Legal

Privacy, plainly.

Effective March 1, 2026 · Last updated September 15, 2026

1. Who We Are

Most privacy policies are written to obscure what a company actually does with your data. This one is written to show it. Every category of data we collect is listed below. Everything we don't collect is listed too. If something isn't on either list, email privacy@luvme.io and we'll answer directly.

Bad Breath Studios Inc. is a corporation incorporated under the laws of Ontario, Canada. We operate the LuvMe relationship training platform.

For any privacy-related inquiries, contact us at privacy@luvme.io.

Privacy Officer: Legal Team, Bad Breath Studios Inc.
375 University Avenue, Suite 3310, Toronto, ON M5G 2J5, Canada

2. What Data We Collect

We collect the following categories of data. We store your conversations because the AI needs them to maintain memory and personality continuity. That is what makes the relationship feel real.

  • Account data: email address, username, display name, date of birth, avatar selection, language preference, onboarding responses.
  • Signup country: when you create your account we check your IP address once against an offline country database and keep the resulting two-letter country code, such as "DE" or "IN". We keep the country, not the address; we do not repeat the check afterwards; and nothing more precise than the country is worked out. We use it to apply the correct legal minimum age for your jurisdiction, and to honour country-level content restrictions where they apply.
  • Conversation data: full text of conversations with AI companions, AI-extracted memories and facts, periodic conversation summaries, and voice call transcripts.
  • Generated content: AI-generated images, video clips, and voice lines created during your use of the platform. These are stored temporarily and subject to tier-based expiry (24 hours to 7 days depending on your subscription).
  • Relationship and activity data: companion selections, relationship stage progression, date history and outcomes, activity and game history, gift history, sticker and cosmetic unlocks.
  • Progression data: XP events, achievement progress, milestone levels, coach skill profiles, leaderboard data (if you opt in).
  • Payment data: transaction confirmations (amount, date, subscription tier) received from our payment processor. We never store credit card numbers, CVVs, or bank details on our servers.
  • Session and usage data: when you open and leave the app, which screens and steps you reach, and whether they worked: for example, that you finished a setup step, opened a chat, or that a message failed to send. Each record is an event name with a handful of numbers and codes; it never contains what you or a companion wrote, a companion's name, or anything you typed. It is stored against your account for up to 180 days, only ever read in aggregate to find where the app loses or frustrates people, and is deleted with your account. Approximate session duration also feeds wellness features such as break encouragement.
  • Content reports: when you report a companion's message, we store the report (the reason and any details you add) together with a snapshot of the surrounding conversation from your own chat, so our team can review what happened and improve companion quality and safety.
  • Diagnostic data: when the app hits an error or crashes, we collect technical diagnostics to fix it: the error type and message, the screen where it happened, the app version, and your device model and operating system version. This is coarse troubleshooting data, not a tracking fingerprint, and it is never used for advertising.
  • Problem reports: when you use "Report a Problem" in Help & Support, we store the summary and description you write, along with the same basic diagnostic and in-app context, so our team can reproduce and fix the issue.
  • App measurement (mobile apps only): our iOS and Android apps include two measurement libraries, Google Firebase Analytics and Meta App Events, so we can tell which of our own app adverts actually bring people who use LuvMe, rather than only which ones are cheapest. Both record the same short list of non-content events: that an account was created and how (email, Google, or Apple), that a first message was sent, that you changed a display preference such as light or dark mode, and that you made a purchase, together with its list price in US dollars. The purchase event carries the amount and nothing else: not which plan or pack you bought, not your receipt, and not your payment details, which never reach us in the first place. Meta additionally records that the app was installed and that it was opened. Alongside those, Google receives a resettable app-instance identifier, your device model and operating system, your country, and, on Android, your Google advertising identifier. Meta receives your device model, operating system and country, and no advertising identifier on either platform, because we switch that collection off. Neither ever receives your messages, your companions, your email, your username, or your account number. Both are switched off until you are signed in to a verified adult account, and off for every account paused under the previous age policy.
  • Download-page visits (this website, not the app): when someone opens our download page we record that a visit happened, which advert link brought them, whether the browser looked like a phone or a desktop, and the two-letter country. This is how we tell which of our adverts actually bring people to LuvMe. The country is worked out the same way as the signup country above: the address is checked against an offline database and only the country is kept. There is no cookie and no identifier of any kind, the record is not linked to any account and cannot be later, and it is deleted after a year.

