Privacy policy
Effective[TODO: effective date]Version[TODO: version number]
What Candlekin knows about you, who else sees it, and what you can do about it. Section 5 is the one to read if you only read one.
1.Who we are and how to contact us
Candlekin is operated by [TODO: legal entity name], [TODO: registered street address, including country], which is the controller of the personal data described here. This policy covers candlekin.com and the Candlekin service.
Contact us at:
- Privacy and data-protection requests: [TODO: privacy email]
- Anything else: [TODO: support email]
- Telephone: [TODO: contact telephone number]
- Representative in the European Union under Article 27 of the GDPR: [TODO: EU representative name and address]
- Representative in the United Kingdom: [TODO: UK representative name and address]
- Data protection officer: [TODO: DPO name and contact, or a statement that one is not required and why]
2.Summary
The short version. Everything below is the long version, and the long version is what counts.
| Question | Short answer |
|---|---|
| What do you collect? | Your email address and a hash of your password, the characters and conversations you create, a record of purchases, and basic technical logs. |
| Does anyone read my conversations? | No person browses them. Automated checks look for the prohibited content described in section 6, and nothing else reads them. |
| Do you train models on them? | No. Not our models, not anyone else's. |
| Who else receives them? | DeepInfra, in the United States, runs the model that writes replies. Oracle hosts the servers. Stripe handles payments. Nobody else. |
| Do you sell my data? | No. We do not sell, rent or share personal information, and there is no advertising on the Service. |
| Can I get it back, or get rid of it? | Yes. “Download my data” and “Delete my account” are both buttons in Settings, and deletion is permanent. |
| Where does it live? | [TODO: hosting region] on Oracle Cloud, with model inference in the United States. |
3.What information we collect
Account information: your email address, a hash of your password (never the password itself), a display name if you set one, the confirmation that you are an adult along with when you gave it, and your interface language.
Content you create: character cards, personas, world books, conversations and every message in them, including branches, edits and earlier versions of a reply, plus the settings attached to a conversation.
Payment information: Stripe takes the payment. We keep a record that a purchase happened — the amount, the currency, the time, the credits granted, and the identifiers Stripe gives us so that the two records can be matched. We never receive or store your full card number, CVC, or bank account details.
Technical information: your IP address, your browser's user-agent string, timestamps, and the request and error logs a server keeps in order to stay up. The session and CSRF cookies described in section 11.
Anything you send us: if you email us, we keep the email and our reply.
We do not collect location beyond what an IP address implies, contacts, advertising identifiers, or anything at all from third-party trackers. There are no analytics or advertising scripts on the site.
4.Why we process it and on what legal basis
Under the GDPR, every kind of processing needs a legal basis. Here is ours, kind by kind. We have deliberately not used “legitimate interests” as a catch-all.
| Information | Why we process it | Legal basis |
|---|---|---|
| Account data: email, password hash, display name | To create your account, sign you in, and keep it secure | Article 6(1)(b) — performance of our contract with you |
| Adult confirmation and its timestamp | To meet our obligation not to provide an adult-oriented service to minors, and to be able to show that we asked | Article 6(1)(c) — compliance with a legal obligation |
| Conversations, characters, personas, world books | To run the Service: store your work, assemble the prompt, generate and display replies | Article 6(1)(b) — performance of our contract with you |
| Moderation and safety signals | To detect content prohibited by the terms, to respond safely to messages indicating a crisis, and to keep users and the Service safe | Article 6(1)(f) — our legitimate interest in a safe service, and yours in the same |
| Payment records | To take payment and grant credits, and to keep the accounting and tax records we are required to keep | Article 6(1)(b) and Article 6(1)(c) |
| Technical logs | To keep the Service available, to debug it, and to detect and prevent abuse | Article 6(1)(f) — our legitimate interest in security and availability |
| Emails you send us | To answer you | Article 6(1)(b), or Article 6(1)(f) where you are not a user |
Where we rely on a legitimate interest, we have weighed it against your rights and interests first. You can object at any time (section 10), and we will stop unless we have compelling grounds that override the objection.
5.Sensitive information in your conversations
This is the section we most want you to read.
Conversations here are fiction, but people write themselves into fiction. What you type may reveal information that Article 9 of the GDPR treats as a special category: health or mental state, sex life or sexual orientation, religious or philosophical beliefs, racial or ethnic origin, political opinions, or trade-union membership.
We ask you not to put that kind of information into the Service. Candlekin does not need it in order to work. Write the story: a character does not need your medical history, and giving it one will not make the writing better.
We do not ask for special category data, we have no lawful basis under Article 9 to process it for purposes of our own, and we do not want it. Where it ends up in a conversation, it is there because you chose to put it there, and we process it only to store and display that conversation back to you, and to run the safety checks described in section 6.
You can take it out again at any time:
- Delete a single message, and the branch below it, from that message's own actions.
- Delete a whole conversation from the conversation list.
- Use “Download my data” in Settings to see exactly what we hold.
- Use “Delete my account” in Settings. That is a permanent deletion of your account, conversations, messages, characters, personas and world books, not a hidden flag on them.
