Legal and Safety Center
EMOTomo is an adults-only AI companion. You communicate with software: every character is fictional and is not a human, therapist or emergency service.
1. Terms of Service
Contract and eligibility
The contracting party is not yet published. You must be at least 18. If you state that you are under 18, you may not register or continue a chat. You must provide accurate account information and protect access to your account.
AI service and safety
Characters and replies are artificially generated, fictional and may be inaccurate, inconsistent or inappropriate. The service does not provide medical, mental-health, legal, financial or other professional advice and cannot contact emergency services for you. In immediate danger, contact local emergency services and a trusted person.
Your content
You retain rights you hold in messages and other content you submit. You grant the operator a limited, non-exclusive licence to host, transmit, reproduce and process that content only as needed to provide, secure and support the service and comply with law. This does not grant a licence for advertising or model training. Do not submit content you lack the right to use.
Rules and enforcement
The Acceptable Use Policy applies. The operator may restrict content or access to protect users, enforce these Terms or comply with law, using automated controls and review of reports. Appeals may be submitted through the privacy/support workflow. Account termination does not waive mandatory consumer rights.
Subscriptions and changes
Billing must remain disabled until the operator confirms launch markets, taxes, withdrawal/refund handling and the contracting party. If enabled, the exact price, currency, billing period, recurring renewal and cancellation terms shown immediately before checkout control. Cancelling a subscription does not delete an account. Material Terms changes require renewed affirmative acceptance; a Privacy Notice update is not treated as blanket consent.
Disclaimers and liability
To the extent permitted by applicable law, the service is provided without a promise of uninterrupted or error-free operation. Nothing excludes liability or remedies that cannot lawfully be excluded, including mandatory consumer rights. Any liability cap, indemnity, governing law, venue or dispute process is reserved for owner and licensed-counsel approval; no arbitration or class-action waiver is imposed by this candidate.
General
Terms on severability, assignment, waiver and the entire agreement will apply only in the final entity-specific version. Registered address: not yet published. Contact: not yet published.
2. Privacy Notice
The controller is not yet published, at not yet published. Privacy contact: not yet published. The table describes the release candidate’s implemented data flows; legal bases are provisional and require market/entity-specific counsel review.
| Data category / examples | Source | Purpose | Proposed legal basis | Recipients | Retention implemented |
|---|---|---|---|---|---|
| Account: email, username, password hash, OAuth subject, profile fields | You; Google if selected | Create, authenticate and secure the account | Contract; legitimate interests for security | Azure; Google for OAuth | Active account; erased from active storage on account deletion, subject to documented backup expiry |
| Age/Terms records: pseudonymous/user ID, document and schema versions, decision, time, surface, locale | Your separate clickwrap actions | Enforce 18+ access and prove contract actions | Contract and legal obligation/legitimate interests, subject to counsel | Azure PostgreSQL | For the account; deleted with it. Temporary under-age block: 30 days |
| Chats: prompts, AI replies, character, timestamps, reactions | You; generated AI output | Provide history and generate replies; enforce safety | Contract; explicit-consent analysis may be required for deliberately supplied special-category data | Azure; active configured LLM provider | Until you delete a message/chat/account; NATS event copies max 24 hours |
| Memory: inferred preference/name/interest/relationship items and sensitivity flag | AI inference from current turn when enabled | User-requested personalisation | Consent is the candidate basis; special-category basis requires counsel | Azure; LLM during extraction | While memory remains enabled; per-item/all deletion available; prohibited items are purged hourly |
| Voice: microphone audio, transcript, TTS text/audio cache | You; AI reply | Optional STT/TTS requested by you | Contract/request; special data may occur in speech | Configured STT/TTS provider; Azure transport/cache | Application does not intentionally persist raw recording in PostgreSQL; transient/provider retention remains contractually unverified; local TTS request URL caches 1–24 hours by code path |
| Billing: plan/status, price acceptance, provider customer/subscription identifiers | You; Stripe | Checkout, renewal, cancellation, receipts and fraud handling | Contract; legal obligations for accounting/tax where applicable | Stripe; Azure | Schedule for tax/invoice records requires operator/counsel input; local account-linked rows delete with account |
| Support/moderation: report text, contact, category, status | You | Respond, investigate abuse and protect users | Legitimate interests/legal obligation, subject to balancing | Azure; authorised reviewers | Exact period/hold rules are a publication blocker |
| Operational: session timing, pseudonymous IDs, errors, security events | Browser/app and servers | Reliability, rate limits, abuse/security | Legitimate interests | Azure; Sentry only if production-configured | Session/job operational rows: 30 days. Azure platform log retention requires production verification |
| Analytics: random browser ID and product events | Browser after opt-in | Optional product measurement | Consent | Amplitude only after analytics opt-in | Vendor setting/contract requires verification; browser ID removed on withdrawal |
| Marketing choice and email delivery | Your optional unchecked choice | Marketing only if separately requested | Consent | Configured SMTP provider | Until withdrawal; provider delivery logs require verification |
Automated processing, training and transfers
AI providers generate replies and may help infer memory; deterministic rules screen inputs and outputs but do not make legal or similarly significant decisions. The repository proves that EMOTomo does not run a first-party model-training pipeline on chats; it does not prove each provider’s retention or training treatment. No no-training promise is made until vendor contracts/settings are evidenced. Primary Azure resources observed in production are in Canada Central; the Static Web App was observed in Central US. Provider regions and lawful transfer mechanisms remain to be verified by contract. No SCC, adequacy or DPA guarantee is claimed here.