3. What We Do NOT Collect

We do not collect browsing history, IP address logs beyond temporary rate-limiting (with one exception: the IP address recorded alongside a face-upload rights confirmation, described in section 5), device fingerprints, ongoing or precise location data, or any information about you from outside LuvMe. The one thing we count on this website is the anonymous download-page visit described in section 2, which records which advert was clicked and never who clicked it. The only location information we hold is the city you optionally set yourself and the one-time signup country described above. Your payment details are handled entirely by our payment processor. We never see or store card numbers or banking information.

The app-measurement identifiers described in section 2 are the one exception worth naming plainly. They are resettable device-level identifiers issued by the operating system or by Google, not a fingerprint we build from your behaviour, and you can reset or clear them from your device settings at any time. On iOS we deliberately ship the build of Google's measurement library that cannot read Apple's advertising identifier at all, and Meta's library is configured never to collect an advertising identifier on either platform. That is also why LuvMe never shows you an app-tracking prompt: there is nothing for it to ask permission for.

The short version: We store your conversations, memories, and relationship data because that's what makes LuvMe work. We do not sell it, share it with advertisers, or use it for anything outside of running your experience. We do email you about LuvMe itself, and you can turn that off in one click; section 4 says exactly what we send. You can see everything we have on you in your Profile under Privacy & Data, export it, or delete it permanently at any time. The one thing that does leave the app for an advertising purpose is app measurement, and it carries none of the above: it is described in section 2 and section 6.

4. How Data Is Used

We use the data we collect strictly for the following purposes:

  • Service delivery and maintaining your account
  • Providing companion memory and conversation continuity
  • Subscription billing and payment processing
  • Platform abuse prevention and safety enforcement
  • Reviewing reports you submit, including the conversation snapshot captured with them, to act on the report and improve companion quality
  • Diagnosing and fixing crashes, errors, and problems you report (technical diagnostics are used only to improve stability, never for advertising or tracking)
  • Understanding how the app is used, in aggregate, to improve it: which steps people finish or abandon, where the app fails them, and whether a change helped. The session and usage data this reads is described in section 2
  • Measuring our own app adverts: knowing which advert led to an install that became a real, active account, so we stop paying for the ones that do not
  • Sending you email about LuvMe itself, but only the kinds you switched on: a short note when a companion has written to you and your phone cannot show notifications, and the occasional update about something new in the app

The email we send you. There are three kinds and we treat them differently. Service email is the mail your account cannot work without: verification and password codes, account-deletion confirmations, support ticket replies, billing notices such as a failed payment or a trial about to end, decisions on content you submitted for review, and anything we are legally required to tell you. You get it because you have an account; it cannot be switched off while the account exists.

The other two kinds are opt-in, and each has its own switch. Companion email: when a companion writes to you and your device cannot show notifications, a short email tells you who wrote, so you can open the app. It never contains the message itself, whatever the conversation is about. We send at most one a day and a few a week, never during your night, and we stop on our own if you do not open the app after a couple of them. Product email: occasional news about new features and offers from the LuvMe team. Neither switch is ever pre-ticked. You choose during onboarding, when the app cannot get notification permission, in a one-time question if your account predates these switches, or at any time under Settings > Notifications. Nothing in either category is sent until you say yes, and we keep a record of each yes and each no: the date, the version of this wording you saw, and where in the app you chose, so we can show what you agreed to.

Every companion or product email carries a one-click unsubscribe link in its footer that works immediately, with no login and no reply needed, and the standard unsubscribe header your mail app can act on. You can also switch either kind off in the app, or email privacy@luvme.io. Withdrawing takes effect at once and does not affect your account. If you mark one of our emails as spam, we treat that as withdrawing from both kinds. Ask us anything about this at support@luvme.io.

Your email address is never sold or rented, and it is never shared with anyone so they can market to you. No third party emails you on our behalf beyond the delivery provider named in section 6, and the content of these emails is written by us, not generated from your conversations.

Approximate session duration is part of the session and usage data described in section 2 and also enables our companion wellness features, such as break encouragement after extended sessions.

