What we collect, how we use it, how we protect it. Your export and deletion rights.
At a glance
Dyva, Inc. ("Dyva," "we," "us") is a Delaware corporation. We run dyva.ai — a social AI platform where people create, share, and chat with AI characters.
This Privacy Policy explains what data we collect, why we collect it, who we share it with, and what rights you have over it. It covers everything: the website, apps, API, integrations, embed widgets, and any other Dyva service.
Under GDPR, Dyva is the data controller. Under CCPA, Dyva is the business that determines how your personal information is processed.
We're going to be straight with you in this document. If you don't agree with how we handle data, don't use the service.
Here's what we do with your data and why. For users in the EEA, UK, and Switzerland, we've listed the GDPR legal basis for each purpose.
| Purpose | Data used | Legal basis |
|---|---|---|
| Run the service — AI conversations, memory, character interactions, scenes, comics, video | Account data, conversation content, voice data, uploaded content | Contract (Art. 6(1)(b)) |
| Process payments and manage subscriptions | Email, billing info (via Stripe) | Contract (Art. 6(1)(b)) |
| Authenticate you and secure your account | Email, password hash, OAuth tokens, session tokens | Contract (Art. 6(1)(b)) |
| Improve and optimize the service — AI quality, safety, performance | Usage data, aggregated conversation metadata | Legitimate interest (Art. 6(1)(f)) |
| Analyze usage trends and generate analytics | Hashed IPs, page views, device data | Legitimate interest (Art. 6(1)(f)) |
| Prevent fraud, abuse, and enforce Terms of Service | IP addresses, usage patterns, account data | Legitimate interest (Art. 6(1)(f)) |
| Content moderation and safety (automated + human review) | Conversation content, generated content, reports | Legitimate interest (Art. 6(1)(f)) |
| Send transactional messages (verification, receipts, security alerts) | Email address | Contract (Art. 6(1)(b)) |
| Send marketing and product updates | Email, usage preferences | Consent (Art. 6(1)(a)) |
| Respond to support requests and legal inquiries | Communications content, account data | Contract / Legal obligation (Art. 6(1)(b), (c)) |
| Comply with laws, regulations, and legal processes | As required | Legal obligation (Art. 6(1)(c)) |
Run the service — AI conversations, memory, character interactions, scenes, comics, video
Account data, conversation content, voice data, uploaded content
Process payments and manage subscriptions
Email, billing info (via Stripe)
Authenticate you and secure your account
Email, password hash, OAuth tokens, session tokens
Improve and optimize the service — AI quality, safety, performance
Usage data, aggregated conversation metadata
Analyze usage trends and generate analytics
Hashed IPs, page views, device data
Prevent fraud, abuse, and enforce Terms of Service
IP addresses, usage patterns, account data
Content moderation and safety (automated + human review)
Conversation content, generated content, reports
Send transactional messages (verification, receipts, security alerts)
Email address
Send marketing and product updates
Email, usage preferences
Respond to support requests and legal inquiries
Communications content, account data
Comply with laws, regulations, and legal processes
As required
Where we rely on legitimate interest, we've confirmed our interests don't override your fundamental rights. You can request a copy of that assessment anytime.
This is the part most people care about. Here's exactly how AI processes your data.
When you send a message, the AI processing pipeline receives:
Your email, password, payment information, and IP address are never sent to AI models. Period.
Characters on Dyva have persistent memory. Facts you share — preferences, interests, biographical details — get stored as vector embeddings so the character can recall them in future conversations. A memory belongs to you and to the character that formed it. It is never shared with other users, and never shared with another character unless you turn on shared-room context (below).
Four separate controls. They are independent — changing one does not change the others — and they do genuinely different things, so it matters which one you reach for.
When you are in a room with more than one character, those characters do not carry what happened there into your private 1:1 chats unless you allow it. Shared-room context is off by default and is an explicit opt-in in Settings → Data Controls. Turning it on covers room events only — what was said in a room you were in. It never gives one character access to your private conversations with another.
