Privacy Policy
1. Introduction
This Privacy Policy explains how MITHRA RESEARCH LTD ("Company," "we," "us," or "our") collects, uses, and protects personal data when you use Lilacs.ai (the "Service").
We act as the data controller responsible for personal data processed through the Service.
By using the Service, you agree to this Privacy Policy.
2. Information We Collect
We collect the following categories of information.
Account Information
- Email address (via Apple Sign In)
- Apple authentication identifier
- Username
- Date of birth (for age verification and NSFW access)
- Subscription status
User Content
- Bots you create
- Bot avatars or uploaded images
- Messages sent to AI characters
- Messages sent to other users
- NSFW preference settings
Technical and Usage Information
- IP address
- Device type
- Operating system
- App version
- Authentication logs
- Session activity
- Usage analytics
We do not collect precise GPS location data.
3. How We Use Your Information
We use personal data to:
- Provide and operate the Service
- Authenticate user accounts
- Generate AI responses
- Store and display Bots and messages
- Enable optional NSFW functionality
- Process subscriptions
- Detect fraud, abuse, or policy violations
- Maintain platform safety
- Improve system reliability and performance
- Comply with legal obligations
We do not sell personal data.
We do not use advertising or cross-site tracking technologies.
4. AI Processing
User messages are processed to generate AI responses.
We may share limited data with third-party AI service providers solely for the purpose of generating responses and operating the Service.
We do not use user conversations to train external AI models.
5. Messaging and Moderation
Messages and Bot interactions are stored on our servers.
We may access, review, and moderate content where necessary to:
- Enforce our Terms of Service
- Maintain platform safety
- Investigate abuse or fraud
- Comply with legal obligations
Lilacs.ai does not provide end-to-end encrypted messaging, and users should not assume absolute privacy.
6. Legal Basis for Processing (GDPR)
Where applicable under GDPR, we process personal data based on:
- Contractual necessity โ to provide the Service
- Legitimate interests โ security, fraud prevention, service improvement
- Legal obligations โ compliance with law
- Consent โ for optional NSFW functionality and marketing communications
7. Marketing Communications
If you sign up to receive marketing emails, we may send updates or announcements about the Service.
You may opt out of marketing communications at any time using the unsubscribe link in our emails or by contacting us.
8. Cookies and Similar Technologies
We use cookies and similar technologies that are strictly necessary for authentication, security, and basic functionality of the Service.
These technologies help us:
- Maintain user sessions
- Secure accounts
- Prevent fraud and abuse
We do not use advertising or cross-site tracking cookies.
Users may control cookies through their browser settings where applicable.
9. Data Sharing
We may share personal data with:
- Hosting providers (such as Supabase)
- AI service providers used for inference processing
- Payment processors (such as the Apple App Store)
- Infrastructure and security providers
We only share data as necessary to operate the Service and subject to appropriate safeguards.
10. Data Storage and Location
We use infrastructure hosted within the European Union.
Data may be processed in the EU and other jurisdictions where our service providers operate, subject to appropriate safeguards.
11. Data Retention
We retain personal data:
- While your account remains active
- As necessary to provide the Service
- As required for legal or regulatory obligations
- For security and fraud prevention purposes
When you delete your account:
- Account information and User Content (including Bots) are removed from active systems
- Secure backups may persist temporarily before automatic deletion
- Limited data may be retained where legally required
12. Your Rights
Subject to applicable law, you may:
- Request access to your personal data
- Request correction of inaccurate data
- Request deletion of your data
- Request restriction of processing
- Object to certain processing
- Request a copy of your personal data
You may exercise these rights by contacting us.
You also have the right to lodge a complaint with your local data protection authority.
13. Security
We implement reasonable technical and organisational measures to protect personal data, including:
- Secure authentication systems
- Access controls
- Encrypted connections (HTTPS)
- Logging and monitoring for abuse
However, no system can guarantee absolute security.
14. Children
Lilacs.ai is intended only for users aged 18 or older.
We do not knowingly collect personal data from minors.
15. Changes to This Policy
We may update this Privacy Policy from time to time.
Continued use of the Service after changes constitutes acceptance of the updated policy.