Atween Privacy Policy (Overseas)

Last updated: 10 July 2026 (overseas draft)

Effective date: upon formal release

Version: v0.1-overseas-review-draft

Not submittable yet. This is the overseas review draft. Before release we must freeze the legal entity, registered address, EU/UK representative (Art. 27 GDPR), data-protection contact, sub-processor list, retention schedule, international-transfer safeguards, and obtain legal review. Core product invariants are identical to the domestic version; only the legal details are adapted to overseas law.

Atween protects intimate records, voice, images, relationship material, crisis signals and AI-derived understanding with the principles of data minimisation, layered protection, user sovereignty, controlled AI reading, deletion & export rights, and separate consent for training.

By default your sensitive interaction data is not used to train models. AI reads only the minimum material needed for the current purpose, still authorised and not deleted, through controlled boundaries (AI Gateway / Context Capsule).

1. Who we are and the legal bases (GDPR / UK GDPR)

The data controller is the Atween operating entity for your region (to be published at release). Where required we appoint an EU/UK representative (Art. 27) and a data-protection contact. We process personal data only on a lawful basis: performance of the contract (providing the service you request), your consent (e.g. voice-cue AI understanding, training), legitimate interests limited to security and abuse prevention, and legal obligations. Special-category data (data revealing intimate life or mental-health-adjacent crisis signals) is processed only with your explicit consent (Art. 9) or to protect vital interests in a crisis.

2. What we collect and why

2.1 Account

Overseas accounts use email one-time codes and Sign in with Apple / Google; we do not require a phone number as your identity. We keep account identifiers, email, session and security logs to create, protect and, if you choose, delete your account.

2.2 Records, Echo, Talk-It-Through, long-term understanding

Text, voice, images, video, files and relationship events you submit are processed for the function you choose: this-session organisation, draft expression, review, long-term understanding, pre-delivery preview, or safety. If you choose "this session only", the content is not put into long-term understanding. If you save or enable long-term understanding, we keep the record, its source, AI-derived understanding, your corrections and a deletion watermark within your authorisation.

2.3 Voice rhythm and emotion candidates

After your first explicit confirmation, an on-device model may produce a transcript plus structured cues (pace, pauses, energy, pitch trend, event-level emotion candidates, confidence, time window, model and version). These are model candidates, not facts about you, not personality conclusions, not medical or psychological diagnoses. We do not show internal emotion labels to you, give them to the other person, or use them for scoring, profiling, advertising, differential pricing or significant automated decisions. You can switch off "voice cues for AI understanding" at any time; basic transcription and text input still work.

2.4 Delivery to the other person

When you use Deliver-to-TA, invitations or shared spaces, we process only the version you confirmed, the recipient relationship identifier, delivery/withdrawal state and necessary safety logs. We never show the other person your unconfirmed original words, media, transcripts, long-term understanding or internal analysis, and we do not reveal open-time, read or online status.

2.5 Security and operations

Device model, OS/app version, network state, IP, crash and performance logs and security events are processed to keep the service safe and stable (legitimate interests / legal obligation).

3. Cookies and similar technologies

The public website is static and sets no cookies, no trackers and no third-party scripts. In-app web views use only what is strictly necessary for login state and security; you can clear or restrict them in your browser, with fallbacks for core functions.

4. Sharing, processors and international transfers

We do not sell personal data. We share only with processors strictly needed to run the service (cloud infrastructure, model inference, payments via the app stores, crash monitoring, support), bound by data-processing agreements (Art. 28) and audit. On-device processing that does not leave your device is not a transfer. Where data leaves your region (e.g. model inference in a specific cloud region), we rely on adequacy decisions, standard contractual clauses or equivalent safeguards, and we publish the recipient, fields, purpose, retention and your opt-out in the Sub-processor List. We do not allow third parties to train on your intimate content, voice, images, transcripts, long-term understanding or AI output unless you separately consent and the contract permits withdrawal and deletion.

5. Storage, security and retention

Records are encrypted (envelope encryption, per-record keys); intimate content, voice, cues, crisis data and minors' data receive stricter protection. The operations console sees only structured SafeView states, never your original words. We keep data only as long as necessary for the purpose or as law requires; beyond that we delete, anonymise or stop processing. Deletion is cryptographic (crypto-shred) and propagates to records, media, transcripts, cues, indexes, long-term understanding, caches, queues, export tasks, provider retries and future Context Capsules; where law requires retention, the retained minimum is isolated from intimate content.

6. Your rights

You may access, rectify, export (portability), erase, restrict, object, withdraw consent (including training consent and "voice cues for AI understanding"), and lodge a complaint with a supervisory authority (EU/UK) or the relevant regulator. In-app paths exist under Account, Data & AI Understanding, Settings and Help. Deletion requests return a verifiable status or receipt. For California residents (CCPA/CPRA): you have the right to know, delete, correct and opt out of "sale" or "sharing"; we do not sell personal information.

7. Children

Atween is intended for adults (18+). We do not knowingly process children's data. If a formal version ever opens to minors, we will implement age-assurance, parental consent and dedicated protections before doing so.

8. Changes and contact

Material changes (purpose, categories, sharing, training, transfers, rights paths) are prominently notified and, where required, re-consented. Formal contact details, the data-protection officer/representative and complaint channels are published at release. Until then this draft must not be submitted or presented as a binding policy.