1. Introduction
OpenChar ("OpenChar", "we", "us", or "our"), operated by OpenChar Ltd, a private company limited by shares registered in the Republic of Cyprus (registration No. HE 174641), with its registered office at 16 Stasikratous Street, 1065, Nicosia, Cyprus, provides a platform for creating AI characters, chatting with them, and generating AI images, including age-restricted (18+) features.
This Privacy Policy describes what personal data we collect, how and why we use it, with whom we share it, how long we keep it, and what rights you have. It applies to the website at openchar.app, the Telegram Mini App, and associated services (collectively, the "Platform").
This Policy is part of our Terms of Service. An overview: our main legal bases are the performance of our contract with you (providing the service), our legitimate interests (security, moderation, service improvement), your consent (optional cookies, marketing, 18+ features), and legal obligations.
If you do not agree with our practices, please do not use the Platform.
Important note about sensitive content. Chat messages and images you exchange with AI characters may contain personal and intimate information. You decide what to write. We process this content to provide the service and to keep the Platform safe, as described below. Please do not enter information you would not want to be processed in this way.
2. Definitions
- "Account" — the account through which you use the Platform: a guest account, an email account, or a Telegram account.
- "Content" — characters, character cards, personas, chats, messages, prompts, images, and other materials you create, upload, or generate on the Platform.
- "Personal Data" — information relating to an identified or identifiable person.
- "Usage Data" — technical and behavioral data collected automatically through your use of the Platform.
- "AI Providers" — third parties that provide large-language-model and image-generation services used to produce AI responses and images.
3. What Data We Collect
3.1 Data you provide directly
| Category | Examples |
|---|---|
| Account / identity | Email address and password (email accounts); Telegram user ID, username, profile name, and avatar (Telegram sign-in); automatically generated guest identifier |
| Profile data | Display name, avatar you upload, language and interface preferences (e.g., UI locale), gender/personas you create |
| Content | Characters and character cards you create or publish, personas, chat conversations and messages you write, prompts, generated and uploaded images |
| Payment data | Purchase amounts, transaction records, subscription and token-balance history. We do not store full card numbers; payment data is handled by our payment providers |
| Communications | Support requests, reports you submit about content or users |
3.2 Data collected automatically
- Usage Data: pages visited, features used, chats opened, images generated, token transactions, referrals, UTM and referrer parameters.
- Device / network data: IP address, browser type and version, operating system, device type, language, approximate location derived from IP.
- Log data: server logs of requests to the Platform (timestamps, URLs, status codes, error logs).
3.3 Cookies and similar technologies
We use cookies and similar technologies in the following categories:
| Category | Purpose | Requires consent |
|---|---|---|
| Strictly necessary | Authentication and sessions, security (CSRF), automatic guest provisioning, load balancing | No — but we inform you |
| Functional | Remembering your interface settings (e.g., language, theme) | Opt-in / manageable |
| Analytics | Understanding how the Platform is used (see Section 7, Analytics) | Yes |
We currently use PostHog for product analytics, proxied through our own domain. Analytics technologies are activated according to your cookie preferences: where consent is required by your jurisdiction, they are not activated until you accept them, and you can change or withdraw your choice at any time via the cookie preferences control on the Platform.
Details of individual cookies are maintained in our Cookie Policy.
4. How and Why We Use Your Data
4.1 Providing the Service (contract). Creating and maintaining your account; authenticating you (including guest auto-provisioning and Telegram sign-in); storing your characters, chats, and images; transmitting prompts and context to AI Providers to generate responses and images; storing generated content (including at third-party object storage and delivering it via CDN); operating your token balance and transactions; subscription and payment processing.
4.2 Safety and moderation (legitimate interests / legal obligations). Enforcing our Terms of Service and Content Rules; detecting and preventing illegal content (Section 12), fraud, abuse, spam, and security incidents; rate limiting; moderation of characters and images, including automated scanning and human review.
4.3 Service improvement and analytics (legitimate interests / consent). Understanding feature usage and performance to improve the Platform; generating aggregated, de-identified statistics.
4.4 Communications (contract / consent). Service and security notices (e.g., account, billing, security incidents) — always. Marketing communications — only with your consent; you can opt out at any time.
