Privacy
Herly holds conversations that are private by design. This page says exactly what is kept, where it is kept, who else can see it, and how to take it away. It is written to be read rather than to be agreed to.
The short version
- Your conversations, her memory of you and every generated picture belong to your account and are never shown to anyone else. There is no feed, no sharing, and no public link.
- Your email address is kept in a separate part of the database from your conversations, and no ordinary query joins the two.
- Messages are sent to a language model to produce her replies. That provider is contractually set to retain and train on nothing.
- If you build a character from a photograph, that photograph is kept for as long as she exists, because it is what keeps her face the same. It is never used for training and never shown to anyone else.
- You can export everything, and delete everything, from Settings. Deletion removes the account itself, including the email address.
- Nothing here is sold, and nothing here is used for advertising.
What is collected
What you give us
- Your email address and a password, or a Sign in with Apple or Google identity. This is the only thing that identifies you as a person.
- Your date of birth. Collected once, at the age gate, to establish that you are 18 or over. It is stored as a date rather than as a tick, because a tick is not evidence.
- The name you would like to be called.
- What you write to her, and what you told us during onboarding: how you met, the character's appearance and personality.
- A photograph, only if you choose to start a character from one. The step is optional and it is skippable in one tap. What happens to it is set out under Photographs below.
What the product produces
- Her replies, and the pictures generated for her.
- Memory. Facts you told her, facts she has worked out, and summaries of older conversation. All of it is visible and editable on the memory screen.
- Your account state: credits, purchases, which items you own, which days you were active, and your settings.
What is not collected
There is no advertising identifier, no third-party analytics or tracking SDK in the app, no location collection, and no contact-list access. We do not build a profile of you for any purpose other than being able to hold a conversation with you.
Photographs
Starting a character from a photograph is optional, and most people never do it. If you do, this is what happens to the file, in full.
- It is read once, before it is uploaded. A vision model looks at it a single time to read hair colour, eye colour, build and how old the person looks, so that you are not asked to describe her by hand. A photograph of anyone who looks under 18 is not accepted. That model keeps nothing, and the request is sent with retention and training denied.
- It becomes her reference. It is sent to the image model each time a picture of her is made, which is what keeps her face the same from one picture to the next. She is built from it and deliberately held short of it, so she reads as somebody the photograph reminds you of rather than as the person in it.
- It is kept for as long as she exists, because it is also her picture in the app. A photograph it replaces is deleted at the moment you replace it, and all of them are deleted with her or with your account. We keep no copy of a photograph you have replaced, and no gallery or archive of the ones you have used. What survives a replacement is the record of the confirmation you gave, described below, which holds no image.
- It is never used to train anything, and it is never shown to anyone else. It is held in a private store that nothing can read without a link we sign, and those links are short-lived.
- It is stripped on the way in. The picker is asked not to hand over EXIF data at all, so the GPS coordinates, the capture time and the device identifier that a phone photograph normally carries never reach us in the first place.
- Characters made this way are permanently private. They cannot be shared, published or shown to anyone else, and that cannot be changed later.
If the photograph is of somebody else. You are asked to confirm that it is of you or of somebody who has agreed to it, and you are asked again every time you change it, because agreement about one photograph is not agreement about a different one. If you are in a picture somebody else uploaded and you want it removed, write to hello@herly.me with the subject "Report an image". We confirm within 48 hours, removal covers the stored file and every picture generated from it and the character itself, and you do not need a Herly account to send one.
We record that you confirmed it. Not the tick alone, but the sentence you were shown, exactly as it was worded, with the date and which screen it was, and a reference to the file it was about. That record is how we can answer the person in a photograph if they ever write to us, which is the whole reason the question is asked. It holds no image and nothing you have written. It is the one thing that outlives deleting your account, and it does so with your account no longer attached to it. See How long it is kept.
Special category data
Conversations in a companion app can reveal things that the GDPR treats as special category data under Article 9, sexual life or orientation among them. We treat everything you write as if it is in that category, which is why identity is separated from conversation storage, why the model provider is set to retain nothing, and why deletion removes the account rather than emptying it.
A photograph of an identifiable face, held so that pictures of a character can be generated from it, is treated the same way. That is why the step is optional, why the disclosures above are on the screen itself rather than in this document alone, and why your confirmation is asked again every time the photograph changes.
Where that law applies to you, our basis for processing it is your explicit consent, given at the age gate before any account exists. You can withdraw it at any time by deleting your account, which is two taps from Settings and takes effect immediately.
