Privacy Policy
Version PRIVACY_POLICY_2026_09_18 · Effective September 18, 2026
This is the canonical Chatalystar Privacy Policy. Material updates receive a new version; prior acknowledgments are not rewritten.
1. Who controls your information
Chatalystar Corporation, 100 King Street West, First Canadian Place, Suite 5700, Toronto ON M5X 1C7, Canada, controls the processing described here. Contact privacy@chatalystar.com. We do not claim an appointed EU or UK representative in this policy.
Members must be at least 18. Human creators (“Stars”) must be at least 21. A public age declaration is not the same as independent identity or age verification.
2. AI and conversation contexts
- Fictional companions (“Muses”): fictional adult AI personas generate replies for the member using the current message and member-specific context.
- Human Mode: a real creator or an authorized person may author replies. Those people can access the applicable creator conversation history to communicate and manage the relationship.
- Simulated Presence: AI replies in a persona configured for a real creator. The applicable creator and authorized account staff can access that conversation history. One member’s private transcript or memory is not used to personalize another member’s conversation.
- Creator-private Memory Vault: notes are scoped to the creator, member, and applicable character relationship. Suggested notes may be extracted from the last 20 messages and existing creator-private notes for that same conversation. They are not shared with other members.
- ALY: ALY is a creator-only assistant, not a member companion. It may receive the creator’s question, recent ALY history, account and operational snapshots, the current portal-page context, and relevant support documents. ALY conversations and privacy-safe usage/session telemetry are retained in Chatalystar systems until deleted under the applicable account or purpose control. If a creator chooses support escalation, authorized support staff may receive the transcript so the creator does not need to repeat it. Starting a new ALY conversation resets the active thread context; it does not itself delete retained messages, session logs, or support records.
3. Processing by purpose
Generate a requested response
- Data involved
- The current message, bounded recent history, persona and system instructions, relationship state, and necessary account/context fields.
- Purpose
- Generate, deliver, and troubleshoot the requested companion or ALY reply.
- Recipients
- Chatalystar and the model route used for that request: the Replit AI Integrations/OpenAI-compatible route, OpenAI, OpenRouter and its selected upstream, or a configured Lambda/Kobold endpoint. A failed or empty primary call can be sent to OpenRouter for recovery.
- Retention
- Messages and responses remain in Chatalystar conversation records until a deletion or applicable purpose-withdrawal process removes unheld records. Provider logging, region, training, and deletion depend on the actual route and account settings; Chatalystar does not promise a universal provider retention period or zero-retention setting.
- Selected basis
- Performance of the requested service. Where the product presents AI conversation as an optional consent-controlled purpose, withdrawal stops new provider dispatch and removes covered unheld records.
Member-specific continuity
- Data involved
- Conversation history, summaries, relationship progress, preferences, and interaction state for that member.
- Purpose
- Continue the same member’s relationship and avoid treating each turn as a new conversation.
- Recipients
- Chatalystar, the applicable companion-response provider, and—on creator conversations—the applicable creator and authorized account staff.
- Retention
- Until the member deletes the account or covered data, withdraws an applicable purpose, or a narrow hold or retained obligation applies.
- Selected basis
- Performance of the requested service; consent where a specific optional control is presented.
Member memory and creator-private notes
- Data involved
- Member-provided facts, relationship notes, summaries, embeddings, and—for creator suggested notes—the same conversation’s last 20 messages and existing creator-private notes.
- Purpose
- Recall information for that member and relationship, or help the applicable creator maintain private relationship notes.
- Recipients
- Chatalystar, the applicable model provider for extraction or response generation, and the applicable creator for creator-private notes.
- Retention
- Until deleted or a memory-withdrawal cleanup removes covered records, unless a narrow legal or safety hold applies. A completed withdrawal removes covered memory and derived rows. The current control is a deletion control; this policy does not represent that every memory path first obtains affirmative purpose consent or is blocked solely by the absence of a consent record.
- Selected basis
- Performance of the member-requested continuity feature or creator note feature. Optional sensitive identity personalization has the separate consent described in Section 4.
Safety moderation and abuse response
Deterministic checks and contextual classifiers may identify messages that could indicate self-harm, suicide, or immediate danger. They can make mistakes, may miss signals, and are not a diagnosis. Restricted Safety Triage reviewers may access the minimum necessary evidence when a credible signal requires review. Creators, simulated personas, and authorized chat partners do not receive private crisis classifications merely because a conversation involves them.
