1.In plain words
chapter3five stores what it needs to run your companions and nothing more. We don’t sell your data, we don’t run third-party ad trackers, and your conversations are never used to train AI models. The rest of this policy is the detailed version of those three sentences.
This policy applies to chapter3five.app and covers everyone who uses the service — creators, inheritors, and visitors.
2.What we collect
- Account basics — your email address and authentication data (a hashed password or sign-in tokens).
- Date of birth— captured once at signup so we can verify you’re 18 or older. We store the date you gave us (not your government-issued ID) and use it to gate access to the app; we don’t use it for marketing, birthday emails, or anywhere outside age verification.
- Your answers — the responses you write to identity questions, including legacy answers you record for someone to inherit.
- Chat messages — what you and your companions say to each other, so your conversations persist and your companions can remember them.
- Photos you choose to share— a photo you upload to create a photo-based identity, or a photo you send in a chat. They are stored in our database’s storage (Supabase Storage) and treated as content you own, like your answers and messages. See Section 6 for how photos are processed by our AI provider.
- Payment metadata — your subscription status, plan, and billing history. Payments are processed by Stripe; we never see or store your card number.
- Device and browser info — IP address, browser type, and basic device information, collected automatically for security, abuse prevention, and error diagnosis.
3.What we don't collect
Just as important. chapter3five does not collect:
- Government ID or identity documents
- Your precise location
- Your contacts or address book
- Camera or microphone data, ever, without an explicit action you take — uploading a photo or tapping the microphone to dictate a message are such actions; nothing is captured in the background
4.How we use it
We use your data only to:
- Generate your companions — your answers and traits are what a companion is synthesized from
- Run your chats — storing history and sending messages to our AI provider to generate replies
- Bill you — managing your subscription through Stripe
- Keep the service safe — preventing abuse, enforcing our Community Guidelines, and diagnosing errors
- Comply with law — when we are legally required to
We do not sell your personal information, and we do not share it with anyone for their own advertising or marketing.
5.Who we share it with
We use a small set of service providers, each bound by their own privacy commitments, and each receiving only what their job requires:
- Supabase — our database and authentication. Stores your account, answers, and chat history.
- Anthropic — our primary AI provider. Receives chat content to generate companion replies (see Section 6 — this one deserves its own section).
- OpenAI — narrow supporting uses only, each covered in more detail in Section 6:
- Content moderation on messages you send and photos you upload (their “Moderations” endpoint — checks for CSAM, graphic violence, self-harm, hate).
- Embeddings that power the semantic-memory search inside your identities (numerical vectors of short memory notes).
- Whisper transcription of the audio you record while answering identity questions, so we can save the text alongside the audio.
- Replicate— image generation. Used in two ways: (a) creating an identity’s initial avatar from a text prompt (no reference photo sent), and (b) generating in-chat photos an identity might “send you” mid- conversation, where we send that identity’s existing avatar as a reference so the generated photo preserves the face, plus a short text prompt describing the scene. Replicate processes these to produce the output; per their terms of service, API traffic isn’t used to train their models. Payloads may transit third-party model hosts that Replicate proxies to (e.g. Black Forest Labs for Flux models) under Replicate’s own privacy contract.
- Stripe — payments. Handles your card and billing details; we receive only subscription metadata.
- Resend — transactional email. Receives your email address to deliver account and notice emails.
- Vercel — hosting. Serves the app and processes requests, including IP addresses, as any web host does.
- Sentry — error monitoring. If something breaks, it receives technical error reports (browser, device, what failed) so we can fix it. It is not an analytics or ad tracker.
- Expo— push-notification delivery. When you opt into push, we send your device push token, notification title, and message excerpt (typically the first 140 characters of a companion reply or a system prompt) to Expo’s Push API so Apple and Google can route the notification to your device. Expo processes the payload for delivery and does not use it for any other purpose.
Beyond these providers, we disclose personal data only if required by law or to protect someone’s safety, and we’ll tell you when we’re legally allowed to.
