Last updated August 31, 2026
Privacy Policy
This Privacy Policy explains what Kissora.ai collects and processes when you create an account, chat with an AI companion, create a character, generate media, buy a subscription or Energy, and use the rest of the product.
1. Information we collect
We collect information you provide directly, including:
- name, email address, authentication details, and age-consent records;
- messages, prompts, character selections, preferences, uploaded references, and other material you submit;
- generated images and videos, favorites, saved characters, and chat history;
- plan selections, Energy balance and ledger activity, and subscription status;
- messages you send to support; and
- account settings and actions such as deletion or analytics opt-out.
We also collect technical and security information such as IP address, browser and device details, page URL, referring site, timestamps, cookies, request logs, and product events. Passwords used for email sign-in are stored as one-way hashes, not as readable text.
2. Payment information
Payments are processed by Stripe-hosted Checkout. We do not store your full payment card number on our servers. Stripe provides us with limited payment and subscription data such as customer ID, session ID, subscription status, and payment outcome.
3. How we use information
We use personal information to:
- create and manage your account;
- run AI conversations and generate the characters, images, and videos you request;
- save and restore conversations, generated media, and product preferences;
- process subscriptions, renewals, cancellations, and refund requests;
- provide customer support and respond to questions;
- protect the service against fraud, abuse, and security incidents; and
- measure and improve reliability, performance, features, and usability.
4. AI and media processing
Prompts, relevant conversation context, character information, and reference images are sent to AI providers when needed to produce a reply or requested media. Current providers include OpenRouter and xAI for chat inference and WaveSpeed for image and video generation. Providers process that material under their service terms and our configuration; they are not the people depicted by a fictional character.
We apply automated content and safety checks before or during some requests. We may retain request status, error category, cost, and output metadata to operate the queue, resolve a billing issue, prevent abuse, and support retry or refund behavior.
5. Legal bases and service providers
We process information to perform our contract with you, to comply with legal obligations, and to pursue legitimate interests such as security, fraud prevention, product improvement, and support operations.
We may share data with trusted service providers that help us run Kissora.ai, including:
- Stripe for checkout, subscriptions, invoices, and payment processing;
- OpenRouter, xAI, and WaveSpeed for requested AI and media generation;
- Cloudflare R2 and our hosting/database infrastructure for storage and delivery;
- PostHog for product analytics and session replay;
- Google Tag Manager and, on specifically scoped campaign pages, Meta Pixel;
- Resend for service email, Sentry for error monitoring, and Google for optional sign-in;
- professional advisers or authorities where required by law.
These providers may process data in countries other than your own. The particular vendors can change as the service evolves; we will update this notice when a change materially affects how personal information is handled.
6. Product analytics and session replay
PostHog product analytics is on by default when configured. We use it to understand page visits, feature usage, errors, and where a flow gets stuck. Named product events are designed not to include chat text, prompts, passwords, payment-card data, email addresses, or generated-media contents.
PostHog session replay can record the visible product experience. Text and form inputs are masked by configuration, but visual page elements — including a generated image or video shown on screen — may appear in a replay. PostHog is currently configured on its United States cloud. Previously saved browser opt-outs remain respected. For privacy questions or requests, please use our Contact Us form.
7. Marketing measurement and advertising data
We want to measure the effectiveness of advertising that drives users to Kissora.ai so we can understand what works and decide where to invest. We run Google Tag Manager in the browser on the production site. For the two Controlling Interest advertising pages only (/funnel/ci-full and /funnel/ci-short), we may also load a Meta Pixel assigned to that advertising campaign. The Pixel is not loaded on the rest of Kissora.ai, and an unrecognised campaign identifier cannot enable it.
What we collect on landing-page visits, during checkout, and during product use:
- advertising click identifiers when present in the URL we receive (e.g.
fbclid,gclid,ttclid); - first-party cookies set by us, including the Meta-spec
_fbp/_fbcidentifiers and our own_lai_*click-id snapshots; - the URL you landed on and the referring website (if your browser sent one);
- your IP address, user-agent, and country (derived from IP at our edge);
- irreversibly hashed (sha256) copies of your email address (and phone number, if we ever collect one); and
- product-interaction events such as page views, character card clicks, paywall views, menu navigation, and plan selection; these event properties are designed not to include your messages, prompts, generated-media contents, or passwords.
Google Tag Manager uses web container GTM-WQM95GDV and our first-party server endpoint at sgtm.kissora.ai. Production measurement is forwarded to Google Analytics and, for the conversion events described below, to Meta. When the scoped browser Meta Pixel is enabled on a Controlling Interest page, it also sends Meta the page view, whether the episode preview was viewed, whether registration completed, and whether the visitor clicked the displayed offer. These requests expose the normal browser and network information involved in a web request, including IP address, user-agent, page URL, and Meta's _fbp / _fbc identifiers when present.
When a new account is created, our server sends Meta a Lead conversion. When that account completes its first paid subscription, our server sends Meta a Purchaseconversion with the subscription value and currency. To match those conversions and avoid duplicate counting, we may send an irreversibly SHA-256-hashed email address and hashed internal account identifier together with the applicable click/cookie identifiers, IP address, user-agent, country, landing URL, event time, and a stable event identifier. We do not send later subscription renewals or Energy top-ups as a first Purchase, and we do not send message contents, prompts, generated media, passwords, or payment-card data in these conversion events.
We retain advertising-measurement data for as long as needed to support attribution and troubleshooting. You can request deletion of your marketing-related data at any time by contacting support; deletion of your account also clears the user-identifying portion of this data.
8. Storage, retention, and deletion
Companion memory is enabled by default unless you have turned it off. While enabled, we use our AI processing provider to extract ordinary details from new messages and retrieve relevant saved details for future conversations with the same companion and content mode. You can review, correct, forget or disable this memory in settings. Disabling it removes derived memories, not the underlying chat history or recent conversation context. Resetting or deleting a chat also removes its source-linked memories. Please do not save sensitive information in companion memory.
Optional email categories start enabled by default and can be disabled separately in Account settings. Prior unsubscribes and delivery blocks are respected. Saving these preferences does not itself send an email. We use meaningful product activity to avoid reminders while you are active. Saved memories may personalize a message inside your chat; notification emails do not contain the private message or remembered details. You can unsubscribe through any reminder email or disable them in Account settings.
We keep information for as long as needed to provide the service, maintain your account, honor transactions, resolve disputes, enforce agreements, and comply with legal obligations.
Deleting a chat removes its transcript. Generated images and videos saved to your gallery are separate records and must be deleted with their own media controls if you also want them removed. Account deletion begins a 30-day grace period during which sign-in can restore the account; after that period, the account and associated product records are scheduled for permanent deletion, subject to records we must retain for legal, security, fraud-prevention, or financial obligations.
Analytics, security logs, backups, and provider-side records can follow separate limited retention schedules. When data is no longer required, we delete or de-identify it within a reasonable period unless law requires longer retention.
9. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. No system is perfectly secure, so we cannot guarantee absolute security.
10. Your choices and rights
You may request access to, correction of, or deletion of your personal information by contacting [email protected].
You can delete individual chats, generated media, characters, or your account through the available product controls. You can also contact support from the email address associated with the account so we can verify and handle a request.
11. Children's privacy
Kissora.ai is not intended for children under 18, and we do not knowingly collect personal information from children under 18.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will post the revised version here and update the “Last updated” date above.