We track crisis detection events (severity category only, never message content) to monitor system effectiveness and ensure safety resources are provided when needed.

5. Data Retention

  • Account data: Held while your account is active. Deleted immediately upon account deletion.
  • Conversation data: Deleted immediately upon account deletion.
  • Content reports: Reports you file and the conversation snapshot captured with them are deleted immediately upon account deletion.
  • Diagnostic and problem-report data: Problem reports you submit are deleted immediately upon account deletion. Crash and error diagnostics are kept in a small, capped log that automatically purges older entries and holds no message content; on account deletion any link to your account is removed.
  • Generated content: Automatically deleted according to your tier's retention period (24 hours to 7 days). All content deleted immediately upon account deletion.
  • Photos you upload for a companion's face: Kept for as long as the companion made from it exists, then deleted with that companion, and in any case deleted with your account. If you upload a photo and never finish creating the companion, the photo is deleted after 30 days. It is stored privately on our own infrastructure, is never shown to anyone, and is used only to draw the companion's face and, if something goes wrong with that drawing, to work out why.
  • Your confirmation that you had the right to use an uploaded photo: Kept for 7 years, and this one record outlives your account. It holds the date, the exact wording you agreed to, your email address at the time, two short mathematical fingerprints of the image -- never the image itself -- and, so that the confirmation can be tied to the device that made it, the IP address, app version and device software description at the moment of upload, together with the results of the automated safety checks (for example the estimated age band and whether a public figure was detected). It holds no copy of the photo and no face scan. We keep it because it is the only way to answer a later complaint from someone who says a photo was used without their permission, and it would be worthless if the person who made the claim could erase it by closing their account. This is the narrow exception the law allows for defending legal claims (UK/EU GDPR Article 17(3)(e); California Civil Code 1798.105(d)(9)). Everything else about your account is still deleted immediately.
  • Session and usage data: Automatically purged after 180 days. Deleted immediately upon account deletion.
  • Billing records: Retained for 7 years as required by law.

Deleted data may persist in encrypted database backups for up to 30 days as part of our standard backup rotation schedule. These backups are encrypted at rest, access-controlled, and automatically purged on rotation. No deleted data is recoverable from backups after this retention window.