To be explicit about the three things people ask about most: your conversations are not used to train any model, ours or anyone else's; they are not used to build a profile of you or to infer anything about you; and they are not used for advertising of any kind.
6.Automated processing and content moderation
Content you submit, and content a model produces, is checked automatically against the prohibitions in the terms. No person reads your conversations as part of this.
One check has a different purpose from the rest. When a message indicates a crisis of self-harm or suicide, the Service returns a fixed safety response containing helpline information and does not call the model at all. The text of that turn is never sent to a model provider.
These checks can result in a reply being blocked, content being removed, or an account being limited or closed.
Where a decision like that is made without human involvement and significantly affects you, you have the right under Article 22(3) of the GDPR to obtain human intervention, to express your point of view, and to contest the decision. Write to [TODO: safety email]. Someone who was not involved in the original decision will review it and tell you the outcome and the reason for it.
We use automated processing for nothing else. There is no scoring, no profiling, and no automated pricing.
7.Who we share information with
Three providers, and nobody else. We do not sell, rent or share personal information, and we do not disclose it for advertising.
| Recipient | What it receives | Why | Where |
|---|---|---|---|
| DeepInfra, Inc., 2625 Middlefield Road #460, Palo Alto, CA 94306, United States | The prompt for each reply: the character card, your persona, the world-book entries that matched, and the recent messages of that conversation | It runs the open-weight DeepSeek models that generate replies | United States |
| Oracle (Oracle Cloud Infrastructure) | Everything the Service stores, in its capacity as the hosting provider | Servers, storage and the database | [TODO: hosting region] |
| Stripe, Inc. | Your email address and the details of a purchase. Card details go to Stripe directly from your browser and never reach us | Payment processing, fraud prevention, and its own tax and accounting records | United States and the European Economic Area |
About DeepInfra, because the distinction matters: your data is processed by DeepInfra in the United States. It is not sent to DeepSeek's own services and is not transferred to mainland China. DeepSeek publishes the weights of its models; DeepInfra runs a copy of those weights on its own machines in its own data centres. The restrictions that several regulators have placed on DeepSeek apply to DeepSeek's consumer service, not to the published weights.
We have contracted with DeepInfra on the basis that prompts and outputs are used only to return the reply and are not used to train models. [TODO: confirm the exact retention and zero-retention terms in the signed DeepInfra agreement and state the retention period here.]
About Stripe: Stripe is an independent controller of the payment data it collects, not only our processor. It decides for itself how to use that data for fraud prevention and for meeting its own legal obligations, and its own privacy policy applies to that use. We never receive or store your full card number, CVC, or bank account details.
We also disclose personal data where we are legally required to — a valid order from a court or a competent authority — and where it is necessary to establish, exercise or defend legal claims, or to prevent serious harm to someone. If the Service is ever transferred to another company, we will tell you before your data moves, and you will be able to delete your account first.
8.International data transfers
We are established in [TODO: country where the entity is established], the Service is hosted in [TODO: hosting region], model inference happens in the United States, and Stripe processes payments in the United States and the European Economic Area.
For transfers of personal data out of the European Economic Area, we rely on the Standard Contractual Clauses adopted by the European Commission in Commission Implementing Decision (EU) 2021/914, Module Two, controller to processor. For transfers out of the United Kingdom we rely on the same clauses together with the International Data Transfer Addendum issued by the Information Commissioner's Office. We have carried out a transfer risk assessment for each recipient. [TODO: complete and date the transfer risk assessments.]
You can ask us for a copy of these safeguards. Write to [TODO: privacy email], and we will send you the relevant clauses, with commercial terms redacted.
9.How long we keep information
We keep things for as long as we need them and no longer. In practice:
| Information | Kept for |
|---|---|
| Account data | As long as the account exists. Deleted when you delete the account. |
| Conversations, messages, characters, personas, world books | Until you delete them, or until you delete your account, whichever comes first |
| Backups | [TODO: backup retention period]. Deleted data disappears from backups when that cycle completes. |
| Technical and request logs | [TODO: log retention period] |
| Moderation records: what was actioned and why | [TODO: moderation record retention period], so that we can answer an appeal and account for the decision |
| Payment, accounting and tax records | [TODO: statutory retention period for the entity's jurisdiction]. We are required to keep these even after you delete your account. |
| Support correspondence | [TODO: support correspondence retention period] |
Deleting your account is a permanent deletion, not a flag. What survives it is the small set of records above that we are legally required to keep, and backups until they expire on their own cycle.
10.Your rights
If you are in the European Economic Area or the United Kingdom, the law gives you the rights below. We extend them to everyone who uses Candlekin, wherever you are, because running two standards would be both harder and worse.
- To know what we hold about you, and to get a copy of it.
- To have it corrected if it is wrong.
- To have it erased.
- To restrict what we do with it while a question about it is open.
- To receive it in a portable, machine-readable form.
- To object to processing we base on a legitimate interest.
- To withdraw consent where we have relied on it, without affecting what we did before you withdrew it.
- Not to be subject to a decision based solely on automated processing that significantly affects you — see section 6.
