Privacy Policy
Last updated: March 20, 2026
1. Introduction
Sweetz ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you use the Sweetz platform ("Service"). This policy applies to all users worldwide, including those in the European Economic Area (EEA), United Kingdom (UK), and California.
By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Service.
2. Data Controller
Sweetz is the data controller for the personal data processed through the Service. For any privacy-related inquiries, contact us at: privacy@sweetz.ai
3. Information We Collect
3.1 Information You Provide
- Account data: Email address, display name, and password hash when you register
- Profile data: Optional avatar image and display preferences
- Payment data: Billing information processed by Stripe (we do not store credit card numbers)
- Chat data: Messages you send to AI characters and AI responses
- Generated content: Images and videos you generate through the Service
- Characters: Custom characters you create, including descriptions and personality data
- Support communications: Emails and messages you send to our support team
3.2 Information Collected Automatically
- Usage data: Pages visited, features used, session duration, and interaction patterns
- Device data: Browser type, operating system, screen resolution, and device type
- Network data: IP address (anonymized for analytics), approximate geolocation (country/region level)
- Cookies: Essential cookies for authentication and preferences. See our Cookie Policy for details
3.3 Information We Do NOT Collect
- We do not collect real names unless you choose to provide one as a display name
- We do not store credit card numbers (handled entirely by Stripe)
- We do not collect biometric data
- We do not access your device contacts, camera, or microphone beyond voice input you explicitly initiate
4. Legal Basis for Processing (GDPR)
For users in the EEA and UK, we process personal data on the following legal bases:
| Processing Activity | Legal Basis |
|---|---|
| Account creation & authentication | Contract performance |
| Providing the chat & generation features | Contract performance |
| Processing payments | Contract performance |
| Sending service-related emails | Legitimate interest |
| Analytics & service improvement | Legitimate interest |
| Content safety & moderation | Legitimate interest & legal obligation |
| Marketing emails (if opted in) | Consent |
| Cookie tracking (non-essential) | Consent |
5. How We Use Your Data
- Provide the Service: Authenticate your account, process messages, generate AI content, and manage subscriptions
- Improve the Service: Analyze usage patterns to identify bugs, improve features, and optimize performance
- Safety & moderation: Detect and prevent abuse, enforce community guidelines, and comply with legal obligations
- Communications: Send account-related notifications, security alerts, and (with your consent) promotional updates
- Payment processing: Process subscriptions and credit purchases through our payment processor
We do not sell your personal data to third parties. We do not use your conversations or generated content to train AI models.
6. Data Sharing & Third-Party Processors
We share data only with service providers necessary to operate the platform:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Database & authentication | Account data, chat messages, generated content |
| Stripe | Payment processing | Email, billing info (card data stays with Stripe) |
| OpenRouter | AI text generation | Chat messages (without account identifiers) |
| RunPod | AI image/video generation | Generation prompts (without account identifiers) |
| Cloudflare R2 | Content delivery | Generated images and videos |
| Vercel | Hosting & deployment | IP address, request logs |
All third-party processors are contractually bound to process data only as instructed by us and to maintain appropriate security measures. For AI processing, we strip account identifiers — your messages are sent without your email, name, or user ID attached.
We may also disclose data if required by law, court order, or to protect our rights, safety, or the safety of others.
7. International Data Transfers
Your data may be processed in countries outside your own, including the United States. Where we transfer data outside the EEA/UK, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements with all sub-processors
- Encryption in transit and at rest
8. Data Retention
- Account data: Retained while your account is active. Deleted within 30 days of account deletion
- Chat messages: Retained while your account is active. Deleted with your account
- Generated content: Retained while your account is active. Deleted with your account
- Payment records: Retained for 7 years as required by tax and financial regulations
- Server logs: Automatically purged after 90 days
- Analytics data: Aggregated and anonymized — individual records purged after 12 months
9. Data Security
We implement industry-standard security measures to protect your data:
- All data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Passwords are hashed using bcrypt — we never store plaintext passwords
- Database access is restricted and uses row-level security (RLS) policies
- Payment data is handled by PCI DSS-compliant Stripe — card numbers never touch our servers
- Regular security reviews and dependency audits
- Rate limiting and abuse detection to prevent unauthorized access
No system is 100% secure. If we become aware of a data breach affecting your personal data, we will notify you and the relevant supervisory authority as required by applicable law.
10. Your Rights
10.1 Rights for All Users
- Access: Request a copy of the personal data we hold about you
- Deletion: Delete your account and all associated data through the profile settings page or by contacting support
- Correction: Update your profile information at any time through the profile settings
- Opt-out: Unsubscribe from marketing emails at any time
10.2 Additional Rights for EEA/UK Residents (GDPR)
- Data portability: Receive your data in a structured, machine-readable format
- Restriction: Request that we restrict processing of your data in certain circumstances
- Objection: Object to processing based on legitimate interest
- Withdraw consent: Where processing is based on consent, you may withdraw at any time
- Supervisory authority: Lodge a complaint with your local data protection authority
10.3 Additional Rights for California Residents (CCPA/CPRA)
- Right to know: Request disclosure of the categories and specific pieces of personal information collected
- Right to delete: Request deletion of your personal information
- Right to opt-out: We do not sell personal information, so no opt-out is necessary
- Non-discrimination: We will not discriminate against you for exercising your privacy rights
To exercise any of these rights, contact us at privacy@sweetz.ai. We will respond within 30 days (or sooner as required by applicable law).
11. Children's Privacy
The Service is not intended for anyone under 18 years of age. We do not knowingly collect personal data from minors. If we learn that we have collected personal data from a user under 18, we will promptly delete the account and all associated data. If you believe a minor is using our Service, please contact us immediately at privacy@sweetz.ai.
12. Cookies
We use cookies and similar technologies to operate the Service. For full details on the cookies we use and how to manage them, please see our Cookie Policy.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email or in-app notice at least 14 days before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.
14. Contact
For privacy-related questions, data requests, or complaints, contact us at:
- Email: privacy@sweetz.ai
- General support: support@sweetz.ai