How we protect your coordination data and privacy
This policy explains what Samsarix collects, why it is used, when it may be shared, and the controls available to you. It applies to Samsarix AI, Samsarix Social, and the shared account and service providers used by Samsarix Realms. The Realms product notice describes Realms-specific processing.
Samsarix uses encrypted HTTPS connections for data sent between supported clients and the service.
Authentication and access controls restrict account and administrative data to authorized access paths.
Samsarix records operational and security events needed to detect failures, misuse, and unauthorized access attempts.
Privacy settings let you control optional analytics, marketing, model improvement, and connected-service data sharing.
To provide AI features, Samsarix sends only the prompt, media, and bounded conversation or character context needed for the requested feature to a selected provider. Not every provider receives every request. Selection depends on the feature, the Mind you choose, provider availability, account access, and server configuration.
Do not submit information you do not want processed for the requested AI feature.
When you attach a photo to a Samsarix Social character chat, the raw image is validated, safety-screened, and sent to an AI provider to create a short scene description. Samsarix does not save the raw chat photo after that analysis. The derived description and a marker that a photo was shared are retained with the conversation so the character can preserve context; they are removed through the same conversation, character, and account deletion paths.
Samsarix Social distributed through Google Play uses the server-owned play_conservativeprofile. It permits safe and mature non-explicit storytelling, but does not permit explicit sexual output. A character's visibility, Safe Search state, age confirmation, subscription, request value, or app setting cannot weaken that Play boundary.
A separate full_private profile may be activated only for an independently isolated, non-Play distribution. If offered, its additional private tier is limited to the authoritative current owner of a mature-flagged private or unlisted character after separate server-side adult-eligibility checks. Social Plus provides capacity and general product features; it is not proof of age and is not sold as an explicit-content benefit. Global rules prohibiting child sexual exploitation, sexual violence or exploitation, and other serious abuse apply in every profile.
Depending on the feature you use, operational processing may also involve Google for sign-in, Play Billing, Play Age Signals, and Firebase Cloud Messaging; Expo for app updates and push delivery; Backblaze B2 for retained media; Oracle Cloud for API hosting; Resend or SendGrid for transactional email; Discord for the operator's moderation-alert channel; and Sentry for optional crash diagnostics.
Push delivery sends the device push token and notification payload to Expo and the underlying platform push service. A safety report's identifiers, category, and any detail you choose to add may be forwarded to the operator's restricted moderation channel. Payment and identity providers process their own transaction or sign-in records under their published terms.
On supported Android installations, the service may receive a limited Play Age Signals result. It is used only to apply age-appropriate access, safety, and legal requirements. It is not used for advertising, marketing, profiling, personalization, analytics, or business intelligence, and is not shared with third parties except when required by law.
The current Samsarix Social Google Play release does not include or initialize a third-party advertising SDK and does not serve ads. We do not use prompts, messages, generated replies, memories, character traits, private or unlisted content, voice transcripts, Play Age Signals, moderation events, or safety reports for advertising or ad personalization. Before any future ad-supported release collects or shares advertising data, we will update this notice, provide applicable privacy choices, and update the Google Play declarations.
Product analytics and crash diagnostics are optional, disabled for new accounts, and controlled in Privacy settings. When enabled, Samsarix stores minimized, account-linked first-party product events so they can be included in an account export or removed with the account. Those events use allowlisted categories and bounded measurements; they exclude prompts, replies, authored text, error text, purchase tokens, and character, adventure, scene, post, and message identifiers. Optional crash reports are sent directly to Sentry after removing personal and request context; screenshots, view hierarchy, sessions, native crash capture, and performance tracing are disabled. On public web pages, Google Analytics and first-party Web Vitals delivery remain off until you choose Accept All in the cookie banner. You can change that choice through Cookie preferences in the site footer; choosing Essential Only stops future analytics delivery and removes accessible Google Analytics cookies. Collection is disabled when the relevant preference is off.
We do not sell your personal information. We may share data only in these circumstances:
Account and user-created content is generally retained while the account or feature remains active. Deletion removes or de-identifies account data through the published deletion process, subject to limited retention needed for security, fraud prevention, legal obligations, dispute resolution, backups, and enforcing safety actions.
An unconverted guest trial and its character-chat content are scheduled for automatic deletion 30 days after the trial is created. Converting the guest before then preserves the conversation and moves it under the normal account retention terms. Limited security, fraud-prevention, legal, and backup records may follow separate retention periods.
Operational logs, reports, purchase records, and consent records are retained only for as long as needed for their stated purpose and applicable legal requirements. Exact periods may differ by data category and service provider.
If you enable optional product analytics, the analytics-retention choice in Privacy settings applies to those first-party events. Finite 30-day, 90-day, and 1-year choices are enforced by automatic cleanup; Forever keeps them until account deletion. This choice does not automatically delete conversations or other account content.
Raw photos attached directly to character-chat messages are processed in memory and are not retained by Samsarix after analysis. A short-lived, account-bound analysis token expires after 15 minutes; only the derived description and photo marker remain with the conversation.
Voice-input recordings are sent to the selected speech-recognition provider. The Samsarix transcription route processes the recording in memory and does not intentionally retain the raw audio; a transcript is retained only if you use or send it as content. Provider processing and retention are governed by the applicable provider terms. Generated character-voice audio may be retained in media storage and a short-lived delivery cache so it can be played back.
Unsent character-chat drafts and per-chat appearance choices are kept in the device's protected local storage, scoped to the signed-in account, and are not transmitted as chat content until you send them. Drafts remain locally until they are sent, cleared, or the app's protected storage is reset.
Depending on your location and applicable law, you may be able to:
Request a copy of all personal information we have about you.
Update or correct any inaccurate personal information.
Permanently delete your account in the app or submit a deletion request.
Export your coordination data in a portable format.
Depending on applicable law, you may also withdraw consent, object to or restrict certain processing, and complain to your local data-protection regulator. These rights may be limited by lawful exceptions.
To exercise these rights, email contact@samsarix.com or use the public account-deletion instructions.
If you have any questions about this Privacy Policy or our data practices, please contact us:
Email: contact@samsarix.com
You can also use the contact page for general support.
We may update this Privacy Policy from time to time. We will notify you of any material changes through an appropriate account, product, or service notice. The date at the top of this page identifies the current published version.