Your choices and rights
You can export account data in JSON, correct profile and memory items, delete individual memory/chat data, clear memory, disable memory, withdraw optional cookies and delete the account. Depending on law you may request access, correction, erasure, portability, restriction, objection, consent withdrawal, appeal and lodge a complaint with a competent regulator. Use Privacy Rights. Statutory response deadlines, controller contact and EU/UK representative details require the final controller/market decision.
Security, minors and changes
HTTPS, password hashing, access checks, signed tokens, rate limits and content-minimising logs are implemented; chats are not end-to-end encrypted. The service is 18+ and blocks a known under-18 result. Material privacy changes are notified; only processing that legally depends on consent is gated by consent.
4. Acceptable Use Policy
Do not use EMOTomo for sexual content involving minors, exploitation, non-consensual intimate content, credible threats, instructions for self-harm, weapons/explosives/drug synthesis/malware, harassment, unlawful discrimination, impersonation, fraud, infringement, privacy violations, attempts to bypass controls, or automated abuse. Adult status does not make all sexual or illegal content acceptable. Reports may be investigated and proportionate restrictions applied; lawful appeals remain available.
5. AI Transparency and Safety Notice
The chat header, onboarding and pre-message surface must always state: You are talking with AI. The character is fictional and is not a human. Replies can be wrong and should not be relied on for professional or emergency decisions.
Before generation, deterministic rules screen narrow high-risk categories and self-harm method/intent signals. Generated output is screened again before display. Controls are bilingual but imperfect and are a safety floor, not proof that every harmful message is detected. User reports enter the human incident process described in the internal runbook.
6. Public Self-Harm and Crisis Response Protocol
When the deterministic layer detects suicidal or self-harm intent or a request for a method, the request does not proceed as an ordinary character reply. The service displays a fixed response that identifies itself as AI, advises contacting local emergency services in immediate danger, suggests contacting a trusted person who can stay with the user, and links to Find A Helpline for country-specific contacts. The service cannot place a call, identify location reliably or provide emergency care.
Generated replies are also checked for self-harm methods before display. Safety telemetry should contain category/count metadata, not conversation content, and is subject to a limited schedule. EMOTomo will maintain de-identified referral counts and protocol evidence for California reporting readiness; it will not include user identifiers in the statutory report. This public summary intentionally omits detection strings and thresholds.
7. Age Policy — 18+ Only
EMOTomo is not for anyone under 18. A separate unchecked 18+ affirmation is required for account creation; anonymous and authenticated chat transports enforce a durable server-side result. The service does not ask for a full birth date. A stated under-18 result blocks registration/chat, removes any pre-decision pseudonymous chat, memory and relationship data from active storage, records only a temporary block result, and does not trigger analytics or marketing. Do not attempt to evade the gate.
8. Voice & Audio Notice
Microphone use is optional and requires device permission. Audio is sent to the active speech-to-text path to create text; the transcript then enters the same chat/AI flow. Reply text may be sent to a text-to-speech provider. The application code does not intentionally write raw microphone recordings to PostgreSQL or create voiceprints. Provider-side retention, region and training restrictions are not asserted without a verified DPA/settings export. Avoid speaking sensitive information you do not want transmitted.
9. Data Retention and Deletion Policy
- Chats/account/profile: until user deletion or account deletion; message correction no longer retains the original text.