6. Third Parties

  • Stripe: Payment processing for web/desktop purchases. Not used by the iOS or Android apps, where all purchases go through Apple or Google (see below). We never see or store card numbers.
  • Apple App Store, Google Play, and RevenueCat: In-app purchase processing for subscriptions and token purchases in our mobile apps. Payments are handled by Apple or Google; RevenueCat manages your subscription status on our behalf. We never see or store card numbers.
  • RunPod: GPU compute for AI chat, image, and video generation. No user-identifiable data is sent; only model prompts and parameters.
  • Vast.ai: GPU compute for AI image generation. No user-identifiable data is sent.
  • ElevenLabs: AI voice for companion voice calls, voice notes, and previews. Receives the text your companion is about to speak, which can reflect your conversation, and, during voice calls and the in-activity voice channel, your voice audio so it can be transcribed into text. Audio is sent only while you are speaking in a call, and LuvMe does not store it. These voice features run only with your AI processing permission, which you can change at any time in the app's Settings.
  • Sightengine: Automated safety checks on a photo you upload. Receives the image so it can tell us whether everyone in it appears to be an adult, whether it shows a recognisable public figure, and whether it contains nudity or sexual content, which we do not allow in an uploaded photo. The image is sent only at the moment you upload it, is used only for that check, and is not attached to your name, email or account identifier. These checks run on every upload and are not affected by your AI processing setting.
  • OpenAI: Converts text into numerical embeddings so your companion can search their memories by meaning. Only the text being indexed is sent, with no name, email, or account identifier attached.
  • Anthropic: Anthropic's Claude models power several AI features, and receive the following to do so:
    • Your messages in AI support chat, to write the answer.
    • Your chat conversations with your companion, used to generate the daily, weekly, and monthly summaries behind their long-term memory.
    • A short extract of your recent conversations and saved memories, used to draft your companion's opening message after a match and the occasional check-in message they send when you have been away. Your companion's replies inside a conversation are not drafted this way: those are generated by LuvMe's own AI model.
    • Your messages during in-chat activities and games, to save notes from them.
    • Your onboarding questionnaire answers, to write your personalized reflection.
    • The text of your saved memories, to detect when a new memory contradicts an older one.
    • Your drafts in the proposal and vow writing helper, together with the memories it draws on.
    • The text you write when creating a Custom Companion, including its automated safety review.
    • The description you type when you ask for a picture, used to check it is safe to generate and to render it in English, which is what our image tools read. This runs on every picture description, in any language, and is not covered by the AI processing setting: it is a safety check rather than a feature. The picture itself is generated on our own infrastructure.
    • The photo you add of yourself, used to describe how you look so your companion can refer to it. The photo itself is stored only on our own servers and is never shown to anyone else, and every picture of you and your companion together is generated on our own infrastructure, so no image leaves it.
    • A photo you upload to give a Custom Companion its face, used to check that it is suitable -- that it shows exactly one clearly adult person, and no well-known public figure -- and to describe the person's general appearance in a fixed set of categories (for example hair colour, eye colour, skin tone and build) so that the generated face resembles them. The safety check runs on every upload whatever the AI processing setting says. The appearance categories are kept with the generated face as its description; they are not a face scan and cannot identify anyone. The photo is kept privately with the companion it was used for. We draw a brand-new face inspired by it on our own infrastructure when you create the companion, keep that generated picture as your companion's face, and keep your photo alongside it for as long as that companion exists -- so that if the drawing goes wrong we can see why. It is never shown to anyone, never published, and never used to train anything, and it is deleted when the companion is deleted, when your account is deleted, or after 30 days if you never finish creating the companion.
    Anthropic also generates official companion profiles and content on our side, which involves no user data. Before your first AI support message we show an in-app notice and ask you to continue; email and support tickets never use AI.
  • Google (Firebase Analytics and Google Ads): App measurement for our iOS and Android apps. Receives the non-content events and device identifiers listed in section 2, and nothing else: no messages, no companions, no email, no username, no account number. We use it for one purpose: to see which of our own app adverts brought people who actually use LuvMe. Off entirely until you are signed in to a verified adult account.
  • Meta (Meta App Events, for adverts on Meta and Instagram): App measurement for our iOS and Android apps. Receives the same non-content events as Google, plus that the app was installed and opened, and your device model, operating system and country. No advertising identifier, no messages, no companions, no email, no username, no account number. We use it for one purpose: to see which of our own adverts on Meta and Instagram brought people who actually use LuvMe. Off entirely until you are signed in to a verified adult account.
  • Resend: Email delivery. Sends the three kinds of email described in section 4: the service email your account needs (verification codes, support ticket replies, billing and account notices) and, only where you opted in, the companion and product email you can switch off at any time. Also tells us when one of those emails bounced or was reported as spam, so we stop sending. Receives your email address and the text of the message being sent, so it can deliver it, and nothing else. It never receives your conversations, your companions, your memories, or your generated content, and it never uses your address for its own purposes.

Each third party listed above acts as a data processor for us, under its data processing terms. Those terms require them to protect your data to a standard equal to the one described in this policy: to process it only for the purpose stated above, to keep it confidential and secure, and not to sell it or use it for their own purposes. The API terms of our AI providers state that data sent through their APIs is not used to train their models. International transfers are covered in section 8 below.

We never sell your data, and we show no adverts inside LuvMe. Your conversations, your companions, your images and your account details are never used for advertising by us or by anyone else, and no advertiser ever receives them.

One thing does leave the app for an advertising purpose, and we would rather say so plainly than bury it: because we advertise LuvMe itself on the App Store and Google Play, the events listed in section 2 (an account was created, a first message was sent, a display preference was changed, a purchase was made and what it cost) and the device identifiers listed there are shared with Google and with Meta so we can measure our own adverts. That tells us which advert brought someone who actually uses LuvMe. It does not tell either of them anything about what you say, who you talk to, or what you generate, and it is never used to target you with adverts from anyone else.

