ToON Novels — Privacy Policy
Effective Date: 26 August 2026 | Last Updated: 26 August 2026 | Version: 2.2
Important Notice
This Privacy Policy ("Policy") explains how we collect, use, store, and protect information when you use ToON Novels: stories and chats ("ToON Novels", the "Service") — an interactive-fiction platform featuring branching narratives and AI-powered conversations with story characters (the "AI Favorites").
This Policy covers all platforms. It applies to the ToON Novels website at novel.toon.org, to the ToON Novels application for Android distributed through Google Play, and to the ToON Novels application for iOS distributed through the Apple App Store. Where a practice applies to only one platform, this Policy says so explicitly.
Read with the Terms of Service. This Policy must be read together with our Terms of Service, which set out additional terms, disclaimers, limitations of liability, dispute resolution and governing law. In the event of any conflict between this Policy and the Terms of Service in respect of liability, dispute resolution, or governing law, the Terms of Service shall prevail.
Age Requirement. The Service is intended for users aged 16 and over. See Section 15.
Geographic Scope. The Service is operated from the Netherlands. The Data Controller is established in the Netherlands and, accordingly, the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") applies to our processing activities pursuant to Article 3(1) GDPR. We comply with GDPR in respect of all personal data we process, regardless of user location. If you access the Service from a jurisdiction where its use would be unlawful, you must not use the Service.
Free of charge. The Service contains no paid features, no in-app purchases and no advertising. We do not collect payment data and do not use advertising identifiers.
Language. This Policy is written in English. Any translation is provided for convenience only; in case of inconsistency, the English version prevails.
1. Who We Are (Data Controller)
The Data Controller for the personal data processed in connection with the Service is:
•
Status: individual service operator (natural person) acting as Data Controller
•
Country of establishment: the Netherlands
•
Contact email: support@toonlabs.co
No corporate legal entity has been established. All privacy-related correspondence should be directed to the contact email above.
2. Platforms Covered by This Policy
The Service is available in three forms, and the data we process differs slightly between them:
•
Web — the browser version at novel.toon.org. Sign-in by email code or with Google. Uses cookies and browser local storage. Web push notifications are supported on desktop browsers only.
•
Android application — distributed through Google Play. Sign-in by email code or with Google. Uses device identifiers, Firebase Cloud Messaging for push notifications, and local device storage instead of cookies.
•
iOS application — distributed through the Apple App Store. Sign-in by email code only; Google Sign-In is not offered on iOS. Uses device identifiers, Apple Push Notification service (APNs) for push notifications, and local device storage instead of cookies.
We do not use Sign in with Apple on any platform.
Your account, story progress and AI conversation history are synchronized when you sign in to the same ToON Novels account, whichever method you used to create it. Without signing in you can still use the Service as a guest — see Section 3.1.
3. Information We Collect
3.1 Account Information
Signing in is optional, and we never create or store a ToON Novels password.
Email sign-in (all platforms). You enter your email address and we send a one-time six-digit code to it; entering the code signs you in. We collect and store:
•
Email address — the address you enter yourself. Used to sign you in, to identify your account across devices, for support correspondence and for service messages.
•
One-time codes and authentication metadata — the code itself, when it was issued and used, and the outcome of sign-in attempts, including failed ones. We keep this to complete the sign-in and to detect brute-force attempts and other abuse.
Sign-in emails are generated and sent from our own infrastructure (see Section 6). We do not use an external mailing or marketing platform and do not pass your address to one.
Google Sign-In (web and Android only). You may instead sign in with your Google account. Google then shares with us your email address, name and profile picture URL, and your Google account identifier, which we use to recognize your account. We do not receive your Google password. Google's processing during sign-in is subject to Google's own privacy policy, and you may revoke our access at any time via myaccount.google.com. Google Sign-In is not available in the iOS application, and we do not use Sign in with Apple, Facebook or any other third-party login anywhere.
Profile. In addition, we store:
•
Display name — only if you choose to set one. It is optional, may be left empty, and may be changed or removed at any time.
•
Avatar — which picture you selected from the fixed set we provide. We store only your choice. The Service has no facility for uploading an image, and we never access your photos, gallery or camera.
Using the Service as a guest. You may use the Service without providing an email address or signing in. When you do so, we create a pseudonymous guest profile identified by an application or device installation identifier. Guest story progress, AI conversation history, AI consent records and related functional events may be transmitted to and stored on our servers so that the Service can operate for that guest profile.