Crisis-derived information is excluded from advertising, recommendations, rankings, unrelated analytics, shared-character development, and model training or development. Chatalystar does not provide continuous human monitoring, cannot guarantee detection or a response, and cannot dispatch emergency services or contact police, family, creators, or other third parties on a member’s behalf.
- Data involved
- Message text, uploaded media, reports, account and device/security signals, moderation verdicts, and limited evidence needed to investigate.
- Purpose
- Detect prohibited or harmful content, protect users and the Service, investigate reports, and meet applicable obligations.
- Recipients
- Authorized Chatalystar Trust & Safety staff and, depending on the material, OpenAI-compatible safety services or Sightengine. Media generation may also involve Replicate; voice generation may involve ElevenLabs.
- Retention
- Source content follows its account/content lifecycle. Verdicts, reports, security evidence, and held material may be retained separately while needed for safety, fraud, disputes, or legal obligations. Provider retention and immediate-delete settings are provider- and account-specific and are not represented as universally enabled.
- Selected basis
- Legitimate interests in safety, security, and enforcing the Service; legal obligation where a specific obligation applies.
Operational analytics
- Data involved
- Feature events, route and session measurements, usage counts, model/provider outcome and token metadata, device/browser/network information, and error telemetry. Prompt text is not intentionally stored in model-usage telemetry.
- Purpose
- Operate reliability, measure feature performance, prevent abuse, and understand service health.
- Recipients
- Chatalystar and relevant hosting/error/analytics services, including Replit, Sentry, Google Analytics, SearchAtlas, and Ahrefs where their scripts or services run.
- Retention
- Member-linked optional analytics is removed where supported after analytics withdrawal or account deletion; aggregate or narrow security/financial evidence may remain. Browser-provider retention depends on provider and deployed account settings.
- Selected basis
- Legitimate interests for necessary security and service-health measurement; consent for optional browser/product analytics where requested.
Age assurance and eligible-member administration
A self-reported date of birth is clearly labeled as self-reported and is not independent proof of age. Where a separate verification process supports it, verification status is recorded and displayed distinctly; verification does not turn a self-reported date into a creator- or member-visible profile field.
- Data involved
- Date of birth submitted by an eligible member during age assurance, together with the source designation and applicable notice or policy version. Underage submissions are not retained as raw dates of birth.
- Purpose
- Confirm the member's age boundary, administer the account, support authorized correction and privacy requests, and produce privacy-minimized demographic analysis using derived age bands rather than exposing exact dates broadly.
- Recipients
- Restricted, authorized age-assurance, account administration, privacy, and compliance personnel at Chatalystar. The exact date is not provided to creators, other members, ordinary analytics consumers, or public APIs.
- Retention
- Held in a restricted age-assurance record only while needed for those purposes and applicable retention rules. It is deleted or de-identified with account/privacy deletion when no legal, safety, fraud, accounting, or legal-hold obligation requires retention.
- Selected basis
- Age-assurance and account administration necessity, with the collection notice presented before submission; applicable legal obligation where required.
Public creator and member activity
- Data involved
- Allowlisted creator public-profile/activity fields (such as the public display name, avatar, rank, points, level, tier, and change where applicable) and an aggregate interaction metric. The public activity response does not contain conversations, member identities or IDs, or private member details.
- Purpose
- Display creator activity and discovery information without publishing the underlying member interaction or relationship.
- Recipients
- Public visitors through Chatalystar public pages/APIs and their delivery, CDN, browser, search, or other caching layers where those layers operate.
- Retention
- Creator activity remains public by default unless that creator uses the creator-specific opt-out. A member's setting is reversible; eligible existing members may be included in a corrective public migration without a new prompt, subject to the available setting. Public caches, search results, embeds, and other derivatives may remain until expiry or invalidation; Chatalystar does not promise instantaneous removal from every cache.
- Selected basis
- Public visibility defaults and the member/creator controls described in Section 5, subject to applicable law and authorized review; this description is not legal approval or a conclusion that publication is consent.
Product improvement
- Data involved
- Privacy-minimized feedback, error categories, aggregate usage, feature outcomes, and reviewed support evidence.
- Purpose
- Fix defects and evaluate product changes. This is separate from operating a current conversation.
- Recipients
- Authorized Chatalystar product, engineering, support, and analytics personnel and their operational providers.
- Retention
- According to the underlying record’s lifecycle and applicable withdrawal/deletion controls. Private conversation text is not designated for general product improvement or cross-user learning merely because it was submitted for a reply.
