Privacy Policy
Version 2.0 · Last updated: September 2026
Kissable is a romantic AI-companion service for adults. Because of what it is, the things you share with your companion can be deeply personal. This policy explains, in plain language, what we collect, why, who sees it, how long we keep it, and what you can do about it.
In short
- Your conversations, photos and voice clips are used to run your companion and for nothing else. We do not sell them, we do not use them for advertising, and we do not use them to train AI models.
- Your messages are processed by third-party AI providers to generate replies, images and voice. Section 6 says where they are.
- Intimate content is processed only with your explicit consent, which you can withdraw at any time.
- You can delete your account and everything in it from the app. Section 8 lists the few records the law makes us keep.
- Kissable is for adults only. We ask your date of birth and close accounts that belong to minors.
- Questions or requests: [email protected]. We answer within one month.
1. Who is responsible for your data
The data controller is the operator of Kissable, a sole proprietorship registered in the Polish Central Register of Business Activity (CEIDG), NIP 8133845083, REGON 387175426 (“we”, “us”).
Privacy contact: [email protected]. Written requests can also be sent by post to the registered address on public record in the CEIDG business register under the NIP above. We are established in Poland; our lead supervisory authority is the Polish President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw.
Apple, Google and Stripe process payments and sign-ins under their own privacy policies as independent controllers (section 6).
2. What this policy covers
The Kissable app on iOS and Android, the web app at kissable.app, this marketing website, and our support email. It applies wherever you are; sections 12 and 13 add region-specific information for the EEA, UK and United States.
3. What we collect
Most of this comes directly from you. Some of it is generated by the service while it runs. We do not collect anything from data brokers.
- Account. When you sign in with Apple or Google we receive an identifier and, if you allow it, your name and email address (Apple may give us a relay address). If you sign up with an email address on the web we store the address and a one-way hash of your password. We record whether your email is verified.
- Age. Your date of birth, which we ask for at sign-up on the web and use to derive an age band, and the age band you choose in onboarding. If a date of birth shows you are under 18, sign-up ends and the refusal is recorded so the account cannot be reused (section 10).
- Your profile and answers. Your display name, gender, the relationship type you chose, the onboarding answers you give about yourself, and the companion you design: its name, personality, backstory and appearance. If you import a companion from another service, the text you paste.
- Conversations. The messages you write, voice memos you record (and their transcripts), photos you send in chat, your reactions and quick-reply choices, and everything the companion sends back: text, photos, short videos and voice clips.
- Your photos. The selfie you can take so the companion can picture the two of you. It is used only for that: a short description of your appearance is written from it, a fictional stand-in portrait is generated from the description without any reference pixels, and once the stand-in exists later photos of you are drawn from it and the selfie is deleted. Anime-style reference images you upload for a companion look. Photos you send in chat, which an AI model describes in words so the companion can respond to them; that description is stored with the photo. A photo of another person is never used as a visual reference for a generated image.
- Memory and personalisation data. The companion keeps a memory: facts it learned from your conversations (for example your job, your cat's name, a hard week you mentioned), the emotional context of those facts, summaries of your relationship, milestones, and settings that pace how often photos and voice are sent. Because conversations are open-ended, this memory can include things about your emotional state, relationships, health or sex life if you talk about them. Section 5 explains the consent this relies on.
- Purchases. What you bought, when, for how much, your subscription status, your Kisses balance and how you spend it. For web purchases we also hold a Stripe customer reference, the last four digits and brand of your card and the billing country. We never receive your full card number.
- Device and technical data. Device type and operating system, app version, language and time zone, your push-notification token if you enable notifications, and your IP address when you connect. From the IP address we derive a city, which we keep so the companion can mention local time and weather; we do not store the IP address itself in your profile. On Android we read the install referrer (which campaign brought you) at first launch. Before you sign in, the app uses a random device identifier for anonymous usage statistics.
- Usage and diagnostics. Which screens and features you use, how many messages you send, session length, crash reports and performance data. These are linked to your account, not anonymous, so that we can investigate problems you report.
