Gemnd Privacy Policy
Status: draft — legal-owner-inputs development fixture; not for release
Effective date: {{owner:effective_date}}
Version: 2026-10-07.1
This policy explains what personal information Gemnd collects, why, who processes it, how long we keep it, and the choices and rights you have. It is written to be read in full. If you only have a minute, start with the short version.
The short version
- Gemnd is an AI companion app for adults. Your companions are artificial intelligence, not people. To reply to you, speak, remember you and create how your companion looks, we have to process what you write and say. Our servers can read your messages, so Gemnd is not end-to-end encrypted.
- Your conversations are personal, and we treat them that way. What you tell a companion can reveal your health, your sex life, your sexuality, your beliefs or other sensitive things. We use that information only to provide Gemnd to you, keep it safe and meet our legal duties.
- We don't sell your personal information, share it for advertising, or show you ads. Gemnd contains no advertising or analytics tools and doesn't track you across other apps or websites.
- We don't use your personal information to train AI models. The AI providers that write your companion's replies are set up so they don't keep your conversations or train on them.
- Before your first conversation, the app names the AI providers that write, check, voice and illustrate your companion, and asks your permission. You can turn AI processing off at any time.
- You're in control in the app. You can read, correct or forget what your companion remembers, download a copy of your data, sign out other devices and delete your account, all from inside the app.
- Deletion is real. When you delete your account, we start erasing your data immediately. We keep limited payment records and a record that the account was deleted, linked to a random account number and not to your email address or your conversations. If you sent an arbitration opt-out or written notice of dispute, we keep that notice and the Terms version it relates to for the period below. If you wrote to us with a privacy request, we keep that request and our answer for 24 months, as the law requires. Backup copies age out on a fixed schedule, described below.
- Gemnd is only for adults 18 and older.
- If you're in crisis, Gemnd shows crisis resources, including the 988 Suicide & Crisis Lifeline. Gemnd's crisis feature never calls, messages or alerts emergency services, crisis lines or anyone else about you.
Contents
- Who we are and how to reach us
- What this policy covers
- Finding this policy and your privacy controls in the app
- Information we collect
- How we use information
- Sensitive personal information
- How AI processes your information
- Safety, moderation and crisis resources
- How we disclose information
- No sale, no sharing, no targeted advertising
- How long we keep information
- Downloading and deleting your data
- Your privacy rights
- Notice at collection
- Consumer health data
- Adults only
- How we protect your information
- Cookies and similar technologies
- Where we process information
- Changes to this policy
- Contact us
Who we are and how to reach us
Gemnd is provided by {{owner:company_legal_name}}, a {{owner:entity_type_and_state}}, doing business as "Gemnd" ("Gemnd", "we", "us" or "our"). We decide how and why your personal information is processed, so we are responsible for it.
- Privacy questions, requests and appeals: {{owner:privacy_email}}, or in the app at Settings → Help and reports → Contact support
- Help with the app: {{owner:support_email}}, or in the app at Settings → Help and reports → Contact support
- Legal notices and requests from authorities: {{owner:legal_notice_email}}
- Mail: {{owner:company_legal_name}}, {{owner:mailing_address}}
- Website: {{owner:website_url}}
We read and answer the privacy inbox. You don't need an account to write to us.
What this policy covers
This policy covers personal information we collect through:
- the Gemnd app for iPhone;
- our website, {{owner:website_url}}, including the pages where we publish this policy, our Consumer Health Data Privacy Policy, our Terms of Use, our subprocessor list and our safety protocol;
- emails we send you and messages you send us.
"Personal information" means information that identifies you or can reasonably be linked to you, directly or indirectly. It includes information we infer about you.
This policy doesn't cover:
- Apple. When you subscribe, Apple processes your payment under its own terms and privacy policy. Apple doesn't share your card details with us.
- Websites we link to, such as the 988 Suicide & Crisis Lifeline. Their own privacy policies apply.
Our Terms of Use explain the rules for using Gemnd. This policy is a notice about your information: you don't have to agree to it for it to describe what we do. When you create an account, and again after any material change, the app asks you to confirm that you've read it, and we record which version you saw. Confirming that you've read this policy is not consent to anything in it. The permissions we ask for, such as AI processing, are separate (see Sensitive personal information).
Finding this policy and your privacy controls in the app
Everything in this policy is available inside the app, before and after you create an account. The legal pages open from the Create account screen, from the Terms and privacy screen shown before your first conversation, and from Settings → Your data and devices. The AI processing screen links the subprocessor list. The legal pages work with VoiceOver and larger text sizes, and they work without an internet connection.
The app includes a copy of this policy so you can read it offline: the version that was current when your version of the app was released. Each copy shows its version and date. The current version is always on our website at {{owner:website_url}}/legal/privacy. When a material change takes effect, the app asks you to update it so you can read and confirm the new version before you continue.
| What you want | Where to find it in the app |
|---|---|
| Read this policy | Settings → Your data and devices → Privacy policy. Also linked on the Create account screen and the Terms and privacy screen |
| Read what we collect before you sign up (notice at collection) | The Notice at collection link on the Create account screen, shown before you send us your email and password. It opens this policy's Notice at collection section directly. Also Settings → Your data and devices → Privacy policy → Notice at collection |
| Read our Terms of Use or subprocessor list | Settings → Your data and devices → Terms of Use or Subprocessors |
| Read our Consumer Health Data Privacy Policy | Settings → Your data and devices → Consumer health data privacy policy. The AI processing screen also links it |
| Read how we handle crisis and safety | Settings → Your data and devices → Safety |
| See which companies process your data | Settings → Your data and devices → Subprocessors. The AI processing screen also lists the AI providers, with a "Who processes your data" link, before you allow processing |
| Turn AI processing off or on | Settings → AI processing |
| See, edit, restrict or forget memories | Menu (≡) → Memory |
| Stop new memories from forming | Menu (≡) → Memory → Remember new conversations |
| Download a copy of your data | Settings → Your data and devices → Download my data |
| See and sign out signed-in devices | Settings → Your data and devices → Signed-in devices |
| Turn saved voice recordings on or off, or clear them | Settings → This device → Voice replays → Save recordings on this device, and Clear saved recordings. The Voice replays section appears only on devices that can save replays |
| Report a reply or a selfie | Press and hold it, then Report. In a call, from the caption line |
| Report a custom avatar | On the avatar's screen, "Report a problem with this avatar" |
| Check on a report or contact support | Settings → Help and reports |
| Make any other privacy request, or appeal a decision | Settings → Help and reports → Contact support, which opens an email to us, or email {{owner:privacy_email}} |
| Reset your password | "Forgot password?" on the sign-in screen |
| Delete your account | Settings → Delete account |
| Follow a deletion in progress | The deletion status screen, which opens as soon as you confirm. We also email you when deletion is finished |
When we make a material change to this policy or our Terms of Use, the app asks you to confirm that you've read the updated version before you continue (see Changes to this policy). Confirming that you've read this policy is not consent to anything in it. The permissions we ask for, such as AI processing, are separate.
Information we collect
We collect only what we need to run Gemnd. Most of it comes from you. Some is created as you use the app, and a little comes from Apple. The Notice at collection lists the same information by the categories California law uses.
Information you give us
- Account details. Your email address and password. We store your password only in a scrambled form that can't be turned back into the password (a bcrypt hash). If you choose, a display name. The app signs you in with your email address and password only.
- Your adult confirmation. Before you can use a companion, you confirm that you're 18 or older. We record that you confirmed it, when, and which version of our first-use disclosure you saw. We don't ask for your date of birth.
- What you tell your companions. Every message you type, everything you dictate or say in a call once it has been turned into text, and the replies your companion gives you. This is the heart of Gemnd, and it can include anything you choose to share.
