Privacy
Last updated (draft): 28 September 2026 (Asia/Hong_Kong).
Sweetling — Privacy Policy
Status: Publish-ready draft for Shipwright (/privacy). Not legal advice. Lawyer review recommended before relying on as binding. Entity registration details pending.
Brand: Sweetling · Site: https://sweetling.app Last updated (draft): 28 September 2026 (Asia/Hong_Kong)
Related: Terms of Service. Hard blocks and age gate align with Trust Ops DRAFTS_v1.md.
This policy is written in plain language with a Hong Kong Personal Data (Privacy) Ordinance (PDPO) mindset: purpose, transparency, retention at a high level, access and correction, and a clear contact. It is not a formal legal opinion.
1. Who we are
Sweetling (“Sweetling,” “we,” “us,” or “our”) is the brand operating sweetling.app — an invite-only adult (18+) romantic AI companion web app.
Formal legal-entity registration name, number, and address will be inserted before publish if counsel requires; this draft does not invent them.
Contact for privacy and support: support@sweetling.app (same inbox for support and legal for now).
2. Scope — what this policy covers
This Privacy Policy explains how we collect, use, share, retain, and protect personal data when you:
- Visit sweetling.app or related pages;
- Create or use an account, pass the age gate, or use companions, memory, media, or billing features;
- Contact us at support@sweetling.app.
It should be read together with our Terms of Service. Capitalized terms used here but not defined have the meanings in the Terms where relevant.
If you do not agree with this policy, do not use the Service.
3. What we collect
We collect personal data needed to run Sweetling. Categories include:
3.1 Account and authentication
Email, account identifiers, and auth-related data processed via our authentication provider (Supabase). Password hashes or magic-link / session tokens as applicable — we do not see your password in clear text when using standard auth flows.
3.2 Age-gate verification signals
Signals that you passed (or failed) the 18+ age gate — for example a verified-adult flag, and possibly date of birth or other affirmation if the product collects it. Exact retention of raw date of birth vs. a boolean “verified 18+” may be refined with counsel; we avoid putting raw DOB into analytics where we can.
3.3 Profile and preferences
Display name or nickname, companion settings, adult-mode opt-in status, persona / version pins, and similar preferences you set.
3.4 Chat messages and companion outputs
Messages you send and replies generated for you. Adult romantic or sexual content may be processed when you opt into adult mode; hard blocks for minors and other prohibited categories still apply (see Terms §5).
3.5 Memory / ledger
Canonical facts, pins, episode summaries, and related continuity data you can typically view, edit, pin, forget, or export in-product.
3.6 Companion version and persona pins
Persona identifiers, prompt / version hashes, model routing choices, and pin / rollback state used for continuity.
3.7 Usage and quotas
Message counts, quota consumption, feature flags, and similar metering so free caps and paid entitlements work fairly.
3.8 Payments and billing
When payments are live, billing is handled by Stripe (or a similar processor). We may receive subscription status, customer identifiers, invoice/receipt metadata, and last-four / card brand style details Stripe provides. We do not store full card numbers on our own systems.
3.9 Support communications
Emails and messages you send to support@sweetling.app (and our replies), including attachments you choose to send.
3.10 Device, log, and technical data
IP address, user agent / device type, approximate location derived from IP, timestamps, request logs, error logs, and security events. We keep safety and moderation logs for hard-block hits and related enforcement (see Terms and our What we refuse policy).
3.11 Optional media (when paid / live)
If image, voice, or other relationship media is enabled on a paid plan, we process the media files and related metadata needed to generate, store, and show them in-thread.
3.12 What we do not intentionally collect
We do not intentionally collect data from anyone under 18. We do not run invent-third-party advertising trackers in this draft’s baseline; see Cookies below.
4. How we use data
We use personal data to:
- Provide the Service — authenticate you, run companions, apply quotas, and show your chats and settings.
- Memory continuity — store and retrieve ledger facts, pins, and episode summaries so the companion can feel continuous under your control.
- Safety and hard blocks — detect, refuse, log, and review prohibited content (especially anything involving minors); escalate and cooperate with authorities where required by law.
- Billing — process subscriptions, show invoices, prevent fraud, and handle cancellations / goodwill refunds when payments are live.
- Support — answer tickets, fix bugs, and restore pins / exports when something breaks.
- Improve the Service carefully — understand reliability, abuse patterns, and product quality. We do not sell your personal chats as a product. Model providers may process prompts/outputs to generate replies under their terms; we aim not to use your private chats for unrelated advertising.
- Legal compliance — meet applicable law, respond to lawful requests, and enforce our Terms.
Adult content may be processed when you opt in; that does not weaken minor protection or CSAM refusal.
