1. Introduction
This Privacy Policy explains how Veyra (“we,” “us,” “our”), operated from Finland, collects, uses, shares, and protects your personal data when you use the Veyra service (the “Service”).
We understand the Service is deeply personal and that you share sensitive information with your AI companions. We treat that data with a correspondingly high level of care. This policy is written to be clear about exactly what we collect and why.
We are the data controller for the personal data described here. For privacy questions or to exercise your rights, contact us at [email protected].
2. Who Can Use the Service
The Service is strictly for adults (18+). We do not knowingly collect personal data from anyone under 18. If we learn that we have collected data from a minor, we will delete it and terminate the account. See our Content Policy.
3. The Data We Collect
3.1 Data you provide directly
- Account data: email address, username, password (stored hashed), and authentication identifiers (including via third-party sign-in, if used).
- Age-verification data: where verification is required, it is processed by a specialist verification provider (see Section 6). We receive a verification result (e.g., pass/fail, and a confirmation that you are an adult); we do not store your government ID or biometric scan ourselves — these are handled by the provider.
- Payment data: handled by our third-party payment processors. We receive limited billing confirmation data (e.g., transaction and plan-access status, partial card/last-four or a payment token); we do not store full card numbers.
- Companion configuration: the characters you create — names, appearance, personality, backstory, and preferences you set.
3.2 Data generated through your use — including sensitive data
- Chat content: the messages you send to and receive from Companions. This may include sensitive personal data, including content of a sexual or intimate nature.
- Memory data: to make Companions feel consistent and personal, the Service extracts and stores information derived from your conversations (for example, facts you share about yourself, preferences, and relationship context) and uses it to personalize future interactions. This “memory” may include sensitive personal data.
- Generated media: images (and, where offered, other media) generated at your request, and associated metadata.
- Usage data: interactions, features used, plan allowances and token consumption, and preferences.
3.3 Data collected automatically
- Discovery source: when available, the website domain that referred you, the first Veyra page path you visited, and the visit time. We can associate these with a new account to understand which sources lead to signups and use of the Service. This record excludes referring-page paths, URL query strings, and fragments; missing referral information remains unknown.
- Technical data: IP address, device and browser type, operating system, identifiers, and approximate location (derived from IP, used for security, fraud prevention, and enforcing geographic restrictions).
- Cookies and similar technologies: as described in Section 9.
4. Special-Category (Sensitive) Data
Because of the nature of the Service, some data we process — in particular chat content and memory data — may constitute special-category data under the GDPR/UK GDPR (data concerning your sex life or sexual orientation).
We process this data only to provide the Service you have requested, and our lawful basis for doing so is your explicit consent and/or that you have manifestly made the data available in the context of a service you deliberately chose to use, and as necessary to perform our contract with you. You may withdraw consent at any time by ceasing use, deleting content, or closing your account (see Sections 8 and 10).
5. How We Use Your Data and Our Lawful Bases
| Purpose | Data used | Lawful basis (GDPR/UK GDPR) |
|---|---|---|
| Provide and operate the Service (chat, Companions, media) | Account, chat, memory, generated media, usage | Performance of contract; explicit consent (for special-category data) |
| Personalize your Companions (memory, continuity) | Chat, memory data | Performance of contract; explicit consent |
| Process payments and manage plans/tokens | Payment/billing data | Performance of contract; legal obligation |
| Verify you are an adult | Age-verification result | Legal obligation; legitimate interests; consent |
| Safety, moderation, and preventing illegal content (esp. child-safety enforcement) | Chat, media, technical, account | Legal obligation; legitimate interests; substantial public interest |
| Security, fraud prevention, and enforcing geographic/access restrictions | Technical, account, usage | Legitimate interests; legal obligation |
| Improve and develop the Service | Usage data | Legitimate interests (and/or consent where required) |
| Communicate with you (service messages, and marketing where permitted) | Account data | Performance of contract; consent (marketing) |
| Comply with legal obligations and respond to lawful requests | As relevant | Legal obligation |
On AI training: we do not use the content of your private conversations or memories to train or fine-tune AI models.