4.5 Legal compliance (legal obligation). Responding to lawful requests from authorities; retaining records where required (e.g., payment and accounting records); disclosing data as described in Section 9.
5. Legal Bases (EEA/UK users)
Our processing relies on the following legal bases under GDPR:
- Performance of a contract — providing and operating the Platform (Art. 6(1)(b)).
- Legitimate interests — security, fraud and abuse prevention, moderation, analytics necessary for the service, service improvement (Art. 6(1)(f)). We balance these interests against your rights and freedoms.
- Consent — optional (non-essential) cookies, marketing communications, 18+ features age confirmation (Art. 6(1)(a)). Consent-based processing stops when you withdraw consent without affecting its past lawfulness.
- Legal obligation — accounting, tax, law-enforcement requests (Art. 6(1)(c)).
6. AI Processing and Third-Party Providers
This section describes the data flows specific to an AI platform.
6.1 AI Providers. When you chat with a character or request an image, your prompt, relevant character definition, and chat context are transmitted to our AI Providers to generate the response or image. We use:
- OpenRouter (and the upstream model providers it routes to) for text generation;
- Runware for image generation.
These providers receive your chat content and prompts as needed to fulfill generation. Depending on the provider's terms, prompts and outputs may be logged or otherwise processed on their side. We do not send your account email, phone, or payment data to AI Providers.
6.2 Managing the AI layer. We do not currently use your chats or images to train our own models. If this changes in a material way, we will update this Policy and, where consent is required, obtain it before such use.
6.3 Hosting, database, and storage. The Platform runs on third-party infrastructure that may process (but does not own) your data: Vercel (hosting and edge network), Neon / PostgreSQL services (database), Upstash Redis (rate limiting and caching), Backblaze B2 (object storage) and BunnyCDN (content delivery of public and private media), Vercel Blob (temporary file storage).
6.4 Analytics. PostHog receives usage events (page views, feature actions, and certain error events) and associated identifiers (e.g., anonymous ID, user ID, approximate location) as configured in the Platform.
6.5 Messaging. If you use the Telegram Mini App, Telegram processes your interactions with our bot/Mini App. Telegram transmission is protected by Telegram's own infrastructure; we validate and use only the initData fields needed for authentication (Section 3.1).
6.6 Payments. Payment processing is handled by our payment providers (see Section 8). Details are disclosed before each purchase.
7. Analytics
We use PostHog to understand how the Platform is used and which features work. Events may include: character views, chat creation, message counts, image generations, purchases, feature interactions, and error events. We seek to keep analytics at the level of aggregate product insight; we do not use analytics data for advertising, and we do not sell analytics data. Where your jurisdiction requires prior consent for analytics (EEA/UK), analytics is treated as an optional cookie category per Section 3.3.
8. How Long We Keep Your Data
We retain Personal Data only as long as necessary for the purposes described above:
| Data | Retention |
|---|---|
| Account data | For the lifetime of your account; deleted after account deletion unless legally required otherwise (Section 11.2) |
| Chats and messages | For the lifetime of your account, or until you delete a chat |
| Characters, images, personas | For the lifetime of your account, or until you delete them; deleted published content may be retained in backups for a limited period |
| Generated content in permanent storage | Until deletion of the underlying content or account |
| Token transactions | As required by law (typically up to 10 years for accounting records); transaction records may be shortened after that period |
| Server / security logs | Up to 30 days, unless needed for an ongoing investigation |
| Analytics data | Per PostHog retention settings, typically up to 12 months |
Some records may be retained after account deletion for account-recovery, security, fraud-prevention, legal, or dispute-resolution purposes, as described in Section 11.
9. How We Disclose Data
We may share data:
- with service providers listed in Section 6, each processing data only as necessary to provide its function;
- with payment providers to process purchases (it receives the data required for the transaction);
- in a business transfer — if we are involved in a merger, acquisition, reorganization, or sale of assets, data may be transferred to the successor entity;
- to legal authorities — when we believe in good faith that disclosure is required by applicable law, legal process, or governmental request, to enforce our Terms, to protect the safety of users or the public, to detect fraud, or to protect our rights;
- with your consent — for other purposes, with your explicit consent.
