Last updated: 15 September 2026 — Alpha version.
1. Who we are
The data controller is XXXXXXXXXXX SAS, [REGISTERED ADDRESS], France, RCS [CITY] [●] (the “Company”). Data protection contact: privacy@meetmymodel.ai. Data Protection Officer: [DPO NAME / dpo@meetmymodel.ai — to be appointed]. Our lead supervisory authority is the French CNIL (cnil.fr).
This policy applies to meetmymodel.ai and to the MeetMyModel application (the “Service”). It is written to comply with the EU General Data Protection Regulation (GDPR), the French Loi Informatique et Libertés, and, where applicable, the UK GDPR and US state privacy laws.
2. Data we process
Account data — email address, password (hashed), display name, optional profile picture, account creation date, subscription status and history, top-up credits.
Conversation data — the messages you send, the replies, images and clips generated for you, the Companions you create and their settings, relationship state (how far a conversation has progressed), and “memory”: facts about you that the Service extracts from what you say (for example your first name, city, pet, job, moods you mention) so that Companions can remember them. Deleting your account erases this memory; you can also ask us to access or erase specific data at privacy@meetmymodel.ai.
Content-safety data — flags raised by our safeguards (for example a message suggesting a user may be a minor, or a request for prohibited content), moderation decisions, complaints you file and their handling.
Payment data — handled by our payment providers (see §6). We receive a customer identifier, the plan purchased, the amount, the date, the last four digits of the card and the payment status; we never receive or store full card numbers.
Technical data — IP address, device and browser type, language, approximate location derived from IP, timestamps, request identifiers, error logs, and the cookies and identifiers described in the Cookie Policy.
Age-assurance data — when age verification is required (§4), the result of the check (verified / not verified) and a verification reference from the provider; the provider does not transmit your identity document to us.
3. Sensitive data and consent
Because the Service is an adult entertainment product, your use of it, your conversations and the Companions you choose can reveal information about your sex life or sexual orientation, which is a special category of data under Article 9 GDPR. We process it only on the basis of your explicit consent, which you give when you create your account and accept this policy, and which you can withdraw at any time by deleting your account. We never use this data for advertising, never sell it, and never share it with third parties other than the processors strictly needed to run the Service (§6). We have carried out a data protection impact assessment for this processing.
4. Why we process your data and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Creating and running your account, delivering conversations, images and clips, memory | account, conversation | Contract (Art. 6(1)(b)); explicit consent for special-category data (Art. 9(2)(a)) |
| Billing, subscriptions, credits, fraud prevention | account, payment, technical | Contract; legal obligation (accounting); legitimate interest (fraud) |
| Keeping the Service safe: detecting attempts to obtain prohibited content, protecting minors, handling complaints, cooperating with authorities | conversation, content-safety, technical | Legal obligation (DSA, French law); legitimate interest in preventing abuse; substantial public interest (Art. 9(2)(g)) for child-safety processing |
| Age assurance | age-assurance | Legal obligation (SREN law / ARCOM standard, and equivalent laws) |
| Improving the Service: measuring quality, fixing errors, evaluating our own models and prompts | conversation (pseudonymised where possible), technical | Legitimate interest; we do not use your conversations to train third-party foundation models |
| Service emails (receipts, security, changes to terms) | account | Contract / legal obligation |
| Marketing emails | account | Consent (opt-in), withdrawable at any time |
| Security, logging, abuse prevention | technical | Legitimate interest |
5. Retention
- Account and conversation data: for the life of the account, then deleted within 30 days of account deletion, except as below.
- Content-safety data and records of prohibited-content attempts: 3 years, or longer where an investigation or legal obligation requires it.
- Billing records: 10 years (French accounting law).
- Technical logs: 12 months (French data-retention rules for hosting providers), then deleted or anonymised.
- Age-assurance results: for the life of the account.
- Complaints and their handling: 3 years after closure.
6. Who receives your data
We use processors bound by data-processing agreements. Current categories and main providers:
- Hosting and delivery: Cloudflare, Inc. (edge hosting; USA/EU, EU–US Data Privacy Framework).
- Database and authentication: Supabase (hosted in the EU, Paris region).
- Image and object storage: Cloudflare R2.
- Language model providing Companion replies and safety checks: Mistral AI (France).
- Image generation: Wiro AI; Civitai, Inc. (USA) as fallback. Video generation: Venice.ai (USA). Image safety review: RunPod, Inc. (USA). These providers receive the generation prompt and the reference images of the fictional Companion; they do not receive your account identity.
- Payments: Stripe Payments Europe Ltd (Ireland) and CCBill IE Ltd (Ireland, regulated by the Central Bank of Ireland) for adult subscriptions.
- Email delivery, error monitoring and analytics providers acting on our behalf.
- Age-verification provider: [PROVIDER — to be selected], which verifies your age without transmitting your identity to us.
We disclose data to public authorities when the law requires it (for example to the PHAROS platform or a court), and to professional advisers under confidentiality. We do not sell personal data.
7. International transfers
Some processors are outside the EU/EEA. Transfers rely on the EU–US Data Privacy Framework where the provider is certified, or on the European Commission’s Standard Contractual Clauses with additional safeguards. You may request a copy of the relevant safeguards at privacy@meetmymodel.ai.
8. Your rights
You have the right to access, rectify and erase your data, to restrict or object to processing, to data portability, to withdraw consent at any time (without affecting prior processing), and to define directives on what happens to your data after your death. You can delete your account directly from the account page, which erases your conversations and memory; for access, rectification, portability and any other request, write to privacy@meetmymodel.ai. We answer within one month. You may lodge a complaint with the CNIL (cnil.fr) or the supervisory authority of your country of residence.
9. Minors
The Service is for adults only. We do not knowingly collect data from anyone under 18. If we learn that an account belongs to a minor we close it and delete the data, subject to legal retention obligations and to the reporting described in the Underage & Child Safety Policy.
10. Security
Data is encrypted in transit and at rest; access is limited to staff and processors who need it; generated images are stored under non-guessable identifiers; passwords are hashed; access to conversation data for moderation is logged. No system is perfectly secure; tell us at security@meetmymodel.ai if you find a vulnerability.
11. Cookies
See the Cookie Policy.
12. Changes
We will notify material changes by email or in the Service at least 15 days before they take effect.