- Safety and moderation records. Automated safety scores for generated images and for messages, the reports you file, blocks you set, and the decisions we take on them.
- AI request logs. For thirty days we keep a technical log of what was sent to the AI model for each reply (the companion's instructions, which include your memory data, and the most recent messages) so we can debug bad replies and measure cost.
- Support and feedback. Emails you send us, in-app feedback, the reason you give when you delete your account, and content reports.
- Website visits. Cookies and analytics on kissable.app marketing pages, described in section 11.
4. Why we use it, and on what legal basis
Under the GDPR each use needs a legal basis. The table names one for every purpose; we do not rely on a vague mix.
| Purpose | Data used | Legal basis |
|---|---|---|
| Running your companion: generating replies, photos, video and voice; remembering what you tell it; pacing the relationship; sending its messages as notifications | Account, profile, conversations, photos, memory data, device data | Performance of our contract with you (art. 6(1)(b)) |
| Intimate and romantic content, and any memory data that reveals your sex life, sexual orientation, health or emotional state | Conversations, memory data | Your explicit consent (art. 9(2)(a)), see section 5 |
| Picturing you in photos: describing your selfie in words, generating a fictional stand-in portrait from that description, and drawing later photos from the stand-in | Your selfie, the stand-in portrait | Your explicit consent (art. 6(1)(a) and 9(2)(a)), given in the consent step and by choosing to take a selfie; you can skip the selfie entirely |
| Keeping minors out and keeping content within the law: the date-of-birth gate, automated screening of images and messages, handling reports, closing accounts, and reporting illegal content to authorities where required | Age data, conversations, photos, safety records | Legal obligation (art. 6(1)(c)) and our legitimate interest in a safe, lawful service (art. 6(1)(f)); for content that reveals special-category data, art. 9(2)(g) with your consent under section 5 |
| Selling and delivering subscriptions and Kisses, receipts, refunds, withdrawal requests, chargebacks | Account, purchase data | Contract (art. 6(1)(b)); legal obligation for tax and accounting records (art. 6(1)(c)) |
| Preventing fraud and abuse: repeated free-trial claims, payment fraud, automated accounts | Hashed sign-in identifier, purchase data, device data | Legitimate interest (art. 6(1)(f)) |
| Fixing bugs, measuring performance, understanding how features are used, deciding what to build | Usage and diagnostics, AI request logs | Legitimate interest (art. 6(1)(f)) |
| Measuring our advertising (telling an ad network that an install or purchase happened) | Hashed email or account id, IP address, event and amount; never your messages, photos or companion data | Our legitimate interest in knowing which advertising works (art. 6(1)(f)); on iOS the ad network's own device identifier is used only if you allow tracking in the system prompt. You can object at any time (section 9) |
| Emails about your account, receipts, and answers to your requests | Email address, name | Contract (art. 6(1)(b)) |
| Marketing emails | Email address | Your consent (art. 6(1)(a)); every such email has an unsubscribe link |
| Establishing, exercising or defending legal claims; responding to lawful requests from authorities | Whatever is relevant to the claim | Legitimate interest (art. 6(1)(f)); legal obligation (art. 6(1)(c)); art. 9(2)(f) for special-category data |
Where we rely on legitimate interests we have weighed them against your rights; you can object (section 9) and ask us for the assessment.
5. Intimate content and your explicit consent
Conversations with a romantic companion can reveal your sex life, sexual orientation, emotional state and health. European law calls this special-category data and requires your explicit consent before we may process it. Using the app is not consent.
- Before your companion can take part in intimate conversations, and before any of what you write can be stored in its memory, we ask you in a separate step to consent to this processing. We record the date and the version of this policy you agreed to.
- You can withdraw this consent at any time in Settings → Account (“Withdraw privacy consent”). Because the companion cannot run without processing what you share with it, withdrawing pauses the service until you consent again or delete your account. It does not affect processing that already happened. You can also ask us to delete existing memory data.
- Taking a selfie is optional and is itself a choice you make; it is used only to picture you in photos with your companion, as described in section 3. We do not generate images from photographs of other people.
