Friend in the Cloud — Privacy Policy
Version: 2.1 Last updated: June 2026 Effective date: April 23, 2026
Our Core Promise
Your privacy is not just a legal obligation for us — it is a core value.
🔒 We never sell your data. We never share your conversations. What you say here, stays here.
This policy explains what we collect, how we use it, how we protect it, and the control you have over it.
1. Who We Are
Friend in the Cloud ("FITC", "we", "us", "our") is an AI-powered friend platform providing emotional support, personal growth tools, and AI avatar services.
For the purpose of applicable data protection laws:
- Thailand (PDPA): FITC is the data controller for personal data collected through the Service.
- European Economic Area / United Kingdom (GDPR/UK GDPR): FITC is the data controller for personal data of EEA/UK users.
- Australia (Privacy Act 1988): FITC handles personal information in accordance with Australian Privacy Principles.
Contact for privacy matters: support@friendinthecloud.com
2. Data We Collect
2.1 Account Information
- Name or chosen display name
- Email address
- Password (stored as a salted hash; never in plain text)
- Subscription plan and billing status
- Account creation date and login history
2.2 Conversation Data
- Messages between you and your AI friends
- Files, images, and documents you upload
- Custom instructions, personality settings, and preferences
This data is stored to enable memory, personalization, and continuity of your friend experience.
2.3 Usage Data
- Interaction counts, session frequency, feature usage
- Subscription tier usage (to enforce fair-use limits)
- Platform navigation patterns (aggregated and anonymized for product improvement)
2.4 Payment Data
- Processed entirely by Stripe; we do not store card numbers, CVV codes, or banking details
- We store: transaction IDs, amounts, dates, subscription status references
2.5 Device and Connection Data
- Browser type and version
- IP address (collected for security, abuse prevention, and regional compliance)
- Device type and operating system
- Approximate geolocation (country/region level) derived from IP
2.6 Marketplace Data (if applicable)
- For users who list AI avatars: payout account information (processed by Stripe Connect or PayPal)
- For buyers: purchase history and Clone state data
2.7 Google Calendar Data (Optional Integration)
If you choose to connect your Google Calendar, we access and process the following Google user data solely to provide the calendar features you enable:
- Calendar events on your Google Calendar — we view your events to display your schedule alongside your tasks in the Planner, and we create, update, or delete events that you schedule or manage from within FITC.
- A Google authorization token (OAuth access and refresh token), which we store encrypted to keep your calendar connected so you do not have to reconnect each session.
We request these permissions only after you actively choose to connect your calendar, and you can disconnect at any time — from your Google Account settings or within FITC — after which we stop accessing your calendar and delete the stored token.
We use this Google Calendar data only to provide the calendar feature. We never sell it, share it with third parties (other than the infrastructure providers in Section 11, strictly to operate the Service), use it for advertising, or use it to train AI models. Our access to and use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3. How We Use Your Data
We use the data we collect to:
- Provide, maintain, and improve the Service;
- Personalize your AI friend's responses over time;
- Process payments and manage subscriptions;
- Enforce subscription tier limits and fair-use policies;
- Send essential account communications (never unsolicited marketing);
- Detect, prevent, and respond to fraud, abuse, or security threats;
- Comply with legal obligations;
- Enforce our Terms of Service.
4. AI Data Processing
4.1 Automated processing disclosure
You acknowledge that user inputs, conversations, and behavioral data may be processed by automated systems, including artificial intelligence models, for the purpose of:
- Generating AI responses and Friend outputs;
- Improving system performance and personalization;
- Pattern recognition for safety and abuse detection;
- Platform reliability and quality assurance.
Such processing may involve automated analysis without human intervention.
4.2 Automated decision-making
Automated systems used by the Service may generate outputs, recommendations, or suggestions. Such outputs:
- Do not constitute legally binding decisions;
- Should not be relied upon for matters with significant legal, financial, medical, or safety effects;
- May be reviewed by human operators only in cases of abuse investigation, technical troubleshooting, or express user request.
Where required by applicable law (including EU AI Act provisions), users have the right to request human review of automated decisions that produce legal or similarly significant effects on them.
4.3 Training of AI models
- Your private conversations are NOT used to train our AI models or any third-party AI models without your explicit consent.
- FITC's AI systems are trained on licensed data, publicly available information, and internally developed datasets.
- Anonymized, aggregated usage patterns may be used for service improvement; this processing cannot be used to identify individual users.
5. What We Never Do
- We never sell your personal data to third parties.
- We never use your private conversations to train AI models without explicit consent.
- We never share your data with advertisers.