- To complain to a supervisory authority.
Two of these are buttons rather than requests. In Settings, “Download my data” gives you a machine-readable file containing your characters, personas, world books and every conversation — that is your right of access and your right to portability, and you do not have to ask us for it. “Delete my account” erases your account and its contents permanently — that is your right to erasure, and it takes effect immediately.
For anything else — a correction, a restriction, an objection, or a question about any of the above — write to [TODO: privacy email]. We answer within one month, and we will tell you if we need longer, which the law allows for complex requests.
There is no charge for any of this. We may ask you to confirm that you are the account holder before we act, because handing your data to the wrong person would be a worse outcome than a short delay.
You can complain to a supervisory authority: in the European Economic Area, the authority in the country where you live or work, and in the United Kingdom, the Information Commissioner's Office. We would rather you came to us first, but you are not obliged to.
11.Cookies and local storage
There are no advertising or analytics cookies on Candlekin, and no consent banner, because there is nothing to consent to. Three things are stored in your browser, and this is all of them:
- candlekin_session — a cookie that keeps you signed in. Your browser sends it back on each request; JavaScript on the page cannot read it. Without it, every page would ask you to sign in again.
- candlekin_csrf — a cookie that lets the site prove a write request came from a page you were actually looking at. It exists to stop another site from acting as you.
- locale — an entry in localStorage holding the interface language you chose, so the site does not come back in the wrong one.
All three are strictly necessary for a service you asked for: two are required to provide and secure sign-in, and the third stores a preference you set yourself. Under Article 5(3) of the ePrivacy Directive (2002/58/EC) and Regulation 6(4) of the UK Privacy and Electronic Communications Regulations 2003, storage of this kind does not require consent.
None of them is used to track you across sites, and none is shared with anyone.
12.Data security
Passwords are stored as hashes, never as passwords. Traffic between your browser and the Service is encrypted in transit. The session cookie is httpOnly, and write requests carry a CSRF token that has to match.
Access to the production database is limited to the people who operate the Service, and it is not reachable from the public internet. Backups are encrypted. [TODO: confirm and describe production access control, who holds it, and when it was last reviewed.]
No service is perfectly secure, and we would rather tell you where the risk in this category actually sits. Every large leak of a companion-chat service in recent years came from an unauthenticated database, queue or storage bucket left open to the internet — not from a model provider. Access control on the data path is therefore the thing we treat as unable to be got wrong.
13.Data breaches
If a personal data breach puts your rights and freedoms at risk, we notify the competent supervisory authority within 72 hours of becoming aware of it, as Article 33 of the GDPR requires.
If the risk to you is high, we tell you directly, and we tell you what happened, what data was involved, what we are doing about it, and what you can do.
We keep an internal record of breaches whether or not they are reportable.
14.Children
Candlekin is for adults. It is not directed at anyone under 18, and we do not knowingly collect personal data from anyone under 18. Here is what that means in practice, rather than as a disclaimer:
- At sign-up we ask you to confirm that you are an adult, and we record the confirmation and its timestamp.
- We do not advertise where children are the audience, and the Service is not designed to appeal to them.
- If we learn that an account belongs to someone under 18 — from a report, from a moderation signal, or from the user themselves — we suspend it immediately, delete the account and its content, and refund any unspent credit balance.
- Anyone can report an account they believe belongs to a minor: write to [TODO: safety email] with whatever identifies it. We handle these before anything else.
- Sexual content involving minors is prohibited outright, including in fiction. Accounts are closed and, where the law requires it, reported.
If you are a parent or guardian and you believe your child has an account here, write to [TODO: safety email] and we will remove it.
15.US state privacy rights
If you live in California, or in another US state with a comprehensive privacy law, that law gives you rights to know what is collected about you, to get a copy of it, to correct it, to delete it, and not to be treated worse for asking.
We do not sell or share your personal information. We have not sold or shared personal information in the preceding 12 months, and we do not process personal information for cross-context behavioural advertising or for targeted advertising. There is no “Do Not Sell or Share My Personal Information” link on this site because there is nothing to opt out of.
Section 3 says what we collect, section 4 why, section 7 who receives it, and section 9 how long we keep it. The categories in section 3 are also the categories we have collected in the preceding 12 months.
To exercise a right, use the buttons in Settings or write to [TODO: privacy email]. You may use an authorised agent, and we will verify that a request comes from you or from someone you authorised.
16.Changes to this policy
We will tell you before a material change takes effect: at least 30 days' notice by email and in the product. Minor changes take effect when we post them.
The effective date at the top of this page is always the date of the version you are reading, and we keep previous versions available so that you can see what changed.
17.Contact
[TODO: legal entity name], [TODO: registered street address, including country].
Telephone: [TODO: contact telephone number].
- Privacy and data-protection requests: [TODO: privacy email]
- Safety reports and moderation appeals: [TODO: safety email]
- Anything else: [TODO: support email]
- Representative in the European Union under Article 27 of the GDPR: [TODO: EU representative name and address]
- Representative in the United Kingdom: [TODO: UK representative name and address]
We answer in English.
Also worth reading
Terms of service