hisugarBack home

Privacy Policy

HiSugar — Privacy Policy

Last Modified: 14 September 2026

This Privacy Policy explains how we collect, use, share, and protect your personal data when you use the HiSugar website hisugar.ai and related services (the "Service").

By using the Service, you consent to the data practices described in this Policy. If you do not agree, please do not use the Service.

1. Who We Are

The data controller for personal data collected through the Service depends on the payment provider used at checkout:

(a) Boros Studio LLC, 1111b South Governors Avenue, STE 7399, Dover, DE 19904, United States.

(b) Oha Tech LTD, Promachon Eleftherias 1, Floor 1, Flat/Office 18/19, Agios Athanasios, 4103, Limassol, Cyprus.

(c) Echka Ltd, Old Town Hall, 30 Tweedy Road, Bromley, BR1 3FE, United Kingdom.

Privacy contact: support@hisugar.ai

Where you purchase through the Outpost checkout channel, Outpost Technologies Ltd. acts as merchant of record and an independent controller of the billing and payment data it processes for that transaction, under its own privacy policy (see Section 4.2).

2. Data We Collect

2.1. Registration Information

When you create an account, we collect:

  • Email address (if you sign in with email or social login)
  • Device identifier (UUID generated by your device)
  • Display name / nickname (if you set one)
  • Age confirmation (you must confirm you are 18+)
  • Preferred language
  • 2.2. Profile and Preferences

    You may optionally provide:

  • Gender
  • Preferred character attributes (ethnicity, eye color, hair, body type — used for character selection and personalization only)
  • 2.3. Chat Content

  • Messages you send to AI Companions
  • AI-generated responses
  • Images and videos generated through the Service
  • Audio played by voice features. Voice features use text-to-speech to generate synthetic audio from text; we do not record, collect, or store your own voice, and we do not create any voiceprint or biometric identifier.
  • Gifts sent to AI Companions
  • 2.4. Payment Information

  • We do not store full credit or debit card numbers or card security codes (CVC).
  • Payment processing is performed by third-party payment providers and Merchants of Record: our web card-payment providers (which may include Stripe, Adyen, and Unlimit, orchestrated via Payrails). Where the checkout channel indicates that the sale is made through Outpost, the transaction is processed by Outpost as Merchant of Record.
  • Data our web payment providers process to complete your purchase includes: your name, email address, card brand, the last four digits and expiry of your card, BIN and BIN country, transaction amount and currency, IP address, a recurring-billing indicator, and authorization/refund response codes.
  • Where your purchase is made through Outpost, Outpost acts as an independent controller of the payment and transaction data it processes and may share information with us to enable delivery, access, and support of the Service, in accordance with the Outpost Merchant of Record Terms and Outpost's privacy policy: https://outpost.ai/privacy-policy/.
  • We store transaction metadata: subscription status, plan type, purchase date, billing period, and a payment-provider customer ID.
  • 2.5. Device and Technical Data

  • IP address (used for geolocation, territory restrictions, fraud prevention, and service rendering)
  • Device model, operating system, app version
  • Browser type and version (for web)
  • Screen resolution
  • Approximate location (country / city — based on IP)
  • 2.6. Usage Data

  • Web events (screen views, button clicks, feature usage)
  • Session duration
  • Daily message count
  • Subscription and purchase events
  • Crash logs and performance metrics
  • 2.7. Server Logs

    Our hosting provider automatically logs: browser type and version; operating system; referrer URL; host name; time of server request; IP address. Logs are kept for 2 weeks for security and error analysis (GDPR Art. 6(1)(f)).

    2.8. Cookies and Tracking

    We use cookies and similar technologies on the website. See Section 6 and our Cookies Notice at hisugar.ai/cookies-notice.

