← EmoTomo home

Legal and Safety Center

Release-candidate document set · version 2026-08-13 · evidence reviewed 2026-10-01

EmoTomo is an entertainment service for adults (18+): interactive stories in which you talk with animated, fictional AI characters, each with a written world. You communicate with software: every character is fictional and is not a human, therapist or emergency service.

1. Terms of Service

Material version: 2026-08-13 · acceptance is recorded separately from age confirmation and Privacy Notice acknowledgment.

Contract and eligibility

The contracting party is not yet published. You must be at least 18. If you state that you are under 18, you may not register or continue a chat. You must provide accurate account information and protect access to your account.

AI service and safety

Characters and replies are artificially generated, fictional and may be inaccurate, inconsistent or inappropriate. The service does not provide medical, mental-health, legal, financial or other professional advice and cannot contact emergency services for you. In immediate danger, contact local emergency services and a trusted person.

Your content

You retain rights you hold in messages and other content you submit. You grant the operator a limited, non-exclusive license to host, transmit, reproduce and process that content only as needed to provide, secure and support the service and comply with law. This does not grant a license for advertising or model training. Do not submit content you lack the right to use.

Rules and enforcement

The Acceptable Use Policy applies. The operator may restrict content or access to protect users, enforce these Terms or comply with law, using automated controls and review of reports. Appeals may be submitted through the privacy/support workflow. Account termination does not waive mandatory consumer rights.

Subscriptions and changes

Pro is an optional paid plan and is not on sale yet. When it launches, the price, currency, billing period, renewal and cancellation terms are shown before you confirm a purchase and are set out in the Refund, Cancellation and Subscription Policy. Canceling a subscription does not delete an account. Material Terms changes require renewed affirmative acceptance; a Privacy Notice update is not treated as blanket consent.

Disclaimers and liability

To the extent permitted by applicable law, the service is provided without a promise of uninterrupted or error-free operation. Nothing excludes liability or remedies that cannot lawfully be excluded, including mandatory consumer rights. Any liability cap, indemnity, governing law, venue or dispute process is reserved for owner and licensed-counsel approval; no arbitration or class-action waiver is imposed by this candidate.

General

Terms on severability, assignment, waiver and the entire agreement will apply only in the final entity-specific version. Registered address: not yet published. Contact: not yet published.

2. Privacy Notice

The controller is not yet published, at not yet published. Privacy contact: not yet published. The table describes the release candidate’s implemented data flows; legal bases are provisional and require market/entity-specific counsel review.

Sensitive conversations. Chats can reveal health, sexuality, religion, political views or other highly sensitive information. Do not share information you do not want processed by the service and its configured AI/voice providers. Long-term memory is off by default; sensitive memory is separately off by default.
Data category / examplesSourcePurposeProposed legal basisRecipientsRetention implemented
Account: email, username, password hash, OAuth subject, profile fieldsYou; Google if selectedCreate, authenticate and secure the accountContract; legitimate interests for securityUpCloud (hosting); Google for OAuthActive account; erased from active storage on account deletion, subject to documented backup expiry
Age/Terms records: pseudonymous/user ID, document and schema versions, decision, time, surface, localeYour separate clickwrap actionsEnforce 18+ access and prove contract actionsContract and legal obligation/legitimate interests, subject to counselPostgreSQL on our UpCloud serverFor the account; deleted with it. Temporary under-age block: 30 days
Chats: prompts, AI replies, character, timestamps, reactionsYou; generated AI outputProvide history and generate replies; enforce safetyContract; explicit-consent analysis may be required for deliberately supplied special-category dataUpCloud; OpenRouter and the model provider that serves the replyUntil you delete a message/chat/account
Memory: inferred preference/name/interest/relationship items and sensitivity flagAI inference from current turn when enabledUser-requested personalizationConsent is the candidate basis; special-category basis requires counselUpCloud; the LLM provider during extractionWhile memory remains enabled; per-item/all deletion available; prohibited items are purged hourly
Voice: microphone audio, transcript, TTS text/audio cacheYou; AI replyOptional STT/TTS requested by youContract/request; special data may occur in speechSpeech-to-text on our own server; Fish Audio for spoken replies; UpCloud transport/cacheApplication does not intentionally persist raw recording in PostgreSQL; transient/provider retention remains contractually unverified; local TTS request URL caches 1–24 hours by code path
Billing: plan/status, price acceptance, provider customer/subscription identifiersYou; StripeCheckout, renewal, cancellation, receipts and fraud handlingContract; legal obligations for accounting/tax where applicableStripe; UpCloudSchedule for tax/invoice records requires operator/counsel input; local account-linked rows delete with account
Support/moderation: report text, contact, category, statusYouRespond, investigate abuse and protect usersLegitimate interests/legal obligation, subject to balancingUpCloud; authorized reviewersExact period/hold rules are a publication blocker
Operational: session timing, pseudonymous IDs, errors, security eventsBrowser/app and serversReliability, rate limits, abuse/securityLegitimate interestsUpCloud; Sentry only if production-configuredSession/job operational rows: 30 days. Server log retention requires production verification
Analytics: random browser ID and product eventsBrowser after opt-inOptional product measurementConsentAmplitude only after analytics opt-inVendor setting/contract requires verification; browser ID removed on withdrawal
Marketing choice and email deliveryYour optional unchecked choiceMarketing only if separately requestedConsentGoogle Workspace email relay (when email delivery is enabled)Until withdrawal; provider delivery logs require verification

