• EN
    check icon
  • DE

The AI Girl – Privacy Policy

Last updated: 28 August 2026

This Privacy Policy explains how ONLYAI LIMITED, Room 5003, 5/F, Yau Lee Centre, 45 Hoi Yuen Road, Kwun Tong, Hong Kong ("Company", "we") processes personal data in the AI Girl application and websites (the "Service"). We are the data controller for this processing. Contact: info@onlyai.ltd (privacy) · support@theaigirl.ai (support).

1. Data we collect

Account data: email address, nickname, stated age/date of birth, password hash, authentication identifiers.

Conversations: your chats with AI characters are stored so that characters keep memory and context. Conversation summaries may be generated and stored for the same purpose.

Reference photos: photos you upload to create a character (up to 3 per reference). These photos depict a face and body and therefore contain personal data of the depicted person; see Sections 3 and 4.

Facial-feature data (biometric information): numerical representations of facial features (face geometry / embeddings and related measurements) that our systems derive from your reference photos and — if you use verification — from your verification selfie. See Section 4.

Verification data: if you verify a reference ("this is me"), a short liveness selfie-check is performed and compared against your reference photos using Amazon Rekognition. We store the verification result (pass/fail, session ID, timestamp).

Generated content: images and other media generated for your characters, and their moderation classifications.

Purchase data: subscription status, coin balance and transactions, store receipts. Payment card details are processed by Apple, Google, or Stripe — we do not receive full card numbers.

Device and usage data: device identifiers, platform, IP address, approximate location derived from IP, app events, crash and performance logs, attribution of the ad campaign that led to your install.

Support data: messages you send to support, and reports you file about content.

2. What we use data for

  • Provide the Service: accounts, chat with persistent memory, character creation, media generation, subscriptions (contract performance).
  • Process reference photos to create and maintain your characters (see Sections 3–4).
  • Verify identity/liveness for photo-based features.
  • Safety and moderation: automated and human review of text and images to detect content prohibited by our Terms of Use, including content involving minors and non-consensual likeness use (legitimate interests; legal obligation for CSAM reporting).
  • Prevent fraud and abuse, secure our infrastructure (legitimate interests).
  • Measure and improve the Service, including advertising-campaign attribution (legitimate interests / consent where required).
  • Comply with law, respond to lawful requests, establish and defend legal claims (legal obligation / legitimate interests).

We use your content only to operate the Service. We do not sell your content, and we do not use your photos or conversations to train AI foundation models. We may use de-identified, aggregated data to improve our systems.

3. How reference photos are processed

When you create a character from photos, the following happens:

  1. Uploaded photos are automatically screened for prohibited content before acceptance.
  2. Photos are stored on our servers and linked to your account.
  3. Automated systems analyze the photos to determine attributes such as style (realistic/anime) and apparent age category, and to derive the facial-feature data described in Section 4.
  4. Your photos and the derived facial-feature data are used as a visual reference that guides our image-generation systems, so that generated images of your character resemble the person depicted in your photos and stay consistent across generations.
  5. Generated images are automatically classified for content safety before being shown.

Steps 1, 3 and 4 involve the service providers listed in Section 6, acting on our documented instructions.

4. Biometric information notice

Some of the data described above — facial geometry and facial-feature embeddings — may qualify as biometric data / biometric information under laws such as the EU/UK GDPR (Article 9) and the Illinois Biometric Information Privacy Act (BIPA). For this data:

  • Purposes. We process facial-feature data only to (i) guide image generation and keep your character visually consistent, (ii) perform the optional "this is me" verification you request, and (iii) detect violations of our Terms.
  • Notice and consent. This processing happens only when you choose to upload reference photos or start verification, after being informed through this Policy and the Terms of Use (Section 5). By uploading photos or starting verification you consent to it. You may decline by not using photo features — character creation without photos remains available.
  • No sale. We do not sell, lease, trade, or otherwise profit from biometric data.
  • Disclosure. Biometric data is disclosed only to the processors listed in Section 6 as needed for the purposes above, or where required by law.
  • Retention and destruction. Facial-feature data and reference photos are permanently destroyed when the purpose of collection is fulfilled, and in any event upon the earlier of: (i) your deletion of the reference or your account, (ii) your verified deletion request, or (iii) three (3) years after your last interaction with the Service.
  • Security. We protect biometric data using at least the reasonable standard of care applicable to confidential information (Section 9).

