Privacy Policy
Sirena (“Sirena,” “we,” “us”) is operated by the Sirena team (Hanoi, Vietnam). This policy explains what we collect when you use the Sirena mobile app (the “App”), why, and the choices you have. By using the App you agree to this policy. If you do not agree, do not use the App.
1. What Sirena is
Sirena lets you chat with AI characters. The characters are software, not real people. Your conversations are processed by AI model providers to generate replies and to screen content for safety (see §4). Sirena is an entertainment product and is not a source of medical, legal, financial, or mental-health advice.
2. Information we collect
We collect only what the App needs to function. We do not collect location, health, contacts, calendar, microphone audio, or browsing history outside the App.
| Category | Examples | Linked to you? | Used to track you across apps? |
|---|---|---|---|
| Account info | Email address; display name | Yes | No |
| Identifiers | Sirena user ID (Firebase UID) | Yes | No |
| Advertising identifier | Apple IDFA (iOS) or Google Advertising ID / AAID (Android), only if you allow personalized ads | No | Yes |
| Your content | Messages you send and AI replies; characters you create; support emails | Yes | No |
| Purchases | Subscription / credit-pack transaction records (no card numbers) | Yes | No |
| Usage data | In-app events (screens viewed, features used) | Yes | No |
| Advertising data | Ad impressions / clicks (free tier only) | No | Yes |
| Diagnostics | Crash logs | Yes | No |
We do not collect or store your payment card details — payments are processed by Apple (App Store) or Google (Google Play), depending on where you installed the App.
3. How we use your information
- Provide the service — authenticate you, store your chats, generate AI replies, enforce your subscription / credit balance.
- Safety & moderation — screen messages and AI output for prohibited content (§4), handle reports, and act on policy violations.
- Improve the App — understand which features are used (analytics) and fix crashes.
- Advertising — show ads to free-tier users. Personalized ads are shown only if you consent (§6).
- Support & legal — respond to you and comply with law.
We do not sell your personal data. We do not use the content of your chats to target ads.
4. AI processing of your content
To generate replies and keep the App safe, the text of your messages and the resulting AI output is sent to our AI infrastructure providers — together with your recent conversation history, conversation summaries and “memory” snippets derived from your chats, and the descriptions of the characters involved (including characters and avatar descriptions you write). Your display name may appear in this content. We do not send your email address, account ID, date of birth, or device identifiers to these providers.
The App shows you this disclosure and asks for your permission before any of your content is shared with these providers, and records which version of the disclosure you accepted and when. You can re-read it at any time in Settings → Privacy → AI & your data.
The providers:
- Generating replies — Google (Gemini) is the primary model; DeepSeek and OpenAI are used as fallbacks when it is unavailable.
- Safety classification — Google (Gemini) classifies your messages and the AI’s replies before they are shown.
- Memory — message text is turned into numeric embeddings by OpenAI so a character can recall earlier parts of your conversation.
- Character avatars — if you generate an avatar image, the description you provide is sent to Google (Gemini).
These providers process the content to return a response, an image, or a safety classification. We instruct providers not to use this content to train their models where such an option is offered; you should review their terms as well.
5. Who we share data with (sub-processors)
| Provider | Purpose | Data involved |
|---|---|---|
| Google (Firebase) | Auth, database, functions, crash reporting, analytics, push, app-integrity | Account info, identifiers, your content, usage, diagnostics |
| Google (Gemini) | Generate AI replies, content moderation, avatar image generation | Message + reply text, avatar prompts |
| DeepSeek | Generate AI replies (fallback provider) | Message + reply text |
| OpenAI | Generate AI replies (fallback provider); memory embeddings | Message + reply text |
Wasabi Technologies (US, us-central-1) | Object storage for generated avatar images and data-export files | Images you upload or generate, export files (which contain your account data) |
| Cloudflare | CDN in front of the image storage above | Image requests and the technical data they carry (e.g. IP address) |
| RevenueCat | Manage subscriptions / purchases | User ID, purchase records |
| Google AdMob | Show ads (free tier) | Advertising data, advertising identifier (post-consent) |
| Apple | App Store payments, Sign in with Apple, app integrity (App Attest) | Purchase, account identifiers |
| Google (Play) | Google Play payments, Google sign-in, app integrity (Play Integrity) | Purchase, account identifiers |
We may also disclose information to comply with law, enforce our Terms, or protect the safety of users (for example, escalating suspected child-safety violations to the appropriate authorities / NCMEC).
6. Advertising & tracking choices
- Free-tier users may see ads via Google AdMob. Paid (Pro) users see no ads.
- Wherever consent is legally required (e.g. the EEA/UK), we ask for it through Google’s User Messaging Platform consent form on both iOS and Android, before any personalized ad is requested. If you decline, ads are non-personalized.
- On iOS we additionally request permission via Apple’s App Tracking Transparency prompt, shown once at first launch, right after the intro screens. If you decline, we do not use your IDFA.
- You can change your mind at any time:
- In the App — Settings → Privacy → Privacy options re-opens the Google consent form (shown where a persistent consent entry point is required).
- iOS — Settings → Privacy & Security → Tracking.
- Android — Settings → Google → All services → Ads, where you can reset or delete your advertising ID.
7. Data retention
- Chats are kept until you delete them or delete your account.
- Account deletion: deleting your account in Settings → Account → Delete Account deactivates it immediately and permanently removes your data after a 30-day grace window. See Delete your account & data for the full list of what is deleted, what is kept, and how to request deletion if you have already uninstalled the App.
- Crash logs are retained ~90 days (Firebase default).
- We keep purchase records as required for tax / accounting / support.
8. Your rights & choices
Depending on where you live (e.g., EEA/UK GDPR, California CCPA/CPRA), you may have rights to access, correct, delete, or port your data, and to object to certain processing. You can access or edit your profile in the App, delete your account and data in Settings → Account → Delete Account, opt out of analytics and ad personalization in Settings → Privacy, or contact us at privacy@sirenastories.com to exercise any right. We will not discriminate against you for exercising your rights.
9. Children
Sirena is not directed to children and is not intended for anyone under 18. You must be at least 18 years old to use the App (see Terms). We apply an age gate at sign-up and remove accounts we learn belong to under-age users. If you believe a child has provided us data, contact privacy@sirenastories.com.
10. Security
We use industry-standard measures (encryption in transit, app attestation, access controls). No method is 100% secure, but we work to protect your information.
11. International transfers
We operate globally; your data may be processed in countries other than yours, including the United States. Where required, we rely on appropriate safeguards.
12. Changes to this policy
We may update this policy. Material changes will be notified in-app or by other means. Continued use after changes means you accept the updated policy.
13. Contact
Sirena Privacy Team — privacy@sirenastories.com — Hanoi, Vietnam