- Profile details. A nickname, a description of yourself or your occupation, if you or your companion add them, so your companion can address and know you.
- Your companions. Each companion's name, character, personas, look, voice and expressions, the relationship style you set (for example romantic or platonic, how flirtatious, boundaries, how it supports you on a hard day), the story themes you choose, and earlier versions of these settings. When you ask a companion in conversation to change its character, we keep the change together with a short quote from your request (up to 512 bytes) so you can review what changed and why.
- Look and selfie requests. The description you write for a custom look, and the line you write when you ask for a selfie (up to 280 characters).
- Reports and support messages. The reason you choose and any note you add when you report a reply or an avatar, and emails you send us.
- Your choices. Whether you allowed AI processing, and each time you changed it; your acceptance of each version of our Terms of Use and your confirmation that you've read each version of this policy; your acknowledgment of how Usage works; and your Memory, voice-recording and other settings.
Information created as you use Gemnd
- Memories and summaries. As you talk, our AI forms memories from your conversations: facts, preferences, feelings, relationships and moments you share, and a running description of you that your companion draws on. It also writes summaries of longer conversations and titles for them. To find the right memory at the right time, we compute search data (numerical "embeddings") from memory text on our own servers. These memories and summaries are inferences about you. You can see and control your memories in Memory. Conversation summaries and search data aren't shown there. Summaries are included when you download your data. Search data, which can be rebuilt from your memories, is not, but you can ask us for it. Both are deleted with your account, or sooner if you ask us.
- Generated media. The images and videos we generate for your companion's look, expressions and selfies. They show your fictional companion, never you.
- Call records. When a call started and ended, how it ended, whether your speech was recognized on your iPhone or by our speech provider, and the language setting. We don't record calls.
- Safety records. For each safety check, what was checked (for example, your message or a reply), the outcome (allowed, supported, declined or unavailable), the reason category, and a one-way fingerprint (a hash) of everything the check looked at, never the content itself. When a message leads us to show crisis resources, that fact is saved with the reply. We also record when we last reminded you in each conversation that your companion is an AI. Each time a look or selfie request is refused or a whole round of generated images is rejected, we record it, together with any pause or review lock that follows.
- Usage and purchase records. Your plan; the records Apple sends us when you subscribe, renew or cancel; and a ledger of how much of your weekly Usage each action used, including which AI model and provider handled it and how many units of text it processed.
- Sign-in and security records. For each signed-in device, the IP address and the type of device and app version it reported (its "user agent") when it signed in, when it signed in and when it was last used. We keep one-way hashes of sign-in and refresh tokens and of one-time codes, never the codes themselves. To slow down attacks, we briefly count sign-in attempts against a keyed hash of your IP address or email address.
- Logs and diagnostics. Like most online services, our servers record each request they receive, including the IP address, device description and the address requested. Our services record operational events and errors with identifiers replaced by keyed hashes, and they are built to leave out email addresses, IP addresses, message text and request bodies. If the app crashes, freezes or hits an unexpected error, it sends a diagnostic report about your device model, operating system and app version, with no conversation content and no account information. Errors on our servers are reported with a keyed hash of your account number, which we could link back to your account, but never with message content.
- Your time zone. The app shares your device's time zone so your companion knows what time it is for you. This doesn't use location services.
Information from other companies
- Apple sends us signed records of your subscription purchases, renewals, cancellations and refunds. To link a purchase to your Gemnd account, we give Apple a random number we generate for your account. It contains no name, email address or payment details, but it is linked to your Gemnd account, so we treat it as personal information.
Information kept only on your iPhone
- Your sign-in. The secret that keeps you signed in is stored in the iOS Keychain, on that device only and excluded from device backups.
- Small pieces of app state in the Keychain, such as which conversation you had open, a purchase or a memory change that hasn't finished, and a report you haven't finished sending. If you delete the app without signing out, iOS may keep Keychain items on the device; signing out first removes your sign-in.
- Saved voice recordings, if you turn on "Save recordings on this device": recordings of your companion's spoken replies, so you can replay them without using Usage. They are encrypted with a key held in the Keychain, excluded from device backups, limited to 250 MB, and deleted after 30 days, when you sign out or switch accounts, or when you delete your account.
- A small cache (up to 4 MB) of your companion's short animation clips, cleared when you sign out.
- Downloads of your data are saved only to the folder you choose in the Files app. We don't keep a copy.
What we don't collect
- precise location, and we never use your IP address to work out where you are;
- photos or videos of you: Gemnd has no access to your camera or photo library;
- stored recordings of your voice: when your iPhone can't recognize speech itself, your audio streams through our servers to our speech provider only while you speak, and neither we nor it keeps the audio (see Voice);
- voiceprints, faceprints or any other biometric identifiers;
- your contacts;
- your date of birth or government ID;
- advertising identifiers or any device identifier beyond your device description;
- push notification tokens: Gemnd doesn't send push notifications;
- payment card details: Apple handles payment.
How we use information
We use personal information only for the purposes below, each tied to the information it needs. We don't use it for any other purpose without telling you first and, where the law requires, asking your consent.
| Purpose | Information used |
|---|---|
| Provide your companion: write and speak its replies, keep each conversation going, remember you across conversations, and personalize replies to you and your local time | Conversations, memories and summaries, profile details, companion settings, time zone |
| Calls, dictation and read-aloud: turn your speech into text and speak your companion's replies | Voice audio while you speak (processed, not stored), transcripts, reply text |
| Create your companion's look, expressions and selfies | Look and selfie requests, your companion's reference portrait, generated media |
| Keep Gemnd safe and within our content rules: check messages, replies and image requests; show crisis resources; remind you that companions are AI; review reports | Conversations, requests, generated media, safety records, reports |
| Run your account: create it, sign you in, verify your email, reset your password, list your devices and sign them out | Account details, sign-in and security records |
| Plans and Usage: give you the plan you paid for, measure weekly Usage, settle what each action cost, and prevent fraud | Usage and purchase records, records from Apple |
| Security and reliability: detect and stop abuse, keep the service running, investigate incidents and fix crashes and errors | Sign-in and security records, logs and diagnostics |
| Help you: answer your messages, handle your privacy requests and keep a record of them | Support messages, account details, request records |
| Honor your choices and rights: record your consent, carry out exports and deletions | Consent and acceptance records, deletion records |
| Meet legal obligations: comply with laws, respond to valid legal process, and establish or defend legal claims | Only the information the obligation requires |
We send email only about your account: verification and sign-in codes, password-reset codes, account-deletion codes and confirmations, and notices the law requires. We don't send marketing email or push notifications.
We don't read or analyze your conversations for product research, advertising or marketing.
Sensitive personal information
What it is. Several state laws treat some information as "sensitive". For Gemnd that can include:
- information about your physical or mental health, including sexual and reproductive health;
- your sex life, sexual orientation, or status as transgender or nonbinary;
- your racial or ethnic origin, national origin, religious or philosophical beliefs, citizenship or immigration status, union membership, or experience as a victim of crime;
- the contents of your messages;
- your account email together with your password.
How it gets to us. Apart from your sign-in details, we don't require any of it. Companions are made for personal conversation: they may ask how you feel or about your life. Sensitive information reaches us when you share it in conversation. It also reaches us through choices you make about your companion, such as a romantic relationship style, how flirtatious it is, your boundaries, how it supports you on a hard day, or what a selfie should show, which can reveal information about your sex life or your health. Memory can then turn what you shared into a stored fact so your companion remembers it.
How we use it. We collect and use sensitive information only as strictly necessary to provide the companion experience you ask for. That means:
- writing your companion's replies;
- keeping your conversation history;
- remembering what you share;
- keeping you and others safe, including showing crisis resources;
- protecting the security and integrity of the service;
- meeting our legal obligations.