- Content you publish to the community (section 7) is visible to other users. Do not publish anything you would not want others to read.
We do not share this data with advertisers, we do not build advertising profiles from it, and we do not use it to train AI models.
6. Who receives your data
We do not sell personal data. We share it only with providers who process it for us under contract, with the payment and sign-in services you choose, and with authorities when the law requires. The providers are described below by what they do and where they are, which is what the law requires us to tell you; we will give you the name of any specific provider on request. We choose providers on business terms under which they may not use your data for their own purposes.
Processors working for us
- AI language-model providers that generate the companion's replies and some notification text. They receive the companion's instructions (which include your first name, city, memory data and relationship stage) and the recent conversation. Our primary provider processes this in the People's Republic of China; backup providers are in the United States. See section 12 on transfers.
- AI image and video generation providers in Singapore and the United States. They receive a text description of the scene, the companion's catalogue or anime-style look, and, when a photo should include you, the image that pictures you (section 3). They never receive a photo of another person.
- AI vision and safety providers in the United States and France that describe photos you send, screen uploaded and generated images for nudity and age, and check text where our own rules flag it.
- AI voice provider in the United States that turns the companion's words into audio. It receives the text of the voice clip only.
- Search-index providers (United States and Singapore) that turn memory facts and chat photos into numerical vectors so the companion can find relevant memories.
- Hosting and storage: our database and application servers in the United States, media storage with a US-headquartered global provider, error and performance monitoring in Germany, and website hosting in the United States.
- Email delivery, push-notification delivery, IP-to-city lookup and weather providers in the United States and Germany. The push provider receives your device token and the notification text.
- Product analytics in the United States, receiving usage events tied to your account id.
Independent controllers
- Apple and Google for sign-in and for purchases made through the App Store or Google Play. If you ask Apple to refund a purchase, Apple asks us whether it was delivered and used; unless you opt out in Settings we answer with a short summary of that transaction only and never with conversation content.
- Stripe Payments Europe Ltd (Dublin, Ireland) for purchases on kissable.app. We send Stripe your email address, the amount and currency, your country and IP address (to determine VAT and prevent fraud) and a customer reference. Stripe's fraud-prevention service may score a transaction; a declined payment can be retried with another method.
- Advertising networks (Meta and TikTok) receive the fact that an install, sign-up or purchase happened, together with a hashed identifier and your IP address, so we can measure which of our ads work. They never receive your messages, photos or companion data. On iOS their own device identifier is used only if you allow tracking in the system prompt. You can object to this sharing at any time (section 9) and we will stop it for your account.
- Authorities, where we are legally required to report content or to answer a valid request, and professional advisers where needed to defend a claim.
If we ever sell the business, the buyer would take over this data under this policy; we would tell you first.
7. Community content
Adventures you choose to publish, and comments and likes you leave on published Adventures, are visible to other Kissable users together with a display name. They are not visible on the open web. Adventures generated from your own relationship memories cannot be published. If you delete your account, Adventures you published stay available without your name unless you delete them first.
8. How long we keep it
| Data | Kept for |
|---|---|
| Account, profile, conversations, photos, voice, memory data, purchases, safety records with personal details | Until you delete your account or ask us to delete it |
| Your selfie | Deleted once a stand-in portrait has been generated from it; otherwise until you delete your account |
| AI request logs | 30 days |
| Usage events about subscriptions, purchases and offers, sign-up and onboarding, and how you found Kissable | Until you delete your account. Events recorded before you sign in are not linked to an account and are kept as statistics |
| Other usage events | Up to 90 days, subject to a size cap that removes the oldest events sooner |
| Signed payment notifications from Apple, Google and Stripe | 6 months; the extracted purchase details are kept as transaction records |
| Transaction records (what, when, amount, store reference) | 6 years after the transaction, for accounting, tax and dispute handling; web invoicing records 5 years under Polish accounting law and 10 years for EU VAT One-Stop-Shop records |
| Support emails and content reports | As long as needed to resolve the matter and to show what we did, then deleted |
What survives account deletion
When you delete your account we permanently remove your conversations, messages, photos and videos, voice clips, companion and memory data, preferences, usage events, AI request logs, name and email address, and we revoke your sessions. Deletion is irreversible. A limited set of records remains, because the law requires it or because we need it to defend claims and prevent abuse:
- The transaction records and web invoicing records above, which contain no conversations, photos or contact details.