    2.9. Age Assurance Data

    The Service is strictly for adults aged 18 and over. To enforce this we process: the age affirmation you give at registration; the adult-cardholder signal inherent in the payment method you use for paid features; behavioural and account signals used to detect suspected underage accounts; the country derived from your IP address, in order to apply territory restrictions; and reports submitted to us about a suspected underage user. We do not currently use a third-party age-verification or age-estimation provider. If we introduce one, we will name it in this Policy, and state which data is shared with it, before it is used.

    2.10. Moderation Data

    To operate the safety systems described in Section 4.13 we process the content of your prompts and of AI outputs, the identifier of the account that generated them, timestamps, the moderation classification applied, and any report submitted about the content.

    2.11. Personal Data of Children

    We do not knowingly collect personal data from anyone under 18. If we learn that a person under 18 has registered, we suspend the account immediately and delete it and its content. Parents or guardians who believe a minor has used the Service may contact support@hisugar.ai. We enforce a zero-tolerance child-safety policy and report apparent child sexual abuse material to the appropriate authorities, including NCMEC. Data preserved for that purpose is retained as required by law and is excluded from deletion requests.

    3. How We Use Your Data

    3.1. Data revealing your sex life or sexual orientation

    Because of the nature of the Service, the conversations you choose to have, the characters you select, and the preferences you set may reveal data concerning your sex life or sexual orientation. This is "special category" personal data under Article 9 of the GDPR and the UK GDPR, and "sensitive personal information" under the CPRA.

    We process this data only on the basis of the separate, explicit consent you give when you register — a dedicated consent that is presented to you on its own, separately from your acceptance of the Terms of Use, and which you must actively give. We process it solely to deliver the conversational experience you ask for, and to meet our legal obligations in relation to platform safety and child protection.

    We do not use this data for advertising, we do not share it with advertising or attribution partners, and we do not use it to train third-party AI models. We do not sell it.

    You may withdraw this consent at any time by deleting your account in Settings → Delete Account, or by contacting support@hisugar.ai. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Because this consent is necessary to deliver the core function of the Service, withdrawing it means the Service can no longer be provided to you.

    3.2. Automated decision-making

    We use automated systems to classify and block prompts and outputs, and to detect suspected underage accounts, fraud, and abuse (see Sections 2.10 and 4.13). These systems can block content or restrict an account without a human first reviewing the case. Where such a decision produces legal effects for you or similarly significantly affects you, you have the right under Article 22 GDPR to obtain human intervention, to express your point of view, and to contest the decision. You can exercise this right through our Complaint Policy at hisugar.ai/complaint-policy or by contacting support@hisugar.ai; a person who was not involved in the original decision will review it.

    4. How We Share Your Data (Third Parties)

    We work with the following categories of third-party service providers. Each provider has access only to the data necessary to perform its function and is contractually obligated to protect your data.

    4.1. AI Model Providers

  • OpenAI Inc. (USA) — AI text generation (chat conversations). Data shared: the content of your messages and prompts, with conversation context. We contract on terms that restrict use of your content to serving your request and prohibit its use to train the provider's own foundation models.
  • OpenRouter / X.AI (Grok) (USA) — alternative AI text generation. Data shared: same scope and same no-training terms as OpenAI.
  • ElevenLabs Inc. (USA) — voice synthesis for voice features. Data shared: the text to be converted to speech. Your own voice is not sent, recorded, or stored.
  • fal.ai (USA) — AI image and video generation. Data shared: text prompts.
  • getimg.ai — character image generation. Data shared: text prompts.
  • A limited number of trained personnel may review de-identified interactions for safety, moderation, and quality purposes.

