images), OpenAI, ElevenLabs, or compatible providers when needed to provide and protect the service. Before an image is generated your instruction is screened by content moderation; illegal or exploitative requests are rejected and the image quota is refunded, SFW characters require a clean result, and NSFW images are produced only for NSFW characters accessed under a valid mature gate. This screening blocks a request but is not a solely automated decision producing legal or similarly significant effects. The spontaneous-photo routing step is likewise a feature-delivery decision only: it can only skip or send an in-chat photo you have opted into, consumes your normal image quota, never runs once that quota is spent, and stops as soon as you turn the permission off in Privacy settings. SFW generated images are stored in our Vercel Blob store; adult (NSFW) generated images are stored in a private, EU-region Cloudflare R2 bucket and served only to their owner through an authenticated, mature-gated proxy. Each carries an NSFW flag and moderation status and is associated with the conversation.

Character-initiated messages are optional. When the global proactiveMessages permission and operator configuration are both on, a worker may select an eligible active web conversation after a quiet period, use recent messages, the character profile, and the selected persona to generate one in-character check-in, and create an in-app notification. Cooldowns, an atomic claim, unread notification anti-stacking, and a per-conversation mute reduce repeated contact. Turning off the permission stops future check-ins; existing messages remain until the conversation or account is deleted.

Relationship milestones use message-count thresholds, anniversaries, and forward changes in the Smart Chat Insights relationship label. The optional public journey card is created only when you request it. Its signed token carries identifiers rather than chat content, and the view is rebuilt behind SFW and safety gates from a small allowlist of journey aggregates. It never publishes messages, persona content, diary text, or your identity.

Friendify does not use solely automated decision-making that produces legal or similarly significant effects. Age-gated mature content may require self-declaration or age assurance depending on apparent region and applicable law. Automated visual classification may mark an uploaded asset as mature, keep it in review, or support public-display gating, but marketplace and asset moderation may still involve manual review, appeal, or support routes where appropriate.

Friendify uses IP-derived coarse region for mature-access compliance and does not store raw IP for age policy decisions unless separately needed for security logs. Self-declaration stores only selfDeclaredAdultAt, policy version, and coarse region. Yoti handles provider verification data where stronger assurance is required, and Friendify stores only the adult result, reference, method, timestamp, and minimal metadata needed for mature access.

Processors And Recipients

We share data with service providers only when needed for the service, safety, payments, support, legal compliance, or user-requested integrations.