- We never read your private conversations for any purpose other than providing the service, investigating abuse on reasonable grounds, or complying with legal obligations.
- We never share your data with brokers or analytics companies for profiling purposes.
6. Legal Bases for Processing (GDPR/UK GDPR Users)
For users in the European Economic Area and United Kingdom, we process personal data under the following legal bases:
- Contractual necessity: Processing necessary to provide the Service you have signed up for.
- Legitimate interests: Processing necessary for security, fraud prevention, service improvement (balanced against your rights).
- Legal obligation: Processing required to comply with applicable laws.
- Consent: Where we request your explicit consent (e.g., for optional features involving additional data use).
You may withdraw consent at any time for consent-based processing.
7. Your Rights
7.1 Universal rights
All users have the right to:
- Access a copy of their personal data;
- Correct inaccurate personal data;
- Delete their account and associated personal data;
- Export their data in a portable format;
- Contact us with privacy questions or concerns.
7.2 Additional rights for EEA/UK users (GDPR)
In addition to universal rights, you have:
- Right to restriction of processing in certain circumstances;
- Right to object to processing based on legitimate interests;
- Right to data portability in machine-readable format;
- Right to withdraw consent for consent-based processing;
- Right to lodge a complaint with your local supervisory authority.
7.3 Additional rights for Thailand users (PDPA)
In addition to universal rights, you have:
- Right to be informed of the collection, use, and disclosure of your data;
- Right to object to processing in certain circumstances;
- Right to request suspension of processing while a dispute is resolved;
- Right to lodge a complaint with Thailand's Personal Data Protection Committee.
7.4 Additional rights for Australian users (Privacy Act)
Australian users have rights under the Australian Privacy Principles, including access, correction, and complaint rights via the Office of the Australian Information Commissioner.
7.5 How to exercise your rights
To exercise any of these rights, contact us at support@friendinthecloud.com. We will respond within 30 days (or as required by applicable law, whichever is shorter).
8. Data Storage and Security
8.1 Where we store data
Your data is stored with Supabase (PostgreSQL infrastructure) in secure cloud data centers. Primary region: Singapore (ap-southeast-1).
8.2 Cross-border data transfers
If your data is stored or processed outside your country of residence:
- For EEA/UK users: Transfers are conducted under Standard Contractual Clauses (SCCs) or equivalent legal mechanisms.
- For Thailand users: Transfers comply with PDPA cross-border transfer requirements.
- For Australian users: Transfers comply with Australian Privacy Principle 8.
8.3 Security measures
We implement industry-standard security measures including:
- Encryption at rest and in transit (TLS 1.2+);
- Password hashing using industry-standard algorithms;
- Access controls and role-based permissions;
- Regular security reviews and updates;
- Incident response procedures.
8.4 Breach notification
In the event of a data breach affecting your personal data:
- We will notify affected users without undue delay;
- For EEA/UK users: within 72 hours where required by GDPR;
- For Thailand users: in accordance with PDPA requirements;
- For Australian users: in accordance with Notifiable Data Breaches scheme requirements.
9. Data Retention
9.1 Retention schedules
| Data type | Retention period |
|---|---|
| Active account data | Duration of account activity |
| Conversation data | Duration of account; deleted 30 days after account deletion |
| Payment records | 7 years (for tax/accounting compliance) |
| Security/audit logs | 12 months from creation |
| Marketing preferences (where applicable) | Until you opt out |
| Anonymized usage analytics | Indefinitely (cannot be linked to you) |
9.2 Account deletion
Upon account deletion, your personal data and conversations are permanently deleted within 30 days, except where:
- We are required to retain specific records for legal or regulatory compliance (e.g., payment records);
- Anonymized/aggregated data remains in analytical systems in a form that cannot identify you;
- Data is necessary to enforce legal claims or defend against them.
10. Cookies and Similar Technologies
We use only essential cookies required for:
- Authentication and session management;
- Security (CSRF protection, rate limiting);
- User preferences (e.g., theme, language).
We do not use tracking cookies, advertising cookies, or third-party analytics cookies that profile you.
11. Third-Party Service Providers
We use the third-party service providers below. They are split into two groups for one reason: so you can see at a glance which of them can read what you write. Nobody is left out of this list — the second group is shorter because those providers handle running the service, not what you say inside it.