    4.2. Payment Processors (Merchants of Record)

  • Stripe Payments Europe Ltd. (Ireland) — website / funnel card payments. Data shared: name, email, card brand, last four digits and expiry of your card, BIN and BIN country, transaction amount, currency, IP address, recurring-billing indicator, and authorization/refund codes. We do not receive your full card number.
  • Adyen N.V. (Amsterdam, Netherlands) — website / funnel card payments. Data shared: same categories as Stripe.
  • Unlimit (Unlimint EU Ltd, Limassol, Cyprus, for EU/EEA users; Unlimit UK Ltd, London, United Kingdom, for other users) — website / funnel card payments. Data shared: same categories as Stripe.
  • Vendo (Vendo Services GmbH, 50 Dorfstrasse, Engelberg, CH-6390, Switzerland) — website / funnel card payments. Data shared: same categories as Stripe.
  • Payrails GmbH (Berlin, Germany) — payment orchestration; routes each transaction to the appropriate payment provider above. Data shared: transaction routing metadata, tokenized payment identifiers, IP address, and device metadata.
  • We may also engage other web payment service providers from time to time for card processing on the website / funnel channel.
  • Outpost Technologies Ltd. (United Kingdom) — Merchant of Record and seller of record for the Outpost checkout channel. For purchases made through this channel, Outpost processes your order, billing, payment, tax, and transaction data as an independent controller under its own privacy policy: https://outpost.ai/privacy-policy/. Data shared: order, billing, and payment information necessary to complete and support your purchase.
  • RevenueCat Inc. (USA) — subscription state management across platforms. Data shared: app/device user identifier, subscription status, and purchase events.
  • Web2Wave — web paywall processing for gem purchases. Data shared: checkout/paywall interaction and purchase events, with transaction metadata.
  • 4.3. Analytics and Attribution

  • Google Firebase Analytics (Google LLC, USA) — app and web behavior tracking. Data shared: pseudonymous app/web event data, device identifiers, and IP address.
  • AppsFlyer Ltd. (Israel) — attribution and marketing analytics. Data shared: device identifiers, IP address, installation events, and purchase events, for advertising attribution purposes.
  • Sentry (Functional Software Inc., USA) — application error tracking. Data shared: crash and error diagnostics, device model/OS, app version, and technical request context.
  • Firebase Crashlytics (Google LLC, USA) — crash reporting. Data shared: crash reports, device model/OS, and app version.
  • Microsoft Clarity (Microsoft Corporation, USA) — session-replay and heatmap analytics on the website. Data shared: anonymized interaction and session-replay data.
  • We do not share the content of your conversations, the characters you interact with, or any data revealing your sex life or sexual orientation with any analytics, attribution, or advertising provider.

    4.4. Advertising and Marketing

  • Meta / Facebook (Meta Platforms Ireland Ltd.) — Facebook Pixel and Meta Ads for advertising, retargeting, and audience building. Data shared: hashed email, device ID, events (visit, purchase, signup), and aggregated audience signals.
  • Google Ads (Google LLC) — search and display advertising, conversion tracking. Data shared: Google Click ID, hashed email, conversion events.
  • TikTok Ads (TikTok Pte. Ltd.) — acquisition and conversion campaigns. Data shared: hashed email, visit and purchase events.
  • Snapchat Ads (Snap Inc.) — acquisition and conversion campaigns. Data shared: device ID, visit events.
  • 4.5. Push Notifications and Engagement

  • Firebase Cloud Messaging (Google LLC) — push notification delivery. Data shared: your device push token.
  • Pushwoosh — push campaign management and engagement analytics. Data shared: device push token, device identifier, and engagement events.
  • Resend — transactional email delivery (magic link, receipts, account notifications). Data shared: your email address and email delivery/open status.
  • 4.6. Infrastructure and Storage

  • Amazon Web Services (AWS) — cloud hosting and S3 media storage (chat images, character photos, voice-feature audio). Data shared: the Service content and account data stored to operate the Service. Data centers may be located in the EU (Frankfurt, eu-central-1) or the USA depending on the resource.
  • Google Cloud / Vercel — hosting and web deployment. Data shared: web application hosting data and request logs.
  • (Our databases and caches — e.g. PostgreSQL and Redis — are internal components operated within the infrastructure above, not separate third-party recipients of your data.)