Automated processing, training and transfers

AI providers generate replies and may help infer memory; deterministic rules screen inputs and outputs but do not make legal or similarly significant decisions. The repository proves that EmoTomo does not run a first-party model-training pipeline on chats; it does not prove each provider’s retention or training treatment. No no-training promise is made until vendor contracts/settings are evidenced. Production runs on a server hosted by UpCloud in Warsaw, Poland (EU). The AI, voice and sign-in providers in the Subprocessor List may process data in other countries, including the United States. Provider regions and lawful transfer mechanisms remain to be verified by contract. No SCC, adequacy or DPA guarantee is claimed here.

Your choices and rights

You can export account data in JSON, correct profile and memory items, delete individual memory/chat data, clear memory, disable memory, withdraw optional cookies and delete the account. Depending on law you may request access, correction, erasure, portability, restriction, objection, consent withdrawal, appeal and lodge a complaint with a competent regulator. Use Privacy Rights. Statutory response deadlines, controller contact and EU/UK representative details require the final controller/market decision.

Security, minors and changes

HTTPS, password hashing, access checks, signed tokens, rate limits and content-minimizing logs are implemented; chats are not end-to-end encrypted. The service is 18+ and blocks a known under-18 result. Material privacy changes are notified; only processing that legally depends on consent is gated by consent.

3. Cookie & Similar Technologies Policy

Strictly necessary storage supports age/access state, authentication, security and the saved consent choice. Functional storage is optional. Analytics (Amplitude) is optional and its SDK, browser identifier and network calls must not start until analytics opt-in. No marketing SDK is presently loaded; the category is kept disabled unless a future deployment truthfully lists one.

The banner offers Accept all, Reject non-essential and Customize with unchecked categories. A permanent Cookie Settings control permits withdrawal; withdrawal clears the analytics identifier. Consent schema version 2 is stored locally. In the web app, authentication uses an HttpOnly session cookie that page scripts cannot read, plus a separate cookie for request-forgery protection; localStorage keeps only a signed-in marker, not the session token.

4. Acceptable Use Policy

Do not use EmoTomo for sexual content involving minors, exploitation, non-consensual intimate content, credible threats, instructions for self-harm, weapons/explosives/drug synthesis/malware, harassment, unlawful discrimination, impersonation, fraud, infringement, privacy violations, attempts to bypass controls, or automated abuse. Adult status does not make all sexual or illegal content acceptable. Reports may be investigated and proportionate restrictions applied; lawful appeals remain available.

5. AI Transparency and Safety Notice

The chat header, onboarding and pre-message surface must always state: You are talking with AI. The character is fictional and is not a human. Replies can be wrong and should not be relied on for professional or emergency decisions.

Before generation, deterministic rules screen narrow high-risk categories and self-harm method/intent signals. Generated output is screened again before display. Controls are bilingual but imperfect and are a safety floor, not proof that every harmful message is detected. User reports enter the human incident process described in the internal runbook.

6. Public Self-Harm and Crisis Response Protocol

When the deterministic layer detects suicidal or self-harm intent or a request for a method, the request does not proceed as an ordinary character reply. The service displays a fixed response that identifies itself as AI, advises contacting local emergency services in immediate danger, suggests contacting a trusted person who can stay with the user, and links to Find A Helpline for country-specific contacts. The service cannot place a call, identify location reliably or provide emergency care.

Generated replies are also checked for self-harm methods before display. Safety telemetry should contain category/count metadata, not conversation content, and is subject to a limited schedule. EmoTomo will maintain de-identified referral counts and protocol evidence for California reporting readiness; it will not include user identifiers in the statutory report. This public summary intentionally omits detection strings and thresholds.

7. Age Policy — 18+ Only

EmoTomo is not for anyone under 18. A separate unchecked 18+ affirmation is required for account creation; anonymous and authenticated chat transports enforce a durable server-side result. The service does not ask for a full birth date. A stated under-18 result blocks registration/chat, removes any pre-decision pseudonymous chat, memory and relationship data from active storage, records only a temporary block result, and does not trigger analytics or marketing. Do not attempt to evade the gate.

