Privacy Policy v1.8 (EN — International Version, with EEA/UK Rights)
- Effective Date: 2026-07-22
- Data Controller: MYCREAM CYP LTD (Reg. No. HE482361)
- Address: Chrysanthou Mylona 1, PANAYIDES BUILDING, 2nd Floor, Flat/Office 1, 3030 Limassol, Cyprus
- Contact (Privacy): social@mycream.ai
- Privacy Officer (CPO): Shinhyung Cho (Director/CEO) — contact: social@mycream.ai
- Data Protection Officer (DPO): Not appointed
This Privacy Policy explains how we collect, use, disclose, and protect personal data when you use our 18+ AI-driven 1:1 chat service (the “Service”). This Policy applies to all users, including fans, creators, and influencers.
1. Personal Data We Collect
We may collect the following categories of personal data:
- Account Information: email address, username/nickname, password hash, (optional) phone number, and a social sign-in provider's unique account identifier and email verification status.
- Verification Data (KYC/Age Verification, where required): verification data processed by our identity verification provider, which may include government ID details, selfie/liveness checks, date of birth/age, and address-related information.
- We generally do not store raw images of ID documents or selfies. We retain limited verification outcomes/metadata (e.g., pass/fail status, verification reference IDs, and timestamps).
- KYC Provider: ComplyCube (may change).
- Payment and Transaction Data: tokenized payment identifiers, transaction amounts/currencies, payment status, refunds/chargebacks, and tax-related information (e.g., VAT/GST where applicable). Payment card numbers and sensitive payment details are typically processed by payment processors and not stored by us. For recurring subscriptions, a tokenized payment credential may be retained to process renewal charges until you cancel.
- Content and Metadata: content you upload or submit to the Service, and related metadata (e.g., permission settings, agent configuration metadata).
- Conversation and Generation Data: text and other inputs/outputs generated during use of the Service, and related metadata.
- Usage and Technical Data: IP address, device/browser identifiers, cookies or similar technologies, timestamps, and security/performance logs.
- Support and Safety Data: messages submitted to customer support, reports, disputes, and records needed to process rights requests or handle safety issues.
2. How We Use Personal Data (Purposes)
We use personal data for the following purposes:
- Service Delivery: account creation, authentication, core functionality, and customer support.
- Payments and Account Administration: processing purchases, recurring subscription billing, refunds, chargebacks, invoicing/receipts, and operational accounting.
- Verification and Risk Management: age gating, identity verification (where required), fraud prevention, and abuse prevention.
- Safety and Policy Enforcement: monitoring, detecting, preventing, and responding to prohibited conduct and policy violations.
- Service Improvement: analytics and performance monitoring to improve reliability and user experience (with data minimization).
- Legal Compliance: complying with applicable laws and responding to lawful requests.
- Marketing (Opt-in): sending updates and promotional communications where you have opted in (you can withdraw consent at any time).
Google Sign-In Data Handling
- Access and collection: When you choose to continue with Google, we receive your Google Account's unique account identifier, email address, and email verification status. We do not request access to your name, profile photo, contacts, Google Drive files, or other Google Account data.
- Use: We use this information only to create your account, sign you in, link accounts, prevent duplicate accounts, and secure the Service. MyCream cannot access your Google password.
- Authentication and storage: The one-time authorization code and access token issued by Google are used only while completing sign-in and retrieving the information above; MyCream does not store them in its database. The Google account identifier, email address, and email verification status are stored as account authentication information.
- Retention and deletion: Google sign-in information is retained while your account remains active. After account closure or completion of a deletion request, we delete or de-identify it unless a legal retention exception applies. See Sections 5 and 8 for the detailed criteria and how to request deletion.
- Protection: We apply the safeguards described in Section 10 to Google sign-in information, including encryption in transit and at rest where appropriate, access controls, and permission management.
- Disclosure and use restrictions: Google sign-in information may be processed by service providers acting on our instructions where necessary for hosting, operations, or security, or disclosed where required by law. We do not sell it, share it for personalized advertising, or use it for advertising or AI model training.