    4.7. Customer Support

  • Zendesk (Zendesk Inc., USA) — customer support ticketing. Data shared: the content of your support messages, your email/contact details, and your account reference.
  • 4.8. Cookie Consent

  • Cookiebot — cookie consent management on the website.
  • 4.9. Legal and Compliance

    We may disclose personal data to law enforcement or other authorities when required by applicable law, subpoena, or court order. We report apparent child sexual abuse material, and the account data associated with it, to NCMEC and to competent authorities, as described in Section 2.11.

    4.10. Business Transfers

    In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity, subject to this Policy.

    4.11. We Do NOT Sell Personal Data

    We do not sell your personal data to third parties for monetary consideration. Our use of advertising and attribution partners (Section 4.4) constitutes "sharing" for cross-context behavioral advertising under the CPRA. You may opt out of this sharing via the "Do Not Sell or Share My Personal Information" control in our cookie consent banner, through your device advertising settings, or by sending a Global Privacy Control (GPC) signal, which we honor.

    4.12. AI Model Improvement

    Your messages and prompts are sent to the third-party AI providers listed in Section 4.1 in order to generate responses. We contract with those providers on terms that restrict use of your content to serving your request and prohibit its use to train their own foundation models.

    Separately, we may use interactions that have been aggregated, de-identified, and/or anonymized to improve our own Service, our models, and our safety systems. Where re-identification is not reasonably possible, such data no longer constitutes personal data under applicable data protection law. Data in that non-identifying form is not deleted when you delete your account (see Section 8).

    A limited number of trained personnel may review de-identified interactions for safety, moderation, and quality purposes.

    4.13. Content Moderation and Safety Systems

    We operate automated classification and filtering over prompts and outputs, model-level safety controls, and human review of flagged material and of user reports, in order to enforce the Blocked Content Policy and our child-safety obligations. This processing is described in Section 3.2 and is carried out by us and by the AI providers listed in Section 4.1 as part of delivering their services.

    5. International Data Transfers

    5.1. Your personal data may be transferred to and processed in countries outside your country of residence, including the United States, the United Kingdom, Switzerland, Israel, and EU member states (e.g. Ireland, Cyprus, Germany, the Netherlands).

    5.2. For transfers from the EU/UK to countries without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (SCCs) or equivalent safeguards. Transfers to the United States may additionally rely on a provider's certification under the EU-US Data Privacy Framework where applicable. Israel and Switzerland each benefit from an EU adequacy decision.

    5.3. You may request a copy of the safeguards we rely on for a specific transfer by contacting support@hisugar.ai.

    6. Cookies and Tracking Technologies

    6.1. We use cookies on our website to: enable basic functionality (necessary cookies); remember preferences (preference cookies); analyze usage (statistical cookies — Firebase, Microsoft Clarity); and display relevant ads (marketing cookies — Facebook Pixel, Google Ads, TikTok Ads, Snapchat Ads).

    6.2. You can manage cookies via the consent banner (Cookiebot) on first visit, or via your browser settings. A detailed, current list of the specific cookies we use, their purpose and duration, is available in the consent banner's preference center and in our Cookies Notice at hisugar.ai/cookies-notice.

    7. Your Rights

    Under GDPR (EU), CCPA / CPRA (California), and other applicable laws, you have the right to:

    To exercise any right, contact support@hisugar.ai. We will respond within 30 days (GDPR) or as required by local law.

    7.1. Account Deletion

    You can delete your account directly in the Service: Settings → Delete Account. Account deletion will:

  • Mark your account as deleted and anonymize personal identifiers.
  • Permanently remove account data within a reasonable period (typically within 90 days of the deletion request), except where retention is required by applicable law (for example, financial transaction records for tax purposes, fraud prevention, or legal claims), and except for aggregated/de-identified data used to improve our Service, which is retained in non-identifying form.
  • Note: Website subscriptions billed via our web payment providers will be cancelled together with account deletion.

    7.2. Marketing Opt-Out

    Unsubscribe from marketing emails via the link at the bottom of each email, or in your account settings.

