Legal
Privacy Policy
Last updated: August 11, 2026
Overview
Linger (“we,” “us,” or “our”) operates an AI character chat platform (the “Service”). This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and what choices you have.
We are accountable for handling your information in line with this policy and with the consent choices you make in the product. If you do not agree with this policy, please do not use the Service.
The Service is intended only for users who are 18 years of age or older. You must confirm your age before use.
Information we collect
We collect information in the categories below. Some is required to operate the Service; other collection is optional and based on your consent.
Account and sign-up data
If you create an account, we collect information you provide at registration, such as your email address (including Apple Hide My Email relay addresses), display name, and authentication credentials managed by our authentication provider (Supabase Auth).
Google sign-in
If you choose “Continue with Google,” Google authenticates you and shares selected profile data with us through Supabase Auth according to the permissions you grant Google during sign-in. Depending on your Google account settings and the scopes requested, we may receive:
- Your email address (primary account identifier)
- Your name (such as full name or given and family name)
- Your Google profile picture URL, which we may store as your avatar
- A provider-specific user identifier used by our auth system to link your Google account
We do not receive your Google password. Google’s handling of your data is governed by Google’s privacy policy. We use Google sign-in data only to operate your Linger account, personalize your profile where applicable, and secure access to the Service.
Apple sign-in
If you choose “Continue with Apple,” Apple authenticates you and shares selected profile data with us through Supabase Auth according to the permissions you grant during sign-in. Depending on your choices, we may receive your email address (including a private relay address if you use Hide My Email), your name on first sign-in, and a provider-specific user identifier. We do not receive your Apple ID password. Apple’s handling of your data is governed by Apple’s privacy policy.
We also store account-related preferences you set, including product-update opt-in status, usage analytics consent, mature-theme preferences, and records that you accepted our Terms of Use, Privacy Policy, and age confirmation.
Email and product updates
We collect and store your email address when you create an account. If you separately opt in to product updates, we record that consent, the date of your choice, and your subscription status in our database. We do not send marketing or product-update emails unless you have opted in. You may withdraw that consent at any time in Account settings or by contacting us.
Subscriptions and billing data
If you purchase a subscription or paid feature, payment information is handled by the applicable payment provider rather than by Linger:
- Apple processes purchases made through the iOS app
- Stripe processes purchases made on the web
We may receive limited billing-related information needed to provide access, such as subscription status, plan or product identifiers, renewal or expiration dates, cancellation flags, and provider transaction identifiers. We synchronize that status with your account so Premium (or other paid) entitlements remain accurate. We do not store full payment card numbers.
Chat and conversation data
To provide chat functionality, we process the messages you send and the AI-generated replies. Depending on how you use the Service, this may include:
- Messages stored locally in your browser for guest chats
- Guest chat messages processed transiently by our servers and AI providers to generate replies (guest transcripts are not saved as durable conversation history in our database)
- Messages and conversation history stored in our database when you use a signed-in account
- Optional “About you” persona or memory fields you choose to provide
Do not submit sensitive personal information (such as government IDs, financial account numbers, or health records) that you do not want processed by the Service or its providers.
Usage, limits, and identifiers
We assign identifiers to enforce usage limits and protect the Service from abuse. Guests receive a server-issued anonymous subject identifier stored in an HttpOnly cookie (and may also keep a matching browser-stored copy for compatibility), plus a session identifier. Signed-in users are associated with their account. When you create an account after using Linger as a guest on the same browser or app install, we may link prior guest usage to your account so limits cannot be reset by signing up.
To prevent limit evasion (for example clearing cookies, using private browsing, or creating multiple free accounts on the same device), we may also process a durable install or device identifier: on native apps, an app-scoped device identifier provided by the operating system; on the web, an install token stored in your browser. We store salted hashes of these identifiers with usage counters (such as messages or tokens used per day or month), not advertising identifiers. We do not use these identifiers to sell your personal information or for cross-app advertising.