Guest data is not synchronized to unrelated devices unless you later sign in and the Service offers a transfer or account-switch flow. If you uninstall the application or clear its local data, the local identifier and locally stored data are removed and you may lose access to the server-side guest profile. Uninstalling the application does not itself send us a deletion request and does not guarantee immediate deletion of the server-side copy.
You may delete the guest profile and its associated server-side data before uninstalling by using Settings → Delete Account. If you can no longer access the guest profile, you may contact support and provide the Support User ID, if available. Retention periods are described in Section 8.
3.2 Game Progress and Story Data
As you use the Service, we collect data about your in-story activity, including:
•
Stories started, completed, or abandoned.
•
Branching choices and decisions you make within stories.
•
Endings reached and replay statistics.
•
Behaviour and relationship statistics accumulated through your choices.
•
Bookmarks, favorites, and characters marked as AI Favorites.
•
Tasks completed within the Service and content unlocked as a result.
•
Reading or play time per story.
This data is used to save your progress, present continuation points, unlock content, and operate Service functionality.
3.3 AI Conversation Data
If you initiate conversations with the AI Favorites (AI-powered character chat), we collect:
•
Text messages and prompts you send to AI Favorites.
•
AI responses generated by the underlying language model.
•
Conversation history and metadata (timestamps, character context).
•
Story context passed to the character, including choices you made in the story, so that the character can refer to them.
Conversations are processed by a third-party AI provider (OpenAI) for response generation. See Sections 6 and 16 for details and disclaimers regarding AI processing.
Separate consent before your first chat. Before you send your first message to any AI Favorite, we show you what is transmitted, to whom and for what purpose, together with a link to this Policy, and ask for your consent. You may decline. If you decline, the AI chat feature is not available to you and no message data is transmitted; all Stories remain fully accessible. You may withdraw this consent at any time in the Service settings, after which we stop transmitting new messages to OpenAI; existing conversations remain readable. We record when you gave or withdrew this agreement, which version of the notice you saw, and on which platform — against your account, or against your device identifier if you are using the Service as a guest.
3.4 Content Reports and Safety Data
The Service provides in-app tools to report a server-persisted AI-generated message or an AI conversation. When you submit a report, we collect the report reason and explanation, the relevant message or conversation identifiers, the character and story involved, the timestamp, and your account identifier or pseudonymous guest identifier. These identifiers allow us to retrieve the reported content and the surrounding context necessary to assess the report.
We use this data solely to review the report, to improve safety filters and character behaviour, to enforce our Terms of Service, and to comply with the content policies of the app stores through which the Service is distributed.
3.5 Device and Application Data
Applies to the Android and iOS applications. When you use the application, we and our processors collect:
•
Device identifiers — including the Firebase installation identifier and the Firebase Analytics app instance identifier, and, for guest use, an identifier of the device installation used to keep your progress. These identifiers are generated by the application or platform. Firebase identifiers generally reset when the application is reinstalled. Depending on the platform, a guest identifier may persist or allow the same guest profile to be recovered on the same device. Uninstalling the application does not itself delete the server-side guest profile.
•
Device and OS information — device model, operating system and version, application version and build, device language and region, screen characteristics.
We do not collect the Android Advertising ID, the iOS Identifier for Advertisers (IDFA), or any other advertising identifier. We do not perform cross-application or cross-site tracking and do not serve advertising.
The applications do not include Crashlytics or another crash-reporting SDK, and we do not collect crash logs or stack traces through such an SDK. We do collect limited first-party operational diagnostics, such as application version, response duration, operation success or failure status, and error category. This information is used to maintain Service functionality, investigate failures and improve operational stability.
3.6 Push Notification Tokens
If you enable notifications, we collect and store a push notification token — a technical identifier issued by the operating system or the messaging platform that allows a message to be delivered to your specific device or browser installation:
•
Android application — a Firebase Cloud Messaging (FCM) registration token.
•
iOS application — an Apple Push Notification service (APNs) device token, handled through Firebase Cloud Messaging.
•
Web (desktop browsers) — a Web Push subscription endpoint and the associated public keys, issued by your browser vendor's push service.
The token is linked to your account so that we can deliver messages relevant to your progress and characters. See Section 11 for what we send and how to turn it off.
3.7 Analytics, Behavioural Data and Service Telemetry
Two different things happen here, and they are governed differently: optional third-party analytics, which run only if you agree, and our own telemetry — part of it necessary to operate the features you request, part of it used to understand and improve the Service.