8. Voice & Audio Notice

Microphone use is optional, requires device permission and is available when signed in. Audio is transcribed into text on our own server by an open-source speech-recognition model (Whisper); the transcript then enters the same chat/AI flow. When voice replies are on, reply text is sent to Fish Audio to generate the spoken reply; you can turn voice replies off in the chat. The application code does not intentionally write raw microphone recordings to PostgreSQL or create voiceprints. Provider-side retention, region and training restrictions are not asserted without a verified DPA/settings export. Avoid speaking sensitive information you do not want transmitted.

9. Data Retention and Deletion Policy

Account deletion is atomic for known active PostgreSQL stores, revokes account-linked rows, attempts cache and Stripe deletion, and returns named outstanding systems rather than falsely claiming completion. Exact schedules for support reports, accounting/tax records, provider copies and server logs require owner/vendor/counsel evidence before final publication.

10. Subprocessor List

ProviderRole/dataProduction evidenceRegion/transfer/training status
UpCloudHosting: the application server, PostgreSQL, Redis, cached files and server logsProduction runs on UpCloud since 2026-09-22Warsaw, Poland (EU); contract/DPA evidence required
GoogleOAuth identity fields when selectedOAuth code paths and public sign-inContract/region retention review required
OpenRouterChat and story prompts, relevant history and enabled memory context; forwarded to the inference provider serving the selected model (configured routes include Novita, StreamLake, Baidu, DeepInfra and Parasail)Production LLM routeProvider regions vary and may be outside the EU; retention, training and transfer terms must be contract verified
Fish AudioReply text sent to generate spoken replies; the returned audioProduction voice provider since 2026-09-23Region, retention and training evidence required
StripeCustomer, checkout, subscription, invoices/payment methodNot active in production: billing is disabled and no payment data is collectedDPA/tax retention review required before launch
AmplitudeOptional pseudonymous product eventsNot active in production (no key configured); the SDK loads only after analytics opt-inVendor retention/settings require verification before enabling
SentryOptional error/diagnostic eventsNot active in production (no key configured)Payload/retention settings require verification before enabling
Google Workspace (email relay)Account and separately consented marketing email deliveryNot active in production: email delivery is currently disabledContractual facts required before enabling

11. Refund, Cancellation and Subscription Policy

Status. Pro is not on sale yet, and nothing can be charged today. The terms below apply once Pro launches; the price and these terms are also shown before you confirm a purchase.

What Pro includes. More daily conversation time than Free (free accounts get 30 minutes a day, guests 15), premium AI models, the Pro rewards track, and exports without a watermark. Pro's exact limits are shown before you confirm a purchase.

Price and payment. Prices are listed in US dollars (USD) on the Pricing page, and the total is shown before you confirm. Payments are processed by Stripe — we never see or store your full card number.

Renewal. Pro renews automatically at the end of each monthly or yearly period, at the price you agreed to, until you cancel. If the price changes, we'll tell you before it applies to your next renewal.

Cancel anytime in your profile or the Stripe customer portal. Canceling stops future renewals; you keep Pro until the end of the period you've paid for. Canceling does not delete your account.

Refunds. First payment: ask within 14 days and we'll refund it in full. Renewals: no refunds for partial periods — cancel any time to stop the next charge. Charged by mistake (for example, after you canceled): we'll refund it. Refunds go back to the original payment method. Nothing here limits your rights under consumer law, including the EU/UK right of withdrawal.

How to ask. Write to the support address in the footer of the home and pricing pages. If a charge looks wrong, contact us first — it's faster than a chargeback.

13. Privacy Choices / Your Privacy Rights

Settings provide JSON export, profile correction, message/chat deletion, memory on/off, sensitive-memory on/off, memory item review/correction/deletion, full memory clearing, Cookie Settings and account deletion. Authenticated users may submit access, correction, deletion, portability, restriction, objection, consent-withdrawal and appeal requests through /api/auth/privacy-requests. A verified public contact and identity-verification procedure must be supplied before launch. You may complain to a competent data-protection authority where the law provides that right.

14. Security Reporting Policy

Do not access other users’ data, degrade the service, use social engineering, retain unnecessary personal data or publicly disclose an unresolved issue. Send a concise report with affected URL/component, impact and reproducible steps without secrets or user content to not yet published. Acknowledgment and safe-harbor commitments cannot be published until an owner-approved response process and mailbox exist. For an active data breach, the internal breach runbook—not this public intake page—controls containment, evidence and regulator/user notification assessment.

Back to top · Home