Euphor.

Privacy Policy

Last updated 20 August 2026

In short. We store your email, a hash of your password, your conversations and your credit history. We never see your card number. We do not sell anything to anyone, and you can have all of it deleted by asking.

1. Who is responsible

Theo, of N2552 Co Rd C, Medford, WI 54451, is the controller of personal data collected through Euphor. Contact us at [email protected].

2. What we collect

WhatWhyKept for
Email address To identify your account, send receipts and answer support Until you delete your account
Password (hashed, never stored in readable form) To let you sign in Until you delete your account
Your conversations and the characters you create To provide the Service — a chat app has to remember the chat Until you delete them or your account
Images you generate or upload To show them to you in the conversation Until you delete them or your account
Credit ledger — purchases, grants and what was spent To run your balance and meet accounting and tax obligations As long as the law requires, typically 6–7 years
Your age confirmation To record that we asked and you asserted you are an adult Until you delete your account
Basic technical logs — IP address, timestamps, errors Security, fraud prevention and keeping the service up Typically 30 days

What we do not collect

We do not receive or store your card number, CVV or bank details. Payments are handled entirely by our payment processor, who sends us only the fact that a payment succeeded and which pack it was for.

We do not use advertising trackers, we do not build advertising profiles, and we do not run third-party analytics that identify you.

3. Legal bases

Where the UK GDPR or EU GDPR applies, we rely on: contract — to give you the service you signed up for; legal obligation — for tax, accounting and age-related records; and legitimate interests — for security, fraud prevention and keeping the service running, balanced against your rights.

4. Who we share with

We do not sell personal data, and we do not share it for anyone else’s marketing.

5. Where your data is processed

Conversations are processed on infrastructure we control. Image generation may run on rented compute located outside your country, including outside the UK and EEA. Where data leaves the UK or EEA we rely on appropriate safeguards such as the UK International Data Transfer Agreement or EU Standard Contractual Clauses.

6. Your rights

Depending on where you live you may have the right to access, correct, delete, restrict or object to our use of your data, to receive a copy in a portable format, and to withdraw consent where we rely on it.

To exercise any of these, email [email protected] from the address on your account. We respond within 30 days. You can also complain to your data protection regulator — in the UK, the Information Commissioner’s Office at ico.org.uk.

Deleting your account

Ask at [email protected] and we will delete your account, conversations, characters and images. We keep the minimum transaction record the law requires us to keep, and nothing more.

7. Cookies

We use one strictly necessary cookie to keep you signed in. We store your age confirmation in your browser’s local storage so we do not have to ask on every visit. We do not use advertising or cross-site tracking cookies, so there is nothing here to consent to or refuse.

8. Security

Passwords are hashed with a slow, salted algorithm and are never stored or transmitted in readable form. Access to production data is limited to those who need it. No system is perfectly secure, and we will tell you and the relevant regulator promptly if a breach affects you.

9. Children

The Service is strictly for adults. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, tell us at [email protected] and we will close it and delete the data.

10. Changes

If we change this policy materially we will say so in the app or by email before the change takes effect.