Application Privacy Policy
Last updated September 13, 2026Version 17
1. Introduction
MYTH ("we," "us," "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your information when you use our application ("the App"). By using the App, you consent to the practices described in this policy.
2. Information You Provide
Account Information:
When you create an account, we collect your email address, username, and password (handled by Clerk). You may optionally provide your name, phone number, profile picture, gender, birthday, timezone, language, bio, and address.
Profile Information:
You may choose to provide a nickname, bio, profile picture, gender, birthday, and other biographical details.
Onboarding Preferences:
During signup, we collect your chosen theme/persona (dark-fantasy, anime-manga, lonely-escapist, creative, custom) and optionally a sub-genre preference.
Character Creation — Backstory & Personality:
When you create a character, you may provide a Backstory (the environment/situation where a chat starts), system prompt, greeting message, description, tags, and 10 personality trait sliders (humor, warmth, aggression, intelligence, flirtiness, mystery, energy, empathy, confidence, creativity). Backstory and personality are stored on the character record and shown as context to anyone who chats with the character. See also §23 for retention and §24 for AI-assisted generation.
AI-Assistance Prompts:
If you use the optional Star (☆) or LET AI FILL assistance during character creation, we collect the short prompt you type plus the minimal character context needed to generate a draft (name, type, description, and — for Backstory/Personality — the system prompt, greeting, and Backstory you have already provided). This prompt and context are sent to our AI provider to generate the draft and are not stored unless you accept the draft.
Communication Content:
All messages you send to AI characters, including text, images, and voice recordings. This includes direct messages with other users, group chat messages, character interactions, and messages sent to the MYTH Assistant (app-management AI).
Referral Program — Codes, Claims, Appeals & Bonuses:
Each account has a personal 6-character referral code (AB12CD, unique, no expiry) stored as users.refer_code / refer_codes. When you claim another user's code (Settings → Refer → Enter refer code) we record the claim (refer_claims) with the code, owner, IP, timestamp, deviceDetails, networkInfo (including push_token), displayInfo, accountInfo/createdAt, suspicious flag, credits granted (25 or 250), and expiryAt (+30d). Credits are stored as users.refer_credits / refer_credits_used / refer_credits_expiry (30-day window, consumed first before your 75/day free quota). If flagged suspicious you may file an appeal (refer_appeals: claimId, reason optional, status pending/approved/rejected) — see Privacy §25. Bonus leaderboard credits (weekly top +100, 3-in-7d streak +50) are also stored as refer_credits with the same expiry. Admins may disable a user's referral code (users.refer_disabled). Referral credits have no cash value.
Voice Calls:
Live voice calls with AI characters (including what you say and what the character says) are processed in real time by a third-party voice-agent service. MYTH does not store voice call audio or call transcripts.
3. Information We Collect Automatically
Usage Data:
Message counts, chat frequency, characters interacted with, features used, interactions liked or rated, badges earned, activity patterns, voice call history (which character you called, when, and for how long), ads watched and bonus tiers claimed (`ads_watched_today`, `messages_sent_today` / `call_seconds_used_today` counters), announcements read (`read_announcements`), and whether a free-mode entitlement is active.
Device & Network Information for Referral Fraud Prevention:
When you claim a referral code we collect your IP address (terms_ip_address / claim IP), device details (terms_device_details / deviceDetails), networkInfo (including push_token), displayInfo, and account creation time for both the claimant and the code owner when an IP match requires an AI same-person check. See §25 for AI processing.
Device Information:
Push notification tokens (Expo push token), device type, app version.
AI-Generated Inferences:
We automatically analyze your conversations to infer psychological traits (Big Five personality traits, attachment style, communication style, conflict style, humor style, decision-making patterns, stress responses, love language), emotional states (mood, stress, trust, embarrassment, energy, excitement, jealousy, affection), interests, fears, values, desires, strengths, insecurities, recurring life themes, linguistic markers, and emotional triggers. These inferences are generated by AI and stored in your profile.