- Selected basis
- Legitimate interests in maintaining and improving the product, balanced against user rights; consent where optional analytics supplies the data.
Model or shared-character development
- Data involved
- Only data collected under a separate, explicit development authorization or data created for that purpose.
- Purpose
- Train, fine-tune, evaluate, or develop a model or character for use beyond the submitting member.
- Recipients
- Only the providers and authorized teams named when that separate program is offered.
- Retention
- As stated in that separate program. Chatalystar does not treat ordinary private member or ALY conversations as authorization for cross-user personalization, shared-character development, or model training.
- Selected basis
- Separate consent or another specifically documented basis—not this policy acknowledgment and not a generic “improve the Service” statement.
4. Optional identity personalization
Attraction, relationship preference, desired companion dynamic, and permission to reference sensitive identity signals are optional. Attraction information may reveal sexual orientation. If enabled, these values personalize only that member’s matching, recommendations, and companion responses. They are not used for advertising, unrelated analytics, cross-user learning, shared-character development, or model development.
Declining does not block ordinary membership. A member may withdraw at any time; withdrawal removes these sensitive values and derived personalization while preserving minimal append-only evidence of the choice. It does not erase ordinary profile choices such as archetype or gender identity, and it is not consent to sexual content.
5. Identity, payments, media, and public chains
Eligible member date of birth: Before an eligible member submits a date of birth for age assurance, Chatalystar explains that the self-reported date is retained in a restricted record for age assurance, account administration, privacy requests, correction and deletion handling, and privacy-minimized demographic analysis. Underage submissions remain minimized to derived block and unlock evidence and are not retained as raw dates. Independent verification, when available, is a separate designation and is not inferred from self-reporting.
Identity verification: Veriff receives legal name and hosted identity/verification media. Chatalystar may retain session and status data, legal name, identity hash, document country, nationality, age/identity outcome, and audit evidence. Exact Veriff retention, region, and subprocessor settings depend on the deployed plan.
Payments: Stripe, Coinbase Developer Platform/Onramp, and the legacy or conditional NOWPayments path receive the data needed for their payment flow. Chatalystar stores transaction, entitlement, subscription, reconciliation, wallet-address, and payment metadata. Full card details are handled by the payment provider.
Media: Wasabi and Replit Object Storage/Google Cloud Storage store app media. Depending on the feature, OpenAI-compatible services, Replicate, Sightengine, or ElevenLabs may also receive prompts, reference media, generated text/media, or voice configuration for generation or moderation.
Synthetic-media provenance: Chatalystar processes source-type labels such as AI-generated, AI-assisted, human-created, or source not verified, along with available creator or rights-holder authorization statements, transformation history, content hashes, Content Credentials or related metadata, moderation decisions, and reports about inaccurate provenance. These records support pre-exposure disclosure, rights management, abuse investigation, and enforcement. A label is not proof of identity, ownership, consent, or authenticity. Provenance and label records may remain with the media while needed for safety, disputes, rights management, security, or legal obligations.
Blockchain: wallet addresses, amounts, timestamps, and transaction hashes broadcast to Base or another public network are public and immutable. Chatalystar cannot erase or change a confirmed public-chain record. RPC providers may receive public wallet and transaction queries.
Communications and social: Resend processes recipient and email content for service and permitted marketing messages. Creator-authorized X features process public posts, mentions, account data, drafts, posting metadata, and direct messages. Chatalystar imports and stores X DM text, participant names/usernames, profile images, identifiers, timestamps, and outgoing replies so the creator can use the unified inbox; creator-authored or templated outgoing DM text is sent back to X. The current inbox code does not send X DM text to a drafting model. Separately, X mention/reply text, author details, parent-post context, and creator persona examples may be sent to OpenRouter and its selected upstream to generate social reply drafts. Neither social drafting path receives unrelated private member-companion conversations.
Public creator and member activity: Public activity uses only allowlisted public fields such as a creator's public display name, avatar, rank, points, level, tier, and change where applicable, together with an aggregate interaction metric. Creators are public by default and may use a reversible creator-specific opt-out. Member onboarding presents an explicit neutral choice between “Public Leaderboard Display” and “Keep My Ranking Hidden”; the member setting is reversible, and an eligible existing-member population may be included in a corrective public migration without a new prompt. This public surface contains no conversation text or transcripts, member names/usernames/IDs or other member identity, private preferences, relationship details, payment or wallet data, verification data, private media, or other private member details. Suspended, deleted, blocked, ineligible, unavailable, or otherwise excluded records are filtered from public responses. Public responses may be cached by browsers, CDNs, search services, embeds, or other delivery layers; a setting change or exclusion is not represented as instantaneous removal from every cached or indexed copy.
