Skip to main content
Back to home
Legal

Privacy Policy

Effective date:

Last updated:

Operator and contact details

Operator
VixanaAI
Privacy and support email
admin@vixana.ai
Jurisdiction
US

Scope and operator

This Privacy Policy explains how this deployment of the AI character chat service collects, uses, shares, retains, and deletes information. The "operator" is the person or organization operating this particular instance and identified in the "Operator and contact details" panel on this page. The operator determines which infrastructure and AI providers the instance uses.

This Policy covers the Service itself. A linked or integrated third party handles information under its own privacy terms when it acts independently.

Chats are not public, but are not confidential

Chat conversations are not ordinarily displayed as public conversations to other members. That does not make them confidential, privileged, end-to-end encrypted, or visible only to you. Message text and related prompts are stored in plaintext form available to the application. Authorized personnel can access content as described below, and configured providers process content to run the Service.

Do not enter passwords, payment-card details, government identifiers, trade secrets, another person's confidential information, or other information you cannot accept being stored, processed, or occasionally reviewed.

Information collected

Depending on how the instance is configured and which features you use, the Service may collect and store:

  • account and profile data, such as email address, display name, authentication records, account role, profile image, and account timestamps;
  • your adult-age affirmation and the time it was recorded;
  • session and technical data, including session identifiers, IP address, user agent, device or browser information, timestamps, and security records;
  • website analytics data, when enabled, including page host and path, referring site, country, device type, browser, operating system, navigation type, page views, and page-load or Core Web Vitals timing metrics;
  • messages and AI outputs in plaintext, chat titles and attachments, recent transcripts, and conversation metadata;
  • character profiles, personas, descriptions, greetings, appearance details, custom characters, and related configuration;
  • relationship memory and progress, including summaries, facts, milestones, scores, recent photo descriptions, simulated-life state, and mood or interaction history;
  • text and image prompts, generated images and files, generation settings, outputs, status, and safety decisions;
  • language, theme, display, accessibility, model, and other preferences; and
  • diagnostic, failed-turn, abuse-prevention, and unsafe-prompt records, which may include submitted prompt text and limited user-message or model-output excerpts.

How information is used

The operator uses information to authenticate accounts; provide chats, memory, characters, images, and preferences; personalize and maintain conversation continuity; operate, monitor, secure, and troubleshoot the Service; prevent and investigate abuse; respond to support requests; enforce the Terms; comply with legal obligations; and understand basic Service operation.

Automated systems may analyze prompts and outputs for routing, generation, memory, moderation, image safety, fraud or abuse prevention, and failure handling. An automated result can be wrong and is not a promise that content is safe or lawful.

AI inference and image endpoints

To generate a reply, the Service may send the configured AI inference endpoint your current message, a recent transcript, character and persona instructions, stored memory or relationship context, safety instructions, and relevant technical parameters. To plan or generate an image, relevant transcript, persona, memory, scene information, and image prompts may be sent to configured AI inference and image-generation endpoints.

Those endpoints may be operated by the operator or by outside providers. A provider may log or retain requests and outputs under its own agreement, settings, and privacy policy. Whether a provider uses requests or outputs to improve or train models depends on that provider's agreement and settings; the operator does not promise that outside-provider processing is training-free. The operator cannot promise that provider-held copies follow the Service's own deletion timing.

Other providers and disclosures

Depending on instance configuration, optional authentication, email delivery, hosting, database, object-storage, network, or cache providers may process account, session, communication, technical, or stored-content data as needed to perform their services.

The operator may also disclose information when reasonably necessary to comply with applicable law or a valid legal process; protect the Service, users, or others; investigate fraud, abuse, or security incidents; or complete a reorganization or transfer of the operated instance, subject to applicable law.

The Service does not use third-party advertising services. When configured in production, the Service uses Cloudflare Web Analytics to measure page views, navigation, and website performance. The browser loads Cloudflare's analytics beacon and sends the analytics data described above to Cloudflare. Cloudflare states that Web Analytics uses no cookies or local storage to collect usage metrics and does not track individual visitors across its customers' sites. Cloudflare processes this data under its applicable terms and privacy policy.