Feedback and surveys
If you submit feedback or complete an in-product survey, we may store your responses, optional comments, related conversation identifiers, and character context to improve the product. Thumbs-up/thumbs-down feedback may include an excerpt of the AI reply you rated. This feedback data is removed from the live Service when you delete your account.
Usage analytics (consent-based)
When analytics collection is enabled for your account or session, we may collect anonymous usage analytics to understand how the Service is used and to improve it. Guests may be offered an optional choice to share anonymous usage statistics when first using the Service. Signed-in users can enable or disable usage analytics in Account settings at any time. If analytics collection is not enabled, we do not send optional analytics events from your browser session.
When usage analytics consent is enabled, we may track events such as:
- Character catalog views and character selections
- Chat sessions started and messages sent (counts and metadata, not message content)
- Session duration and conversation length metrics
- In-product survey choice metrics you complete (ratings/categories and whether free-text was provided — not the free-text itself in analytics events)
- Basic error or reliability signals needed to improve stability (cause codes and lengths, not chat message content)
Analytics events may include a stable anonymous subject identifier stored in your browser, a session identifier, character or conversation identifiers, timestamps, and coarse usage properties. We do not use optional analytics to sell your personal information. Analytics data may be stored in server logs and aggregated for internal product metrics. Optional analytics events are not accepted by our servers unless your applicable consent record shows you granted analytics consent.
We record your usage analytics consent choice, the date of that choice, and the policy version in our database when you are signed in, or in our consent audit log for guest acceptance flows.
Technical and security data
We may process technical information necessary to operate and secure the Service, including IP addresses (for rate limiting, shared guest usage limits, and abuse prevention), request metadata, timestamps, security or error logs, and salted hashes of install or device identifiers used only for usage-limit enforcement. This processing supports fraud prevention, availability, and incident response.
Legal and consent records
We maintain an audit trail in Supabase that records when you accepted our Terms of Use, accepted our Privacy Policy, affirmed that you are 18 years of age or older, and (where applicable) granted or revoked consent for anonymous usage analytics and product-update emails. These records may include the policy version accepted, timestamp, source (such as the welcome modal or Account settings), IP address, user agent, and your account email when signed in. For guests who accept before creating an account, we may store consent with an anonymous subject identifier until you sign in and records are linked to your account.
How we use information
We use collected information to:
- Create and manage your account and authenticate you
- Provide, maintain, and personalize chat functionality
- Process subscriptions and synchronize paid access (such as Premium) with your account
- Enforce usage limits and prevent abuse, spam, or security incidents
- Send product or account emails you have requested (such as sign-in links, account confirmation, or product updates you opted into)
- Process feedback and improve characters, reliability, and product quality
- Understand optional usage analytics, when you have consented
- Comply with law and respond to lawful requests
Legal bases and consent
We rely on different legal bases depending on the activity:
- Performance of the Service — processing needed to provide chat, accounts, subscriptions, usage limits, and core functionality
- Consent — optional usage analytics, product-update emails, and any other processing where we ask for your explicit agreement
- Legitimate interests — security, abuse prevention, debugging, and improving the Service, balanced against your privacy expectations
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that already occurred, and some features may not work without certain necessary data.
Email communications
We may send transactional emails related to your account, such as email verification, passwordless sign-in links, or security notices. These are part of operating the Service.
Product-update emails are sent only if you opt in at sign-up or later in Account settings. Each product-update email will include a way to unsubscribe, or you may turn off product updates in Account settings. We maintain records of opt-in and opt-out status so we can honor your choices.