ProviderPurposeData
StripeStripe-hosted Checkout, customer portal, subscriptions, one-time creator tips in payment mode, invoices, fraud controls, taxes, refunds, and payment records. Friendify is the merchant of record and does not use Stripe Connect.Billing identifiers, plan and subscription metadata, one-time tip amount, currency, platform commission, checkout session and payment intent IDs, tip and payment status, customer contact details, invoices, and fraud signals handled by Stripe.
OpenRouterRouting AI requests to OpenRouter or OpenAI-compatible model providers for character replies, group-chat turns, character-assistant suggestions, Smart Chat Insights and diary generation, memory-related processing, character-initiated messages, spontaneous-photo routing, and in-chat image generation (OpenRouterImageAdapter, /chat/completions with the image modality).Conversation context, speaker attribution, prompts, character instructions, selected user persona, relationship context, stored character appearance prompts, optional user image instructions, character-assistant history and draft fields, safety metadata, and technical request metadata needed to generate replies, insights, suggestions, and images.
ModelsLabGenerating uncensored adult (NSFW) in-chat character images for mature characters accessed under a valid age gate, when the operator has enabled ModelsLab image routing. Runs with the provider safety checker off; Friendify's own moderation scan screens every result before it is stored.The assembled image prompt (character appearance and scene description derived from the conversation) and technical request metadata needed to generate the image. No account identifiers or raw chat transcripts are sent.
OpenAIAutomatic safety classification of uploaded visual assets, including adult-content detection for mature marketplace and asset moderation workflows where enabled.Uploaded image bytes or data URLs, content type, safety classification output, and technical request metadata needed to classify visual assets.
ElevenLabsOptional voice processing where enabled, including speech-to-text transcription, text-to-speech generation, and a real-time, turn-based voice call mode. Processing occurs in the United States under Standard Contractual Clauses, the UK International Data Transfer Addendum, and ElevenLabs' Data Privacy Framework certification. Zero-retention mode is not available on Friendify's current plan, so ElevenLabs may retain request data under its own privacy policy; Friendify has opted out of ElevenLabs using its voice inputs for model training.Short microphone audio captured for transcription, text for speech generation, speech-to-text transcripts, generated audio and audio metadata, voice usage counters, and processor response metadata. ElevenLabs may retain this request data under its own retention schedule, which Friendify does not control.
Brave SearchOptional web search in chat, where enabled and where you have allowed the Web search permission. A lookup runs only when a message asks for current information; the reply then cites the sources returned. Processing occurs in the United States. Brave states that search queries submitted through its search API are not personal data and that it is not a processor, service provider or third party in respect of them; Friendify treats those queries as your personal data because Friendify can link them to your account, and records that difference of position in its internal sub-processor register.A short search query derived from your message and capped at 50 words, with email addresses, phone numbers, API keys and long tokens stripped out beforehand, plus Friendify's own API key. No account identifier, conversation identifier, character identifier or IP address is sent. Brave retains a record of queries made through the search API for up to 90 days for billing and troubleshooting.
YotiAge assurance for mature marketplace content, NSFW chat, or other age-gated experiences where stronger assurance is required by apparent region.Yoti stores or handles provider verification data in its flow. Friendify stores only adult status, verification reference, method, timestamp, coarse region, and minimal metadata needed to confirm eligibility.
Google AnalyticsConsent-based aggregate usage measurement (Google Analytics 4) that runs only after you allow analytics cookies through the consent banner, the cookie preferences dialog, or the Analytics permission in Privacy settings. Google Analytics 4 does not log or store individual IP addresses. Processing may occur in the United States under Google's Data Privacy Framework certification and Standard Contractual Clauses.Pseudonymous cookie identifiers (_ga and _ga_*), pages viewed, referrer, approximate location derived by Google, device and browser metadata, and usage events. No account email, display name, chat content, or message text is sent to Google Analytics.
Google AdsConsent-based advertising conversion measurement that runs only after you allow advertising cookies through the consent banner, the cookie preferences dialog, or the Advertising permission in Privacy settings. Google Consent Mode signals limit Google Ads to the categories you allowed. Processing may occur in the United States under Google's Data Privacy Framework certification and Standard Contractual Clauses.Advertising cookie identifiers (_gcl_au and related _gcl_*/_gac_* cookies), ad click identifiers, conversion events, pages viewed, and device and browser metadata. No account email, display name, chat content, or message text is sent to Google Ads.
DiscordDiscord OAuth, optional account linking, bot delivery, server/channel setup, and bot usage events.Discord account profile data, Discord IDs, server/channel IDs, bot installation metadata, and message routing metadata.
Google OAuthGoogle sign-in and account identity verification when selected by the user.Google account ID, email, verified email status, display name, and avatar URL.
Email and hosting providersEmail magic links, service notices, legal notices, infrastructure hosting, database, queueing, and observability.Email addresses, delivery events, application data, logs, encrypted records, and redacted diagnostics.
Vercel (hosting and Blob storage)Application hosting and Blob object storage for uploaded assets and SFW AI-generated chat images.Application requests, uploaded and SFW generated image bytes, storage keys, URLs, content type, isNsfw flag, moderation status, and technical metadata. Processing may occur in the United States and other Vercel regions.
Cloudflare R2Private, EU-region object storage for adult (NSFW) AI-generated chat images, served only through Friendify's authenticated, owner-only proxy and never a public URL or CDN.Adult generated image bytes, storage keys, content type, and technical metadata, stored in an Eastern-Europe region for EU data residency.

International Transfers

Friendify is a UK company and may process data in the UK, EEA, United States, and other locations used by our providers. Our international transfers rely on adequacy regulations, standard contractual clauses, the UK international data transfer addendum, processor contracts, and technical safeguards where required.

If a provider changes processing location or introduces a new transfer that materially affects users, we update this policy and relevant in-product notices before starting the new processing where required.

Retention

We keep personal data only as long as necessary for the service, safety, legal obligations, disputes, accounting, and user-controlled privacy requests.

Sessions

The friendify_session cookie is HttpOnly, SameSite=Lax, Path=/, Secure in production, and expires with the API session period, currently up to 30 days.

Guest trial data

Guest profiles, sessions, Terms and Privacy Policy acceptance records, conversations, messages, and related trial records are hard-deleted after at least 30 days from guest creation, or later if the configured session lifetime is longer. If you sign up before cleanup, the guest conversation and messages move to the account and then follow the normal account and conversation retention rules.

Privacy requests

Access, correction, portability, restriction, objection, Discord unlink, memory deletion, conversation deletion, and account deletion requests are targeted for response within 30 days.

Account deletion

Account deletion keeps a 30-day cooling-off period so accidental or unauthorized requests can be cancelled before irreversible deletion steps continue.

Exports

Prepared export artifacts are encrypted and expire after 7 days unless a shorter expiry is configured.