Free Modes & Announcements:
Admin-configurable free modes (Free Message, Free Call, Everything Free) and free-period flags affect only your entitlement to send messages or place calls — they do not add new personal-data collection. Announcements are admin-authored in-app messages; dismissing one stores its ID in `read_announcements` so we do not show it again.
Referral & Profile Notices:
Referral claims, suspicious flags, credits/expiry/debt, and bonus leaderboard state are usage data retained per §25. Profile notices (app_settings profile_notice_mode / profile_notice_custom_text / profile_notice_level — Off/default/Custom with GOOD/MEDIUM/LOW/CRITICAL and a shaking icon on CRITICAL) are admin-configured operational messages shown below follower counts on your profile and as a shaking app-bar icon on discover when CRITICAL; they do not collect personal data from you.
4. How We Use Your Information
To Provide AI Character Interactions:
Your messages, character context (including Backstory, system prompt, greeting, description, tags, personality traits), memories, psychological profile, mood state, relationship meter, and world context are sent to our AI provider to generate character responses.
To Provide AI-Assisted Character Creation:
If you use Star (☆) or LET AI FILL, your assistance prompt plus minimal character context is sent to our AI provider to generate a draft system prompt, greeting, Backstory, or personality trait values. Drafts are shown for review and not saved until you accept. See §24 for details.
To Provide AI App Management (MYTH Assistant):
Your messages to the MYTH Assistant are processed by our AI provider to answer questions, manage characters, update settings, and provide app guidance. The assistant may create, modify, or delete characters on your behalf based on your instructions.
To Personalize Your Experience:
Your interests, favorite categories, liked/blocked tags, and learned preferences are used to personalize your discover feed and character recommendations.
To Improve Our Service:
Aggregated usage patterns, satisfaction ratings, and support tickets help us improve the App.
To Ensure Safety:
Content moderation, abuse detection, report processing, and account warnings/ban enforcement.
For Referral Fraud Prevention, Credits & Appeals:
To operate the Referral Program and prevent self-referral abuse we use your claim IP, device/network details, and limited account details (email, name, device_details, networkInfo/push_token, displayInfo, createdAt for both accounts when an IP match triggers review) to decide suspiciousness via an AI same-person check (Gemini Flash via proxy; confidence >0.7 → suspicious). Credits (25 suspicious / 250 normal / 400 on successful appeal; -25 debt on rejected appeal; leaderboard bonuses weekly top +100 / 3-in-7d +50) are credited with 30-day expiry and consumed refer-first before daily free quota. Appeals are reviewed by admins. See §25 for retention and sharing.
For Profile Notices:
To show operational status we read admin-configured profile notice settings (mode/text/level) and render the notice + level color/animation. No personal data is collected for this.
To Communicate With You:
Push notifications (including admin announcements via Expo Push Service), in-app announcement banners, updates, and email communications (if enabled). You can dismiss individual announcements; we remember dismissed IDs to avoid re-showing them.
5. Data We Share With Third Parties
AI Service Providers:
Your messages (text and images), character system prompts (including Backstory and greeting), AI memories, mood data, relationship data, psychological profile, emotional anchors, world events, secrets known to characters, character relationships, goals, dreams, and schedule context are sent to our AI provider (Gemini 3 Flash via a proxy service) to generate responses. Text payloads routed to external AI model providers are structurally decoupled from account identity — providers receive anonymous text strings (plus character context needed for the reply), never a named user profile, age, or account identifier. If a minor ever chats about mature content, the third-party provider sees only anonymous text, not a minor's profile. When you use Star / LET AI FILL assistance, your assistance prompt plus minimal character context (name, type, description, and — for Backstory/Personality — the system prompt, greeting, and Backstory) is also sent to the same AI provider to generate the draft. MYTH Assistant messages are sent to the same AI provider for app-management assistance.
Voice Transcription:
Voice recordings are sent to Groq (Whisper) for speech-to-text processing.
Live Voice Calls:
Your live voice call audio is processed by Vapi, our voice-agent provider, and character speech is synthesized by ElevenLabs. Vapi generates and holds call transcripts on its own platform per its privacy policy; MYTH does not store voice call audio or call transcripts.