How we share information
We do not sell your personal information. We share data only as needed to run the Service, including with service providers that process data on our behalf under contractual obligations to protect it:
- Supabase — authentication, database, and storage
- Vercel — hosting and delivery
- OpenRouter — AI model inference (chat messages are sent to generate replies)
- Google — if you choose Google sign-in
- Apple — App Store purchases and related subscription status
- Stripe — web billing and related subscription status
- Cloudflare — bot-protection checks (Turnstile) during certain sign-up flows; may process a verification token and IP address
- Sightengine — automated moderation of uploaded profile or character images
- Upstash (when configured) — short-lived rate-limit / abuse-prevention keys
These providers have their own privacy policies. Chat content sent for AI inference is processed according to our instructions and their terms. Payment providers process payment details under their own policies. Image moderation providers receive the media you upload for scanning. We may also disclose information if required by law or to protect rights, safety, and integrity of the Service.
Cookies and local storage
We use browser storage and cookies that are necessary to operate the Service and to remember your choices:
- Authentication session data (via Supabase Auth) so you stay signed in
- An HttpOnly guest subject cookie used to associate guest consent and usage limits with your browser session
- Local storage for guest chat transcripts on this device, legal/age acceptance, analytics consent choice, anonymous subject/session identifiers, and similar product preferences
Clearing site data in your browser removes local guest transcripts and local consent caches. Signed-in account preferences and consent records remain in our database until you change them or delete your account.
Retention and account deletion
We retain information only as long as needed for the purposes described in this policy, unless a longer period is required by law. For example:
- Account data is kept while your account is active
- When you delete your account from Account settings, we remove your profile, chats, custom characters, persistent memories, and related account data from the live Service promptly
- A secure backup archive of deleted account data may be retained for up to 30 days for legal, security, and dispute-resolution purposes, then permanently deleted, unless a longer period is required by law
- If anonymous usage analytics collection was enabled for your account or session, aggregated usage metrics derived from your activity (without message content or personal identifiers) may be retained after deletion. When analytics collection is not enabled, we do not retain such chat-related analytics from your account after deletion
- Billing-related records needed for accounting, fraud prevention, or legal compliance may be retained for a limited period even after a subscription ends
- Product-update consent records are kept to document consent and honor unsubscribe requests
- Guest chat transcripts are stored in your browser (local storage). Anonymous guest identifiers and server-side usage/rate-limit counters may persist longer as needed for abuse prevention and fair-use limits
- Local browser data persists until you clear it or reset your browser storage
- Security and compliance logs may be retained for a limited period for investigation, abuse prevention, and legal obligations
Retention practices may change as the Service evolves. We will update this Privacy Policy when they do.
Security
We use administrative, technical, and organizational measures designed to protect personal information, including encrypted transport (HTTPS), access controls, rate limiting, input screening, and provider security features. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
Your choices and rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate account or profile information
- Delete your account and associated data from Account settings (self-service)
- Withdraw consent for optional usage analytics or product-update emails
- Object to or restrict certain processing where applicable law provides that right
- Receive a copy of certain data in a portable format, where applicable
You can manage many preferences directly in the Service:
- Account settings — display name, product updates, usage analytics, mature themes, delete account
- Clear local guest chat data — use in-app clear chat or browser storage controls
- Sign out — ends your authenticated session on that device
- Subscriptions — manage or cancel through the payment provider that processed your purchase (Apple for App Store subscriptions; Stripe customer portal for web subscriptions), where available
To exercise other privacy rights or ask questions about our handling of your data, contact us using the email below. We will respond within a reasonable timeframe and may need to verify your identity before fulfilling certain requests.
Children
Linger is not directed to anyone under 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us information, contact us and we will take steps to delete it.
International users
The Service may be operated from the United States. If you access Linger from outside the United States, your information may be processed in the United States or other countries where our providers operate. Those countries may have different data protection laws than your jurisdiction.
Changes to this Privacy Policy
We may update this Privacy Policy as the Service evolves. When we make material changes, we will update the “Last updated” date and may ask you to review and accept the updated Privacy Policy before continuing to use the Service.
Contact us
For privacy questions, consent concerns, data access or deletion requests, or product-update unsubscribe help, contact:
Please include enough information for us to identify your account (such as the email address associated with it) and describe your request. We are responsible for responding to privacy inquiries related to the Linger Service.