Privacy Policy - xeve.ai
Privacy Policy
Effective Date: August 10, 2026
Who We Are (Controller)
Jay Web Development & Services
Daxerstraße, 82140 Olching, Germany
Email: info [at] xeve.ai
We are the controller within the meaning of Art. 4(7) GDPR for the processing described in this policy.
What This Service Is — and Why That Matters for Your Privacy
xeve.ai is an adult (18+) entertainment service: you chat — by text, and in the video chat optionally by voice — with fictional AI characters, and you can generate images and videos of these characters. What you write in such conversations is often intimate and can reveal information about your sex life. This policy therefore explains in concrete terms what happens with that content, which service providers are involved, how long we keep what, and which choices you have.
The short version: your conversations are processed only to run the service. They are not sold, not used for advertising, and not used by us to train AI models. Chat sessions are deleted automatically twelve months after their last activity.
Your Account
- Data processed: your email address, your login credentials, an optional first name you can set for the characters to use, your subscription and credit status, your language, your consent records, and the time and IP address of your last login.
- Login service: authentication (email/password or Google sign-in) is operated by Firebase Authentication, a Google service; Google may process authentication data in the USA.
- Legal basis: performance of the contract with you (Art. 6(1)(b) GDPR).
- Retention: until you delete your account. What happens on deletion is described under “Deleting Your Account”.
Chat Conversations
When you chat with a character, we store the conversation — your messages, the character's replies and the session settings (chosen character, scene, language) — on servers of Google Cloud in the EU (region europe-west1, Belgium). This is what makes it possible for a character to remember your conversation when you come back.
- Anonymous use: you can chat without an account. Such sessions are stored under a random identifier that is kept in your browser and are not linked to any account. Without that identifier we cannot attribute a session to you (Art. 11 GDPR); if you want such a session deleted before its automatic deletion, contact us and include the session identifier from your browser's local storage.
- Retention: every chat session is deleted automatically twelve months after its last message. Active conversations are never affected — the twelve months count from the last activity.
- Summaries: to keep long conversations coherent, shortened summaries of conversation excerpts are created and cached without any account reference.
- Legal basis: performance of the service you request (Art. 6(1)(b) GDPR) and — because the content of an erotic chat can reveal information about your sex life — your explicit consent (Art. 9(2)(a) GDPR), which you give before your first chat message. You can withdraw it at any time with effect for the future; without it, the chat cannot be used.
How Your Messages Are Processed (AI Service Providers)
The characters' replies are generated by large language models operated by specialised providers. For this purpose, the following recipients process conversation content on our behalf:
- Reply generation: Together AI (USA) and DeepInfra (USA) receive the recent part of the conversation, the character description and — if you set one — your first name, and return the character's reply. They do not receive your email address or any account identifier, and they process the content solely to generate the reply.
- Content moderation: every conversation is additionally checked by an automated moderation model to block prohibited content, in particular any sexual depiction of minors. This check runs on the same infrastructure as the reply generation.
- Quality evaluation: a small random sample of conversations (without any account data) is rated for quality by an OpenAI (USA) model. OpenAI does not use this data to train its models.
- Voice replies: when a character speaks, the reply text is converted to audio by ElevenLabs (USA).
- Image and video generation: when you request an image or video, the generation prompt derived from your request and reference images of the character are processed by AtlasCloud. The generated media are stored with your account.
Legal basis: Art. 6(1)(b) and Art. 9(2)(a) GDPR for the reply generation (see “Chat Conversations”); for the moderation, our legal obligations regarding illegal content and the protection of minors (Art. 6(1)(c) GDPR) and our legitimate interest in a safe service (Art. 6(1)(f) GDPR); for the quality evaluation, our legitimate interest in improving reply quality (Art. 6(1)(f) GDPR).
Safety Records
If a message is blocked because it attempts to obtain prohibited content — above all any sexual depiction of minors — we record the attempt: the blocked message, the time, the IP address and, if you are logged in, your account email. We keep these records to be able to demonstrate and enforce our protection measures and to establish, exercise or defend legal claims (Art. 6(1)(f) and Art. 9(2)(f) GDPR). They are kept for as long as this purpose requires — as a rule the applicable statutory limitation periods — and, for the same reason, are not deleted when you delete your account (Art. 17(3)(e) GDPR).
Payments and Subscriptions
- Payment processors: payments are handled by CCBill (USA) or CentroBill on their own hosted payment pages. Your full card number is entered there and never reaches our servers.
- Data we store: transaction records (amount, date, product, provider reference), your subscription and credit status, and the email address used for payment.
- Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and our statutory bookkeeping and tax obligations (Art. 6(1)(c) GDPR).
- Retention: financial transaction records are kept for the statutory commercial and tax retention periods (in Germany up to ten years) and are exempt from earlier deletion (Art. 17(3)(b) GDPR).
Identity and Age Verification
In certain cases — for example when a payment provider requires it or when age verification is legally required — we ask you to verify your identity through our verification provider Didit. Didit processes your identity document and a selfie on its own systems; we receive the result of the check and a verification reference. Legal basis: our legal obligations (Art. 6(1)(c) GDPR), in particular the protection of minors, and our legitimate interest in preventing fraud (Art. 6(1)(f) GDPR).
