Legal

Privacy Policy

Last updated: 19 August 2026

1. Who we are

Flirtly is operated by Operator — to be confirmed before launch. For users in the European Union, our representative is EU representative — to be confirmed before launch. This is an 18+ service; we do not knowingly process data of anyone under 18.

2. The short version

Flirtly is designed so that we hold as little real identity as possible:

  • Accounts are pseudonymous: email and password, no real name required.
  • Payment identity lives at our payment processor; we hold tokens, not card data.
  • Age-verification identity lives at the verification vendor; we hold a boolean result.
  • We never receive identity documents, document numbers, names from ID, dates of birth, face scans or biometric data — in any table, log, backup or error report.

3. What we process and why

  • Account data — email, password hash, the display name you choose, session and device information. Basis: performance of the contract.
  • Content — chat messages, character descriptions, generated images and video, and memories. Basis: performance of the contract and your explicit consent.
  • Safety data — classifier verdicts, refusal logs and reports. Basis: legal obligation and legitimate interests in service integrity.
  • Age attestation — timestamp, IP-derived country and region, method and a user-agent hash. Raw IP addresses are kept for no more than 30 days. Basis: legal obligation.
  • Payment events — handled by the processor. Basis: performance of the contract.

4. Special-category data and consent

Using Flirtly reveals sexual-life data, which is a special category of personal data under the GDPR. We process it on the basis of your explicit consent, given at signup separately from these terms. You may withdraw consent at any time (see section 9); withdrawal does not affect processing already done.

5. Who receives data

  • AI generation provider. Prompts and generated content are sent to a machine-learning provider based in Singapore, which produces the images and video.
  • Payment processor and age-verification vendor, as described above.
  • Safety tooling providers that classify content before it is stored or served.
  • Authorities, where the law requires — including reports to NCMEC of apparent child sexual abuse material.

We do not sell personal data. Ever.

6. Retention

  • Chat: one year, rolling. Older turns are deleted automatically.
  • Generated media: kept while your account is open.
  • Long-term memory: distilled summaries, not raw transcripts. These are kept while your account is open, so your companion still remembers you after old turns expire.
  • Account and payment records: while the account is active, and afterwards for the periods accounting and tax law require.
  • Safety and report records: 3 years.
  • Child-safety records: the statutory preservation period (see section 7).

Backups roll off on a fixed schedule of about 35 days. Backups cannot be surgically edited, so deletion of your data is complete when the last backup containing it expires; a restored backup re-applies deletions before returning to service. We state this plainly rather than pretending deletion is instantaneous.

7. Child-safety records — a carve-out we disclose

When the safety system refuses content that appears to involve minors, or a report concerns such content, we preserve the prompt, verdicts, hashes and related account references in a segregated, encrypted store for the statutory preservation period — currently understood to be one year, extended as the law requires. These records are exempt from deletion requests, and they may be reported to NCMEC or to law enforcement as the law requires. This is a legal obligation and it survives account deletion.

8. Encryption — and its honest limits

In transit, all connections use TLS 1.3. At rest, chat and media are encrypted with per-user keys, so a stolen database alone does not yield readable content. This is not end-to-end encryption: the application must read content to moderate it and to generate responses, so a compromised application server could see plaintext. We say so plainly rather than overclaim.

9. Your rights

You have the right to access, rectify, erase, restrict and object to the processing of your personal data, and to receive a machine-readable export of your account data, chat and characters. Consent is withdrawable at any time. These rights do not extend to the child-safety records described in section 7. To exercise any right, email report@flirtly.co; we answer within 30 days.

10. Deletion

Delete your account in settings or by request. We hard-delete within 30 days across our stores, subject to the backup-expiry note in section 6 and the child-safety carve-out in section 7.

11. Breaches

If personal data is breached, we notify the relevant supervisory authority within 72 hours where the GDPR requires, and notify affected users where the law requires.

12. Changes

When our practices change, this page changes with a new “Last updated” date, and material changes are announced on the service.

13. Contact

report@flirtly.co · Complaints & Contact · EU representative: EU representative — to be confirmed before launch