Authentication:
Your authentication data (email, password, OAuth tokens) is processed by Clerk. If you use Google OAuth, your name, email, and profile picture are shared with Clerk and stored in our system.
Push Notifications & Announcements:
Your push token and notification/announcement content are sent to Expo Push Service to deliver chat notifications, nudges, and admin announcements.
Advertising:
Rewarded and banner ads, when enabled by admin, are counted locally (`ads_watched_today`) against the daily limit (`ads_daily_limit`); no third-party ad SDK currently tracks you for behavioral advertising. If we integrate a third-party ad network in the future, we will update this section and disclose it.
Referral Fraud AI Check:
When a referral IP matches the code owner's IP we send limited details of both accounts (email, name, device_details, networkInfo/push_token, displayInfo, accountInfo/createdAt) to our AI provider (Gemini Flash via proxy) with the prompt "Are these two accounts the same person — self-refer? ..." to return {same, confidence 0–1}. If confidence >0.7 the claim is marked suspicious (25 credits + appeal option). This is the only referral data sent to an AI provider; all other referral data stays in Convex.
Infrastructure:
All data is stored with Convex, our database and backend provider.
6. Data Retention & Schedule
We retain different data types for different periods:
• Chat messages, MYTH Assistant conversations, psychological profiles, AI memories: retained until account deletion
• Characters you create (including Backstory, system prompt, greeting, description, tags, personality traits, voice settings): retained until character deletion or account deletion
• AI-assistance prompts: not stored unless you accept the generated draft (then stored as part of the character as above); discarded drafts are not retained
• Voice recordings: deleted immediately after transcription
• Voice call metadata (character, date, duration): retained until account deletion
• Voice call audio and transcripts: not stored by MYTH; call records held by Vapi are subject to Vapi's data retention policy
• Referral data (refer_codes, refer_claims, refer_appeals, users.refer_credits/refer_credits_used/refer_credits_expiry/refer_debt/pending_refer_appeal/refer_disabled): refer_claims retained until account deletion (expiryAt marks credit expiry 30d after grant, not deletion); refer_appeals retained until account deletion; refer_credits expire 30d after grant then only 75/day remains; rejected-appeal debt (-25) carries to the next day's total if you have <25 remaining; bonus leaderboard credits follow same 30-day expiry
• Profile notice settings (app_settings profile_notice_mode/custom_text/level): admin-configured operational data, not per-user personal data
• Ads/announcement state (`ads_watched_today`, `read_announcements`, quota counters): retained until account deletion or daily reset (counters reset every 24 hours)
• IP addresses and device fingerprints collected at acceptance: retained until account deletion
• Support tickets: retained indefinitely
If you delete your account, your data is deleted immediately.
7. Your Rights
You have the right to:
• Access your personal data through your profile settings
• Correct inaccurate data through edit features (including Backstory, personality, and other character fields)
• Delete your account and associated data via Settings (or delete individual characters you created)
• Export your data via the Data & Storage settings
• Opt out of push notifications and announcement pushes in device settings
• Disable AI memory features per character
• Request deletion of a minor's account as a parent or guardian (see §30 — dual-consent parental deletion)
To exercise these rights, use the in-app settings or contact us through the support system.
8. Psychological Profiling Disclosure
The App uses AI to analyze your conversations and create a psychological profile, including personality traits, attachment style, love language, emotional patterns, fears, desires, insecurities, and behavioral triggers. This profiling is a core feature of the App — it enables characters to respond in a personalized, emotionally aware manner. This data is not used for advertising, credit decisions, employment screening, educational placement, or insurance underwriting. It is not sold to third parties. You may disable this feature by not using AI characters, but it cannot be individually disabled while maintaining core functionality.
Your Consent: By using the App, you provide explicit consent to this processing of potentially sensitive personal data. You may request review or deletion of your psychological profile independently of account deletion by contacting our support team.
