Last updated: August 8, 2026. This document is subject to revision as our service evolves. Material changes will be communicated to active users. Questions: [email protected].
Privacy Policy
Operator: MEMORIS Global AI Studio · Operating in Slovenia / European Union · Corporate structure under finalization
1. Who We Are
TRUENECT is operated by MEMORIS Global AI Studio (the "Controller"). We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Slovenian Data Protection Act (ZVOP-2).
Contact for privacy matters: [email protected]
A Data Protection Officer is not required under GDPR Article 37, as our processing does not involve large-scale systematic monitoring or large-scale special-category data.
2. What Data We Collect
We collect only data necessary to operate TRUENECT:
- Account data: email, hashed password
- Profile data: display name, gender preferences, intent tags (from onboarding)
- Age confirmation: your date of birth if you gave one at registration, and a record of the moment you confirmed you are 18 or older, the date and time, the IP address the confirmation came from, and the version of the wording you agreed to. Legal basis: legal obligation and our legitimate interest in operating an adult service and being able to show that the confirmation was given. Retained for as long as the account exists, and deleted with it.
- Usage data: messages you send, photos you attach to chat, voice recordings (if you use voice features), conversation history
- Camera frames (video calls, optional): if you turn your camera on during a video call, individual frames are processed transiently so your persona can respond to what it sees. Raw camera frames are never stored: not on our servers and not in our database. See section 9.
- Payment data: handled exclusively by Stripe, we never store credit card details
- Technical data: IP address, browser, device type
We do NOT collect: real name (unless you provide), location, contacts, biometrics, health data, or political/religious beliefs.
3. Legal Bases for Processing
Under GDPR Article 6, we process data based on:
- Contractual necessity (Art. 6(1)(b)): to provide the service you signed up for
- Legitimate interest (Art. 6(1)(f)): security, fraud prevention, service improvement
- Consent (Art. 6(1)(a)): marketing emails, voice features
- Legal obligation (Art. 6(1)(c)): tax records (7 years for Stripe)
4. How We Use Your Data
- Provide AI persona conversations and platform features
- Generate personalized responses via the Claude API (Anthropic)
- Process subscription payments (Stripe)
- Detect and prevent abuse, fraud, and security incidents
- Send service-related emails (e.g., password reset, billing receipts)
- Improve the service through anonymized usage analytics
5. Third-Party Processors
We share specific data with these processors under signed Data Processing Agreements (DPAs):
- Anthropic (USA): Claude API for AI response generation. Conversations sent for processing only, not retained for training under their policy.
- Hetzner Cloud (Germany, EU): hosting and primary database storage
- Stripe (USA): payment processing
- Resend (USA): transactional email delivery
- ElevenLabs (USA): voice synthesis (optional, only if you use voice features)
- Cloudflare (USA): DNS and DDoS protection
- xAI (USA): image and video generation, when you ask a persona for a photo or video. The text of your request and the persona's reference image are sent; your conversations are not.
- Groq (USA): speech-to-text transcription of voice messages and call audio
- Akool (USA): real-time video avatar rendering during video calls
- Microsoft (USA): neural text-to-speech for the on-site assistant and creator interview voice (text of the spoken lines only)
Transfers to non-EU processors rely on EU Standard Contractual Clauses (SCCs) under GDPR Article 46.
6. Data Retention
- Active accounts: data retained while your account exists
- Deleted accounts: 30-day grace period, then permanent purge
- System logs: 90 days
- Billing records: 7 years (Stripe legal requirement)
- Anonymized analytics: indefinitely
7. Your Rights Under GDPR
You have the right to:
- Access: request a copy of your data (Article 15)
- Rectification: correct inaccurate data (Article 16)
- Erasure: delete your account and data (Article 17)
- Portability: export your data in machine-readable JSON (Article 20)
- Restriction: limit processing (Article 18)
- Objection: opt out of certain processing (Article 21)
- Withdraw consent: at any time for consent-based processing
- File a complaint: with the Slovenian Information Commissioner (ip-rs.si)
You can exercise the two most important rights yourself, instantly, without writing to anyone: Settings → Export my data downloads everything we hold about you as JSON (Article 20), and Settings → Delete account permanently erases your account, every conversation, and all three memory layers your personas keep about you (Article 17). For everything else, email [email protected] from your account email. We respond within 30 days.
8. Cookies
We use minimal cookies:
- Essential cookies: session, login (required for service)
- Functional cookies: user preferences (with your consent)
- NO tracking cookies: we do not profile users for advertising
- NO third-party advertising cookies
9. AI Training & Camera Disclosure
We do NOT use your conversations to train AI models. Your messages are sent to the Claude API (Anthropic) for response generation only. Anthropic does not retain conversations for training under their data usage policy.
Camera processing during video calls. Your camera is off by default and only ever activates when you turn it on. While it is on, a small frame is captured every few seconds and sent, together with your spoken words, to our AI provider so the persona can react to what it sees in the moment. Frames exist only for the duration of that single response: we never write camera frames to disk or to our database, they are not used for training, and they are not shared with any processor other than the one generating the reply. Photos you deliberately attach to a chat message are different, those are stored as part of your conversation, and are deleted with it.
10. Data Breach Notification
In the event of a data breach, we notify the Slovenian Information Commissioner within 72 hours of discovery, as required by GDPR Article 33. Affected users will be notified when the breach is likely to result in a high risk to their rights and freedoms.
11. International Data Transfers
Primary data storage is in Germany (EU). Some processors (Anthropic, Stripe, Resend, ElevenLabs, Cloudflare, xAI, Groq, Akool, Microsoft) operate in the United States and process data under EU Standard Contractual Clauses (SCCs) under GDPR Article 46.
12. Children's Privacy
TRUENECT is intended for users 18 years and older. Access requires an explicit, recorded confirmation of adulthood (see section 2). We do not knowingly collect data from minors. If we discover an account belongs to a minor, we delete it immediately. Parents may contact [email protected] with concerns.
13. Marketing Communications
Marketing emails are opt-in only at signup. Every email contains an unsubscribe link. We do not share your data with third-party marketers.
14. Changes to This Policy
We may update this Privacy Policy as our service evolves. The "Last updated" date at the top reflects the most recent revision. Material changes will be notified to active users via email at least 14 days before taking effect.
15. Contact
Privacy questions: [email protected]
General inquiries: [email protected]
Slovenian regulator: ip-rs.si