    7.3. Advertising Opt-Out

    Use the cookie consent banner on the website.

    8. Data Retention

    8.1. We retain personal data only as long as necessary for the purposes described in this Policy or as required by law.

    8.2. General retention periods:

  • Active account data: retained while your account is active.
  • Deleted account data: anonymized following the deletion request, fully removed within a reasonable period (typically within 90 days), except data required for legal retention (for example, billing records for tax purposes — typically 5–10 years depending on jurisdiction).
  • Chat messages and generated media: retained while your account is active, removed in line with account deletion.
  • Aggregated/de-identified data used to improve our Service and models: retained in non-identifying form and not deleted with your account.
  • Moderation records and enforcement decisions: 2 years from the decision, so that we can handle appeals and demonstrate compliance.
  • Records relating to apparent child sexual abuse material, and the associated account data: retained and disclosed as required by applicable law, and excluded from deletion requests.
  • Content-removal requests, complaints, and IP claims: 2 years from closure of the request.
  • Age-assurance records (your age affirmation and the date it was given): retained while your account is active, plus 1 year, as evidence of compliance with the 18+ requirement.
  • Server logs: 2 weeks.
  • Crash and error logs: 90 days.
  • Marketing consent records: retained for the duration of consent + 3 years for proof.
  • Records of the explicit consent under Section 3.1 (the fact, date, and version consented to): retained while your account is active, plus 3 years, as evidence that consent was validly obtained.
  • 9. Security

    9.1. We use industry-standard technical and organizational measures to protect your personal data: SSL / TLS encryption for data in transit; encryption at rest for sensitive data; access controls and authentication; regular security audits; incident response procedures.

    9.2. Access to conversation content and generated media is restricted to a limited number of trained personnel, is logged, and is permitted only for safety, moderation, quality, security, and support purposes.

    9.3. Despite our measures, no internet transmission is 100% secure. You use the Service at your own risk.

    9.4. If we become aware of a personal data breach affecting your rights, we will notify the relevant data protection authority and (where required) you, within 72 hours of becoming aware.

    10. California Privacy Rights (CCPA / CPRA)

    10.1. If you are a California resident, you have additional rights under CCPA / CPRA, including: the right to know what categories of personal information we collect; to delete personal information; to correct inaccurate personal information; to opt out of "sale" or "sharing" of personal information; to limit the use of sensitive personal information; and to non-discrimination for exercising privacy rights.

    10.2. We collect "sensitive personal information" within the meaning of the CPRA, namely data revealing sex life or sexual orientation (Section 3.1). We use it only to provide the Service you request and to meet our safety and legal obligations — uses for which the right to limit does not require us to stop processing — and we do not use or disclose it to infer characteristics about you.

    10.3. To exercise these rights, contact support@hisugar.ai or use the "Do Not Sell or Share My Personal Information" link in our cookie consent banner. We honor Global Privacy Control (GPC) signals.

    11. Changes to This Policy

    We may update this Policy at any time. Material changes will be communicated via in-service notification, email, or website banner. Where a change affects the explicit consent described in Section 3.1, we will ask for your consent again. Your continued use of the Service after a change constitutes acceptance.

    12. Contact

    For privacy questions or data subject requests, you can contact:

    Merchant of Record (Company / Seller), Boros Studio LLC, 1111b South Governors Avenue, STE 7399, Dover, DE 19904, United States — support@hisugar.ai

    Merchant of Record (Company / Seller), Oha Tech LTD, Promachon Eleftherias 1, Floor 1, Flat/Office 18/19, Agios Athanasios, 4103, Limassol, Cyprus — support@hisugar.ai

    Merchant of Record (Company / Seller), Echka Ltd, Old Town Hall, 30 Tweedy Road, Bromley, BR1 3FE, United Kingdom — support@hisugar.ai

    Support: support@hisugar.ai · https://support.hisugar.ai/