Privacy Policy
Last updated: February 11, 2026
This Privacy Policy describes how TuringMate ("we," "us," or "our") collects, uses, discloses, and protects your personal information when you use our website at turingmate.com, applications, APIs, and related services (collectively, the "Service"). By using the Service, you consent to the practices described in this policy.
1. Information We Collect
1.1 Account Information
When you create an account through our authentication provider (Clerk), we collect:
- Email address
- Username (if provided)
- First name and last name (if provided)
- Profile photo URL
- Age verification status and timestamp
1.2 Profile Information
You may voluntarily provide additional profile information including:
- Profile photo (uploaded to our cloud storage)
- Profession
- Location
- Interests
- Relationship preferences ("looking for")
- Age range preference
1.3 Conversation Data
When you use the chat features, we collect and store:
- All messages exchanged between you and AI characters (text and image content)
- AI-extracted memories and facts from conversations (used for persistent character memory)
- Message metadata (timestamps, read status, importance scores)
- Conversation session data and relationship summaries
1.4 Photos & Images
When you upload or interact with photos, we process and store:
- Uploaded photos (stored on Cloudinary for standard content and AWS S3 for adult content)
- AI-generated descriptions of uploaded photos
- Facial recognition data (face vectors used to identify known individuals across photos within a session)
- AI-generated images created during conversations
1.5 Payment & Transaction Data
- Credit balance and transaction history
- Partial payment card information (last four digits and card brand only — full card numbers are not stored)
- Purchase amounts and timestamps
1.6 API & Technical Data
- API key metadata (creation date, last used, access permissions)
- Webhook endpoint URLs and delivery status
- Technical logs (error logs, request metadata for debugging and security)
1.7 Automatically Collected Data
- Cookies set by our authentication provider (Clerk) for session management
- Browser type and version
- Device information
- Age verification status stored in your browser's local storage
1.8 Analytics & Session Recording Data
We use Mixpanel, a third-party analytics service, to understand how users interact with the Service. Mixpanel automatically collects:
- Page views and navigation patterns
- Clicks, form interactions, and other UI interactions (autocapture)
- Session recordings — visual replays of your browsing session, including mouse movements, scrolls, clicks, and on-screen content. Sensitive fields (credit card numbers, CVV codes) are masked and never recorded.
- Heatmap data (aggregate click and scroll patterns)
- Browser type, operating system, screen resolution, and device type
- Referring URL and landing page
- Country and city (derived from IP address; IP addresses are not stored by Mixpanel)
- Custom events we track: character selections, messages sent/received, photo reveals, sign-in/sign-up clicks, profile actions, credit purchases, and errors
2. How We Use Your Information
We use the information we collect for the following purposes:
Providing the Service: To operate the chat platform, maintain character memory, generate AI responses, process photo features, and deliver API functionality.
Personalization: To enable AI characters to remember past conversations and maintain continuity, and to match characters for proactive outreach based on your interests.
Facial Recognition: To identify individuals in uploaded photos within your conversation sessions, enabling characters to recognize and refer to people you share photos of.
Content Moderation: To filter and moderate user-submitted content for safety and compliance using automated tools.
Payment Processing: To process credit purchases and maintain transaction records.
Security & Fraud Prevention: To protect accounts, verify API access, detect abuse, and maintain the integrity of the Service.
Analytics & Product Improvement: To understand how Users interact with the Service, identify usability issues, measure feature adoption, debug errors, improve AI quality, and enhance the overall user experience. This includes session recordings, event tracking, and heatmap analysis via Mixpanel.
Communication: To send proactive messages from characters (where enabled in your privacy settings) and deliver webhook notifications.
3. Third-Party Services & Data Sharing
We use the following third-party services to operate the platform. Each service receives only the minimum data necessary for its function:
Clerk (Authentication)
Manages user authentication, sessions, and account data. Receives your email, name, and login credentials.
Privacy policy: clerk.com/legal/privacy
MongoDB Atlas (Database)
Stores all application data including user profiles, messages, memories, and transaction records. Data is encrypted at rest and in transit.
Privacy policy: mongodb.com/legal/privacy-policy
Cloudinary (Image Storage)
Stores user-uploaded photos, profile images, character photos, and safe AI-generated images. Provides image optimization and delivery.
Privacy policy: cloudinary.com/privacy
Amazon Web Services — S3 (File Storage)
Stores adult/NSFW images in encrypted S3 buckets with presigned URL access. Content is access-controlled and not publicly available.
Privacy policy: aws.amazon.com/privacy
Amazon Web Services — Rekognition (Facial Recognition)
Compares faces in uploaded photos to identify known individuals within conversation sessions. Receives photo data for face comparison only.
Privacy policy: aws.amazon.com/privacy
Google Gemini / GenAI (AI Text & Image Generation)
Generates AI character responses, creates embeddings for memory search, and generates images. Receives conversation context, user messages, and photo data for analysis.
Privacy policy: policies.google.com/privacy
OpenAI (Content Moderation)
Receives user messages for automated content moderation to detect prohibited content. Message text is sent for classification only.
Privacy policy: openai.com/privacy
APIFree / DeepSeek (AI Text Generation)
Generates AI text responses for mature content conversations. Receives conversation context and user messages.
OpenRouter / Qwen-VL (Photo Analysis)
Analyzes uploaded photos to generate descriptions for AI character context. Receives user-uploaded images.
Privacy policy: openrouter.ai/privacy
Venice AI (Vision Analysis)
Provides fallback vision analysis for adult content validation. Receives image data for content classification.
