AI Bestie — Privacy Policy

Last updated: September 13, 2026

AI Bestie ("the App", "we") is your personal AI companion, built to be privacy-first. In plain terms: your conversations are not stored on our servers, we never use them to train AI models, and you are never tracked across apps or sold to anyone. Your history, memories, journal, and meeting transcripts live on your device. This policy explains the little that is necessarily processed to make the App work, the few places data does leave your phone, and the controls you have over all of it.

1. What We Never Do

The one marketing use of your data is email you ask for: if you turn on "Product news and tips", your email address is passed to our own customer-relationship system so we can send it. That is described in Section 5, and one tap turns it off.

2. How Cloud Answers Work (transient processing)

AI Bestie is a cloud AI companion, so to answer you the App must send your message to an AI provider and get a reply back — the same way any AI app works. This is processing to serve you in the moment, not collection: we do not keep it.

3. Recording Conversations With Other People

Meeting Mode records and transcribes everyone who speaks, not only you. Before your first recording the App shows a notice you have to accept, because recording other people carries obligations that are yours, not ours.

We are not able to obtain the other participants' consent for you, and we do not monitor whether you did. If you record people without telling them, that is your responsibility, not a feature of the App.

4. Your Account

You sign in with an email address, or with Sign in with Apple or Google (handled by our authentication provider, Clerk). If you use Sign in with Apple and choose to hide your email, we only ever see Apple's relay address. We keep your email address to secure your account, remember your subscription, and let you restore access on a new device. We do not use it for advertising, and we only send you marketing email if you ask us to (Section 5). You can delete your account and your email at any time (Section 11).

So our servers can tell a real install of the App from anything else, the App registers a device token the first time it runs. It is derived from a random ID created on your phone and stored only as a one-way hash — it is not your phone number, advertising ID or hardware serial. On iPhone we may also use Apple's App Attest to confirm requests come from a genuine copy of the App. We use the token to authenticate requests, count usage against fair-use limits, and prevent abuse.

5. Email From Us

We send two kinds of email. Service email — receipts, security notices, password resets — comes with the account and cannot be switched off while your account exists. Product news and tips is marketing, and it is off unless you turn it on in Privacy & Permissions.

6. Subscriptions

Bestie Pro is sold through the Apple App Store / Google Play and managed via RevenueCat. Purchases are processed by the app stores — we never see your card details. We store only your subscription status (active/free) so the App can unlock Pro features. You manage or cancel your subscription in your App Store / Google Play account.

If you use refer-a-friend, we record which code was used and whether it earned a reward, so the reward can be applied. We do not contact the person you referred.

7. Service Providers That Process (not store) Your Requests

To run the App we rely on the providers below. AI providers process your request in the moment to return a reply; we do not send them your identity, and your API keys are never in the app binary (all calls go through our backend proxy). None of these are used to build a profile of you.

None of these providers' terms allow them to use your content to train their models. We deliberately do not use AI services, such as free tiers from some providers, whose terms would allow that.

8. Reports and Diagnostics

We do not keep copies of your conversations to improve the App. Two small things do reach us, both so we can fix problems:

9. Permissions

10. Data Retention

Conversations are session-based on our servers and not retained after your reply. On-device data — history if enabled, memories, journal, meeting transcripts — stays until you delete it, and you can set a memory auto-delete window in Settings. Account and subscription records are kept while your account exists and are deleted with it. Content reports and error diagnostics (Section 8) are kept only as long as we need them to review the report or fix the problem. Marketing consent records are kept for as long as we rely on them, plus a short period afterwards as proof the consent was given.

11. Your Rights & Controls

Wherever you live, you can use every control below. If you are in the UK, EU, or a US state with a privacy law (California, Colorado, Connecticut, Virginia, Texas, Oregon, Montana, and others), you also have the legal rights listed underneath.

Your legal rights: access, correction, deletion, a portable copy, and the right to object to or restrict processing. Where we rely on your consent you can withdraw it at any time without affecting what came before. You will never be treated differently for exercising a right. You can appoint someone to make a request for you, and you can appeal a decision by replying to our refusal — we will respond with reasons. You also have the right to complain to your data protection authority (in the UK, the ICO; in the EU, your national supervisory authority).

We do not sell personal data and do not share it for cross-context behavioural advertising, so there is nothing to opt out of and no need for a "Do Not Sell or Share" link. We honour Global Privacy Control signals on our website. We do not use your data for automated decisions that produce legal or similarly significant effects, and we do not profile you for advertising.

To make a request, use the in-app controls above or email us at the address in Section 16. We will verify a request through the email address on your account and respond within the time your law allows (one month in the UK/EU, 45 days in the US states, extendable where permitted).

12. Why We Are Allowed To Process Your Data

For users in the UK and EU, our lawful bases under the GDPR are:

Where you choose to tell Bestie something that counts as special category data — about your health, beliefs or sex life — we rely on your explicit consent. It is stored only on your device, but like any message it is sent to an AI provider in the moment to generate a reply, and is not retained by them or by us.

13. Where Your Data Is Processed

Our servers and the providers listed in Section 7 are located primarily in the United States. If you are in the UK or EU, that means your data is transferred outside your country. Where it is, the transfer is covered by the European Commission's Standard Contractual Clauses (and the UK Addendum), together with technical safeguards including encryption in transit. You can ask us for details of the safeguards that apply to you.

14. Children

The App is not for children. You must be at least 13 to use it, and at least 16 in countries where that is the age of digital consent (including Germany, the Netherlands, Ireland and others) unless a parent or guardian consents on your behalf. We do not knowingly collect data from anyone below that age, we do not advertise to children, and we do not target the App at them. If you believe a child has used the App, contact us and we will delete the account and any associated data.

15. Changes to This Policy

We may update this policy as the App evolves. We will update the date above and, for material changes, notify you in the App and ask you to accept the change before continuing.

16. Contact

Questions, requests, or complaints about your privacy? Email sugar.raymond110@outlook.com and we will respond within the time your law allows. We are the controller of the data described in this policy.