This Privacy Policy explains how Paluma Labs (“Paluma”, “we”, “us”) collects, uses, and protects your information across both palumachat.com (the “Site”) and the Paluma mobile app (the “App”). Paluma is a community-first AI character network where people create, publish, and roleplay with AI characters.
The Site and the App collect different things, so the sections below say which applies. If you only care about one thing, read how your conversations are processed by AI providers. It is the part that most affects you.
We respect your privacy and aim to honor the same core rights for everyone, wherever you live, including protections under the EU/UK GDPR, the California CCPA/CPRA, and India’s DPDP Act.
Information we collect
- Email address: when you join the waitlist, so we can identify your signup, send launch updates, and connect an eligible Launch Pass to a Paluma account created with the same email.
- Platform preferences: the optional Android, iPhone or iPad, web, or not-sure choices you make so we can notify you when Paluma is available where you want it.
- Android beta interest: if you select Android, whether you volunteer to be considered for possible pre-release testing.
- Referral information: if you arrive through a referral link or share your own, we record the referral code and the connection between signups so we can run the “skip the line” feature.
- Usage & device data (only if you accept analytics cookies): via Google Analytics and PostHog: pages viewed, referring links, approximate location derived from your IP, and basic device/browser information, to understand how the Site is used. Neither loads until you accept in the cookie banner shown on your first visit; see our Cookie Policy.
- Security data: we store a one-way hashed version of your IP address (never the raw IP) to prevent spam and abuse of the waitlist.
Payments for Paluma Plus are processed by Google Play, not on this Site. We do not collect or store your card or payment details. Paluma is for adults: you must be at least 18 to create an account, and we do not knowingly collect data from anyone under 18.
Information we collect in the Paluma app
The section above covers this website. The Paluma mobile app collects more, because it is a product you sign into and hold conversations in. In the app we collect:
- Account information: your email address and Google account identifier when you sign in with Google. We never receive your Google password.
- Profile information: the handle, display name, bio, avatar, and banner you choose. These are public.
- Date of birth: Paluma is an 18+ product, so we collect and store your date of birth to confirm eligibility. It is not shown to other users.
- Your conversations: the full text of every message you send to a character, and every reply. These are stored on our servers so your chats persist across devices and sessions.
- Derived memory: to make characters remember you, we automatically derive summaries, saved facts, and relationship state from your conversations, and store them as structured records alongside numeric embeddings used for retrieval.
- Personas: the names, descriptions, and traits of the personas you create and roleplay as.
- Characters you create: including private draft content that is never shown publicly.
- Images: avatars and banners you upload, and images generated for you, together with the prompts used to generate them.
- Usage and diagnostics: feature usage and crash/error reports, via PostHog and Sentry.
- Technical data: IP address and basic device information in server logs, used for security, rate limiting, and debugging.
- Subscription status: your Paluma Plus tier and the Google Play purchase token used to verify it. We never see your card details.
- Voice input (if you use it): if you dictate a message, Paluma uses your device’s built-in speech-recognition feature to convert speech to text. Depending on your device and settings, that conversion may happen on your device or on the recognizer app’s own servers (commonly Google’s, if installed) before the resulting text reaches us. Paluma itself never receives or stores your raw audio, only the text you end up sending.
- Push notification identifiers: a device token from Firebase Cloud Messaging, used only to deliver notifications you have enabled, and your notification preferences.
How your conversations are processed by AI providers
This is the most important thing to understand about using Paluma, so we want to be direct about it.
When you send a message, we assemble a prompt containing your message, recent conversation history, relevant memory, your active persona, and the character’s definition, then transmit it to a third-party AI model provider to generate the reply. Your conversation content therefore leaves our servers and is processed on infrastructure we do not own.
We use AI routing services, model providers, embedding providers, and image-generation providers for generation, summarisation, memory extraction, safety classification, retrieval, and images. The provider handling a request can vary by the task, model availability, and your subscription tier.
We send only the content needed for each task and choose provider settings intended to minimise retention and prevent training where those controls are available. Provider retention and processing terms still apply once data reaches them. If you would not want a sentence processed by a third-party AI service, do not put it in a chat message.
Please do not share sensitive personal information in conversations. This includes financial details, government identifiers, health information, passwords, or another person’s private information.
How we use your information
- To operate the waitlist and deliver launch, Launch Pass, and early-access communications.
- To send availability updates for the platforms you selected.
- To identify and contact Android users who volunteered for possible beta testing.