Optional analytics — only with your consent. We collect product analytics data through Amplitude, Google Analytics (web) and Firebase Analytics (applications), including:
•
Screens and content viewed; navigation paths within the Service.
•
Session duration, frequency of visits, time of access.
•
Interaction events (taps, clicks, scrolls, feature use).
•
Approximate location derived from IP address (city/country level only).
•
Device and browser information: browser type and version, operating system, screen resolution, user-agent string, language.
•
Referring URL and campaign parameters, where you reached the Service through a marketing link (web).
•
Install and first-open events (applications).
Analytics do not run until you have given consent. Where you have not yet answered the consent request, analytics are treated as refused. You can change your choice at any time in Settings.
First-party operational and product telemetry. In addition to optional third-party analytics, the Service sends a limited set of events directly to ToON Novels servers.
Some events are necessary to perform an action requested by you, including confirming task completion, updating unlocked content, submitting a content report, sending an author application, maintaining server-side progress, verifying operation results, preventing abuse and protecting the Service. These operational events are processed regardless of your analytics choice because the requested feature cannot operate correctly without them.
We also collect limited first-party product telemetry, including novel-click and novel-view events, onboarding and authentication funnel steps, chat funnel events, social-link interactions, response duration, success or failure status, and similar information about how Service features are used and perform.
Depending on the event, the data may include the event type and timestamp, your account identifier or pseudonymous guest identifier, application version, feature context, operation result and error category. Operational events are processed as necessary to provide the Service. First-party product telemetry is processed on the basis of our legitimate interests in understanding, maintaining and improving the Service. You may object to this processing as described in Section 9.
This data is sent directly to us and our infrastructure providers. It is not shared with Amplitude or Firebase Analytics unless you have separately accepted optional analytics. It is not used for advertising, cross-application tracking or cross-site tracking.
3.8 Server Logs
Our servers and infrastructure automatically generate technical logs necessary for operation and security, which may include:
•
Date and time of requests.
•
URLs or API endpoints requested and HTTP response status.
•
User-agent string and application version.
Server logs are used for security, debugging, fraud prevention, and operational stability.
3.9 Cookies and Local Storage
Web: we use cookies and similar browser storage technologies. See Section 17 for the full list and your choices.
Applications: the applications do not use cookies. Equivalent information — your session, preferences, consent choices and cached story content — is stored locally on your device by the application itself and is removed when you delete the application.
3.10 Communications with Support
If you contact us by email or otherwise, we receive and store your communications and any data you choose to include for the purpose of responding and improving our support.
3.11 What We Do Not Collect
We do not collect or process: payment or financial data (the Service contains no paid features), photos, videos, audio uploads, precise GPS geolocation, contacts, calendar, SMS, call logs, health or fitness data, biometric data, installed application lists, or messages from other applications on your device. We do not access your device camera, microphone, gallery or files, and the Service accepts no uploaded images of any kind — avatars are chosen from a fixed set we provide.
3.12 Where Each Category Applies
Data category
Web
Android app
iOS app
Email sign-in data (address, one-time codes)
●
●
●
Sign in with Apple data
—
—
—
Guest profile and progress (server-side, pseudonymous)
●
●
●
Game progress and story data
●
●
●
Content reports and safety data
●
●
●
Device and application identifiers
—
●
●
Crash logs and stack traces
—
—
—
Limited first-party operational diagnostics
—
●
●
Push notification token
● desktop only
●
●
Optional analytics (after you agree)
●
●
●
First-party telemetry (operational and product)
●
●
●
4. How We Use Your Data
We use collected data for the following purposes:
•
To operate and provide the Service, including saving your progress and delivering branching content.
•
To enable AI-powered conversations with AI Favorites and to give characters memory of your choices.
•
To deliver push notifications you have agreed to receive.
•
To review reports of inappropriate AI content and to keep the Service safe.
•
To maintain Service stability, performance and security, and to detect and prevent abuse.
•
To operate features you request, including confirming completed tasks and updating what content is unlocked.
•
To conduct optional product analytics (with your consent).
•
To respond to support requests and communicate with you about the Service.
•
To enforce our Terms of Service and prevent abuse, fraud, and unlawful use.
•
To comply with legal obligations, with the policies of the app stores that distribute the Service, and to respond to lawful requests from authorities.