Occasional staff and administrator review

Authorized staff or administrators may occasionally review prompts, chat content, and AI outputs when needed for diagnostics, support, safety, abuse prevention, or security. Administrators can also review generated-image prompts, safety decisions, and generated outputs. Failed-turn records may make limited user-message and model-output excerpts available in administrative tools, while unsafe-prompt records may preserve the submitted prompt.

This access is not a promise that a person reviews every prompt, conversation, output, report, or safety issue. Most items may receive no human review, and the absence of review does not mean the operator approves, verifies, or guarantees content. Access should be limited to authorized purposes, but you should not treat the Service as a confidential communications channel.

Retention and deletion details

Successful chats, messages, characters, relationship memory and progress, preferences, and generated-image records generally have no automatic deletion period (no TTL). They may remain until you delete eligible data, delete your account, or the operator deletes them. This describes current application behavior, not a guarantee that any data will persist.

  • Using the bulk "Delete chats and progress" control removes chat and relationship records while preserving and detaching generated-image records, prompts, and stored files. Deleting one chat generally deletes its associated generated images when they are not shared or reused elsewhere; an image referenced elsewhere may remain.
  • Failed-turn diagnostic records are trimmed to approximately the newest 500 records across the instance. A failure record can survive deletion of the related chat, but deleting the linked account removes linked failure records.
  • Unsafe or blocked image-prompt records may retain the submitted prompt and safety decision until the linked account is deleted or the operator deletes the record. Account deletion removes linked safety records.
  • Outside providers may retain requests, outputs, logs, caches, or backups according to their own settings, contracts, and policies.
  • Deletion can be delayed by active processing, retry queues, caches, backups, storage cleanup, fraud or security needs, legal obligations, and technical failures. Some information may be kept when and only as long as law permits or requires.

No data-persistence promise

Retention descriptions are not warranties. The operator does not promise that an account, chat, message, history, character, memory, relationship progress, prompt, image, file, preference, log, backup, or any other data will be stored, synchronized, remembered, recoverable, exportable, or available for any period. Data can be lost, changed, corrupted, deleted, or become unavailable. Keep an independent copy of anything important.

Limited reuse of eligible character images

To reduce unnecessary generation, an eligible character image created automatically at an AI character's direction may be selected from the image archive and shown in another member's conversation when it closely matches a requested scene. Reuse observes the requested explicitness: an explicit image is eligible only for an explicit request, and a non-explicit image only for a non-explicit request. Cross-user reuse does not include images created from a member's direct /image command or studio prompt, and it does not share the originating member's account identity with the recipient.

Selection may use the image's scene description and character or generation attributes. The same underlying character image file may therefore appear in more than one member's chat even though the chats themselves are not public. A reused image may later become unavailable if its source record or stored file is deleted.

Security

The operator may use access controls, authentication, transport encryption, logging, provider safeguards, and other administrative or technical measures appropriate to the instance. No measure, database, transmission, model provider, or storage system is perfectly secure. The operator does not guarantee that information will never be accessed, disclosed, altered, lost, or destroyed.

Protect your credentials, use a unique password when password login is available, sign out of shared devices, and notify the operator at the privacy and support email displayed in the "Operator and contact details" panel on this page if you suspect unauthorized account access.

Your choices and rights

Available settings may let you update profile data and preferences, delete a chat or relationship progress, or permanently delete your account. Review the retention section before deleting a chat because image prompts and files may remain. Account deletion is intended to remove data linked to the account from the Service's active systems, subject to queued storage cleanup, technical limits, provider-held copies, and retention that applicable law permits or requires.

Depending on where you live, law may give you rights to request access, correction, deletion, portability, restriction, or objection, or to appeal or complain to a data-protection authority. These rights can have exceptions and may require identity verification. Exercise available self-service controls or contact the operator at the privacy and support email displayed in the "Operator and contact details" panel on this page. Nothing in this Policy waives a right that cannot lawfully be waived.

Adults only

The Service is intended only for people who are at least 18 and at least the age of legal majority where they live. It is not directed to children or minors. If the operator learns that an ineligible minor has provided personal information, the operator may delete the account and associated information, subject to applicable law and technical limits.

Policy updates

The operator may update this Policy to reflect changes to the Service, providers, practices, or legal requirements. The last-updated date will identify the current version. When required by law, the operator will provide additional notice or request consent. Continued use after an update takes effect is subject to the updated Policy to the extent permitted by law.

Privacy Policy · Vixana