Deleted conversations and memory candidates

Soft-deleted conversations and expired memory candidates are retained for up to 30 days for recovery, safety, and audit handling before cleanup.

Voice audio and transcripts

Speech-to-text transcripts are stored as part of your conversation and are removed when the conversation is deleted, subject to the soft-delete recovery window. Microphone audio is streamed to ElevenLabs for processing; because zero-retention mode is not available on Friendify's current plan, ElevenLabs may retain that audio and the resulting transcript under its own privacy policy and retention schedule, which Friendify does not control. Friendify has opted out of ElevenLabs using voice inputs for model training.

Web search queries and sources

The query used for a lookup and the sources returned are stored alongside the reply that used them, and are removed when that conversation is deleted, subject to the soft-delete recovery window. Brave separately keeps a record of queries made through its search API for up to 90 days under its own retention schedule, which Friendify does not control.

Audit records

Privacy and admin audit records are retained for 365 days unless a longer period is required for legal, security, or dispute reasons.

Billing records

Invoice, subscription, and tax records may be retained for the period required by accounting, tax, consumer, and anti-fraud obligations.

Generated chat images

AI-generated chat images (SFW in Vercel Blob, adult in the private Cloudflare R2 bucket) are kept while the owning account and associated conversation exist. They are removed when you delete the image or conversation and, on account deletion, after the 30-day cooling-off period, subject to soft-delete recovery windows and any safety or legal hold.

Personas, milestones, diary, notifications, and share cards

Personas remain until you delete them or the account. Conversation milestones, diary output, proactive state, and related notifications follow the owning conversation or account and are removed through the corresponding deletion workflows, subject to recovery, safety, audit, or legal holds. Relationship share tokens are derived rather than stored as public content; a valid link can remain usable until the underlying conversation becomes unavailable, fails the SFW safety gate, or an expiry encoded in the token is reached.

Character assistant browser data

Character-assistant history and model choice in IndexedDB remain in that browser until you clear the assistant history or browser site data. The history is capped at 40 messages per character draft.

Tip and commission records

CreatorTip records, including amount, platform commission, status, message, and Stripe identifiers, may be retained for the period required by accounting, tax, consumer-protection, chargeback, and anti-fraud obligations, even after an account is closed.

Your Rights

Depending on where you live and the processing involved, you may have the following rights under UK GDPR, EU GDPR, and the Data Protection Act 2018.

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restriction
  • Right to data portability
  • Right to object
  • right to withdraw consent

You can use the Privacy center for consent controls, export requests, deletion requests, memory deletion, conversation deletion, and Discord unlink requests, or contact [email protected]. You also have the right to complain to the Information Commissioner's Office or your local supervisory authority.

Data Protection Complaints

You can make a data protection complaint by emailing [email protected] and stating that your message is a data protection complaint. You do not need to quote a law. Include enough information for us to identify the account or processing and understand what you believe went wrong, but do not send passwords, identity documents, payment card data, or unrelated sensitive content.

We will acknowledge a data protection complaint within 30 days, take appropriate steps to investigate without undue delay, keep you informed where an investigation remains open, and communicate the outcome without undue delay. This process does not remove your right to complain to the Information Commissioner's Office or another competent supervisory authority.

Cookies, Security, And Changes

Friendify uses strictly necessary cookies and limited local storage as described in the Cookie Policy. Optional Google Analytics cookies and optional Google Ads conversion-measurement cookies are set only after you allow them through the cookie consent banner, the cookie preferences dialog available from the Cookie settings link on every page, or the Analytics and Advertising permissions in Privacy settings, and you can withdraw each choice at any time through the same controls. Any further non-essential analytics or advertising storage must not be introduced without the required notice and consent flow.

We use security measures such as HttpOnly session cookies, server-side session handling, redaction of sensitive audit metadata, access controls, encryption in transit, and encryption at rest where supported. No system is perfect, so users should keep OAuth accounts secure and contact us quickly about suspected abuse.

We may update this policy when the service, law, providers, or processing changes. Material changes will be communicated in a way appropriate to the change before the new processing begins where required.

Friendify flower logoFriendifyAI companions

AI companions who remember you — your characters, private chats, and everything that makes them feel real, all in one place.

Follow us

FRIENDIFY LTD - Company number 16656938

Product

FeaturesPricingDiscover charactersCreate a character

Free tools

All character & story toolsCharacter Name GeneratorStory Prompt GeneratorCharacter Archetype QuizOC Profile Card MakerCharacter Relationship MapStory DiceWorldbuilding Prompt BuilderCharacter Backstory Builder

Resources

BlogHelp centerContact

Trust

Privacy controlsAge verificationPrivacy PolicyTerms of ServiceCookie Policy