Location and public-source outreach: IP geolocation services, including ip-api.com and Country.is where configured, may receive an IP address to estimate country or city for security, eligibility, or localization. Some older integrations can use unencrypted provider transport even when the member-facing site uses HTTPS. Apify may process publicly available creator or business profile and contact information for authorized outreach operations. These paths are separate from private companion conversations.
Operational logs: application and provider diagnostics can contain request identifiers, provider responses or error bodies, account references, network data, and verification/payment status details. Access is restricted to authorized operational personnel, but provider payload minimization and log retention vary by path; users should not assume that every provider error is free of personal information.
6. International processing and security
Chatalystar is based in Canada. Providers and their subprocessors may process information in Canada, the United States, and other countries where they operate. The actual location varies by provider, model route, account setting, and subprocessor. Where required, Chatalystar uses an applicable contractual or other transfer mechanism; this policy does not claim that one mechanism applies to every transfer.
We use access controls, password hashing, encrypted member-facing transport, and provider/storage safeguards. Some older provider-to-provider paths may not support encrypted transport, as disclosed above. No networked system is completely secure. Do not put passwords, private keys, government ID numbers, or unnecessary financial or highly sensitive information in chat.
7. Retention, deletion, and withdrawal
- Member deletion: the account is locked and ordinary profile/authentication fields are de-identified. Unheld conversations, memory, derived relationship/preference data, member-linked analytics, private generated content, and owned media are deleted or queued for retry. The status can be completed, partial, blocked, or retry; the Service does not report success while a tracked deletion target is unresolved.
- Creator deletion: the creator is hidden and sessions are invalidated when deletion is requested. A 30-day cancellation period normally precedes purge. Paid-entitlement preservation, legal holds, or failed media cleanup can delay or limit destructive deletion.
- Narrow retention: payment, entitlement, tax/accounting, identity/age verification, fraud/security, moderation, wallet provenance, consent/acknowledgment evidence, and legal-hold records may be restricted and retained when needed. They are not reused for personalization, marketing, or new AI processing after deletion.
- Eligible DOB records: an eligible member's self-reported date of birth is restricted to authorized age-assurance, account-administration, privacy, and compliance access. Members may request correction or deletion through the authenticated controls where available or by contacting privacy@chatalystar.com. Existing members without a retained eligible date are not backfilled or reconstructed from historical events.
- Backups: live deletion does not rewrite immutable disaster-recovery snapshots. Snapshots have a measured 90-day retention horizon and are removed by scheduled age-based pruning, subject to successful storage access and a documented narrow hold or obligation.
- Providers: local deletion does not erase public blockchain records. Chatalystar’s current deletion workflow does not provide universal downstream deletion across providers. Provider-held records may remain under provider-controlled retention, legal, security, backup, fraud, or account settings even after local records are deleted.
- Withdrawal: member controls separately cover personalization, analytics, marketing, AI conversation, memory, and public activity where that control is available. AI-conversation withdrawal blocks new model dispatch; other controls delete covered unheld local data where implemented. Public activity settings are reversible, and creators have a separate reversible public-activity opt-out. A corrective migration of eligible existing members may occur without a new prompt and does not make the setting irreversible. Memory withdrawal currently removes covered memory records but is not represented as an affirmative-consent gate across every extraction path. A hold or transient cleanup failure can produce a blocked or retry result. Public caches, search indexes, embeds, and other derivatives may require expiry or invalidation and are not promised to disappear instantly. Necessary transactional communications are separate from marketing.
8. Your choices and requests
Depending on your location, you may request access, correction, deletion, restriction, objection, or portability, and may complain to your local privacy regulator. These rights can have exceptions. Use the authenticated account controls where available or email privacy@chatalystar.com. We may verify a request through an authenticated channel and will explain any partial, blocked, or retained category.
Chatalystar does not sell private conversation content. Optional marketing and analytics choices are controlled separately from using the core Service.
9. Policy versions and acknowledgment
Policy acknowledgment means you were shown a particular version; it is not consent to every processing purpose. Chatalystar records policy acknowledgments append-only with the version, time, and source evidence. Terms acceptance, Privacy Policy acknowledgment, and purpose-specific consent are separate events. Withdrawing optional consent does not rewrite a prior policy acknowledgment.
For a material update, we publish a new version and may ask you to acknowledge it. We do not silently change the version attached to historical evidence.