A character can form a reason to message you before you message it — internally we call it a knock. The capability exists in the product and is governed by the controls below, but delivery is currently switched off: no knock is delivered to a user, and the push notification for it defaults to off. Nothing in this section describes messages you are receiving today.
If and when delivery is enabled, these govern it, and all of them are re-checked at the moment of delivery rather than only when the message was formed:
All of these settings are included in your data export and deleted with your account.
We use a combination of proprietary and third-party AI infrastructure for generating responses. Some features like intent classification, content safety, and content analysis use additional model services. Your data is processed for the inference you requested — response generation, not model training (see Section 8 for the training permission, which is off unless you turn it on).
We don't use your data for automated decisions that produce legal or similarly significant effects (GDPR Article 22). AI responses are conversational output — not decisions affecting your legal rights, employment, credit, or anything like that.
Voice is one of the more sensitive data categories we handle. Here's the full picture.
When you speak during a voice conversation, your audio is transcribed to text in real time by our speech recognition provider (Deepgram). The raw audio is discarded immediately after transcription — it is not stored. Only the text transcript is retained as part of your conversation history.
AI text responses are converted to spoken audio by our TTS provider (ElevenLabs). The synthesized audio is streamed to you and not stored after playback. Text inputs are not retained by ElevenLabs after synthesis is complete, per our data processing agreement.
Pro and Creator plans can upload audio samples to create custom character voices. Those samples are processed to build a voice model and retained for the duration of your subscription plus 30 days to allow for model updates. You can delete a voice model and its source samples anytime from your character's voice settings.
Deepgram receives your raw audio for transcription. ElevenLabs receives AI-generated text for synthesis. Neither provider receives your account information, conversation history, or any other personal data. Both are bound by data processing agreements.
We do not sell your data. We do not share it with ad networks. We do not trade it.
We share data only in these situations:
| Provider | Purpose | Data they see |
|---|---|---|
| Stripe | Payment processing | Billing name, email, card details, billing address |
| ElevenLabs | Text-to-speech synthesis | AI-generated text for audio conversion, voice clone samples |
| Deepgram | Speech-to-text transcription | User audio input (discarded after transcription) |
| fal.ai | Video and image generation | Generation prompts, parameters, style settings |
| AI Model Providers | Conversation generation, intent classification, safety | Conversation content, display name, character system prompts |
| Google (OAuth) | Authentication | Name, email, avatar (user-authorized) |
| Discord (OAuth) | Authentication | Username, email, avatar (user-authorized) |
Stripe
Payment processing
ElevenLabs
Text-to-speech synthesis
Deepgram
Speech-to-text transcription
fal.ai
Video and image generation
AI Model Providers
Conversation generation, intent classification, safety
Google (OAuth)
Authentication
Discord (OAuth)
Authentication
Creators publish characters; they are not given a window into the people who talk to them. A creator receives aggregate reporting only — counts and trends for their character.
We keep data only as long as we need it — or as long as the law requires.