5. Photos that depict other people

You may upload a photo of another person only with that person's explicit consent (see Terms of Use, Section 5). We rely on your confirmation of that consent; providing notice directly to the depicted person is not possible for us because we have no contact with them.

If you are depicted in content on the Service without your consent, contact us via the Report an Issue page or support@theaigirl.ai. We restrict the content upon complaint, require the uploader to evidence consent, remove the content permanently if they cannot, and remove reported non-consensual intimate imagery within 48 hours. Depicted persons may exercise the rights in Section 8 with respect to their data, including deletion of photos and derived facial-feature data.

6. Processors and recipients

We share personal data with processors acting on our instructions:

ProviderPurposeDataLocation
GPU hosting providers operating our image-generation serversAI image generationReference photos, promptsEU (France)
OpenRouter, Inc. (routing to Google Gemini models)Photo attribute analysis, content-safety classification, chat AIPhotos (by link), chat messagesUSA
Amazon Web Services — RekognitionLiveness check and face comparison for verificationVerification selfie, reference photosUSA (us-east-1)
ElevenLabsVoice generation for callsText to be voicedUSA
Apple / Google / StripePayments and subscriptionsPurchase dataUSA/global
Google FirebasePush notifications, app infrastructureDevice identifiersUSA/global
SingularInstall attribution and campaign measurementDevice identifiers, install eventsUSA
Hosting and infrastructure providersRunning the ServiceAll of the aboveEU

We may also disclose data: to competent authorities where the law requires it (including mandatory reporting of child sexual abuse material to NCMEC); to rights holders' representatives in the course of a substantiated likeness or copyright complaint (limited to what the complaint requires); and to a successor in a merger or acquisition under this Policy.

We do not sell personal data. We may share limited device identifiers with advertising-attribution partners to measure ad campaigns; you can opt out of tracking in your device settings (e.g., iOS App Tracking Transparency) or by contacting info@onlyai.ltd.

7. International transfers

We are established in Hong Kong and use providers in the EU and the USA. Where data of EU/UK residents is transferred outside the EEA/UK, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) or other lawful transfer mechanisms with each provider.

8. Your rights

Depending on your location (including under the GDPR, UK GDPR, and California CCPA/CPRA), you have the right to: access your data and obtain a copy; correct it; delete it; port it; restrict or object to processing; withdraw consent (including consent to biometric processing) at any time without affecting past processing; and not be discriminated against for exercising rights.

To exercise rights: use the in-app account settings, or email info@onlyai.ltd from your account email. We verify each request (we may ask you to confirm control of the account email) and respond within one month (GDPR) or 45 days (CCPA), extendable as the law allows. Authorized agents may act for you under CCPA with proof of authorization. If we refuse a request, we explain why and you may appeal by replying to our decision.

You may also complain to a supervisory authority: your local EU data-protection authority, the UK ICO, the Hong Kong PCPD, or your state attorney general.

California notice. Categories collected (see Section 1): identifiers; commercial information; internet activity; approximate geolocation; audio/visual information (photos, generated media); biometric information; inferences. We collect them from you and your devices for the purposes in Section 2, disclose them to the processors in Section 6, and retain them per Section 10. We do not sell personal information and do not knowingly process data of consumers under 18. We limit use of sensitive personal information (photos, biometric data) to providing the services you request and safety purposes.

9. Security

We use encryption in transit, access controls, isolation of storage, and logging. No system is perfectly secure; we will notify you and the competent authority of personal-data breaches where the law requires.

10. Retention

DataRetention
Account dataLife of the account; deleted or de-identified after account deletion
Conversations and summariesWhile the account exists; deleted or irreversibly de-identified upon account deletion
Reference photos and facial-feature dataUntil you delete the reference or account, or upon verified deletion request; at the latest 3 years after your last interaction (Section 4)
Verification selfies and liveness dataProcessed for the verification session; we retain the verification result (pass/fail)
Generated mediaUntil you delete the character or account
Purchase and transaction recordsAs required by tax and accounting law (typically 7 years)
Technical logsFor a limited period for security and diagnostics, then deleted or anonymized
Data related to violations, legal claims, or mandatory reportsFor the duration of the matter and applicable limitation periods

Backups are purged on a rolling schedule after the primary copy is deleted.

11. Children

The Service is strictly for adults 18+. We do not knowingly collect data from anyone under 18; if we learn that a user is under 18, we terminate the account and delete the data. Content involving minors is removed and reported as described in our Terms of Use.

12. Changes

We will post any changes to this Policy here and, for material changes, notify you in the app or by email before they take effect. The "Last updated" date shows the current version.