9. Children's Privacy
The App is not intended for users under 18, and signup requires a typed birth year plus an explicit over-18 affirmation under penalty of perjury. We do not knowingly collect or maintain data from individuals under 18. GOOD FAITH PURGE: if we discover that an account belongs to a minor — on our own, or through a verified parental request — we invoke an automatic, permanent server purge that completely deletes all chat records, characters, psychological profiles, memories, and device logs for that account within 24 hours, and the account is banned. Parents can start this at myth-app.cv/parental-control: after email verification, the in-app user must explicitly AGREE (20-second review lock) or DENY (fake reports are blocked and flagged) — see §30. If you believe a minor is using the App, contact us or use parental control.
10. Data Security
We implement industry-standard security measures including encryption in transit (TLS) and at rest. Authentication is handled by Clerk, a SOC 2-compliant provider. However, while message text is encrypted at rest (AES-256-GCM) so a database breach alone cannot reveal it, it is not end-to-end encrypted and we may access messages as described in our Terms of Service. No system is completely secure. We cannot guarantee absolute security of your data. You are responsible for maintaining the security of your account credentials.
11. International Data Transfers
Your data may be processed and stored in any country where our service providers operate. By using the App, you consent to the transfer of your data to countries that may have different data protection laws than your country of residence.
12. Cookies & Tracking
The App does not use cookies or third-party tracking for advertising. We use essential authentication tokens (provided by Clerk) for session management. No analytics SDKs (Firebase Analytics, Amplitude, Mixpanel, etc.) are integrated. We do not engage in behavioral advertising or sell your data to advertisers.
Advertising in the App. When enabled by admin settings, the App may show rewarded video ads (watch to earn bonus messages or call time) and banner ads. Ad eligibility and daily limits (`ads_enabled`, `ads_daily_limit`) are managed server-side and counted locally (`ads_watched_today`); watching an ad increments the counter and grants the advertised bonus. Ads are not personalized with your personal data and no third-party ad SDK currently tracks you. If we integrate a third-party ad network, we will update this disclosure.
13. Automated Profiling Disclosure
The App uses fully automated AI to create psychological profiles (Big Five traits, attachment style, emotional patterns, fears, desires, triggers). These automated decisions are integral to how characters respond to you. This profiling cannot be disabled while using the App. This data is not used for advertising, credit decisions, employment, or insurance.
14. AI Training Disclosure
We use third-party AI providers to generate character responses. These providers may use data for model training. You may object to this processing by contacting our support team. We will review your objection and, where technically feasible, take reasonable steps to accommodate it. If we cannot honor your objection due to provider limitations, we will inform you of the reasons and your sole remedy is to discontinue use of the App.
15. Data Upon Acceptance
When you accept our Terms of Service, we record IP address, device model, operating system, screen resolution, user-agent string, and timestamp as evidence of consent. This data is stored server-side (not in localStorage) and retained until account deletion. Only the specific fields listed above are collected.
16. CCPA Notice (California Residents)
California residents: We do not sell your personal information. You have the right to request disclosure of categories of data collected and request deletion. To exercise these rights, contact us through the in-app support system. We will respond within the timeframe required by law.
17. Governing Law
This Privacy Policy is governed by the laws of India. Any disputes shall be subject to the exclusive jurisdiction of the courts in Aligarh, Uttar Pradesh.
18. Message Monitoring Disclosure
Message text is encrypted at rest (AES-256-GCM) so a database breach alone cannot reveal it, but it is not end-to-end encrypted. We use purely programmatic, automated systems strictly limited to security orchestration, threat mitigation, and legal compliance automated audits to decrypt and review content. Manual review occurs only for reported violations or valid legal demands. You have no expectation of privacy from the platform in communications made through the App, as technical access is required for AI features to function, but human access is minimal and logged.
19. Changes to This Policy
We may update this Privacy Policy. Material changes will be notified via email or in-app notice. We encourage you to review this policy periodically. Continued use after changes constitutes acceptance.
20. Contact
For privacy-related inquiries, data deletion requests, or questions about this policy, contact us through the in-app support system (Settings → Contact Support). We will respond within 30 days.