We do not sell your Personal Data.
10. International Data Transfers
Our infrastructure providers process data in data centers that are primarily located in the European Union, the United States, and other regions. Some providers (e.g., AI model routing, CDN, analytics) may process data outside your country of residence.
Where Personal Data is transferred from the EEA/UK to a country without an adequacy decision, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses (SCCs) with our providers — together with supplementary measures where required.
Data related to AI generation may be processed by AI Providers in various jurisdictions under our contracts. We aim to keep the platform's primary storage within the EEA wherever possible.
11. Data Security, Deletion, and Account Deletion
11.1 Security measures. We implement technical and organizational measures, including encryption in transit (HTTPS), access controls, rate limiting, secure development practices, and separate production / test environments. No method of transmission over the Internet is completely secure; we cannot guarantee absolute security, but we take the protection of your data seriously.
11.2 Account deletion. You can delete your account at any time through account settings or by contacting support@openchar.app. Upon deletion:
- your account is deactivated first; within a grace period you may restore it by signing in;
- after permanent deletion, your characters, chats, and personal data are removed from production systems, in line with Section 8;
- some records may be retained (as described in Sections 8 and 10) for legal, security, fraud, or dispute purposes.
11.3 Refusal is protected. Where processing is based on consent rather than necessity (Section 5), you may refuse or withdraw consent without losing access to the main features of the Platform.
12. Children's Privacy
The Platform is not intended for persons under 18. We do not knowingly collect Personal Data from persons under 18. If we learn that a person under 18 has registered or provided data, we will promptly delete their account and Personal Data. If you believe we have data from a person under 18, contact support@openchar.app immediately.
We also do not knowingly include personal information of children in content: any attempt to sexualize or depict minors (real or drawn) is strictly prohibited on the Platform (see Terms of Service, Section 7).
13. Third-Party Links
The Platform may contain links to third-party services or websites not operated by us (e.g., character sources, external documentation, social links). This Policy does not apply to third-party services; their own policies govern. We are not responsible for their content, policies, or practices.
14. Do Not Track
Some browsers transmit "Do Not Track" signals. There is no common standard for interpreting them; our Platform does not currently respond to DNT signals. You can manage tracking via browser settings and our cookie preferences control.
15. Your Rights
Depending on your jurisdiction, you may have the following rights:
General rights (EEA/UK under GDPR; analogous rights elsewhere):
- Access — obtain information about the Personal Data we hold about you;
- Portability — receive a copy in a structured, commonly used, machine-readable format;
- Correction — correct inaccurate or incomplete Personal Data;
- Deletion (erasure) — request deletion of your Personal Data (Section 11.2);
- Restriction and objection — restrict or object to certain processing (e.g., based on legitimate interests);
- Withdrawal of consent — withdraw consent at any time without affecting the lawfulness of prior processing;
- Complaint — lodge a complaint with your local supervisory authority.
California (CCPA/CPRA). Californian residents have rights to know, delete, correct, and opt out of "sharing" personal information. We do not sell personal information as defined under CCPA/CPRA and do not knowingly share it for cross-context behavioral advertising.
Exercising your rights. Contact support@openchar.app. Identity may be verified where necessary. We will respond within the timeframe required by applicable law (typically 30 days under GDPR).
Marketing emails. You may opt out of marketing communications using the unsubscribe link in each email or by adjusting your account settings. Essential service notices (security, billing, account) are always sent.
16. Changes to This Policy
We may update this Policy over time to reflect changes in our practices, services, technologies, or law. When we make material changes, we update the "Last Updated" date and post the new version on the Platform; for significant changes we may additionally notify you in-app or by email, and, where required by law, request consent for materially changed processing before it takes effect. Your continued use of the Platform after the effective date of the updated Policy constitutes acceptance of it, to the extent permitted by law.
17. How to Contact Us
- General support: support@openchar.app
- Privacy inquiries and data requests: support@openchar.app
- Data controller: OpenChar Ltd - registered office: 16 Stasikratous Street, 1065, Nicosia, Cyprus; reg. No. HE 174641
We will make every effort to respond to your inquiry within a reasonable timeframe and in accordance with applicable law.