We don't use it to infer characteristics about you for any other purpose. We don't use it for advertising, marketing, pricing or model training. We never sell it.
Your consent and control.
- Before your first conversation, the app asks for your permission on the AI processing screen, separate from our Terms of Use. The screen names the AI providers that write, check, voice and illustrate your companion, what each does and where it processes data. You allow processing by tapping Allow.
- Nothing you write or say is sent to those providers, and no memory forms, unless you allow it. If you don't allow it, you can still use Settings, download your data and delete your account.
- We never treat accepting our Terms of Use or confirming that you've read this policy as consent to process sensitive information.
- You can withdraw that permission at any time in Settings → AI processing. Withdrawing is as easy as giving it, and it takes effect right away.
- You decide what to share, and you can forget any memory, or turn off Remember new conversations, at any time.
Some states have specific rules for health information. See Consumer health data.
How AI processes your information
The models behind your companion
Your companion's replies, conversation summaries and memories are written by DeepSeek V4.1 Flash, an openly published AI model developed by DeepSeek. The model runs on servers of Together AI in the United States; we never use DeepSeek's own service, and none of your data is sent to DeepSeek or processed in China. Our requests reach Together AI through OpenRouter, a routing service.
- What they receive: what your companion needs to reply. That is its character and persona, the memories relevant to the moment, recent conversation, your latest message, and the name and details your companion knows you by.
- Zero data retention. We send these text requests only to endpoints that OpenRouter lists as zero data retention, and our requests forbid data collection. OpenRouter and Together AI don't keep your prompts or replies after the request is answered and don't train models on them. DeepSeek receives none of your data. This text-route policy is not a zero-retention claim for image or video generation.
Other AI providers
TypeSafe (Jev 1.13), and Together AI (tev1-4b-experimental), through OpenRouter
- What they do: check text against our content and safety rules. Jev 1.13 is the primary check; the Together-hosted model is a parallel hedge.
- What they receive: your message with the reply before it, each sentence of a reply, companion character text, and look and selfie requests.
- How they treat your data: these text requests go only to zero-data-retention routes through OpenRouter, with data collection denied. They don't train on your data and receive no user identifier.
OpenAI (omni-moderation and GPT-5.4 mini)
- What it does: checks generated images and video frames against our content rules.
- What it receives: generated images with their context text.
- How it treats your data: doesn't train on it. It may keep abuse-monitoring logs for up to 30 days, and our requests ask it not to store responses. It is not the provider that writes your companion's replies or memories.
Deepgram
- What it does: turns your speech into text when your iPhone can't, and speaks your companion's replies.
- What it receives: your voice while you speak, only when your iPhone can't recognize speech itself, and reply text to be spoken.
- How it treats your data: we opt out of its model-improvement program on every request, so it keeps audio and text only while processing them and doesn't train on them.
Black Forest Labs (FLUX 3 Image at 2K) and xAI (Grok Imagine Video 1.5 Lite), through OpenRouter
- What they do: generate your companion's looks, expressions, animations and selfies.
- What they receive: the look or selfie request text and your companion's reference portrait.
- How they treat your data: OpenRouter records a 30-day retention policy for Black Forest Labs. xAI's video files must be retained briefly for its asynchronous operation, so this route is not zero-data-retention eligible. We copy delivered files to our private storage. [pending: exact BFL retention and written no-training confirmation, and xAI's retention and no-training terms for the selected video endpoint]
- Where they process it: [pending: an enforceable commitment excluding China and Hong Kong throughout processing, storage, support and external grounding for these exact routes before release]. A provider's headquarters, a regional endpoint name or a no-training setting does not establish that commitment. Current credentials and regional catalogs do not prove that either selected media endpoint is available through US in-region routing. We do not claim these routes already process exclusively in the United States.
Serper
- What it does: web search when your companion looks something up during a conversation.
- What it receives: the search query your companion writes, which can reflect your conversation, and web addresses it reads.
- How it treats your data: receives no user identifier. Its public policy doesn't say how long it keeps queries or whether it uses them to improve its services.
Every provider in this section is listed, with its location, on our subprocessor list. The AI processing screen in the app lists the AI providers that write, check, voice and illustrate your companion, with what each does, before you allow processing, and links the full subprocessor list. If the AI providers listed on the AI processing screen change, the app asks you again before any new one receives your data.
We don't train AI on your data
We don't collect, use or sell your personal information to train, fine-tune or improve large language models or any other AI model, and we don't build training datasets from your conversations, memories, voice or images.
Memory
Memory is how your companion remembers you, and it is shared by all your companions.
- How memories form. After you talk, our AI reads the conversation and saves facts, preferences, feelings, relationships and moments worth remembering. It also keeps a running description of you. You can also ask your companion to remember or correct something.
- What you can do, in Menu (≡) → Memory:
- see every memory and where it came from;
- edit its wording yourself, for free, or ask your companion to correct it, which uses Usage;
- mark it "Don't use this";
- forget it, which removes it together with its earlier versions;
- forget all saved memories at once. They stop being used right away and are removed as cleanup finishes. Earlier versions that Memory keeps for your review may still appear there, and your conversations stay in your history.
- Remember new conversations, the switch in Memory, stops new messages from becoming memories. It doesn't delete existing memories.
- Automatic tidying.
- Once a moment from an older conversation has been folded into longer-term memory, its detailed record is deleted after 180 days.
- Suggested connections between memories that were never confirmed are deleted after 90 days.
- People and topics noted only as possible memories are deleted if they haven't come up for 12 months.
- Other people and topics, apart from you, are archived if they haven't come up for 12 months.
- Where it runs. Memories are formed by the same AI model and providers as your companion's replies. The search data that helps your companion find the right memory is computed on our own servers, not by an outside provider.
- Not used for decisions about you. We use memory only for your own conversations with your own companions. We never use it to make decisions about you that have legal or similarly significant effects, such as decisions about credit, housing, employment, insurance, education or health care.
Voice: dictation, calls and read-aloud
- On your iPhone first. When your iPhone has an on-device speech model for your language, your speech is turned into text on the phone, and only the text reaches us.
- Our speech provider only when needed. If your iPhone can't recognize speech itself, for example because the speech model is missing or still downloading or your language isn't supported, your audio is streamed over an encrypted connection to our servers and on to Deepgram, which turns it into text.
- Calls. During a call, our call-media provider carries your companion's voice to you and, when your iPhone can't recognize speech itself, your voice to our servers.
- No recordings. We never store recordings of your voice. What you say becomes text and is kept as part of your conversation. In a call, each thing you say is held as encrypted text for at most 60 seconds while it becomes a message.
- Your companion's voice is generated by Deepgram from the reply text.
- No voice identification. We don't create voiceprints, don't analyze your voice for emotion, and never use your voice to identify you.
Avatars and selfies
- Never from images of you. Gemnd never asks for a photo or video of you. Looks and selfies are made from text and your companion's own reference portrait, never from images of you or any real person.
- Checked before you see them.
- Selfie requests are checked against our content rules before anything is generated.
- Every image and every video frame is checked against our content rules, at Apple's line for apps rated 18+, by OpenAI before it is delivered. These checks decide what you see, whatever the generation provider does.
- Kept privately. We store generated media privately with Cloudflare and show it only to you, through your signed-in account. OpenRouter records a 30-day retention policy for Black Forest Labs; xAI retains its asynchronous video output briefly. [pending: exact selected-endpoint retention terms, including storage, security and abuse-monitoring copies]. No-training requirements do not mean no retention.
- Yours to download. It is included, as image and video files, when you download your data, and it is erased from our storage when you delete your account.