Emails
We send emails through the delivery service Postmark (ActiveCampaign, USA). Transactional emails (for example receipts, subscription notices, verification emails) are sent on the basis of Art. 6(1)(b) GDPR. Marketing emails are sent only if you agreed to them at registration (Art. 6(1)(a) GDPR); you can opt out at any time via the unsubscribe link in every such email, and unsubscribes take effect automatically.
Hosting and Content Delivery
The service and its data run on Google Cloud in the EU (region europe-west1, Belgium). Images and videos — including media you generate — are stored and delivered via the content delivery network bunny.net (EU).
Log Files
Every request to our servers is logged with the IP address, browser type, timestamp, the requested resource and, for logged-in requests, an account reference. We use these logs to operate the service securely, diagnose faults and prevent abuse (Art. 6(1)(f) GDPR). Request logs are deleted automatically after 30 days. Error records — which in the case of a fault can include an excerpt of the affected conversation — are kept only as long as needed to analyse and fix the fault.
Cookies and Local Storage
We store information in your browser's cookies and local storage: your consent decisions, the session identifiers of your chats, your login state, interface settings, A/B test group assignments, your subscription and credit status, and — as described below — campaign identifiers from links you followed. Strictly necessary storage is based on our legitimate interest in providing the service you request; everything else only happens after your consent via the cookie banner. Your decision in the banner — including “Only essential” — is remembered permanently until you change it on the Privacy Choices page or clear your browser data. We also honour the Global Privacy Control signal.
Advertising & Retargeting (Pixels/Tags)
We do not use advertising or retargeting pixels. No advertising network's tag, pixel or script runs on this website. We do not build advertising profiles about you and we do not share your data with advertising networks for ad targeting.
Affiliate and Campaign Attribution
If you reach our website through an affiliate link or an advertising campaign, that link carries identifiers in the web address (for example a campaign name or a click ID). We store these identifiers on your device so we can later tell which partner referred you.
- Data processed: the campaign and click identifiers contained in the link you followed, the website that referred you, the page you arrived on, your operating system category, and — if you make a purchase — the fact and value of that purchase.
- Purpose: attributing a purchase to the partner who referred you so that partner can be paid their commission, and measuring which campaigns work.
- Recipients: the affiliate network or partner that referred you. When you make a purchase, our server sends that partner the click ID from your link together with the commission amount. No content of your chats, no email address and no other account data is sent.
- Legal basis: your consent (Art. 6(1)(a) GDPR) for storing and reading these identifiers on your device, and our legitimate interest in paying our partners correctly and measuring our marketing (Art. 6(1)(f) GDPR).
- Retention: the identifiers stay in your browser's local storage until you clear your browser data; a click ID transmitted with a purchase is retained with the purchase record.
- Transfers: some of these partners are established outside the EEA, in which case the data may be processed outside the EEA.
Voice Input (Speech Recognition)
In the video chat you can optionally speak to a character instead of typing. This feature is off by default, is only ever started by you pressing the microphone button, and is only asked for after you have explicitly agreed to it.
Speech recognition is not performed by us and not on your device. It is performed by your web browser: in Google Chrome by Google LLC, in Apple Safari by Apple Inc. When voice input is switched on, your browser transmits the recorded microphone audio to that provider, which returns the recognised text. This connection is established by your browser, not by our servers. We therefore have no control over it and cannot enter into a data processing agreement covering it, which is why we ask for your explicit consent before it starts.
- Data processed: the audio recorded by your microphone while voice input is switched on, and the text recognised from it.
- Purpose: converting what you say into a chat message so you can talk to a character instead of typing.
- Legal basis: your explicit consent (Art. 6(1)(a) and, where the content concerns your sex life or sexual orientation, Art. 9(2)(a) GDPR). You give it in a separate dialogue before the first use.
- Recipients: Google LLC (Chrome) or Apple Inc. (Safari), depending on the browser you use. See the privacy policy of the respective provider for how they handle the audio.
- Transfers: the audio may be processed outside the EEA, in particular in the USA.
- What we receive and store: only the recognised text. It is sent as a chat message and stored with your conversation exactly like a message you typed. We do not receive, store or record the audio itself.
- Duration: the microphone is only open while voice input is switched on. It switches itself off automatically after about two minutes without detected speech, and you can switch it off at any time with the microphone button.
- Withdrawal: you can withdraw your consent at any time and with future effect on our Privacy Choices page. Withdrawal does not affect the lawfulness of processing carried out before it.
Please make sure that no other people can be heard by your microphone without their knowledge while voice input is switched on.
Web Analytics (Google Analytics)
With your consent (Art. 6(1)(a) GDPR), we use Google Analytics, a web analytics service provided by Google, to understand how the website is used and to improve it. Google Analytics uses cookies and similar identifiers; the information generated about your use of the website (including your IP address) is transmitted to and stored by Google, including on servers in the USA. For logged-in users a pseudonymous user reference is included so that usage can be measured across devices. Analytics never receives the content of your conversations.