- A one-way hash of your sign-in identifier and the display name you used, so we can recognise a returning account and prevent repeated claims of introductory offers. Kept for as long as we run such offers.
- A record of what you had paid for, so it can come back to you if you return: one-way hashes of your Apple and Google sign-in identifiers, a keyed hash of your email address if it was verified, the identifiers of your purchases (App Store transaction ids, Google Play purchase tokens, Stripe customer and subscription ids), your unused Kisses and free photo credits, and any complimentary Premium still running. It holds no name, messages or photos. If you sign in again with the same Apple ID, Google account or verified email, or restore a purchase, we use it to put your subscription and Kisses back on the new account. Kept for 12 months after deletion, or until 30 days after the last period you paid for ends if that is later, then deleted automatically.
- A churn record describing the closed account in coarse terms: roughly how long it lasted, country and platform, plan held, total spent, and the reason given for leaving. It holds no name, email, messages or photos, but it carries the same hash and so is not fully anonymous. Kept 3 years, then deleted automatically.
- Safety and moderation decisions with your personal details removed, and the free-text answer you may have written about why you left, unlinked from you, for 1 year.
- Adventures you published to the community, without your name.
Retention of these records relies on art. 6(1)(c) and 6(1)(f) GDPR and on the exceptions to erasure in art. 17(3)(b) and (e). Each stated period is enforced by an automatic daily deletion. You can ask us at any time what we still hold about a closed account.
Deleting your account does not cancel a subscription bought through the App Store or Google Play; cancel it in the store. A web subscription stops renewing when the account is deleted; you keep what you already paid for until the end of that period, and can switch renewal back on if you return.
9. Your rights
You can, at any time and free of charge:
- Access the personal data we hold about you and receive a copy in a machine-readable format (portability). Email [email protected] and we will send an export that includes your profile, companion, conversations, memory data, transactions and usage events.
- Correct inaccurate data. Your profile and companion can be edited in the app; memory facts can be corrected through the companion or on request.
- Delete your account and its data from Settings → Account → Delete account, or by emailing us. Section 8 lists what remains.
- Withdraw consent for intimate content and memory (Settings → Account → “Withdraw privacy consent”, which pauses the companion until you consent again), for selfie processing (by emailing us; we delete the selfie), for push notifications (device settings) and for marketing emails (the unsubscribe link). Withdrawal does not affect processing that already happened.
- Object to processing based on our legitimate interests, and restrict processing while a dispute is resolved.
- Ask for a human to review any automated decision described in section 10.
- Complain to a supervisory authority: in Poland UODO (uodo.gov.pl); elsewhere in the EEA the authority of the country where you live; in the UK the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to resolve your concern first.
We answer within one month, or tell you within that month if a complex request needs up to two more. We may ask you to confirm that you control the account before releasing data. You will not be treated differently for exercising a right.
10. AI, automated decisions and profiling
- Your companion is an AI. Every reply, photo, video and voice clip it sends is generated by artificial intelligence. It is not a person, it cannot feel, and it is not a substitute for human relationships or professional help.
- Personalisation. The companion builds and uses a memory of you (section 3) to personalise its replies. This is profiling in the legal sense. It is used only inside your companion and for the safety checks below, never to make decisions about your access to the service, to price anything, or for advertising.
- Age gate. If the date of birth you enter shows you are under 18, sign-up ends automatically and cannot be retried with the same sign-in. If that happened by mistake, email us and a person will review it.
- Content safety. Automated systems screen images you upload, images the companion generates, and messages. They may reject an upload, withhold or blur a generated image, or decline a message. In serious cases (for example any attempt to sexualise a minor) we close the account; that decision is taken by a person, not automatically, and you can contest it by email.