When a person sees your content
We don't look at your conversations to run Gemnd. A person on our team sees conversation content only when:
- you report a reply, selfie or avatar (they see the reported content and your note);
- you send it to us yourself, for example in a support email;
- we need to investigate a security incident or a serious safety or legal matter;
- the law requires it.
Access is limited to people who need it for that task.
Safety, moderation and crisis resources
Gemnd is a companion app, not a health care, therapy, counseling or crisis service. No companion is a therapist, counselor or doctor, and companions can't diagnose or treat anything.
Our full safety protocol is published on our website at {{owner:website_url}}/legal/safety and in the app at Settings → Your data and devices → Safety.
-
Content checks. Gemnd is built for adults and allows romance, role-play and dark themes in fiction. We automatically check:
- your messages before your companion replies;
- each sentence of a reply before you see or hear it;
- companion character settings;
- look and selfie requests;
- generated images.
Within Apple's line for apps rated 18+, companions go along with your story and don't refuse or lecture. The checks stop content beyond that line, such as explicit sexual content and the sexualization of minors or real people, and look for real-world harm. A sentence of a reply that goes beyond the line is left out without a notice. These checks are automated. We store only the outcome, a reason category and a one-way fingerprint of the checked content, as described above, and our logs record the checks' scores as numbers only. Three refused look or selfie requests, or rejected rounds of generated images, within 30 days pause image generation, including looks and selfies, for 30 days. A request that appears to sexualize a minor pauses image generation until our team reviews it.
-
Crisis resources. We automatically check your messages and call transcripts for signs that you may be thinking about suicide or self-harm, including when you say it in other words or in character during a role-play. Violence toward others in fiction never triggers crisis resources.
- When we see those signs, the app shows crisis resources, including the 988 Suicide & Crisis Lifeline, with your companion's reply, including when our safety checks are unavailable and your companion can only send a short supportive reply. In a call, your companion says them first.
- We note on the reply that resources were shown, and we log that a crisis response happened without logging what you said.
- Neither your companion nor Gemnd ever contacts emergency services, crisis lines or anyone else about you.
- Counting referrals. Some state laws require us to report how often we showed crisis resources. We report only a total, with no name, account number, message content, IP address or location, to the state agencies that require it, such as the California Office of Suicide Prevention, which publishes the totals.
-
AI reminders. The app tells you that your companion is an AI, not a person, with your companion's first reply in each interaction, at least every three hours while an interaction continues, and whenever you sincerely ask whether you are talking to a person or an AI, in chat and in calls. In a call, the reminder appears as a caption on the call screen. An interaction begins with your first message after 30 minutes without one. We record when we last showed the reminder in each conversation so the next one comes on time.
-
Minors. If anything in a conversation suggests that the person writing is under 18, companions drop all romantic and flirtatious framing, and a message that says the writer is under 18 is refused. If we learn that an account belongs to someone under 18, {{owner:minor_account_action}}.
-
Reports. A report sends the reported reply or avatar and your note to our review queue, encrypted. Our support inbox is told only that a report arrived, with its reference, reason and time, never its content. You can follow the outcome in Settings → Help and reports. Reports are deleted after 30 days.
How we disclose information
We disclose personal information only in the ways below.
Service providers. Companies that process personal information on our behalf to provide Gemnd. Every service provider works under a written contract that lets it use your information only to provide its service to us, on our instructions. The contract forbids it to sell or share your information or to use it for its own purposes, including training or improving AI models. It requires the provider to keep your information confidential and secure, to protect it at least as well as this policy does, to help us honor your rights, and to delete your information when we ask. The same applies to the crash-reporting software built into the app. If a company related to us, such as a parent, subsidiary or affiliate, ever has access to your information, it must protect it the same way. Where a provider's own practice differs, such as how long it keeps data, this policy says so. [counsel: no written contract with our web search provider, Serper, is known to contain these terms (no DPA barring training or secondary use); sign one or narrow this paragraph before publication.]
What the AI providers receive and how they treat it is described in How AI processes your information. Our subprocessor list names each provider, with its purpose and location, and on request we'll send you each one's contact details. The categories are:
- AI model hosting and routing: OpenRouter and Together AI. They receive conversation context, memories and companion character text. DeepSeek supplies the model but receives no requests from Gemnd.
- Content safety: TypeSafe and Together AI (text), and OpenAI (images and video frames). They receive messages, replies, character text, requests and generated images.
- Speech recognition and voice: Deepgram. It receives voice audio when your iPhone can't transcribe it, and reply text.
- Image and video generation: Black Forest Labs (FLUX 3 Image) and xAI (Grok Imagine Video 1.5 Lite), through OpenRouter. They receive look and selfie requests, companion portraits and generated media.
- Web search for companion replies: Serper. It receives search queries and web addresses.
- Cloud hosting, databases, logging and encryption keys: Google Cloud. It stores and processes all the information described in this policy for us.
- Media storage: Cloudflare. It stores generated images and videos.
- Real-time call media: our call-media provider, named on the subprocessor list. It receives call audio while a call is active, and your device's IP address while a call is connected.
- Email delivery: our email provider, named on the subprocessor list. It receives your email address and the codes and notices we send.
- Support mailbox: our mailbox provider, named on the subprocessor list. It receives emails you send us.
- Crash and error reporting: Sentry. It receives crash and error diagnostics with message content removed.
Apple. Apple runs the App Store and processes your subscription payments under its own terms, as an independent company, not as our service provider. We send Apple only the random purchase number described above, which is linked to your account.
Legal requirements and safety. We may disclose information if we believe in good faith that the law requires it, for example to answer a valid subpoena, court order or search warrant, or to report apparent child sexual abuse material to the National Center for Missing & Exploited Children, as federal law requires. We review every request and disclose only what the law requires. We may also disclose information when needed to:
- protect Gemnd, our users or others from fraud or security threats;
- respond to an emergency request from a government authority where someone's life is at imminent risk;
- enforce our Terms of Use or defend legal claims.
These broader disclosures never apply to consumer health data. For consumer health data, only the narrower cases in Consumer health data apply: we never disclose it in response to a request that doesn't legally compel us, such as a voluntary emergency request, or to enforce our Terms of Use or defend legal claims, unless you consent.
Business transfers. If we are involved in a merger, acquisition, financing, reorganization, bankruptcy or sale of assets, personal information may be transferred as part of that deal. Anyone who receives it must keep honoring this policy and the laws that protect consumer health data. We will tell you before your information becomes subject to a different privacy policy.
At your direction. We disclose information when you ask us to.
We don't disclose personal information to anyone for their own marketing. We don't sell it to data brokers or anyone else.
No sale, no sharing, no targeted advertising
These statements are true today and have been true for the past 12 months:
- We don't sell personal information, including sensitive personal information and consumer health data, to anyone, for money or anything else of value.
- We don't share personal information for cross-context behavioral advertising, and we don't use it for targeted advertising. Gemnd shows no ads.
- We don't sell or share the personal information of anyone under 16, or of anyone at all.
- No other company tracks you through Gemnd. No third party collects information about your activity in Gemnd over time or across other apps or websites.
- We don't profile you to make decisions that have legal or similarly significant effects, and we make no automated decisions about your access to financial services, housing, education, employment, health care or essential goods and services.
- We use and disclose sensitive personal information only for the purposes the law permits without an opt-out: providing the service you asked for, security, safety, preventing fraud, quality and legal compliance.
- We offer no financial incentive or price difference tied to your personal information. Our plans and prices depend on how much you use Gemnd, not on your data.
- We don't train AI models on your personal information (see above).
Because we don't sell, share, target ads or profile you in these ways, there is nothing for you to opt out of. We don't need a "Do Not Sell or Share" or "Limit the Use of My Sensitive Personal Information" link. If we ever wanted to do any of these things, we would change this policy first and ask for your consent where the law requires. Information we collected under this policy would never be sold or shared without your consent.