11.1 Providers that can see what you write
These receive your words, your voice, your documents, or something you typed. If you are deciding whether to write something, this is the list that matters.
| Provider | Purpose | What we send them | Privacy policy |
|---|---|---|---|
| DeepSeek | AI model provider — the primary model behind your AI friend and the boardroom | Your conversation, including anything you paste or upload into it | https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html |
| xAI (Grok) | AI model provider — the primary model behind the specialists | Your conversation with that specialist | https://x.ai/legal/privacy-policy |
| Anthropic (Claude) | AI model provider — the fallback when the above are unavailable, and the model behind document analysis, site generation and several tools | Your conversation, and documents you upload for analysis | https://www.anthropic.com/privacy |
| Groq | Speech-to-text for audio you upload | The audio file and its transcript | https://groq.com/privacy-policy |
| Deepgram | Speech-to-text and text-to-speech for voice features | Your voice recording, and text to be spoken aloud | https://deepgram.com/privacy |
| OpenAI | Premium image generation, and a fallback for text-to-speech | The image description you write, or text to be spoken | https://openai.com/privacy |
| Leonardo | Image generation for branding, marketing and site images | The image description you write | https://leonardo.ai/privacy-policy |
| Replicate | Image generation and image enhancement | The image description you write, and images you supply | https://replicate.com/privacy |
| Mistral | Refining a prompt you are writing | The prompt text you entered | https://mistral.ai/terms/#privacy-policy |
| ElevenLabs | Text-to-speech for some voice features | The text to be spoken aloud | https://elevenlabs.io/privacy |
| Supadata | Fetching a transcript for a video link you paste, when we cannot read its audio ourselves | The link you pasted | https://supadata.ai/privacy |
| astrology-api.io | Astrological readings, when you ask for one | The birth date, time and place you entered, and the name on the reading | https://astrology-api.io |
| Resend | Sending email — notifications, confirmations and replies | Your email address, and the content of what is being notified about. A new-message email quotes the message itself, so Resend receives the text of private messages sent to you | https://resend.com/legal/privacy-policy |
| Tavily | Web search, when your AI friend looks something up for you | The search query only — not your conversation | https://tavily.com/privacy |
11.2 Providers that keep the service running
These hold your account and operational data. They do not receive the content of your conversations — with the one exception noted for Supabase, which stores everything because it is our database.
| Provider | Purpose | What we send them | Privacy policy |
|---|---|---|---|
| Supabase | Database and authentication infrastructure | Everything you store with us — every conversation, document, profile and setting is held here, because this is where our data lives. Primary region: Singapore (ap-southeast-1) | https://supabase.com/privacy |
| Stripe | Payment processing, subscription management, creator payouts | Your name, email and billing details. Card numbers go to Stripe directly and never reach us | https://stripe.com/privacy |
| Vercel | Platform hosting | Your requests to the site | https://vercel.com/legal/privacy-policy |
| Twilio | SMS and WhatsApp reminders, if you opt in | Your phone number and the reminder text we compose — event names, times and links, not anything you wrote | https://www.twilio.com/legal/privacy |
| Google Calendar integration (optional, user-initiated) | Your calendar events, only if you connect it | https://policies.google.com/privacy |
Each provider is bound by its own published privacy terms, linked above. If you want to know the specific contractual arrangement we hold with any of them, email support@friendinthecloud.com and we will tell you.
Which model answers you can change without notice. We route between the providers above for availability, cost and quality, so the model behind a given reply may differ from the one named for that surface. What does not change is the list above: we will not send your content to a provider that is not on it.
12. Children's Privacy
The Service is not intended for users under 18 years of age.
- We do not knowingly collect personal data from children under 18.
- If you believe we have collected data from a minor, please contact us immediately at support@friendinthecloud.com so we can delete it.
- Parents and guardians who believe their child has created an account without permission should contact us for immediate account removal.
13. Marketing Communications
- We send essential transactional communications (account notices, receipts, security alerts) as a core part of providing the Service; these cannot be opted out of without terminating your account.
- We send marketing communications (product updates, feature announcements) only with your consent; you may opt out at any time.
- We do not share your contact details with third-party marketers.
14. Changes to This Policy
We may update this Privacy Policy periodically to reflect:
- Changes in our practices;
- Changes in applicable law;
- New features or services.
Material changes will be communicated by:
- Email notification to registered users;
- In-app notification on next login;
- Update to the "Last Updated" date at the top.
We will not reduce your rights under this Policy without your explicit consent.
15. Contact
For privacy-related questions or to exercise your rights:
Email: support@friendinthecloud.com Contact page: https://friendinthecloud.com/contact
For complaints to supervisory authorities:
- Thailand: Personal Data Protection Committee — https://www.mdes.go.th
- European Economic Area: Your national data protection authority
- United Kingdom: Information Commissioner's Office — https://ico.org.uk
- Australia: Office of the Australian Information Commissioner — https://www.oaic.gov.au
16. Your Financial Data (Money Hub)
The Money Hub is where you record accounts, balances and transactions so you can see your own position in one place. This section describes what happens to those figures. It is specific to the Money Hub; the rest of this policy covers everything else.