Why we hold it
| What | Why | Legal basis (GDPR) |
|---|---|---|
| Email and password | To sign you in and give you a way back into your account | Contract |
| Date of birth | To establish that you are an adult | Legal obligation, and legitimate interest in not serving minors |
| Conversations, memory, pictures | They are the product. Without them there is nothing to come back to | Contract, and explicit consent for anything special category |
| A photograph you start a character from | To keep her face the same from one picture to the next | Explicit consent, given on the upload screen and asked again on every change |
| The confirmation you gave about that photograph, and its date | So we can answer the person in a photograph if they ever ask, and show that the question was put | Legal obligation, and legitimate interest in being able to account for what was uploaded |
| Credits, purchases, settings | To give you what you paid for and to keep your preferences | Contract |
| Safety checks on outgoing messages | To refuse a narrow, specific class of content, described in the Terms | Legal obligation, and legitimate interest in operating lawfully |
Who else can see it
Nobody else can see your conversations in the ordinary course of using Herly. There are three kinds of company involved in running it, and this is all of them:
- Supabase: the database, sign-in and file storage, hosted in the United States
(
us-east-1). Everything you have is held here. - Fly.io: the small server that builds her replies, in the same region. It holds no copy of your data; it reads what a request needs and writes what a reply produces.
- OpenRouter, and through it a single named model provider: the language model that writes her replies. Every request is sent with retention and training explicitly denied, and the provider is pinned rather than chosen dynamically, so your conversation does not travel to whichever company is cheapest that hour. The same route, pinned to its own named provider, carries the vision model that looks once at a photograph you start a character from, at the moment you upload it.
- fal, and through it Black Forest Labs: the image model that makes her pictures. If you started her from a photograph, that photograph is sent with each request, because it is what keeps her face the same from one picture to the next. It is sent as a link we sign that expires within the hour, and it is sent to generate your own picture and for nothing else.
That is the whole list. Nobody else receives a picture of her, and nobody at all receives a photograph you uploaded except the two providers named above: the vision model once, when you upload it, and the image provider for each request that uses it.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in the California Consumer Privacy Act.
We would disclose data if we were legally compelled to. If that ever happens and we are permitted to tell you, we will.
Where it is held, and transfers
Herly runs in the United States. If you are in the United Kingdom, the European Economic Area or Switzerland, using it means your data is transferred there. Those transfers rely on the Standard Contractual Clauses in our agreements with the providers above.
How long it is kept
Your conversations and her memory are kept for as long as your account exists. That is the point of the product: a companion that forgets on a schedule is the thing Herly was built against. Nothing expires on a timer, and nothing is quietly aged out. Deletion is the mechanism, and it is yours to use.
A photograph you started a character from is kept for as long as that character exists. It is deleted the moment you replace it, and it is deleted with her and with your account. It is the one thing in the product that is deleted without you asking. Replacing a photograph removes the one it replaced, because keeping every photograph somebody has ever uploaded is retention nobody agreed to.
The record of the confirmation you gave about a photograph is the one thing that outlives deleting your account. Your account is unlinked from it at that moment, so what remains is that a confirmation in those words was made on that date: no photograph, no conversation, nothing that identifies you. We keep it because it is the only way to answer someone who writes in afterwards to say a picture was of them, and because a record we can be made to destroy on request is a record that we ever asked being erasable by the person who answered. If you want to query it, write to us at the address below.
Backups are retained by our database provider for up to 30 days, so a deleted account can persist in an encrypted backup for that long before it ages out.
Your rights, and how to use them
Two of these are buttons in the app rather than a request you have to send us, which is deliberate. A right you have to ask for is a right with a queue in front of it.
- Get a copy of everything: Settings → Export everything. It produces a readable JSON file containing your account, your settings, every message, every memory, your wardrobe and your credit history.
- Delete everything: Settings → Delete everything. It removes the pictures, then every row, then the account and the email address with it. It is not reversible and there is no grace period. The single exception is the confirmation record described under How long it is kept, which stays with your account unlinked from it.
- Correct what she knows: the memory screen. Every fact can be edited, confirmed, dismissed or removed in place.
- Object, restrict, or ask a question: write to hello@herly.me. We answer within 30 days.
If you are in the EEA or the UK you may complain to your data protection authority. If you are in California you may exercise the CCPA/CPRA rights above, and we will not treat you differently for doing so.
Security
Every table is protected by row-level security, so a request can only ever read the rows belonging to the account that made it. The email address lives in a separate database schema that is not reachable from the app at all. On phones and tablets your sign-in session is encrypted with a key held in the device keychain or keystore. Generated pictures are stored in a private bucket with no public URL. No system is perfect, and we would rather tell you what the controls are than promise that nothing can go wrong.
Children
Herly is for adults and is not offered to anyone under 18. We ask for a date of birth before an account can be created. If you believe a minor has an account, write to hello@herly.me and we will remove it.
Changes
If this policy changes in a way that affects what we do with what you have already given us, we will say so in the app before the change takes effect, rather than only updating the date at the top of this page.