21. Admin Data Access
Authorized administrators may access user data including profiles, messages, characters, and settings for moderation, support, and platform maintenance. This includes editing or deleting individual messages, suspending individual chats, exporting user data, and deleting accounts. Day-to-day safety review is performed by automated systems; a human accesses your chat content only on a filed report, an automated severe-content flag, a support request you submit, or a valid legal obligation. All such access is logged in an immutable audit log, limited to trained staff, and restricted to the minimum data needed. We do not routinely browse user chats.
22. Admin User Insight Analysis
Authorized administrators may use an AI-assisted user insight analysis tool to better understand your account and behavior. This tool analyzes your stored data — including your messages, chat history, characters, feed preferences, interests, and stored psychological profile — to answer questions about your psychology, communication style, emotional patterns, and preferences for the purposes of support, moderation, abuse prevention, and platform safety. This analysis re-uses data already stored in your account; it does not collect new personal data. The results are used only by authorized personnel and are not shared with third parties.
23. Character Creation — Backstory & Personality Data
What we collect: When you create a character, we store the character record including name, type, language, image, description, tags, system prompt, greeting message, Backstory (the environment/situation where a chat starts), 10 personality trait values (humor, warmth, aggression, intelligence, flirtiness, mystery, energy, empathy, confidence, creativity — each 0–100, stored 0–1), NSFW flag, and voice settings. Backstory and personality are user-provided (or AI-generated at your request) and are part of User Content under Terms §4. They are displayed as initial context to anyone who chats with the character and are used to personalize AI replies. You may edit or delete them at any time via the character edit screen, and they are deleted when the character or your account is deleted.
24. AI-Assisted Generation — How Your Prompts Are Processed
The character-creation wizard offers optional AI assistance: Star (☆) for system prompt, greeting, and Backstory, and LET AI FILL for personality. If you use these, the App sends your short assistance prompt plus minimal character context (name, type, description, and — for Backstory/Personality — the system prompt, greeting, and Backstory you have already provided) to our AI provider (Gemini 3 Flash via our proxy) to generate a draft. For Backstory the system prompt and greeting must already be filled; for personality the AI returns 10 trait values 0–100. Drafts are shown for your review and are not saved until you tap Accept; tapping Cancel discards the draft (an Undo is offered briefly, then the draft is gone). Your assistance prompt and the character context sent for generation are processed as AI Service Provider data under §5 and are subject to the same AI Training and Message Monitoring disclosures. If you do not use these features, no assistance prompt is sent. As with all AI features, drafts may be inaccurate — always review before saving.
25. Referral Program — Data, AI Check, Credits & Appeals
What we collect for referrals. Your personal referral code (6-char AB12CD, unique, no expiry) and every claim you make or receive (refer_claims: fromUser, toOwner, code, IP, deviceDetails, networkInfo/push_token, displayInfo, accountInfo/createdAt, suspicious flag, creditsGranted 25 or 250, createdAt, expiryAt +30d). Credits stored on your user record (refer_credits, refer_credits_used, refer_credits_expiry, refer_debt for -25 carry, pending_refer_appeal, refer_disabled). Appeals (refer_appeals: claimId, reason optional, status pending/approved/rejected, createdAt/resolvedAt) and bonus state (weekly top +100, 3-in-7d +50) are also stored.
AI fraud check & sharing. Self-refer (same subject) is automatically suspicious. Otherwise if your IP matches the code owner's IP we collect limited details for both accounts and send them to Gemini Flash via our proxy with the prompt "Are these two accounts the same person — self-refer?" The model returns {same, confidence 0–1}; confidence >0.7 → suspicious (25 credits + appeal prompt), otherwise 250 credits. Only this fraud-check payload is sent to the AI provider; all other referral data stays in Convex.
How credits work. Referral credits expire 30 days after grant; each message send consumes refer credits first until 0, then your daily free quota (75/day, resets daily; refer credits do not reset until expiry). After expiry only 75/day remains. If your referral is flagged you see "Suspicious refer — This refer is marked as self refer, if you think we made a mistake please tell us about it" with a Request Appeal button. Appeals accept an optional justification and are reviewed by admins. Approved → +400 (250 + 150 apology) and suspicious cleared; Rejected → -25 debt (carries to next day if you have <25, deducted from next day's refer+free total). Max two appeals per flagged claim (one pending + one retry). Admins may disable a user's referral code. Credits have no cash value, are non-transferable, and may be revoked for abuse. Leaderboard bonuses are automatic and follow the same 30-day expiry.