Global Privacy Control and Do Not Track. We don't sell or share personal information, we don't use it for targeted advertising, and we don't let anyone track you across other websites or apps. So a Global Privacy Control or browser "Do Not Track" signal has nothing to switch off, and Gemnd works the same whether or not your browser sends one. The iPhone app doesn't receive browser signals, and the same commitments apply there. If we ever started selling, sharing or targeting ads, we would change this policy first and honor these signals as requests to opt out.
How long we keep information
We keep personal information only as long as we need it for the purposes in this policy. The table gives each period. "Until you delete your account" means we keep it while your account exists, because your companion depends on it, and it is erased when you delete your account.
| Information | How long we keep it |
|---|---|
| Account details (email, password hash, display name, sign-in method) | Until you delete your account |
| Your adult confirmation, AI-processing consent and its history, acceptance of our terms and confirmation that you've read this policy | Until you delete your account |
| Conversations: messages, replies, call transcripts, summaries and titles | Until you delete your account |
| Speech held while it becomes a message | At most 60 seconds, as encrypted text. Voice audio is never stored |
| Memories and their search data | Until you forget them or delete your account, with the automatic tidying described under Memory. After you forget all memories, earlier versions kept for your review remain until you delete your account |
| Profile details and time zone | Until you delete your account |
| Companions, personas, their earlier versions and the quotes kept with character changes | Until you delete your account. Archiving a companion hides it but doesn't delete it |
| Generated looks, expressions and selfies, with their requests | Until you delete your account. Generated images that are never used are cleared automatically |
| Call records (times, how a call ended, how speech was recognized) | Until you delete your account |
| Safety records (the outcome of each check, its reason category and its one-way fingerprint) | Until you delete your account |
| The note that crisis resources were shown with a reply, and AI-reminder times | Until you delete your account, so your history still shows the resources |
| Records of refused look and selfie requests and image-generation pauses | Until you delete your account. A refusal counts toward a pause for 30 days. A review lock lasts until our team clears it |
| Reports (the reported content and your note) | 30 days. A record that a reviewer opened a report, with no content, is kept 90 days |
| Sign-in records (IP address, device description, times) and hashed sign-in tokens and codes | Until you delete your account. One-time codes stop working after 10 or 15 minutes. Sign-in attempt counters last 15 minutes or less |
| Usage ledger and subscription records | Until you delete your account. After that we keep them without your email or other contact details, linked only to a random account number, for {{owner:financial_retention_years}} years after the end of the year they relate to, for accounting, tax, fraud prevention and legal claims, and then we delete them. We keep the record that you subscribed, including the subscription terms shown to you, for at least three years, or one year after your subscription ends if that is later, as California's automatic renewal law requires |
| Signed purchase proofs from Apple | 24 hours or less |
| Account deletion status | 30 days. The email address for the completion notice is kept 7 days or less |
| A record that an account was erased | Permanently, under its random account number, with no email address or other details. We use it only to make sure an erased account stays erased |
| Privacy requests and our responses | 24 months after we close the request, then deleted. We use them only as a record of how we handled your request |
| Arbitration opt-out notices, notices of dispute and the Terms version they relate to | {{owner:legal_notice_retention_years}} years after your account ends, so we can honor an opt-out after deletion |
| Other support emails | As long as we need them to resolve your request |
| Server request logs and operational telemetry | {{owner:log_retention_days}} days, never more than 30 |
| Crash and error reports | {{owner:crash_report_retention_days}} days, the period our crash-reporting provider keeps them |
| On your iPhone | Sign-in until you sign out. Saved voice recordings up to 30 days. See Information kept only on your iPhone |
| Copies held by AI providers | Text prompts and replies require ZDR for OpenRouter, Together AI and TypeSafe; operational metadata is separate. Only while processing for Deepgram; up to 30 days of abuse-monitoring logs for OpenAI. OpenRouter records 30-day retention for BFL; exact written terms remain pending. xAI retains asynchronous video output briefly and is not ZDR eligible; the exact period remains pending. Serper does not publish a query-retention period. |
| Emails between you and us, at our email delivery and support mailbox providers | As long as each provider's contract with us allows, and no longer than needed to deliver mail and handle your request |
Written arbitration opt-outs and notices of dispute are encrypted separately from your conversations and restricted to authorized legal operators. Deleting your account starts the fixed retention period above; reading a notice or repeating the deletion does not restart it. This exception preserves the notice and its related Terms version, not your conversations, your conversation key or your general Terms-acceptance history.
Backups
We back up our databases automatically so we can recover from failures. Backups can't be edited, so something you delete stays in older backups until those backups are deleted.
- We keep automatic backups for 30 days, then delete them, along with 7 days of change records that let us restore a database to an earlier moment. So anything you delete is gone from our backups within about 30 days.
- Your messages, memories, memory corrections, personal profile (nickname, occupation and description, including earlier copies kept when your profile changes), conversation summaries, companion character text and the text of your companion's spoken replies are also locked with a key that belongs only to your account. That key is itself locked by a master key held in Google Cloud's key management service.
- When you delete your account, we destroy that key.
- Every month we also replace the master key, and we destroy each old version once our backups have aged out and one more replacement has passed.
- So within about 60 days of your deletion, no one, including us, can read that text in any backup.
- Other information is not locked with your key, including look requests, conversation titles and the numerical search data computed from memories. It is erased with your account and leaves our backups within 30 days, like everything else.
Downloading and deleting your data
Download my data
In Settings → Your data and devices, tap Download my data. The app then prepares a ZIP file and saves it straight to a folder you choose. We don't keep a copy on our servers. The download includes:
- your account details, profile, time zone and settings;
- all your conversations, transcripts, summaries and the factual claims extracted from them;
- your memories, with their earlier versions and sources, and the text prepared for memory search;
- your companions, personas, their versions and character changes;
- your custom looks, expressions and selfies, as image and video files, with their requests;
- call records (not audio, which we don't keep);
- your safety records and reports;
- your AI-processing choices, consents and their history;
- your plan, purchase records and Usage ledger.
The download doesn't include:
- passwords, sign-in codes and tokens, which we keep only as one-way hashes for security;
- the raw signed records Apple sends us;
- the IP addresses and device descriptions stored with your sign-ins (the device descriptions appear in Signed-in devices);
- the numerical search data (embeddings) computed from your memories, which can be rebuilt from them;
- data kept only on your iPhone;
- logs and diagnostics;
- copies held by our providers;
- your emails with us.
You can ask us for any of these that we hold by emailing {{owner:privacy_email}}.
Delete your account
In Settings → Delete account, confirm with your password or a code we email you. Then:
- Right away, we sign you out on every device and start erasing your account. There is no waiting period.
- In fixed steps, we erase your memories, your conversations, your companions, your generated images and videos, and finally your account details. We confirm that the media files are gone from storage before we erase their records. If a charge for something you started is still being settled, erasure waits until it settles. Either way, your conversations, memories and other consumer health data are erased from our active systems within 30 days of your request.
- When it's done, we email you. Right after you confirm, the app shows a deletion status screen that follows the steps.
What we keep after deletion, linked only to a random account number and never to your email or conversations, except where this list says otherwise:
- the Usage ledger and subscription records, for accounting, tax, fraud prevention and legal claims, for the period in the table above;
- the subscription's identifier, so an erased purchase can't be claimed again;
- a record that the account was deleted;
- for 24 months, the privacy requests the account made and our answers, which can include the email address you wrote from;
- the permanent erasure record described above.
Where your data can remain for a while: backups, until they expire (see Backups); logs, until they expire; copies at our providers, as described above; and any download you saved yourself.
