The Veil
Privacy Policy
FaeFrame Privacy Policy
Effective: June 24, 2026 · Version 1.0.0
This Privacy Policy explains what information FaeFrame collects, how it is used, and what choices you have. By using FaeFrame you agree to the practices described here. If you have questions, please contact us at the address at the bottom of this page.
Note: This policy is written in plain language to be useful to you. It is not legal advice, and operating in certain jurisdictions (notably the EU/UK under GDPR and California under CCPA) may grant you additional rights beyond what is listed here. Where applicable law conflicts with this document, applicable law controls.
1. What FaeFrame Is
FaeFrame is a cinematic roleplay platform that lets you create and converse with fictional characters. The service includes character creation tools, conversation history, memory keeping, and AI-generated text and image responses voiced by the characters you create or choose.
FaeFrame is currently in a closed beta. The features, data model, and this policy may change as the product matures. We will bump the version above and prompt users to re-acknowledge when material changes are made.
2. What Information You Provide
When you use FaeFrame we collect and store:
- Account information — your email address, an optional display name, an optional avatar URL, and either your hashed password (we never see or store the plaintext) or your Google account identifier if you sign in with Google.
- Profile information — any persona description, deep traits, language preference, age-verification attestation, and similar account-level fields you choose to fill in.
- Content you create — characters you author (their names, descriptions, personalities, backstories, voice settings, image references), conversations you have with characters, memories you save, story snapshots you generate, and feedback you submit.
- Operational metadata — timestamps, message counts, soft and hard delete flags, character visibility (private/public), tier attestations, invite codes used at signup, and similar bookkeeping.
- Diagnostic data — anonymized error logs that may include the short hashed prefix of a message that triggered a safety check, but never the raw text of your conversations or characters.
We do not collect your physical address, government ID, payment information (the service has no paid tier today), browser fingerprints, ad-tracking identifiers, or social-graph data from third parties.
3. How That Information Is Used
We use the information above only to:
- Operate the service — authenticate you, load your characters and chats, route messages to the correct AI provider, generate responses, save memories, and deliver story snapshots back to you.
- Maintain product safety — enforce the age gate, enforce content rules, throttle abuse, and respond to support requests.
- Improve the service — aggregate, non-identifying analytics about feature usage to guide product decisions during closed beta.
- Communicate with you about important account or service events (security notices, terms updates, scheduled maintenance).
We do not sell your information, share it with advertisers, or use the content of your characters or conversations to train any public-facing AI model.
4. AI Providers and How Your Prompts Travel
FaeFrame uses third-party AI providers to generate character responses and images. When a character speaks, the conversation history, your message, the character's system prompt, and (for image generation) your selected style references are sent to one of the following providers depending on which model the chat is configured to use:
- Anthropic, OpenAI, and Google — used for routine ("safe") and "mature" tier text generation, routed through the upstream provider that FaeFrame holds an account with.
- Google's Nano Banana image model — used to generate avatars and story snapshot images.
- An adult-capable third-party provider (OpenRouter at the time of writing) — used only when an "explicit" tier chat is active and only when the operator has explicitly enabled the explicit tier. Most users will never trigger this path.
These providers operate under their own privacy policies and data practices, which we link to or summarize in our public documentation when material changes occur. Routing decisions are made server-side; your browser never holds an AI provider's credentials.
If you do not want your messages sent to a third-party AI provider, do not use FaeFrame — the service cannot operate without an AI provider on the back end.
5. Cookies and Authentication
FaeFrame uses a single HTTP-only session cookie (session_token)
plus your local browser storage to keep you signed in across visits
and to remember small preferences (e.g. your preferred language).
The session cookie is:
- HTTP-only and Secure — it cannot be read by browser JavaScript or sent over insecure HTTP.
- Same-site — it is not sent to third parties.
- Time-limited — it expires after 30 days of inactivity.
We do not use third-party tracking cookies, advertising pixels, cross-site tracking scripts, or fingerprinting libraries.
Signing out of FaeFrame deletes the session cookie immediately. You may also delete it manually from your browser's settings.
6. Your Rights and Choices
You have the right to:
- Access the data we hold about you. You can see your account profile, characters, chats, and memories from inside the app.
- Correct your account profile fields (display name, avatar, persona, language preference) from your Profile page.
- Delete content you have created (characters, chats, memories, snapshots) using the corresponding delete actions in the UI. Soft deletes are recoverable for a short window before being purged.
- Delete your account — request full deletion of your account and all associated data by emailing the support address at the bottom of this page. We will confirm the request, then delete your account and content within 30 days.
- Withdraw consent at any time by deleting your account and ceasing use of the service.
If you live in a jurisdiction with additional privacy rights (e.g. the EU/UK under GDPR or California under CCPA), you may have rights to portability, restriction, or to object to certain processing. Email the support address below and we will honor any right that applies under your local law.
7. Children and Minimum Age
FaeFrame is not intended for, and does not knowingly serve, anyone under the minimum age required to use online services in your jurisdiction (16 in the EU, 13 in many other regions, with local variation). Some content categories are gated behind an additional adult (18+) attestation. If you believe an account exists for a minor, please contact us at the address below and we will take prompt action.
8. Data Retention and Storage
Account information and your characters/chats/memories are stored until you delete them (or for 30 days after an account-deletion request, after which they are purged). Operational and diagnostic logs are retained for up to 90 days, then purged on a rolling basis. Data is stored on managed cloud infrastructure with industry-standard encryption in transit and at rest.
9. Changes to This Policy
When this policy materially changes we will increment the version number at the top of this page and prompt you to re-acknowledge it on your next sign-in. Continued use of the service after the version is bumped constitutes acceptance of the new policy.
10. Contact
Questions, deletion requests, or other privacy concerns: please email support@faeframe.com.
(Placeholder address — replace with the official support inbox before public launch.)