Retention & rights. Referral data is retained until account deletion (expiryAt marks credit expiry, not row deletion). You may request deletion of referral data via account deletion or contact support; leaderboard aggregates are anonymized.
26. Profile Notices
We may show an informational Profile Notice on your profile screen (below follower/following, above your characters/chats) to communicate operational status. The default notice reads: "We acknowledge some features of app aren't working properly, and we are giving our best to fix them asap, if you found one? report it in HELP & Support by scrolling down to bottom and selecting Help & Support or Bug Report - both take to same screen" (GOOD level, green #22c55e background). Admins control the notice via app_settings keys profile_notice_mode (Off / default / Custom), profile_notice_custom_text, and profile_notice_level (GOOD green #22c55e, MEDIUM yellow #eab308, LOW red #ef4444, CRITICAL red #ef4444 plus a shaking animation on the discover header/profile icon). When mode is Off no notice is shown. Profile notices are operational messages only and do not collect personal data from you or affect your credits/quota unless explicitly stated.
27. Creator Verification Data
For users applying for Creator status, we collect only the legal name you type as your digital signature — no address form, no photo, no government ID. This data is collected solely for legal compliance, identity verification, and anti-fraud purposes. It is stored securely on encrypted database layers (isolated `creator_applications` table) and is never sold, shared with advertisers, or exposed to the public. Only you and authorized admins (via secure admin dashboard, §36 Terms) can access it. When you sign the Creator Terms, we also record your IP address, device information (model, OS, brand), screen resolution, user-agent, and timestamp as evidence of consent — the same consent-evidence pattern as Terms acceptance (§15). Applications are auto-approved on submission+signature but remain reviewable: admin may reject, which freezes your public characters (only owner can use). It is retained until account deletion or until your application is withdrawn; approved creator identity is retained for legal hold as long as you host characters. Private character counts (3 free + floor(total/5)) are stored as character metadata, not PII.
28. GDPR Notice (EEA/UK Residents)
If you are in the EEA/UK, we process your data under GDPR legal bases: contractual necessity for AI chats, memories, and psychological profiling under Terms §6/§7/§21 (core service — explicit consent via continued use, cannot be disabled while using the App), legitimate interests for fraud prevention (§31/§25), creator verification (§36/§27), and safety, and legal obligation for creator identity handover where required. Automated profiling (§7/§21) is performed only with explicit consent as contractual necessity; you have rights to access, rectification, erasure, restriction, objection, portability, and to lodge a complaint with your supervisory authority, plus human review of profiling. Contact us to exercise rights; we respond within 30 days.
29. Creator Liability & PII Handling — Disclosure
Creator verification PII is isolated: the `creator_applications` table is never queryable by ordinary users or standard API fetches — only `getMyApplication` (own) and admin `listApplications/reviewApplication` (admin role) can read it. Photos are stored via Convex encrypted storage (`_storage`) and accessed only via signed URLs. Indemnification under Terms §36 does not change this Privacy Policy's sharing limits — handover of real name/address/photo/IP logs occurs only upon valid subpoena, DMCA notice, or legal demand as described in §36(3).
30. Parental Dual-Consent Deletion
Parents or guardians can request permanent deletion of a minor's account at myth-app.cv/parental-control. (1) The parent enters the account username plus their own email; we send a 6-digit verification code (30-minute expiry) to prove email ownership. (2) Once verified, the very next app open shows the user a forced, un-dismissible notice with the exact request text and a 20-second countdown locking the AGREE button; DENY is always instant. AGREE confirms the relationship and triggers an immediate ban plus a complete server purge (chats, characters, memories, profiles, device logs) within 24 hours — irreversible. DENY cancels the request as a fake report and flags the reporting IP for trolling. Every step (request, email verification, agree/deny choice, purge) is written to an encrypted server log as legal evidence of good-faith compliance. A banned minor shell (no content, ban reason only) is kept to enforce the ban.