Your subscription continues until you cancel it with Apple. Deleting your account doesn't cancel it. Cancel in your iPhone's Settings → [your name] → Subscriptions, or in Gemnd under Menu (≡) → Plan & Usage → Manage subscriptions.
Delete specific information
- Memories: forget one, or all, in Memory.
- Reports: deleted automatically after 30 days.
- Conversations and companions: you can't delete a single conversation or companion in the app. Deleting your account deletes all of them. If you want specific information deleted without closing your account, email {{owner:privacy_email}}, and we'll handle it as a deletion request under Your privacy rights.
Turn off AI processing
In Settings → AI processing, tap Turn off.
- Chat, calls, memory updates and avatar creation stop right away, including a reply already in progress, until you turn processing back on.
- We stop sending your conversations and memories to our AI providers and stop forming new memories. Your conversations, memories and account stay stored, so they're there if you turn processing back on, and you can still download your data, manage your devices and delete your account. To have them deleted, delete your account or email us.
- Turning processing off can't recall what was already sent. The providers that write your companion's replies keep nothing. OpenAI may keep abuse-monitoring logs of image checks for up to 30 days, and our image and video generation providers keep request data and generated files for [pending: media provider retention], as described in How long we keep information.
[counsel: confirm that storage-only retention after withdrawal, with deletion available only through account deletion or an emailed request, meets Conn. Gen. Stat. §42-520(a)(1)(G) and ORS 646A.578(1)(d) ("cease to process"); health-biometric-breach Q6.]
Your privacy rights
We give every Gemnd user in the United States the rights below, wherever you live, even if your state's law doesn't require them. They are based on the privacy laws of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, Nevada, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, Washington and other states.
Your rights
- Know and access. Ask whether we process your personal information, and get a copy of it, including the inferences we've made about you, such as memories. You can also ask for the categories we collect, where it comes from, why we use it, the categories of providers we disclose it to, and what we keep.
- Portability. Get your information in a portable, machine-readable format. The download is a ZIP of standard JSON files plus your media files.
- Correct. Fix inaccurate information. You can edit or correct memories and your companion settings yourself in the app. For anything else, such as your account email, write to us.
- Delete. Have your personal information deleted, including information derived from it. You can delete your account in the app, or ask us to delete specific information.
- List of recipients. Get a list of the specific companies we've disclosed your personal information to. That is our subprocessor list, plus Apple (the random purchase number described above), plus any authority or other party we disclosed your information to as described in How we disclose information. We name each of them in our answer to you, and on request we add each one's contact details.
- Withdraw consent. Withdraw any consent you gave, as easily as you gave it. AI processing stops immediately when you turn it off.
- Stop collection. Ask us to stop collecting, using and disclosing your consumer health data. Turning off AI processing in Settings → AI processing does this right away for anything new. After that, we keep what you already have only so you can read, download or delete it, and we don't process it in any other way. To have it removed too, delete your account or ask us. [counsel: Nevada NRS 603A.505(1)(c) and the "collect includes retain" definitions.]
- Opt out of sale, sharing, targeted advertising and significant profiling, and limit the use of sensitive personal information. You have these rights, but they don't arise at Gemnd, because we don't do any of those things.
- Appeal any decision we make on your request (see below).
- Equal treatment. We will never deny you service, charge you a different price or give you a worse experience because you used your rights. Withdrawing AI-processing consent pauses the features that need AI processing, because they can't work without it.
How to make a request
- In the app, for the requests the app handles directly: Download my data, Delete account, AI processing, Signed-in devices and Memory. For any other request or an appeal, Settings → Help and reports → Contact support opens an email to us.
- By email to {{owner:privacy_email}}, for any request. Write from the email address on your account if you have one, say which right you want to use, and tell us your state of residence.
- By mail to {{owner:company_legal_name}}, {{owner:mailing_address}}.
You don't need a Gemnd account to make a request. Requests are free.
How we verify requests
- In the app, being signed in identifies you. Before we delete your account, the app also asks you to confirm with your password or a code we email you.
- By email or mail, we'll ask you to confirm the request from the email address on your account. We may ask for more information if a request is unusually sensitive, and we use what you give us only to verify you.
- Without an account, we match what you tell us against the information we hold, to the degree of certainty the request calls for.
- Requests to opt out need no verification.
If we can't verify a request, we'll tell you why and what would let us.
Authorized agents
You can have someone make a request for you. We'll ask the agent for your signed permission, and we may ask you to confirm your identity or the request directly with us. A valid power of attorney is also accepted.
When you'll hear from us
- Within 10 business days, we confirm we received your request and tell you how we'll handle it.
- Within 45 days of receiving it, we respond.
- If we need more time, we tell you why within those 45 days, and we take at most 15 more days.
- Within 60 days of receiving it, we confirm that we've carried it out.
- If we decline any part of it, we explain why and tell you how to appeal.
- For consumer health data, we delete within 30 days of verifying the request, and in every case within 45 days of receiving it (60 if we extend as above), and we tell every provider that may still hold a copy to delete it. OpenAI's abuse-monitoring logs, kept for up to 30 days, and our image and video generation providers' request data and files, kept for [pending: media provider retention], are deleted on those providers' own schedules, described in How long we keep information.
How to appeal
If you disagree with our decision on your request, you can appeal:
- reply to our decision email with the word "Appeal" in the subject line, or email {{owner:privacy_email}} with that subject;
- say which decision you are appealing and why.
We answer in writing within 45 days, with our reasons. If we deny your appeal, you can complain to your state attorney general. Our decision will include a link to your attorney general's online complaint form.
State-specific information
- California.
- The Notice at collection lists the categories of personal information we have collected in the past 12 months, their sources, purposes and retention, and the categories of providers we disclosed them to for a business purpose.
- California's "Shine the Light" law (Civil Code §1798.83): we don't disclose personal information to third parties for their direct marketing purposes. You can ask us about this once a year at {{owner:privacy_email}} or by mail, and we'll respond within 30 days.
- Automated decision-making rights don't arise, because we make no automated decisions with legal or similarly significant effects.
- Nevada. We don't sell covered information. You can still send a request not to sell to our designated address, {{owner:privacy_email}}, and we'll record it.
- Colorado, Connecticut, Virginia and other states that require consent for sensitive data.
- We process sensitive data, including inferences such as memories, only after you give the AI-processing consent described in Sensitive personal information, and only as needed to provide Gemnd.
- In Virginia, we obtain and disclose reproductive or sexual health information only with that consent.
- [counsel: the AI processing screen does not name the sensitive-data categories or sexual and reproductive health, and has no separate sensitive-data consent; confirm whether that consent meets the Virginia, Colorado and Connecticut sensitive-data consent requirements and Washington's My Health My Data Act consent requirement before publication.]
- Maryland. We collect and process sensitive data only when it is strictly necessary to provide the service you asked for, and we never sell it.
- Connecticut. We don't collect, use or sell personal data to train large language models. The providers that write, check, voice and illustrate your companion are barred by contract from training on your data, and our web search provider receives only search queries, with no user identifier (see We don't train AI on your data).
Notice at collection
This notice tells you, at or before the point we collect personal information, what we collect, why, whether we sell or share it (we don't) and how long we keep it. It applies to California residents and everyone else. You can open it directly, without scrolling through the rest of this policy, at {{owner:website_url}}/legal/privacy#notice-at-collection, and, before you download Gemnd, from the link to {{owner:website_url}}/legal/privacy#notice-at-collection on our App Store page. In the app, the Notice at collection link on the Create account screen, shown before you send us your email and password, opens this section directly.
- We collect the categories below. The category names are the ones California law uses. We have collected these categories, and only these, in the 12 months before this policy's effective date.