We do not sell personal data, do not share it with advertisers, do not serve advertising, and do not use your content to train AI models.
5. Legal Basis for Processing
Under GDPR, we rely on the following legal bases:
•
Performance of a contract (Article 6(1)(b)) — to deliver the Service, to sign you in by email code or with Google, to maintain your account or guest profile, to save your progress, to process the operational events without which a requested feature cannot work, and to operate the AI Favorites feature once you have agreed to it.
•
Legitimate interests (Article 6(1)(f)) — for security, fraud and abuse prevention, essential server logs, operational diagnostics, review of content reports, and first-party product telemetry used to understand, maintain and improve the Service, balanced against your rights and freedoms. You may object to processing based on legitimate interests as described in Section 9.
•
Consent (Article 6(1)(a)) — for non-essential cookies, optional product analytics (Amplitude, Google Analytics, Firebase Analytics), and push notifications. Your explicit agreement is also required before any message is transmitted to OpenAI. You may withdraw consent at any time, in which case we cease the relevant processing.
•
Legal obligation (Article 6(1)(c)) — where processing is necessary to comply with a legal obligation to which we are subject.
6. Third-Party Service Providers
We rely on third-party processors to operate the Service. We engage only processors that provide sufficient guarantees to implement appropriate technical and organisational measures, as required by Article 28 GDPR, and we contract with them on the data-processing terms they make available for that purpose. Those terms require them to process data only on our instructions, to keep it confidential and secure, and to assist us in responding to your requests.
We remain responsible for choosing these processors, for how we integrate them, and for disclosing to you what is transferred and why. Where a provider also acts as an independent controller for its own purposes, its own privacy policy governs that processing, and we identify such cases below.
Provider
Purpose
Platforms
Location
Privacy Policy
Amazon Web Services (AWS)
Cloud hosting, database, storage, and delivery of sign-in and service email
All
United States (us-east-1, Virginia)
aws.amazon.com/privacy
Google LLC — Identity
Google Sign-In (OAuth)
Web, Android
Global
policies.google.com/privacy
Google LLC — Google Analytics (GA4)
Web analytics
Web
Global
policies.google.com/privacy
Google LLC — Firebase Cloud Messaging
Push notification delivery
Android, iOS
Global
firebase.google.com/support/privacy
Google LLC — Firebase Analytics
Application product analytics
Android, iOS
Global
firebase.google.com/support/privacy
Apple Inc. — APNs
Push notification delivery on iOS
iOS
United States
apple.com/legal/privacy
Amplitude
Product analytics
All
United States
amplitude.com/privacy
OpenAI (GPT family models)
AI response generation for AI Favorites
All
United States
openai.com/policies/privacy-policy
App stores. The applications are distributed through Google Play (Google LLC) and the Apple App Store (Apple Inc.). Those stores independently collect data about downloads, installations and, where applicable, device compatibility, under their own privacy policies. We receive only aggregated, non-identifying statistics from them.
OpenAI processing. We use language models from OpenAI's GPT family to generate AI Favorites responses. The specific model in use may be updated from time to time without amendment to this Policy. Content of your inputs (text messages to AI Favorites and contextual character and story data) is transmitted to the OpenAI API for one-time inference. Per OpenAI's API data usage policy, API inputs are not used to train OpenAI models. OpenAI may retain inputs for a limited period for abuse-monitoring purposes, after which they are deleted in accordance with OpenAI's policies. OpenAI acts as our processor under its data-processing terms, and we are responsible for having selected it and for disclosing this transfer to you; its internal operations are governed by those terms and by its own published policies.
No external mailing provider, and no Apple login. One-time codes and service email are generated and sent from our own infrastructure on AWS; we do not pass your address to an external mailing or marketing platform. Google Sign-In is offered on the web and on Android as an alternative to email sign-in; we do not use Sign in with Apple, Facebook or any other third-party login on any platform.
No payment processors. The Service contains no payment functionality. We do not use payment processors and do not collect any financial or payment data.
7. International Data Transfers
Your data is stored and processed primarily in the United States (AWS us-east-1, Virginia, and OpenAI infrastructure). Google, Apple and Amplitude may also process data in the United States and other jurisdictions. By using the Service you acknowledge and consent to your data being transferred to and processed in such jurisdictions, which may have data protection laws different from those of your country of residence.