- Memory: off by default; stored only while enabled; per-item and full purge available; legacy unconsented context purged hourly.
- NATS message/response/memory/session events: maximum 24 hours in release code.
- Expired signup, email and password challenge records: purged hourly after expiry.
- Under-18 and inactive guest age results: up to 30 days under implemented rules.
- Session/job operational rows: 30 days by default.
- Azure PostgreSQL production backup setting observed 2026-08-13: 7 days, geo-redundant backup off. A deletion tombstone prevents intentional restoration of a deleted subject during that window.
Account deletion is atomic for known active PostgreSQL stores, revokes account-linked rows, attempts cache and Stripe deletion, and returns named outstanding systems rather than falsely claiming completion. Exact schedules for support reports, accounting/tax records, provider copies and Azure platform logs require owner/vendor/counsel evidence before final publication.
10. Subprocessor List
| Provider | Role/data | Production evidence | Region/transfer/training status |
|---|---|---|---|
| Microsoft Azure | App Services, PostgreSQL, Redis, Static Web App, platform logs | Azure inventory observed | Core resources Canada Central; SWA Central US; contract/DPA/SCC evidence required |
| OAuth identity fields when selected | OAuth code paths and public sign-in | Contract/region retention review required | |
| xAI / OpenRouter | Chat prompt, relevant history and enabled memory context | Outbound router code; active route is deployment-config dependent | Active provider, retention, training and transfer terms must be runtime/contract verified |
| ElevenLabs | TTS text/audio; fallback STT path | Voice integration code | Active path, voice licence, region, retention and training evidence required |
| Stripe | Customer, checkout, subscription, invoices/payment method | Production public plans endpoint and billing code; live charging not proven without checkout | Billing remains release-gated; DPA/tax retention review required |
| Amplitude | Optional pseudonymous product events | SDK code now loads only after analytics opt-in | Production key and vendor retention/settings require verification |
| Sentry | Optional error/diagnostic events | SDK integration present | Production enablement and payload/retention settings require verification |
| SMTP provider | Account and separately consented marketing email delivery | SMTP code present | Provider identity and contractual facts required |
11. Refund, Cancellation and Subscription Policy
Launch state: billing is disabled by default and fails closed in production until legal release approval and verified operator fields are present. The previously public plans response advertised Pro at USD 9.99/month and USD 99.99/year, but the audit could not lawfully prove whether live charging was enabled without entering checkout. No purchase should be offered until the deployment checklist is complete.
If enabled, checkout must display the total price and period, recurring auto-renewal, cancellation and current policy versions beside an unchecked affirmative confirmation. Stripe Checkout processes payment. The billing portal provides cancellation; cancellation affects renewal/entitlement and does not delete the account. Refund and statutory withdrawal outcomes depend on purchase country, service commencement and mandatory law; owner/counsel must approve an operational matrix before launch. Nothing in this candidate limits non-waivable refunds or remedies.
12. Copyright and Takedown Policy
Rights holders may send a sufficiently detailed notice identifying the work, allegedly infringing material and location, contact information, a good-faith statement, an accuracy/authority statement and signature to not yet published. The operator will assess, remove or restrict where appropriate, notify affected users when lawful and accept a counter-notice process where applicable.
EMOTomo does not claim that an ordinary email address is a U.S. Copyright Office designated agent. Section 512 safe-harbour status is not claimed unless the operator registers and renews an agent in the Copyright Office directory and satisfies all other requirements. Character, Live2D model, image, voice, font, music and generated-asset publication remains blocked unless the provenance register has commercial-use evidence.
13. Privacy Choices / Your Privacy Rights
Settings provide JSON export, profile correction, message/chat deletion, memory on/off, sensitive-memory on/off, memory item review/correction/deletion, full memory clearing, Cookie Settings and account deletion. Authenticated users may submit access, correction, deletion, portability, restriction, objection, consent-withdrawal and appeal requests through /api/auth/privacy-requests. A verified public contact and identity-verification procedure must be supplied before launch. You may complain to a competent data-protection authority where the law provides that right.
14. Security Reporting Policy
Do not access other users’ data, degrade the service, use social engineering, retain unnecessary personal data or publicly disclose an unresolved issue. Send a concise report with affected URL/component, impact and reproducible steps without secrets or user content to not yet published. Acknowledgement and safe-harbour commitments cannot be published until an owner-approved response process and mailbox exist. For an active data breach, the internal breach runbook—not this public intake page—controls containment, evidence and regulator/user notification assessment.