- We don't sell or share any of them, and we don't use sensitive personal information beyond what the law allows without an opt-out (see No sale, no sharing, no targeted advertising).
- We keep each one only as long as described below and in How long we keep information.
- "Service providers" means the categories in How we disclose information, named on our subprocessor list.
Identifiers
- What: email address, display name, account number, sign-in and device records with IP address and device description, Apple purchase number.
- Sources: you; your device; Apple.
- Purposes: running your account, security, Usage and purchases, support, and letting your companion address you by the name you choose.
- Disclosed to: cloud hosting; AI model hosting and routing, and content safety (the name or nickname your companion knows you by); email delivery (your email address); our support mailbox provider (your email address, when you write to us); our call-media provider (your device's IP address while a call is connected); operational monitoring and crash reporting (as keyed hashes only); and Apple (the random purchase number only).
- Kept: until you delete your account; sign-in records until you delete your account; logs for {{owner:log_retention_days}} days, and crash and error reports for {{owner:crash_report_retention_days}} days.
Personal information described in California Civil Code §1798.80(e)
- What: your name, and anything in that list you choose to tell your companion, such as a description of yourself or medical information.
- Sources: you.
- Purposes: providing your companion.
- Disclosed to: AI model hosting and routing, content safety, cloud hosting.
- Kept: until you delete your account or forget the memory.
Characteristics of protected classifications
- What: that you are an adult (18+); anything you choose to tell your companion about your sex, gender, sexual orientation, religion, national origin, disability, age or similar characteristics.
- Sources: you.
- Purposes: the adult confirmation; providing your companion.
- Disclosed to: AI model hosting and routing, content safety, cloud hosting.
- Kept: until you delete your account or forget the memory.
Commercial information
- What: your plan, Apple purchase records and your weekly Usage ledger.
- Sources: Apple; created as you use Gemnd.
- Purposes: providing your plan, measuring Usage, preventing fraud, accounting.
- Disclosed to: cloud hosting.
- Kept: until you delete your account, then without contact details for {{owner:financial_retention_years}} years after the end of the year they relate to, for accounting, tax, fraud prevention and legal claims, and then we delete them.
Biometric information
- Not collected. Your voice is turned into text and never used to identify you.
Internet or other electronic network activity
- What: request logs, how you use the app's features as needed to run them, crash and error diagnostics.
- Sources: your device.
- Purposes: operating, securing and fixing Gemnd.
- Disclosed to: cloud hosting, operational monitoring, crash and error reporting.
- Kept: request logs and telemetry {{owner:log_retention_days}} days; crash and error reports {{owner:crash_report_retention_days}} days.
Geolocation data
- Not collected. We use your device's time zone, not its location.
Audio, electronic, visual and similar information
- What: your messages and your companion's replies; your voice while you speak (streamed, not stored); call transcripts; generated images and videos; saved voice recordings on your iPhone.
- Sources: you; created at your request.
- Purposes: conversations, calls, dictation and read-aloud, avatars and selfies, safety checks.
- Disclosed to: AI model hosting and routing, content safety, speech, image and video generation and review, web search, call media, media storage, cloud hosting.
- Kept: conversations and media until you delete your account; speech text 60 seconds or less while it becomes a message; saved voice recordings on your iPhone up to 30 days.
Professional or employment information
- What: only what you choose to tell your companion or add to your profile.
- Sources: you.
- Purposes: providing your companion.
- Disclosed to: AI model hosting and routing, content safety, cloud hosting.
- Kept: until you delete your account or forget the memory.
Education information
- What: only what you choose to tell your companion.
- Sources: you.
- Purposes: providing your companion.
- Disclosed to: AI model hosting and routing, content safety, cloud hosting.
- Kept: until you delete your account or forget the memory.
Inferences
- What: memories, the running description of you, and conversation summaries.
- Sources: created by our AI from your conversations.
- Purposes: letting your companion remember you.
- Disclosed to: AI model hosting and routing (to form and use memories), cloud hosting.
- Kept: until you forget them or delete your account, with automatic tidying.
Sensitive personal information
- What: your account email with your password; the contents of your messages; and, when you share them in conversation or in companion settings, information about your health, sex life, sexual orientation, racial or ethnic origin, religious or philosophical beliefs, citizenship or immigration status or union membership.
- Not collected: government ID numbers, financial account numbers, precise geolocation, genetic, biometric or neural data.
- Sources: you.
- Purposes: providing the service you ask for, security, safety and legal compliance only.
- Disclosed to: as for the audio and inferences categories.
- Kept: as for the audio and inferences categories. Passwords are stored only as a one-way hash.
Consumer health data
Some state laws protect "consumer health data": information linked to you that identifies your past, present or future physical or mental health, including information inferred from other data. These include Washington's My Health My Data Act, Nevada's consumer health data law and Connecticut's privacy law.
Our separate Consumer Health Data Privacy Policy describes how we handle consumer health data for every user, as Washington's My Health My Data Act requires. This section summarizes it and adds what Nevada and Connecticut require.
What we collect and how we use it
- What you tell your companions about your health: for example your physical or mental health, mood, medications, treatment, sexual or reproductive health, or gender-affirming care, typed, dictated or said in a call. We use it to reply to you, keep your conversation history and remember what you share.
- Memories and summaries about your health, which our AI creates from your conversations. We use them so your companion stays consistent with you.
- How you ask a companion to support you, in its character settings. We use it to shape replies.
- Character changes you ask for in conversation, with the short quote from your request that we keep (up to 512 bytes), if it mentions your health. We use it so you can review what changed and why.
- Safety signals: a record that we showed crisis resources or gave a supportive response, without your message. We use these only for safety and to meet our legal duties.
- Reports and messages you send us, if they mention your health: the reported reply and your note (deleted after 30 days), and emails or letters you send us, including privacy requests. We use them to review the report or answer you.
- Your voice, when your iPhone can't transcribe it. It is streamed to our speech provider to be turned into text and isn't kept. We keep the text, not the audio, and we never use your voice to identify you. Washington law can treat voice recordings as biometric data, so we list it here.
Where it comes from. From you, and from our systems and AI providers, which create memories, summaries and safety signals from what you share.
How it is processed.
- It is stored encrypted on Google Cloud servers in {{owner:hosting_region}}, in the United States, with your messages, memories, memory corrections, conversation summaries, companion character text and the text of your companion's spoken replies encrypted under a key unique to you.
- It is processed by automated systems and by the AI providers that write your companion's replies, on our instructions.
- People on our team see it only in the situations listed in When a person sees your content.
Sharing. We never sell consumer health data, and we don't share it with any third party or affiliate for its own purposes. We disclose it only in the limited ways below.
-
To our service providers, which process it under written contracts, only on our instructions and only to provide Gemnd:
- what you tell your companions about your health goes to AI model hosting and routing, content safety, speech recognition, call media, web search for companion replies, and cloud hosting and storage;
- memories and summaries go to AI model hosting and routing, and cloud hosting and storage;
- support preferences and character-change quotes in companion settings go to AI model hosting and routing, content safety, and cloud hosting and storage;
- safety signals go to cloud hosting and storage and, without your words, operational monitoring;
- your voice, when your iPhone can't transcribe it, goes to speech recognition and call media;
- reports go to cloud hosting and storage, and messages you send us go to our support mailbox provider.
They are named on our subprocessor list. On request we'll send you each one's contact details.
-
When we disclose it to anyone else. We disclose consumer health data without your consent only:
- to prevent, detect, protect against or respond to security incidents, identity theft, fraud, harassment, malicious or deceptive activities, or illegal activity, or to investigate, report or prosecute those responsible; or
- when a court order, search warrant or subpoena legally compels us. [counsel: the Washington My Health My Data Act has no express exception for legal process (RCW 19.373.100(3)); confirm this bullet before publication.]