5. Why we process data (plain-language bases)
Hong Kong PDPO focuses on purpose and fairness rather than EU-style “legal bases,” but we state our justifications plainly for transparency (including for users elsewhere):
| Purpose | Plain justification |
|---|---|
| Running your account, chat, memory, pins, quotas | Needed to perform the contract / provide the Service you asked for |
| Age gate and 18+ enforcement | Protect minors; comply with our Terms and safety obligations |
| Hard-block / security / fraud logs | Legitimate interests in safety and security; legal obligations where applicable |
| Billing via Stripe | Contract / payment processing |
| Adult-mode processing | Your opt-in / consent-style choice plus contract to provide the feature |
| Support email | Responding to your request |
| Marketing email | Not default. Only if we later ask and you consent (or another lawful basis); you can opt out |
| Legal holds / mandatory reporting | Legal obligation where it applies |
6. Sharing and processors
We share personal data with service providers who process it on our instructions or as independent controllers where their product requires it:
| Category | Examples (high level) | Role |
|---|---|---|
| Auth + database | Supabase | Account, profiles, chats, memory, quotas |
| Payments | Stripe (when live) | Subscriptions and payment data |
| Hosting | Our hosting provider (Vercel-class or equivalent) | Serve the app and related infrastructure |
| AI / models | xAI and other model API providers | Generate companion replies and related features |
| Email routing for support@sweetling.app | Support and transactional mail |
We may also disclose data if required by law, to protect minors or someone’s safety, to enforce our Terms, or in a merger / acquisition with notice where required.
International transfers. Providers may process data outside Hong Kong (for example in the United States or other regions). By using the Service you understand that data may leave Hong Kong to reach those providers. We aim to use reputable providers and appropriate contractual or practical safeguards; counsel may add transfer wording before publish if needed.
We do not sell your personal data.
7. Retention
High-level practices (exact periods may be refined with counsel and ops):
- Account life — Account and profile data while your account is active.
- Chats and memory — Kept while the account is active so continuity works; you can edit, forget, export, or request deletion.
- After deletion / export requests — We aim to delete or anonymize personal data within a reasonable period (target: measured in days for routine requests), except where backups, legal holds, dispute, or safety/audit needs require longer.
- Safety / hard-block logs — May be retained longer than ordinary chat history when needed for minor protection, abuse investigation, or legal compliance.
- Billing records — Kept as needed for accounting, tax, chargebacks, and legal requirements (via Stripe and our records).
- Support emails — Kept as needed to resolve your request and for a reasonable follow-up period.
When we no longer need data for these purposes, we delete or anonymize it where practicable.
8. Your rights
Subject to applicable law (including the Hong Kong PDPO), you may:
- Access — Ask what personal data we hold about you.
- Correction — Ask us to correct inaccurate data.
- Deletion / erasure — Request deletion of your account or certain data, subject to legal and safety retention.
- Export / portability — Use in-product export where available, or ask support for a copy of key data we can reasonably provide.
- Withdraw consent — Where processing relies on consent (for example adult mode or any future marketing), you may withdraw; that does not undo prior lawful processing.
- Object / complain — Contact us first at support@sweetling.app. You may also contact the Hong Kong Privacy Commissioner for Personal Data (PCPD) about PDPO concerns. Users in other regions may have additional rights under local law (for example GDPR or CCPA/CPRA); we will consider those requests in good faith where they apply.
To exercise rights, email support@sweetling.app from your account email when possible, and describe what you need. We may need to verify your identity before acting.
9. Cookies, local storage, and analytics
Essential. We use cookies and/or local storage as needed for authentication, sessions, security, and basic app function (for example keeping you signed in and remembering age-gate / preference flags).
Analytics and ads. This draft does not invent third-party advertising trackers. If we add product analytics (for example privacy-respecting usage metrics), we will update this policy and, where required, obtain consent or provide controls.
Do Not Track. There is no single industry standard for DNT signals; we will describe any future analytics controls here when added.
10. Children — 18+ only
Sweetling is not for anyone under 18 (or under the age of majority where you live, if higher). We do not knowingly collect personal data from children. If we learn that an account belongs to a minor, we will disable it and delete or restrict associated personal data as appropriate, subject to safety and legal obligations. See also Terms §2 and hard blocks in Terms §5.
11. Security
We use reasonable technical and organizational measures appropriate to the nature of the Service (access controls, encrypted transit where standard, provider security features, least-privilege practices, and safety logging). No method of transmission or storage is 100% secure. You are responsible for protecting your account credentials.
If we become aware of a personal-data security incident that requires notice under applicable law, we will notify you and/or regulators as required.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on sweetling.app and revise the “Last updated” date. For material changes, we will provide additional notice (for example email or in-app) where required by law or appropriate for the change.
Continued use after the effective date means you acknowledge the updated policy, except where mandatory law requires a different consent method.
13. Contact
Privacy and support: support@sweetling.app Website: https://sweetling.app Terms: Terms of Service
14. Governing approach
We design this policy around Hong Kong expectations (PDPO: purpose, transparency, retention, access/correction, and accountable contact). Other regions’ rights may also apply to you (for example EU/UK GDPR or US state privacy laws). Nothing here is intended to waive non-waivable rights. If counsel later adds region-specific addenda, they will be linked from this page.
Entity registration details remain to be inserted before publish if counsel requires.
End of Privacy Policy — publish-ready draft for Shipwright. Not lawyer-approved. Entity registration details pending. Not for production reliance until counsel sign-off.