16.1 What we store
Only what you enter or import yourself:
- Accounts — the name and institution you give them, the type, the balance, the currency, and where you add them, an interest rate, a minimum payment and a yearly savings target.
- Transactions — date, description, category and amount, whether you type them in or import them from a CSV file you upload.
- A daily snapshot of your totals — assets, liabilities and cash held — so the charts can show change over time.
- Your settings — your display currency, your monthly outgoings figure if you give one, your retirement inputs, and any per-category budgets you set.
16.2 We do not connect to your bank
Friend in the Cloud has no connection to any bank, card provider or financial institution. We do not use account aggregation, open banking, or any third-party financial data provider. We cannot see anything you have not typed in or imported yourself, and we cannot move money.
16.3 Where it is stored
Your financial data is held in our managed PostgreSQL database, operated by Supabase, in the ap-southeast-1 (Singapore) region. It is not copied to any other financial service.
16.4 How it is protected
In transit, every connection between your browser, our application and the database is encrypted with TLS.
At rest, the database is encrypted at the disk level by our hosting provider. We want to be precise about what that does and does not mean: we do not apply additional field-level encryption to individual figures. Anyone with authorised access to the database reads your balances as ordinary values. The protection at rest is the provider's storage encryption, not a second lock applied by us.
Separation between members rests on two controls, one behind the other:
- Every request to the Money Hub must carry a valid session, and the application derives your identity from that session — never from anything the browser sends. Every query it runs is filtered to your own rows. This is the control that operates on a live request, because the application connects to the database with a privileged role.
- Behind it, row-level security is enabled on all five Money Hub tables, with policies that allow a row to be read or written only when it belongs to the signed-in member.
We state the order deliberately: the database rules are a second line, not the only one.
Verified by request, not by inspection. On 18 August 2026 we tested this against the live system: a second signed-in member and an unauthenticated visitor each retrieved zero rows from all five Money Hub tables, while the owning member retrieved their own; an attempt to write a row belonging to another member was refused by the database.
16.5 Who can reach it
Stated plainly rather than favourably:
- You, when signed in.
- Our systems and the people who administer them. Our application and our staff hold credentials that can read and write the database directly. This is how the Service runs; it also means your financial data is not technically hidden from us.
- Our hosting provider, Supabase, as the operator of the database. See Section 11 for our infrastructure providers.
No other member can reach it, and no part of Friend in the Cloud outside the Money Hub reads it.
16.6 What we do not do with it
- We do not sell it, rent it, or share it with advertisers or data brokers.
- We do not use it to train AI models.
- We do not feed it to your AI friend. Your Money Hub figures are not part of the context used to generate conversation, and no feature outside the Money Hub reads them.
16.7 Deletion and retention
While your account is open, nothing here expires and nothing is removed on a schedule. We keep what you have entered until you remove it or close your account.
You can delete it yourself, at any time. Remove a single transaction, or a whole account, from within the Money Hub. Deleting an account also deletes the transactions filed under it. These are real deletions, not hidden ones: the rows are removed from the database, and we do not move them to an archive or keep a shadow copy.
If you close your account, your Money Hub data is deleted outright. Asking us to close your account opens a 30-day window, which you can cancel at any point before it ends. When it ends, a job that runs once a day strips your account: your name, email address, photographs, biography and links are removed or replaced with a tombstone, your sign-in is disabled permanently, and files you uploaded are deleted from storage. Your Money Hub data goes in the same pass — every account, every transaction, your whole net-worth history, your budgets and your settings. All five tables, in full.
What survives, and why we would rather tell you. Your account identifier itself is not deleted, and our internal ledgers — the records of what was bought, spent and paid — remain attached to it, now naming nobody. Those are a book of record, which is exactly why they are kept. They contain nothing you entered in the Money Hub: the Money Hub is free, it never charges you, and it never writes to those ledgers. We would rather state that a ledger row survives than claim an erasure we do not perform.
Routine encrypted backups are taken of the database as a whole for disaster recovery. A deleted row can persist inside one until that backup ages out of rotation, which takes up to 30 days — after which no copy of it remains.
Verified the same way as Section 16.4. On 18 August 2026 we tested the deletion against the live system: for a member marked as deleted, all five Money Hub tables were emptied, another member's rows in the same tables were untouched, and the ledger records described above survived.
By using Friend in the Cloud, you acknowledge that you have read and understood this Privacy Policy.