6. How We Share Your Data
We do not sell your personal data. We share it only as described here, with providers bound by contract to protect it:
- AI processing providers. To generate Companion responses and media, we process your inputs through AI systems. Some processing occurs on our own infrastructure (including our self-hosted models and memory systems), and some is performed by third-party AI providers who process inputs to generate outputs on our behalf. We select providers under data-processing agreements and instruct them to process data only to provide the Service.
- Payment processors. Specialist payment providers process your payments. They handle your payment details under their own privacy policies and applicable standards. We receive only limited confirmation data.
- Age-verification provider. Where age verification is required, it is performed by a specialist provider, which processes the verification data (which may include an image or ID) under its own privacy terms and returns a result to us.
- Infrastructure and operational providers. Hosting, storage, content delivery, analytics, email, and security providers that support the Service, under data-processing agreements.
- Safety and legal disclosures. We may disclose data where necessary to comply with law, respond to lawful requests, enforce our Terms, protect our rights and safety and those of others, and — in particular — to report child sexual abuse material or child-safety threats to NCMEC and/or law enforcement, and preserve related evidence, as required or permitted by law.
- Business transfers. In a merger, acquisition, or asset sale, data may be transferred subject to this policy.
7. International Data Transfers
We are based in Finland (EU). Some providers may process data outside the European Economic Area (e.g., in the United States). Where we transfer personal data internationally, we rely on appropriate safeguards, such as the EU Standard Contractual Clauses (and the UK Addendum/IDTA for UK data), or an adequacy decision where available.
8. Data Retention
We keep personal data only as long as necessary for the purposes described, or as required by law:
- Account, chat, and memory data: retained while your account is active, to provide continuity of your Companions. When you delete specific content or memories, we delete or de-identify them from active systems (backups are overwritten on a rolling basis). When you close your account, we delete or anonymize your personal data within 90 days, except data we must retain for legal, security, or safety reasons.
- Payment records: retained as required by tax and accounting law (typically several years).
- Safety-related records: where we identify prohibited content (especially child-safety matters), we may preserve relevant records as required or permitted by law, even after account deletion.
- Age-verification records: retained per legal requirement and per the provider’s terms; we aim to retain the minimum necessary (e.g., a verification confirmation rather than underlying documents).
9. Cookies and Similar Technologies
We use strictly necessary cookies to operate the Service (e.g., authentication, security) and, with your consent where required, functional and analytics cookies.
Our first-party veyra_acquisition cookie retains the first observed discovery source for up to 30 days across the website and app, including during sign-in. Its expiry is not extended by later visits. The acquisition capture respects browser Global Privacy Control and Do Not Track signals. Once associated with an account, the discovery record follows the account-data retention period described in Section 8.
10. Your Rights
Depending on where you live, you may have rights to:
- Access the personal data we hold about you;
- Rectify inaccurate data;
- Erase your data (“right to be forgotten”);
- Restrict or object to certain processing;
- Data portability;
- Withdraw consent at any time (without affecting prior processing);
- Lodge a complaint with a supervisory authority. In Finland, this is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto); EU/UK users may also contact their local authority (e.g., the UK ICO).
US residents (e.g., California and other states) may have rights to know, delete, correct, and opt out of “sale”/“sharing” of personal information; we do not sell personal data.
To exercise your rights, contact [email protected]. We may need to verify your identity. We respond within the timeframes required by law.
11. How We Protect Your Data
We use technical and organizational measures appropriate to the sensitivity of the data, including encryption in transit (and at rest where appropriate), access controls, and internal policies limiting access to personal data. Given the sensitivity of the Service, we place particular emphasis on safeguarding chat and memory content. However, no system is perfectly secure, and we cannot guarantee absolute security.
12. Children
The Service is for adults only. We do not knowingly process data of anyone under 18. If you believe a minor has used the Service, contact us immediately at [email protected] so we can act. We maintain strict child-safety safeguards as described in our Content Policy.
13. Changes to This Policy
We may update this policy. We will post the updated version with a new “Last updated” date and, for material changes, provide additional notice (e.g., email or in-Service). Your continued use after changes take effect constitutes acceptance where permitted by law.
14. Contact
Privacy enquiries: [email protected]
Your privacy is fundamental to a service this personal. If anything here is unclear, please contact us.