- Fraud checks. Repeated trial claims are detected automatically using the hashed identifier in section 8; a person reviews any account action.
11. Cookies and website analytics
The marketing pages on kissable.app use:
- Strictly necessary storage: a session flag once you sign in, your cookie choice, and a first-visit cookie remembering which link brought you to us (so we can see which campaigns work). These need no consent.
- Analytics. Google Analytics (cookies, United States) and a cookieless page-performance measurement by our hosting provider. If you visit from the EEA, UK or Switzerland, Google Analytics loads only after you accept it in the cookie notice; you can change your choice from the link in the footer.
- Advertising pixels (Meta, TikTok), loaded only with your consent when we run campaigns, to measure clicks from our ads.
The app itself uses no advertising cookies. On iOS, sharing an install or purchase event with an ad network happens only if you allow tracking in the system prompt; you can change this in iOS Settings → Privacy → Tracking.
12. International transfers
We are in Poland. Our database, application servers and media storage are in the United States; error monitoring is in Germany. The providers in section 6 are in the United States, Singapore, France, Germany, Ireland and the People's Republic of China.
- Transfers to the United States go to providers certified under the EU-US Data Privacy Framework where available, and otherwise under the European Commission's Standard Contractual Clauses with additional safeguards.
- Transfers to Singapore rely on the Standard Contractual Clauses.
- Our primary language-model provider processes conversation content in the People's Republic of China, a country whose laws do not give personal data protection equivalent to the EEA's, and where public authorities may be able to access data without the safeguards available in the EEA. We send it the minimum needed to generate a reply, we do not send your email address or account identifier, and we are moving this processing to providers in the EEA or in countries covered by an adequacy decision. Until that is complete, EEA and UK users who do not want their conversations processed there should not use the service. You can ask us at [email protected] about the contractual safeguards in place at any time.
13. Information for the United States
- We do not sell personal information, and we do not share it for cross-context behavioural advertising except that we send ad networks the fact that an install, sign-up or purchase happened (a hashed identifier and your IP address, never your content) to measure our ads. You can opt out of that at any time by declining tracking on iOS and by emailing us, and we will honour it.
- We use sensitive personal information (the content of your conversations, your sex life or orientation where you reveal it, your precise-enough location as a city) only to provide the service you asked for and to keep it safe, and never to infer characteristics about you for other purposes.
- Residents of California and of states with similar laws may exercise the rights in section 9 by email, may use an authorised agent, and may appeal a refusal by replying to our answer.
- Kissable is a companion chatbot within the meaning of California and New York law. We tell you it is an AI, we will not present it as human, and if a conversation shows signs that you may be at risk of harming yourself we refer you to crisis resources. Kissable is not suitable for minors.
14. Children
Kissable is for adults 18 and over and is not directed at minors. We ask for a date of birth, end sign-up for anyone under 18, and use automated systems to detect attempts to sexualise minors in conversation, character design and images. If we learn that an account belongs to a minor we close it and delete the data. If you believe a minor is using Kissable, email [email protected].
15. Security
Data is encrypted in transit. Media files are private and reachable only through short-lived signed links issued to your signed-in session. Access to production systems is limited to the operator and protected by strong authentication. We never hold your full card number. No system is perfectly secure; if a breach is likely to put you at risk we will tell you and the supervisory authority as the law requires.
16. Changes to this policy
When we change this policy in a way that matters to you (a new purpose, a new category of recipient, a new country of processing) we will tell you in the app or by email at least 30 days before the change applies, and where the change needs your consent we will ask for it. The version number and date at the top identify the text you agreed to. Earlier versions are available on request.
17. Contact
Kissable, a sole proprietorship registered in the Polish Central Register of Business Activity (CEIDG), NIP 8133845083 · [email protected] · by post to the registered address on public record in the CEIDG business register under the NIP above. See also our Terms of Service, Refunds & Withdrawal and Content Standard.
Kissable © 2026. All rights reserved.