Analytics only starts after you accept it in the cookie banner. You can withdraw your consent at any time on the Privacy Choices page, via the Google Analytics opt-out browser add-on, or by enabling Global Privacy Control. For more information see Google's Privacy Policy.
Disclosure of Information
Beyond the processors named in this policy, we disclose personal information only:
- As required by law, such as to comply with a subpoena, or similar legal process.
- When we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
- To any other third party with your prior consent to do so.
- With the affiliate partner who referred you, limited to the click ID from your referral link and the commission amount, as described under “Affiliate and Campaign Attribution”.
We do not sell personal data.
International Transfers
Some of the providers named in this policy are established in the USA or process data there (in particular Together AI, DeepInfra, OpenAI, ElevenLabs, Postmark, CCBill and Google). Where personal data is transferred outside the EEA, we rely on an adequacy decision of the European Commission — for US providers certified under the EU-US Data Privacy Framework — or on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
Data Security
All connections to our service are encrypted (TLS). Access to stored data is restricted to what operating the service requires. No transfer of your personal data takes place to an organization or a country unless there are adequate controls in place including the security of your data.
How Long We Keep Your Data (Overview)
- Chat sessions: deleted twelve months after the last message of the session.
- Server request logs: deleted after 30 days.
- Account data: until you delete your account.
- Financial transaction records: statutory commercial and tax retention periods (in Germany up to ten years).
- Safety records: for the duration required to establish, exercise or defend legal claims — as a rule the statutory limitation periods.
- Consent records: for as long as we must be able to demonstrate your consent.
Deleting Your Account
You can delete your account at any time in your account settings. Deletion removes your account record including your profile, subscription state and conversation access. What remains are only the records we are legally required or entitled to keep: financial transaction records (statutory retention periods) and safety records (defense of legal claims), as described above. Chat sessions that were never linked to your account are deleted automatically twelve months after their last activity.
Your Rights
You have the right to:
- Request access to your personal data (Art. 15 GDPR).
- Request correction of the personal data that we hold about you (Art. 16 GDPR).
- Request erasure of your personal data (Art. 17 GDPR).
- Request the restriction of processing of your personal data (Art. 18 GDPR).
- Request the transfer of your personal data to another party (Art. 20 GDPR).
- Object to processing based on our legitimate interests (Art. 21 GDPR).
- Withdraw any consent you have given, at any time and with effect for the future (Art. 7(3) GDPR) — for analytics and voice input directly on the Privacy Choices page.
- Lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence, your place of work or the place of the alleged infringement (Art. 77 GDPR).
To exercise these rights, contact us at the email address in the contact section. Note that for anonymous chat sessions we can only act if you provide the session identifier from your browser, because we cannot attribute such sessions to a person ourselves (Art. 11 GDPR).
Automated Decision-Making
We do not make automated decisions about you that have legal effects or similarly significantly affect you (Art. 22 GDPR). The automated content moderation described above only filters prohibited content out of conversations.
Minors
This service is exclusively for adults (18+). We do not knowingly process data of minors; if we become aware of such data, we delete it.
Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
Reporting Illegal Content
To report illegal content, request removal of content depicting you, or file a complaint, please see our Complaints & Illegal Content Reporting page.
Contact Us
If you have any questions about this Privacy Policy, or wish to exercise your data protection rights, please contact us:
Jay Web Development & Services
Daxerstraße, 82140 Olching, Germany
Email: info [at] xeve.ai
Frequently asked questions about this Privacy Policy
Where is my data stored?
The service and its data run on Google Cloud in the EU (region europe-west1, Belgium). Images and videos, including media you generate, are stored and delivered via the content delivery network bunny.net (EU). Some of the providers named in the policy, such as the AI inference providers and Google, process data in the USA under an adequacy decision or the EU Standard Contractual Clauses.
What is the retention period for chat sessions?
Every chat session is deleted automatically twelve months after its last message; active conversations are never affected, because the twelve months count from the last activity. Server request logs are deleted after 30 days, and account data is kept until you delete your account.
Who can see my conversations?
Your conversations are processed only to run the service: they are not sold, not used for advertising and not used by us to train AI models. The AI providers that generate replies receive the recent part of the conversation and the character description, but not your email address or any account identifier. Every conversation is additionally checked by an automated moderation model to block prohibited content.
Which providers process my data?
Character replies are generated by Together AI and DeepInfra, voice replies by ElevenLabs, and images and videos by AtlasCloud; a small random sample of conversations without any account data is rated for quality by an OpenAI model. Login runs on Firebase Authentication, payments on CCBill or CentroBill, emails through Postmark, and media are delivered by bunny.net. The policy above lists each provider with its legal basis.
How do I exercise my GDPR rights?
You can request access, correction, erasure, restriction or transfer of your personal data, object to processing based on our legitimate interests, and withdraw any consent at any time with effect for the future. Contact us at the email address on the contact page; consent for analytics and voice input can be withdrawn directly on the Privacy Choices page. You may also lodge a complaint with a data protection supervisory authority.
For the connected reference view, see Safety, privacy, age rules, and moderation and Company, trust, and legal overview.