- To match your waitlist email with the same email on your Paluma account and activate an eligible 7-day Plus Launch Pass when you send your first chat.
- To run the referral program and measure signups.
- To understand and improve how the Site performs.
- To protect the Site against spam, fraud, and abuse.
In the app, we additionally use your information:
- To generate character replies and run the conversation itself.
- To build and retrieve memory so characters recall your shared history.
- To operate discovery, search, favourites, and creator profiles.
- To enforce our Content Policy and investigate reports.
- To meter usage and enforce subscription entitlements.
- To diagnose crashes and improve reliability.
We do not sell your personal information, and we do not use your private conversations for advertising. Chat processing is automated, and staff do not browse or read your conversations out of curiosity. A staff member may view the specific message you or someone else reported, or a message involved in a legal or serious safety investigation, strictly to review that report or investigation. Automated safety systems also operate on your messages; see the Community Guidelines.
Legal bases (for EEA/UK users)
We process your email, platform preferences, and beta interest based on your consent (which you can withdraw at any time), and we process security and analytics data based on our legitimate interests in keeping the Site safe and understanding its use.
Who we share it with
We do not sell your personal information. We share data only with service providers who help us run the Site, under appropriate confidentiality and data-processing terms:
- Hosting & infrastructure: our cloud server provider and database (Supabase/PostgreSQL).
- Analytics (only if you accept analytics cookies): Google Analytics and PostHog, to understand Site usage.
- Caching / rate-limiting: Upstash, to keep the waitlist reliable and abuse-free.
For the app, we additionally share data with:
- AI routing, model, embedding, and image-generation providers: they receive the conversation content or prompts needed to generate replies, build and retrieve memory, run safety checks, or create images. See the section above.
- Object storage: stores your uploaded and generated images.
- Search infrastructure: indexes public character data only. Your conversations are never indexed.
- Error monitoring: receives crash and error reports.
- App-store billing: handles payments and the subscription lifecycle.
- Push notifications: Firebase Cloud Messaging delivers notifications you have enabled, using your device’s push token.
We may also disclose information if required by law or to protect our rights and users’ safety.
International transfers
Paluma serves a worldwide audience, so your information may be processed in countries other than your own. Where required, we rely on appropriate safeguards (such as standard contractual clauses) to protect your data during these transfers.
How long we keep it
We keep your waitlist email, platform preferences, beta interest, referral information, and Launch Pass claim status until Paluma has launched on the selected platforms and for a reasonable period afterward to deliver communications and the offer, or until you ask us to delete it, whichever comes first. If you activate a Launch Pass, we retain the claim record as needed to prevent duplicate redemption and administer the offer.
In the app:
- Account, profile, conversations, memory, personas, and images: kept for as long as your account exists. Deleted when you delete your account.
- Server logs (including IP addresses): kept only as long as needed for security, abuse prevention, and debugging, then deleted.
- Backups: deleted data may persist for a limited period in encrypted backups used for disaster recovery before those backups roll over. Backups are not accessible in the product.
- Moderation and billing records: retained after deletion where we are legally required to, in anonymised form where possible.
Deleting your account and data
You can delete your Paluma account at any time from Profile → Settings → Delete my account in the app. The action is irreversible: your access is revoked and you are signed out immediately, and the deletion itself cannot be undone once confirmed.
Your account, profile, all conversations and messages, all derived memory, your personas, your private character drafts, and your images are then permanently removed. This clean-up runs automatically and reliably in the background and is normally complete within a short time, even if a step needs to retry. Characters you published are unpublished immediately and disassociated from you; see the next page for exactly what happens to them.
If you have already uninstalled the app, email support@palumachat.com from your account email address. Full details, including exactly what is retained and why, are on our Delete Your Account & Data page.
Your rights & choices
Wherever you live, you can ask us to:
- Access the personal data we hold about you.
- Correct or update it.
- Delete it, or withdraw your consent and leave the waitlist.
- Object to or restrict certain processing, and request a copy of your data.
To exercise any of these, email us at support@palumachat.com. Every launch email will also include an unsubscribe link. EEA/UK users may also lodge a complaint with their local data-protection authority.
Cookies
The Site uses a small number of cookies and local storage for analytics and to remember referral information. See our Cookie Policy for details.
Changes to this policy
We may update this policy as Paluma develops. We’ll revise the “last updated” date above, and for material changes we’ll take reasonable steps to let you know.
Contact us
Questions or requests? Email support@palumachat.com.