1. Who is responsible for your data
Asyncsphere is the data controller for Amigify and the Amigify Companion app. Our registered address is:
Village: Kangnek Tokbi, Baghpani
Town: Dokmoka
District: Karbi Anglong
State: Assam
PIN: 782441
Country: India
You can reach our privacy contact at privacy@amigify.com.
2. What we collect
When you join the waitlist
- The name or nickname you give us, and your email address — so we can send your invite and reach you if there is a problem with it. We do not ask for your phone number.
- Whether you signed up as a user or a companion — so you get the right onboarding.
- Your confirmation that you are 18 or over, and whether you opted in to marketing email.
- Your IP address, your browser's user-agent string and the page that referred you — see section 4 for what the IP is used for.
When you use the app
- Account details — nickname, email address, date of birth (our 18+ check), and anything you choose to add to your profile such as an avatar, interests and languages. Your email address and date of birth are held to identify and verify your account, and to contact you about it. They are never shown to companions or to other users, and we do not share or sell them. What the other person in a conversation sees is your nickname and whatever you choose to tell them. The one exception is a lawful demand — a court order, a warrant or a valid request from a government or law enforcement authority — which we must comply with; see section 6.
- Conversation content — messages you send. These are encrypted with AES-256-GCM.
- Media you send — images, audio, video and documents shared in a conversation, stored in our cloud storage.
- Call metadata — who called whom, when, the call type and how long it lasted, because calls are billed by the minute. We do not record the audio or video of your calls. Call media travels directly between the two devices over WebRTC, relayed through a TURN server when a direct connection is not possible.
- Transactions — Amigo Coin and heart purchases, call and message charges, hearts sent or received, and companion payouts.
- Payout details, for companions — bank account, holder name and IFSC or SWIFT code, held encrypted, plus the identity documents used for verification.
- Device and session data — device model and type, OS and app version, a device identifier, your push token, the IP address of each active session and the approximate location derived from it, so you can see and revoke your own sessions in Settings.
- Diagnostics and product analytics — crash reports, error traces, and events about how features are used.
3. Why we use it
- To run the service — deliver messages, connect calls, bill coins, pay companions, and keep your account working across devices.
- To keep people safe — screen content against our safety rules, investigate reports, and enforce the community guidelines.
- To contact you — waitlist invites, transactional email and push notifications, and marketing email only if you opted in. Every marketing email has an unsubscribe link; transactional messages about your account are not marketing and are not opt-out.
- To improve the product — aggregated analytics about which features are used and where the app fails.
- To meet legal obligations — tax and accounting records for payments and payouts, and responses to lawful requests.
We do not sell your personal data. We do not use your conversations for advertising, and we do not use them to train machine-learning models.
4. IP addresses
We store the IP address associated with a waitlist signup and with each app session, in readable form rather than hashed, and the approximate location we derive from it. It is a security signal, and we use it only for:
- Security and fraud prevention.
- Detecting and blocking abusive or automated accounts.
- Login and account-security monitoring.
- Investigating payment fraud and chargebacks.
- Detecting account takeover, so you can spot a session you don't recognise.
- Basic security analytics, such as spotting a flood of signups from one network.
- Responding to legitimate legal requests.
We do not use IP addresses for advertising, profiling or building a marketing picture of you, and we do not sell or share them for those purposes. They are deleted with your account, except where an open fraud or safety investigation or a legal obligation requires us to keep them longer.
5. Automated content moderation
Every message and every image is checked automatically before it is delivered. This is machine screening, not a person reading your conversation — no human sees any of it unless the content is escalated or reported.
- Text — every message you send is scanned by our own algorithm, running on our servers, which matches it against our safety rules and scores it by category. Message text is not sent to any third-party service for this.
- Images — every image is analysed by an AI moderation model, the OpenAI Moderation API, which classifies the image and returns category scores. OpenAI does not use content submitted to that API to train its models.
Both produce a score per category, and it is the score against our thresholds — not a human judgement — that decides whether a message is delivered, blocked or escalated.