| Data | How long | Notes |
|---|---|---|
| Account information | Until you delete your account | Deletion runs immediately in one transaction — see §7.1 for what is deleted, anonymized, and retained |
| Conversations and memories | Until you delete them or your account | Delete individual conversations or everything at once |
| Voice audio (STT input) | Not stored | Discarded immediately after transcription |
| Voice clone samples | Subscription duration + 30 days | Deletable anytime from character voice settings |
| Generated content (video, comics, images) | Free: 30 days. Paid: until deleted | Prompts retained as account activity data |
| Analytics data (hashed IPs, page views) | 90 days | Auto-purged. IPs stored only as SHA-256 hashes |
| Application logs | 30 days | Automatically rotated and purged |
| Payment and billing records | As required by tax law | Typically 7 years. Card details stored only by Stripe |
| Support communications | 2 years after resolution | Longer if tied to an ongoing legal matter |
| Deleted account data | Purged within 30 days | Backups fully cycled within 90 days |
Account information
Deletion runs immediately in one transaction — see §7.1 for what is deleted, anonymized, and retained
Conversations and memories
Delete individual conversations or everything at once
Voice audio (STT input)
Discarded immediately after transcription
Voice clone samples
Deletable anytime from character voice settings
Generated content (video, comics, images)
Prompts retained as account activity data
Analytics data (hashed IPs, page views)
Auto-purged. IPs stored only as SHA-256 hashes
Application logs
Automatically rotated and purged
Payment and billing records
Typically 7 years. Card details stored only by Stripe
Support communications
Longer if tied to an ongoing legal matter
Deleted account data
Backups fully cycled within 90 days
Deleting your account runs immediately, as a single database transaction, and writes a receipt recording how much was deleted, anonymized, and retained. Running it again changes nothing. Your data does not have one fate — it has three.
Your account row survives as a tombstone. Email, display name, username, avatar, biography, password hash, date of birth, and linked Google or Discord identities are cleared from it. The row itself cannot be removed, because the payment records we are required to retain are attached to it and would be destroyed with it — and because that row is what makes a second deletion request a safe no-op.
Characters and rooms other people are in stay. A character someone else has chatted with, bought, or subscribed to, and a room someone else joined or posted in, are not yours alone to destroy. They remain, owned by the tombstone rather than by you.
Your data, your rights. Exercise them by emailing [email protected] or using the tools in your account settings. Here's what you can do:
Sec-GPC: 1 signal, we honor it across the platform without you having to ask: training permission is forced off on your account and stays off while the signal is present, and we do not record share-page views for your requests. Data Controls shows the signal only when we are genuinely receiving it. We also accept the legacy DNT: 1 header the same way — see the Cookie Policy.We respond within 30 days (extendable by 60 for complex requests under GDPR). For CCPA requests, we verify your identity by matching information you provide with our records. You can designate an authorized agent with written authorization.
Dyva is not for children under 13. We do not knowingly collect personal information from anyone under 13, in compliance with COPPA (15 U.S.C. 6501-6506).
EEA users: The minimum age is 16 (or lower where local GDPR implementing law permits) per GDPR Article 8.
How we check. Age is self-declared. At sign-up we ask for your date of birth and refuse the account if it states an age under 13. We do not verify age at registration — that check is the answer you give us, not a document or a database. Where a jurisdiction or an age-restricted area of the product requires more, we run a separate third-party verification and keep only the provider's name and a one-way reference hash as proof the check happened.
If we discover we've collected data from a child below the applicable age threshold, we delete it. Fast.
Parents and guardians: If you believe your child provided data without your consent, contact [email protected] immediately. We'll verify and delete it. Users aged 13-17 need parental consent as described in our Terms of Service.
Dyva is US-based. Your data is processed and stored on US servers. If you're outside the US, your data crosses borders.
For transfers from the EEA, UK, or Switzerland to countries without adequate data protection (per GDPR Articles 44-49), we use:
Want a copy of our SCCs or more details about transfer mechanisms? Email [email protected].
We take security seriously. Here's what we do (per GDPR Article 32):
No system is perfectly secure. We can't make absolute guarantees. But we address vulnerabilities fast and take every incident seriously.
This policy may change as our practices, technology, or legal requirements evolve.
Continued use after a revision means you accept it, to the extent permitted by law.
Questions about your data? We'd rather you reach out than wonder.
Dyva, Inc.
If you're in the EEA, UK, or Switzerland and believe we've violated your GDPR rights, you can file a complaint with your local supervisory authority (GDPR Article 77). EEA authorities are listed at edpb.europa.eu. In the UK, contact the ICO at ico.org.uk.
But reach out to us first. We want to fix things directly.