Transfers from the Netherlands (where the Controller is established) to the United States are made on the basis of (i) the EU-US Data Privacy Framework where the recipient is certified, and/or (ii) Standard Contractual Clauses (SCCs) approved by the European Commission. We rely on the standard data-processing terms offered by AWS, Google, Apple, Amplitude and OpenAI, each of which incorporates SCCs for international transfers.
8. Data Retention
We retain data for as long as reasonably necessary for the purposes set out in this Policy. Indicative retention periods (not strict deadlines):
•
Active accounts — account data and progress are retained while your account is active.
•
Inactive accounts — we use reasonable efforts to schedule for deletion personal information of accounts that remain inactive for at least two (2) consecutive years.
•
One-time sign-in codes — valid for a few minutes and deleted once used or expired.
•
Sign-in attempt records — up to 90 days, to detect brute-force attempts and other abuse.
•
Guest profiles and progress — stored on our servers against a pseudonymous application or device installation identifier while the guest profile remains active. Uninstalling the application removes local access but does not itself delete the server-side profile. Guest profiles may be deleted through the in-app Delete Account flow. Inactive guest profiles are handled according to the inactive-account retention period described above.
•
AI conversation history — retained while your account is active, so that characters can refer back to what you said earlier. The Service does not currently provide a way to delete an individual message or a single conversation. Your entire chat history is deleted when you delete your account (Section 10), and you may also request erasure by writing to support@toonlabs.co (Section 9).
•
Content reports — retained for up to twelve (12) months from resolution, for safety review and to identify repeat issues.
•
First-party telemetry — events linked to an account or guest profile are retained while that profile is active; events tied only to a pseudonymous identifier are retained for up to twenty-four (24) months.
•
Push notification tokens — retained until you disable notifications, delete your account, or the messaging platform reports the token as expired or invalid. Uninstalling the application may eventually invalidate the token but does not send us an immediate deletion request.
•
Server logs — typically retained for up to 90 days for security and debugging.
•
Analytics data — retained per Google Analytics, Firebase and Amplitude default settings (typically 14 months to 2 years).
•
Backups — routine backups are rotated within 30 days, after which deleted data no longer persists in them.
•
Aggregated and anonymized data — may be retained indefinitely as it does not identify you.
We may retain data for longer where required for legal, regulatory, tax, accounting, dispute-resolution or fraud-prevention purposes.
9. Your Rights and How to Exercise Them
Under GDPR, you have the following rights:
•
Right of access (Article 15) — obtain confirmation of whether we process your data and a copy of such data.
•
Right to rectification (Article 16) — request correction of inaccurate or incomplete data.
•
Right to erasure (Article 17) — request deletion of your personal data. See Section 10 for the fastest route.
•
Right to restriction of processing (Article 18) — request that we limit how we use your data in certain circumstances.
•
Right to data portability (Article 20) — receive your data in a structured, commonly used, machine-readable format.
•
Right to object (Article 21) — object to processing based on legitimate interests.
•
Right to withdraw consent (Article 7(3)) — at any time where processing is based on consent, including analytics consent and push notifications, via the settings within the Service.
•
Right to lodge a complaint (Article 77) — with a competent data protection authority, including the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl).
How to Exercise Any of Your Rights
To exercise any of the rights listed above, send a written request to support@toonlabs.co from the email address linked to your account. Please include:
•
Your account email and any user identifier visible in the Service.
•
A clear statement specifying which right you wish to exercise.
•
Any further information reasonably necessary to verify your identity.
We will respond to verified requests within one month of receipt. Where requests are complex or numerous, we may extend this period by up to a further two months and will inform you of the extension, and of the reasons for it, within one month of receiving your request. We may refuse or charge a reasonable fee for requests that are manifestly unfounded, excessive or repetitive, or where we cannot verify your identity.
10. Deleting Your Account and Data
You can delete your account and the personal data associated with it in any of the following ways:
1.
In the Android and iOS applications — open Settings → Delete Account and confirm. Deletion can be initiated and completed directly within the application; contacting support is not required. This flow is available to both signed-in accounts and pseudonymous guest profiles.
2.
Through our external deletion resource — visit https://novel.toon.org/account-deletion. This resource is available without installing or launching the application and provides a way to request deletion as required by Google Play.
3.
By email — write to support@toonlabs.co. If you have a signed-in account, write from the email address associated with it. If you are using or previously used a guest profile, include the Support User ID, if available, so that we can identify the relevant profile.