When a conversation is reported — by a person, or automatically because screening escalated it — we take a snapshot of the last 20 messages in that conversation and attach it to the report. That snapshot is what a moderator reviews. We do not open the rest of the thread, and we do not read conversations that have not been reported.
Depending on what is found, a message may be blocked, an account may receive a warning or a strike, or the account may be suspended or removed. Content suggesting a risk of self-harm raises a safety flag for our team rather than a penalty. You can ask a human to review any enforcement decision — see the community guidelines.
6. Who we share it with
Only the processors we need to operate, each bound by contract to use the data solely on our instructions:
- Resend — sends our email from noreply@amigify.com.
- Amazon Web Services — media storage and delivery.
- Firebase Cloud Messaging and Apple Push Notification service — push notifications.
- Razorpay — payment processing for coin and heart purchases. We never see or store your card details.
- Apple and Google — sign-in with Apple and Google, and in-app purchases where an app store requires its own billing.
- OpenAI — image moderation only, as described above.
- Sentry — crash and error diagnostics.
- PostHog — product analytics about how the apps are used.
Legal and government requests
Beyond those processors, the only other time your data leaves us is when the law compels it. We may disclose personal data — including your email address, date of birth, transaction records and, where the order covers it, conversation content — in response to a court order, a warrant, or a valid and legally binding request from a government, regulator, tax authority or law enforcement agency. We may also disclose data where it is necessary to protect someone from serious harm, such as a credible threat to life.
We review every request, we push back on requests that are overbroad or not legally valid, and we disclose only what the request actually requires. Where we are legally permitted to tell you that your data was requested, we will.
7. How long we keep it
- Waitlist entries — until launch, and up to 12 months after, unless you ask us to delete them sooner.
- Account data — while your account is active. Deleting your account removes your profile, your credentials and your sessions immediately, and ends your access to your conversations. The other person in a conversation keeps their copy of that thread, with your account shown as deleted; see delete your account for the detail.
- Transaction and payout records — as long as tax and accounting law requires, typically 7 years. These survive account deletion because we are obliged to keep them.
- Reported conversations and moderation logs — retained for as long as the safety investigation and any appeal require.
- Encrypted backups — roll off on their own schedule, so a copy may persist briefly after deletion.
8. Your rights
Wherever you live, you can ask us to access, correct, export or delete your personal data, and to stop sending you marketing. Depending on your jurisdiction (for example the GDPR in the EU/UK, the DPDP Act in India, or the CCPA in California) you may also have the right to object to certain processing or to lodge a complaint with your data protection authority.
You can delete your account yourself at any time from Settings in either app. For anything else, email privacy@amigify.com and we will respond within 30 days. To leave the waitlist, that one email is all it takes — no account needed.
9. Security
- Messages are encrypted at rest with AES-256-GCM and versioned keys.
- Companion bank details are encrypted at rest with AES-256-GCM.
- All traffic to our apps and API is over TLS.
- Passwords are hashed with bcrypt and are never recoverable by us.
- Screenshot and screen-recording protection is enabled in the apps, so a conversation cannot simply be captured off the screen. It raises the cost of copying a conversation; it cannot make it impossible, since a second device can always photograph a screen.
- Your email address is never exposed to the other person in a conversation.
- You can see every active session, with its device and approximate location, and revoke any of them from Settings.
- Access to production data is restricted to staff who need it, and is logged.
No system is perfectly secure. If a breach affects you, we will notify you and the relevant authority as the law requires.
10. International transfers
Our infrastructure and processors may store data outside your country. Where that happens we rely on appropriate safeguards, such as the EU Standard Contractual Clauses.
11. Children
Amigify is for adults aged 18 and over, on both sides of the conversation. We ask for date of birth at signup and verify the age of every companion. If we learn that we hold data about someone under 18, we close the account and delete it.
12. Cookies
This website does not use advertising or analytics cookies. See our cookie policy for the full detail.
13. Changes
If we change this policy materially we will email you before the change takes effect and update the date at the top of this page.