6.How AI inference works
When you chat with a companion, your messages and relevant identity content are sent to Anthropic, whose Claude models generate the companion’s replies. This is the only way an AI conversation can work, and we want you to understand it clearly:
Chat content sent to Anthropic runs under a zero-data-retention configuration: Anthropic processes it to generate the reply and does not retain it afterward, and your messages are never used to train AI models.
The same applies to photos sent to Anthropic’s vision capability. A photo you upload to create a photo-based identity, or send in a chat conversation, is stored in Supabase Storage as content you own, and when it’s sent to Anthropic for vision inference it runs under the same zero-data-retention terms as your chat text: used to generate the response or the identity, retained by Anthropic no longer than that, and never used to train AI models.
Your conversations are stored only in our own database (Supabase), under your account, where you can delete them.
What OpenAI actually receives
OpenAI does notgenerate your companion’s replies. Its use is limited to three narrow supporting jobs, each on a separate endpoint:
- Moderation.Text messages and any photo you upload are checked against OpenAI’s Moderations endpoint for CSAM, graphic violence, self-harm, and hate. This is a required App Store surface and it’s how we keep the product safe.
- Embeddings.Short memory notes we store about your identities (e.g. “prefers being called Grandpa,” “grew up in Detroit”) are sent to OpenAI’s embeddings endpoint to produce numerical vectors that power semantic search. The embedding is a hash-like number, not the text.
- Whisper transcription.When you record an audio answer to an identity question, that audio clip is sent to OpenAI’s Whisper endpoint to produce the text transcription that’s saved alongside it.
Unlike our Anthropic path, we are not on an OpenAI zero-retention agreement — their API default allows retention for up to 30 days for abuse-monitoring purposes, after which the data is deleted. API traffic is not used to train OpenAI models unless the developer opts in; we do not opt in.
7.How long we keep it
- While your account is active — we keep your data so the service works.
- After you delete your account — everything is permanently deleted within 30 days, except records we’re legally required to keep (for example, billing records).
- Legacy identities are different, on purpose. When an inheritor redeems an inherit code, they receive their own independent copy of the identity in their account. Each redeemed copy is kept until the inheritor who holds it deletes it, or 100 years have passed— whichever comes first. A legacy identity is a gift meant to outlive its creator: the creator deleting their account removes the creator’s own archive and any codes that were never redeemed, but it does not remove copies inheritors have already redeemed.
8.Your rights
Wherever you live, we extend you the rights in GDPR and the California Consumer Privacy Act:
- Access — ask for a copy of the personal data we hold about you
- Correction— fix anything that’s wrong
- Deletion — delete your account and data, from settings or by emailing us
- Export — receive your answers and chat history in a portable format
- No discrimination — exercising these rights never costs you features or service quality
Email privacy@chapter3five.app and we’ll respond within 30 days. We may need to verify you own the account first — that verification protects you. EU/EEA residents also have the right to lodge a complaint with their supervisory authority; Californians may exercise CCPA rights through an authorized agent.
10.Children
chapter3five is for adults. You must be 18 or older to have an account, and we do not knowingly collect personal information from anyone under 18. If we learn we have, we will delete it. If you believe a minor has an account, tell us at privacy@chapter3five.app.
11.Where your data lives
Your data is stored and processed in the United States. If you use chapter3five from elsewhere, you’re transferring your data to the US, where privacy laws may differ from your country’s. For users in regions with data-transfer requirements (like the EU/EEA and UK), we rely on appropriate safeguards such as our providers’ standard contractual clauses.
12.If something goes wrong
If a data breach affects your personal information, we will notify you by email within 72 hoursof confirming it, tell you plainly what happened and what data was involved, and what we’re doing about it. We will also notify regulators where the law requires.
13.Changes to this policy
If we change this policy in any material way, we’ll email you at least 30 days before the change takes effect and update the date at the top of this page. We will never quietly reduce your privacy protections.
14.How to reach us
For any privacy question or data request: privacy@chapter3five.app. For everything else: hello@chapter3five.app.