What is deleted:
•
Account or guest profile information: your email address if you provided one, the pseudonymous guest identifier, display name if you set one, chosen avatar, and any unused sign-in codes. If you signed in with Google on the web or on Android, the Google account identifier and profile data we received are deleted as well.
•
Your AI conversation history with all characters.
•
Your saved game progress, choices, statistics, bookmarks and unlocked content.
•
Your push notification tokens.
•
Your content reports, other than any record we are required to keep for safety or legal reasons.
What is retained in anonymized form:
•
Aggregated story-completion and analytics records, retained in non-identifiable form for product analytics. These records cannot be linked back to you.
How long it takes. In the Android and iOS applications, deletion begins as soon as you confirm it. For requests sent through the external resource or by email, we first verify that the request comes from the account holder or, for a guest profile, that it can be identified. In all cases deletion is completed, and your data removed from our active systems and from routine backups, within thirty (30) days.
Signing up again. Your email address is released as soon as deletion is initiated, not after 30 days. You may register again with the same address immediately — but that creates a new, empty account: the previous progress, conversations and unlocked content are not restored and are not visible to you.
Exceptions. Some data may be retained beyond a deletion request where required by law, for the establishment, exercise or defence of legal claims, or where deletion is technically infeasible without disproportionate effort (in which case the data will be isolated from further active use). Data held by our analytics and diagnostics processors expires according to the retention periods in Section 8 rather than at the moment of deletion; from that point it is no longer linked to you.
Deleting your ToON Novels account does not delete your Google account. If you used Google Sign-In on the web or on Android, you can additionally revoke our access to your Google profile at myaccount.google.com. If you signed in by email, there is no external permission to revoke.
A guest profile currently accessible on the device can be deleted through the same in-app Delete Account flow. Deleting a signed-in account does not automatically delete a separate guest profile created under a different installation identifier.
11. Push Notifications: Consent and Opt-Out
What we send. Notifications fall into two categories:
•
Character messages — a character from a story you have encountered writes to you first, in character, referring to your progress and choices.
•
Service messages — a new chapter is available, a chapter you started is waiting to be finished, or someone you invited has joined.
How consent works. Notifications are never enabled silently:
•
Android 13 and above — the operating system asks for the POST_NOTIFICATIONS permission; notifications are not delivered until you grant it.
•
iOS — the operating system asks for notification authorization; notifications are not delivered until you allow them.
•
Web — your browser asks for permission; web push is supported on desktop browsers only.
Declining costs you nothing: no story content, feature or part of the Service is withheld because you refused notifications, and refusing does not affect your progress.
How to turn them off. At any time, either in Settings → Notifications within the Service, or in your operating system or browser settings for the ToON Novels application or site. Turning notifications off in the operating system stops delivery immediately; we delete the associated token when the messaging platform reports it as no longer valid.
12. Automated Decision-Making and Profiling
We do not use your personal data to make decisions, based solely on automated processing (including profiling), that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR. AI Favorites responses generated by the Service are conversational outputs only and do not constitute decisions of legal or similar significance. Automated safety filtering of AI content may prevent a particular message from being generated or shown, which does not produce legal or similarly significant effects.
13. Security; No Warranty of Security
We apply technical and organizational measures consistent with industry practice, including:
•
Encryption in transit (HTTPS/TLS) between your device, our servers, and third-party processors.
•
Encryption at rest for stored data on AWS.
•
Access controls on a need-to-know basis.
•
Passwordless authentication: we never create or store a ToON Novels password. Email sign-in codes are single-use and short-lived; on the web and on Android, Google Sign-In uses Google OAuth and we never see your Google password.
•
Platform-provided secure storage for session tokens on mobile devices.
•
Periodic reviews of our infrastructure and dependencies.
No system is fully secure. Despite reasonable measures, no method of transmission over the Internet or method of electronic storage is completely secure. We do not warrant or guarantee the security of any data and, to the maximum extent permitted by law, we expressly disclaim all liability for any unauthorized access, loss, alteration, or disclosure of data, including but not limited to losses caused by third parties, hacking, social engineering, malware, or events outside our reasonable control (force majeure).
14. Personal Data Breach Notification
In the event of a personal data breach (within the meaning of Article 4(12) GDPR) that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority (the Dutch Data Protection Authority, Autoriteit Persoonsgegevens) without undue delay and, where feasible, not later than 72 hours after having become aware of the breach, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify affected users without undue delay in accordance with Article 34 GDPR, unless an exception under Article 34(3) applies.