3. Legal Bases (Where Required)
Where applicable (including in the EEA/UK), we rely on the following legal bases:
- Contract: to provide the Service you request.
- Legitimate Interests: to secure, operate, and improve the Service and prevent fraud/abuse.
- Legal Obligations: to comply with applicable laws and lawful requests.
- Consent: for optional marketing communications (withdrawable at any time).
4. Cookies and Similar Technologies
We use cookies and similar technologies for authentication, security, preferences, and analytics. You can manage cookies through your browser settings and, where available, our cookie preference tools.
5. Data Retention
- Account and authentication information: We retain it while your account remains active. After account closure or completion of a deletion request, we delete or de-identify it unless continued retention is necessary for legal obligations, dispute resolution, or abuse prevention.
- Usage records and technical logs: We generally retain them for up to 12 months, to the extent necessary to provide and secure the Service.
- After that period, unless we must retain data to comply with legal obligations or to resolve disputes, we will securely delete it or de-identify it (anonymize/pseudonymize) and use it only for limited purposes such as aggregated analytics.
- Backup data may persist for a limited period due to system constraints and may be removed on a rolling basis.
6. Sharing and Disclosure
We may share personal data with:
- Service providers that help us operate the Service (e.g., hosting/cloud infrastructure, payment processing, identity verification/KYC, customer support tools, security monitoring, analytics).
- Authorities or third parties where required by law, to protect rights and safety, or to enforce our policies.
We require service providers to protect personal data and process it only on our instructions, subject to appropriate contractual safeguards.
7. International Data Transfers
We are based in Cyprus and may process or store personal data in Cyprus and other countries where we or our service providers operate. When personal data is transferred internationally, we take steps designed to ensure an adequate level of protection, such as contractual safeguards (including EU Standard Contractual Clauses where appropriate) and technical measures like encryption and access controls.
8. Your Rights
Depending on your location, you may have rights to:
- access, correct, or delete your personal data;
- restrict or object to certain processing;
- request data portability;
- withdraw consent where processing is based on consent.
To exercise your rights, contact us at social@mycream.ai. We may need to verify your identity before responding, and certain legal exceptions may apply.
EEA/UK Additional Rights (GDPR/UK GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom, you may have additional rights under GDPR/UK GDPR, including the right to:
- lodge a complaint with your local supervisory authority; and
- contact our Data Protection Officer (DPO) (if appointed) regarding privacy matters.
Cyprus Supervisory Authority: Office of the Commissioner for Personal Data Protection.
9. Adults Only (18+)
The Service is intended for adults only. We may use age-gating and verification measures and may restrict or suspend access if we suspect a user is underage.
10. Security
We maintain reasonable technical and organizational measures to protect personal data, including access controls, encryption where appropriate, and monitoring for security risks. No system is completely secure, but we work to reduce risks.
11. Automated Processing
We may use automated tools to detect fraud, enforce policies, and help keep the Service safe. Where required by law, you may request human review of certain decisions.
12. Third-Party Services
The Service may contain links to third-party websites or services. We are not responsible for their privacy practices, which are governed by their own policies.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If changes are material, we will provide notice through the Service or by other reasonable means. Continued use after notice may be treated as acceptance where permitted by law.
14. Contact
- Privacy inquiries: social@mycream.ai
- Privacy Officer (CPO): Shinhyung Cho (Director/CEO)
- DPO: Not appointed
- Address: Chrysanthou Mylona 1, PANAYIDES BUILDING, 2nd Floor, Flat/Office 1, 3030 Limassol, Cyprus
Service analysis
Allow MyCream to use Google Analytics to measure page visits and feature use. We do not send messages, search terms, names, email addresses, or raw content.
Loading analysis preference
Personalized ads
Choose whether MyCream may use Meta Pixel cookies and device, browser, and page-visit data for campaign measurement and remarketing. No chat text or raw content is sent.
Loading preference