Privacy policy: venice.ai/privacy
Mixpanel (Analytics & Session Recording)
Collects usage analytics, event tracking, heatmap data, and session recordings to help us understand how Users interact with the Service and improve the user experience. Receives page views, clicks, device information, and visual session replays. Sensitive fields (payment card numbers, CVV codes) are masked in session recordings. Mixpanel may derive approximate location (city/country) from your IP address but does not store IP addresses.
Privacy policy: mixpanel.com/legal/privacy-policy
Vercel (Hosting & Infrastructure)
Hosts the web application and API. May collect standard web server logs including IP addresses and request metadata.
Privacy policy: vercel.com/legal/privacy-policy
Google Fonts (Typography)
Provides the Geist and Geist Mono typefaces used in the application interface. Font files are loaded from Google's servers, which may collect standard web request data.
Privacy policy: policies.google.com/privacy
We do not sell your personal information to third parties. Data shared with the services above is used solely for the purpose of operating the Service as described.
4. Cookies & Local Storage
Authentication Cookies: We use cookies set by Clerk for session management and authentication. These are essential cookies required for the Service to function.
Local Storage: We use your browser's local storage to store your age verification status (preventing repeated verification prompts) and Mixpanel analytics identifiers (to associate your activity across sessions on TuringMate).
Analytics Tracking: We use Mixpanel for product analytics, session recordings, and heatmap analysis. Mixpanel uses local storage to maintain a consistent identity across your visits to TuringMate. We do not use advertising cookies or tracking pixels. We do not track you across other websites. Analytics data is used solely to improve the Service.
Session Recordings: Mixpanel session recordings capture visual replays of your browsing sessions on TuringMate, including page content, mouse movements, scrolls, and clicks. Credit card numbers and CVV codes are automatically masked and never captured. Session recordings are used to identify usability issues and improve the Service. You can disable session recordings by enabling your browser's "Do Not Track" setting.
5. Data Retention
Account Data: Retained for as long as your account is active. If you request account deletion, we will delete your data within 30 days, except where retention is required by law.
Conversation Data: Messages and memories are retained for the duration of your account. You may delete individual conversation sessions, which removes all associated messages, memories, and known-person data for that session.
Facial Recognition Data: Face comparison data (known persons) is scoped to individual conversation sessions and is deleted when the session is deleted.
Payment Data: Transaction records are retained for accounting and legal compliance purposes.
Uploaded Files: Photos and images stored on Cloudinary and AWS S3 are retained until the associated account or session is deleted.
Analytics Data: Event data, session recordings, and heatmap data collected by Mixpanel are retained in accordance with Mixpanel's data retention policies. We do not independently retain analytics data beyond what is stored by Mixpanel.
6. Data Security
We implement reasonable technical and organizational measures to protect your personal information, including:
- Encryption of data in transit (TLS/HTTPS).
- Encryption of data at rest in our database and storage services.
- API keys are hashed using SHA-256 before storage — raw keys cannot be retrieved.
- Webhook payloads are signed with HMAC-SHA256 for integrity verification.
- NSFW content is stored in access-controlled S3 buckets with time-limited presigned URLs.
- Session isolation ensures conversation data is not shared between users.
While we strive to protect your data, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security.
7. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete personal data.
- Deletion: Request deletion of your personal data, subject to legal retention requirements.
- Portability: Request your data in a structured, machine-readable format.
- Objection: Object to certain processing of your personal data.
- Withdrawal of Consent: Withdraw consent where processing is based on your consent.
To exercise any of these rights, please contact us at privacy@turingmate.com. We will respond to your request within 30 days.
8. Your Privacy Controls
The Service provides the following privacy controls accessible through your profile settings:
- Cold Outreach Preferences: Control whether AI characters can proactively initiate conversations with you.
- Character Blocking: Block specific characters from contacting you, with the option to delete associated conversation data.
- Session Deletion: Delete individual conversation sessions, which removes all messages, memories, and facial recognition data for that session.
- API Key Management: Create, view, and revoke API keys at any time.
9. Children's Privacy
The Service is strictly intended for individuals aged 18 and older. We do not knowingly collect personal information from anyone under the age of 18. If we become aware that we have collected personal data from a minor, we will take immediate steps to delete that information. If you believe a minor has provided us with personal information, please contact us at privacy@turingmate.com.
10. International Data Transfers
Your data may be transferred to, stored, and processed in countries other than your country of residence. Our third-party service providers (including AWS, Google, Cloudinary, Clerk, Mixpanel, Vercel, and others) operate globally. By using the Service, you consent to the transfer of your data to these providers, which may be located in the United States or other jurisdictions. We ensure that appropriate safeguards are in place as required by applicable data protection laws.
11. Biometric Data Notice
The Service uses facial recognition technology (AWS Rekognition) to compare faces in uploaded photos. This constitutes biometric data processing. Important details:
- Facial comparison is performed on-demand when you upload photos in conversations.
- Face data is scoped to individual conversation sessions and is not shared across users or sessions.
- We do not create a centralized database of facial templates.
- Facial recognition data is deleted when you delete the associated conversation session.
- By using the photo features, you provide informed consent to this biometric data processing.
If your jurisdiction has specific biometric data laws (e.g., BIPA in Illinois, USA), please review this section carefully. Contact us if you have questions about biometric data handling.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. If we make material changes, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically. Your continued use of the Service after any changes constitutes your acceptance of the updated policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
TuringMate — Privacy Team
Email: privacy@turingmate.com
General inquiries: support@turingmate.com
Website: turingmate.com