15. Age Requirement
The Service is intended for users aged 16 and over. The Service contains mature romantic themes and AI-generated conversational content, and is rated accordingly in Google Play and the Apple App Store.
We rely on the age rating published in the app stores and on the parental control tools those stores provide. We do not operate a separate age-verification screen and do not otherwise verify your age.
Sixteen years is the highest age of digital consent applied under Article 8 GDPR in any EU member state. Accordingly, for our intended audience no parental consent mechanism is required in respect of consent-based processing.
We do not knowingly collect personal data from anyone under 16. If we become aware that we have inadvertently collected personal information from a person under 16, we will use reasonable efforts to delete it promptly. If you believe a child has provided us with information, please contact support@toonlabs.co.
16. Artificial Intelligence Notice and Disclaimer
The Service uses language models from OpenAI's GPT family to power conversations with AI Favorites. These models are provided by an independent third party and subject to change without notice. You acknowledge that:
•
AI outputs are generated and may be inaccurate, inconsistent or out of character. AI Favorites responses are fictional roleplay and do not represent actual statements of any real person or our editorial position.
•
Not professional advice. AI outputs do not constitute, and shall not be relied upon as, medical, legal, financial, psychological, mental-health or any other professional advice.
•
AI may produce unexpected or unsafe outputs. You agree not to rely on AI outputs for any decision having material consequences. If you encounter a message you consider inappropriate, use the report function described in Section 3.4.
•
Do not submit sensitive information (financial credentials, government IDs, health data, or details about other identifiable individuals) to AI Favorites.
•
We do not control how the underlying model produces a given response. Subject to the limitations set out in the Terms of Service, and to any liability that cannot be excluded under applicable law, we do not accept responsibility for the content of individual AI outputs.
•
One-shot processing. Your inputs are sent to OpenAI for a single inference operation and are not used to train AI models.
17. Cookies, Local Storage and Tracking Technologies
17.1 Web
A cookie is a small text file that a website stores on your browser. We use cookies and similar technologies (such as localStorage) for the categories described below. When you first visit the Service we display a cookie banner allowing you to accept or reject non-essential cookies.
Strictly necessary (no consent required). Essential for the Service to function and cannot be switched off. Examples: authentication and session cookies; security cookies to detect fraud and abuse; preference cookies storing your cookie-consent choices. These do not require your consent under Article 5(3) of the ePrivacy Directive.
Analytics (consent required). With your consent: Google Analytics (GA4) and Amplitude. These services may set cookies and process device and browser identifiers, approximate location (from IP address), and behavioural data.
Your choices. Accept or reject non-essential cookies via the banner on first visit; change your mind at any time via the cookie controls within the Service; block or delete cookies via your browser settings (blocking strictly necessary cookies will prevent the Service from functioning); opt out of Google Analytics at tools.google.com/dlpage/gaoptout. Our Service does not currently respond to Do Not Track browser signals, as no consistent industry standard exists.
17.2 Applications
The applications do not use cookies. Session data, preferences, consent choices, guest progress and cached content are stored locally on your device using platform storage mechanisms, and are removed when you uninstall the application. Analytics consent within the applications is requested on first launch in the same way as on the web, and you can change your choice at any time in Settings, in the privacy section.
The analytics choice controls collection by Amplitude and Firebase Analytics. It does not disable the first-party operational and product telemetry described in Section 3.7. Operational events are used to provide requested features, while first-party product telemetry is processed on the basis of our legitimate interests. You may object to legitimate-interest processing as described in Section 9.
18. Changes to This Policy
We may modify this Policy from time to time to reflect changes in our practices, technology, partners or legal obligations. Where reasonably practicable, we will provide notice of material changes via the Service or by email. The current version is identified by its Effective Date and version number. Your continued use of the Service after the Effective Date of a revised Policy constitutes your acceptance of the revised Policy.
19. Governing Law
This Policy is governed by, and construed in accordance with, the laws of the Netherlands, without regard to its conflict-of-laws provisions. Provisions on liability and dispute resolution are set out in the Terms of Service.
20. Severability
If any provision of this Policy is held to be invalid, illegal or unenforceable in any jurisdiction, the remaining provisions remain in full force and effect, and the invalid provision shall be modified to the minimum extent necessary to make it enforceable while preserving its original intent.
21. Contact
For any questions, concerns, requests, or to exercise your privacy rights:
Data Controller: Ilia Chasovnikov, the Netherlands
Email: support@toonlabs.co