We disclose only what is required and, unless the law forbids it, we tell you first. We never disclose it in response to a request that doesn't legally compel us, and our crisis feature never contacts anyone.
-
Business transfers. If Gemnd is merged with or sold to another company, that company must follow this policy and the laws that protect consumer health data.
Consent. Before we collect consumer health data, the app asks for your consent on the AI processing screen. The consent is separate from our Terms of Use. We also collect consumer health data only as needed to provide the companion you asked for. You can withdraw consent at any time in Settings → AI processing.
Your rights. You can confirm whether we collect, share or sell your consumer health data; see and download it; get the list of companies that process it; ask us to stop collecting and sharing it (Settings → AI processing → Turn off, or email us); withdraw consent; and have it deleted. The paths are in Downloading and deleting your data and Your privacy rights.
- Deletion. We delete consumer health data from our active systems within 30 days of verifying your request, and we tell every provider that may hold a copy to delete it. Safety entries in our operational logs carry only a coded identifier and no message text, and they expire within {{owner:log_retention_days}} days, which is never more than 30. Backup copies expire within 30 days and become permanently unreadable within about 60 days (see Backups), well within the six months Washington law allows.
- Response time. We respond to requests within 45 days and to appeals within 45 days. If we deny an appeal, we give you your attorney general's contact details: in Washington, atg.wa.gov/file-complaint; in Nevada, ag.nv.gov.
- Correction. You can review and change memories in the app at any time.
Other commitments.
- We don't use location and we never geofence health facilities.
- No third party tracks you across apps or websites through Gemnd.
- If we change how we collect, use or share consumer health data, we tell you in the app first and ask for your consent again before the change applies.
Adults only
Gemnd is only for adults 18 and older and is not directed to children. Companion chatbots may not be suitable for some minors.
- We don't knowingly collect personal information from anyone under 18.
- Before anyone can use a companion, they must confirm that they are 18 or older. If they say they are under 18, they can't use Gemnd. That screen offers only Sign out. To have the account deleted, email {{owner:privacy_email}}.
- If anything in a conversation suggests that the person writing is under 18, companions drop all romantic and flirtatious framing, and a message that says the writer is under 18 is refused.
- If we receive age information from your device or app store, we use it only to keep minors off Gemnd, to comply with the law and to apply safety settings. We never sell or share it, and we keep it no longer than the check requires.
- If we learn that an account belongs to someone under 18, {{owner:minor_account_action}}.
If you believe someone under 18 is using Gemnd, or you are a parent or guardian with a concern, email {{owner:privacy_email}}.
How we protect your information
We protect personal information with safeguards suited to how sensitive it is.
- In transit: connections between the app and our servers, between our services, and to our providers are encrypted. Our services verify the identity of the database server before connecting.
- At rest:
- Our databases are encrypted with keys we manage in Google Cloud's key management service.
- Generated media is encrypted by Cloudflare.
- Your messages, memories (including names, aliases, claim labels and personal profile values recorded in memory), memory corrections, personal profile (nickname, occupation and description, including earlier copies kept when your profile changes), conversation summaries, companion character text and the text of your companion's spoken replies are additionally encrypted with a key unique to you, which is itself protected by a key held in Google Cloud's key management service. Their content fingerprints are keyed per user and destroyed with the key, not plain hashes. Fingerprints of the content each safety check looked at are plain one-way hashes. Those safety fingerprints are deleted with your account and leave our backups within 30 days.
- Reports, pending speech and purchase tokens have a further layer of encryption in our application.
- Access:
- Our services connect to our databases with separate roles that can't change the database's structure, over connections that verify the database server's identity.
- Access to each user's data is restricted by checks in our application.
- Secrets are kept in a secrets manager, never in the app.
- Accounts:
- Passwords are stored as bcrypt hashes.
- Sign-in is protected by limits on repeated attempts and, for accounts that use it, an emailed one-time code.
- A password reset signs you out on every device.
- Deleting your account asks you to confirm with your password or an emailed code.
- Your sign-in secret stays in your iPhone's Keychain, and the short-lived access token stays only in the app's memory.
- Logs and diagnostics: our application logs, telemetry and crash and error reports are built to leave out message text, email addresses and IP addresses, and identifiers in them are replaced by keyed hashes. Our hosting provider's request logs do record IP addresses and device descriptions, as described in Logs and diagnostics.
- Not end-to-end encrypted. Our servers have to read your messages to generate replies.
No method of storing or sending information is completely secure. If a security breach affects your personal information, we will notify you and the authorities as the law requires.
You can help by using a strong password you don't use elsewhere and signing out devices you no longer use (Settings → Your data and devices → Signed-in devices).
Cookies and similar technologies
- The iPhone app uses no cookies, advertising identifiers or tracking technologies.
- Our web pages, including this policy, set no cookies and load no third-party trackers or analytics. They store a display-theme preference and a technical marker that helps the page reload correctly after we update the site in your browser's storage. Both stay on your device.
- Like any website, our servers log each request, including your IP address and browser description (see How long we keep information).
Where we process information
Gemnd is offered only in the United States. This policy is written for users in the United States. Service availability in the United States is not a promise that every processor is located there.
We store your information on Google Cloud servers in {{owner:hosting_region}}, in the United States. Our providers' confirmed regions and pending commitments are listed on our subprocessor list ({{owner:dpa_regions}}). We do not infer processing location from a company's headquarters. Other routes whose location needs confirmation include:
- web search through Serper;
- image and video generation, depending on the provider (see the Subprocessors page);
- media storage with Cloudflare.
[pending: confirm the exact full-lifecycle no-China/Hong-Kong commitment for all selected media routes, including any web or image grounding; ordinary global-provider terms do not provide a blanket country exclusion. No EU launch is planned.]
If you use Gemnd from outside the United States, your information is transferred to and processed in the United States, where privacy laws may differ from those where you live. If we offer Gemnd in other countries, we will publish the additional information their laws require before we do.
Changes to this policy
The effective date at the top of this policy is the date this version took effect. We update this policy at least once every 12 months, and whenever our practices change. Each update carries a new date, even when nothing about our practices has changed.
- Material changes. A material change is one that affects the categories of information we process, why we process it, who we disclose it to, who we are, or how you exercise your rights. Before such a change applies to you, the app shows you the updated policy and asks you to confirm that you've read it before you continue using your companion. If the change would use information we already hold in a materially different way, or involves a new use of sensitive information or consumer health data or a new company receiving it, we ask for your consent separately, and you can say no. Confirming that you've read the policy is never treated as that consent. We record which version you saw and when. Where the law requires, we also tell the App Store before the change takes effect.
- New uses of information. We won't use information we already hold for a new purpose that you wouldn't reasonably expect without your consent.
- AI providers. If the AI providers listed on the AI processing screen change, the app asks you to review the new list and allow processing again before any new one receives your data.
- Smaller changes, such as clearer wording or updated contact details, take effect when we publish them on our website with a new date.
Earlier versions of this policy are available on request at {{owner:privacy_email}} or {{owner:support_email}}.
This policy is available in English, the language of the app. If you need it in a different format because of a disability, email {{owner:privacy_email}} and we'll provide one. You can print or save this policy from our website at {{owner:website_url}}/legal/privacy.
Contact us
- Privacy questions, requests and appeals: {{owner:privacy_email}}, or Settings → Help and reports → Contact support
- Help with the app: {{owner:support_email}}, or Settings → Help and reports → Contact support
- Legal notices and requests from authorities: {{owner:legal_notice_email}}
- Mail: {{owner:company_legal_name}}, {{owner:mailing_address}}
- Website: {{owner:website_url}}