7. Legal Basis for Processing (GDPR Article 6)

We process personal data under the following legal bases:

  • Contract performance: Processing necessary to deliver the service you signed up for (account, chat, content generation).
  • Consent: You consent to data processing by creating an account and accepting our Terms of Service. Separately, the companion email and product email described in section 4 are sent only on your explicit opt-in, which you can withdraw at any time using the unsubscribe link in any such email, the switches under Settings > Notifications, or by emailing privacy@luvme.io, without affecting your account.
  • Legitimate interest: Platform security, fraud prevention, service improvement through anonymised analytics, and the service email that running your account requires.
  • Legal obligation: Retention of billing records as required by applicable tax and financial regulations.

8. International Data Transfers

Your data may be processed on servers located in Canada and the United States. GPU compute tasks (image/video generation) may be processed on cloud infrastructure in various regions.

No user-identifiable data is transmitted to GPU compute providers. Only AI model prompts and parameters are sent, which contain no personal information.

For users in the European Economic Area (EEA), transfers to Canada are covered by the European Commission's adequacy decision. For transfers to the United States, we rely on standard contractual clauses where applicable.

9. Your Rights (GDPR + PIPEDA)

Regardless of where you reside, we extend the following rights to all users:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request corrections to inaccurate data.
  • Deletion: Exercise your "right to be forgotten" and have your data permanently removed.
  • Data portability: Receive your data in a structured, commonly used format.
  • Withdraw consent: Withdraw your consent to data processing at any time.

To exercise any of these rights, contact privacy@luvme.io.

You don't need to file a formal request to exercise most of these rights. Data access, export, and deletion are all available directly in the app under Profile → Privacy & Data. For anything that requires manual processing, email privacy@luvme.io and you'll hear back from a real person within 5 business days.

For detailed instructions on deleting your account or specific data, see our Account & Data Deletion page.

10. Cookies & Local Storage

We use one session cookie for media authentication. We do not use tracking cookies, advertising cookies, or any third-party analytics cookies. This section is about browser storage; the app-measurement SDK described in section 2 uses no cookies and does not run on this website.

The desktop app uses browser local storage to remember your login session, theme preference, and UI state (such as dismissed banners). This data stays on your device and is never sent to our servers. You can clear it at any time via the app settings. For full details, see our Cookie & Local Storage Policy.

11. Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected users within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33 and applicable Canadian privacy laws. Notification will be sent via the email address associated with your account.

12. Children's Privacy & Age Requirements

LuvMe is an adults-only service for users 18 and older (or older where local law sets a higher age of majority). We do not knowingly collect personal information from anyone under the minimum age for their jurisdiction.

If we discover that an account belongs to a user under the minimum age, we will terminate the account and delete all associated data within 14 days.

COPPA Compliance (United States)

LuvMe is not directed at children under 13. We do not knowingly collect personal information from children under the age of 13. If a parent or guardian believes their child has provided personal information to LuvMe, they should contact us at safety@luvme.io. We will terminate the account and delete all associated data within 24 hours of a verified request.

GDPR-K Compliance (European Union / EEA / United Kingdom)

The LuvMe minimum age is 18 in every jurisdiction, which meets or exceeds the digital age of consent everywhere, including EU member states and the United Kingdom. Users under 18 are blocked from registration.

Accounts Created Under the Previous Age Policy

LuvMe became an adults-only service on August 14, 2026. Accounts created before that date by users aged 16-17 are paused: they cannot use the service, their data is retained unchanged, and access returns automatically on the account holder's 18th birthday. A paused account holder may instead permanently delete their account and all associated data at any time from within the app. No third-party analytics identifiers are shared for any user under 18.

Date of Birth

We collect your date of birth during account creation to verify age eligibility. Your date of birth is stored in encrypted form and is never displayed to other users or shared with third parties. It is used for age verification and age-class routing, and the day and month alone are used to show your star sign and how it matches a companion's. The year is never used for that feature, and your date of birth itself is never shown to anyone.

Parental Contact

Parents or guardians who believe their minor child has created an account may contact safety@luvme.io. Upon verification, we will:

  • Immediately suspend the account
  • Delete all associated data within 24 hours
  • Confirm deletion via email

13. Changes to This Policy

If we make material changes to this Privacy Policy, we will provide at least 30 days' notice via email before the changes take effect. Continued use of the platform after the notice period constitutes acceptance of the updated policy.

Questions about your privacy?

Contact our privacy team at privacy@luvme.io