Privacy Policy
Last Updated: February 1, 2026 | Effective Date: February 1, 2026
1. Introduction
Lucy Dorris Studio Inc ("Company," "we," "us," or "our") operates Feliona (the "Service"), an AI companion platform accessible at feliona.app. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Service.
By using Feliona, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Service.
2. AI Companion Disclosure
Feliona AI is an artificial intelligence system. All interactions you have through our Service are with AI-generated responses, not human beings. The 3D avatar and conversational interface are designed to provide an engaging user experience, but you should be aware that:
- You are communicating with an AI, not a human
- Responses are generated by machine learning models and may not always be accurate
- The AI does not have genuine emotions or consciousness
- We recommend taking breaks during extended sessions and maintaining real-world social connections
3. Information We Collect
3.1 Information You Provide
- Account Information: When you sign up using Google Sign-In or other authentication providers, we receive your name, email address, and profile picture
- Conversation Data: Messages and interactions you have with our AI companion
- User Preferences: Settings and customizations you make within the Service
3.2 Information Collected Automatically
- Usage Data: Information about how you interact with the Service, including session duration, features used, and interaction patterns
- Device Information: Browser type, operating system, and device identifiers
- Log Data: IP address, access times, and pages viewed
3.3 Google User Data
When you authenticate using Google Sign-In, we access only the following data from your Google account:
- Basic profile information (name, email address, profile picture)
- OpenID identifier for authentication purposes
We do not access your Google contacts, calendar, drive files, or any other Google services data.
Google API Services User Data Disclosure
This section specifically addresses how we handle data obtained through Google Sign-In, in compliance with the Google API Services User Data Policy.
Limited Use Disclosure: Feliona's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
1. Data Accessed
When you sign in with Google, we access only the following data from your Google account:
- Name — to personalize your experience and display in your profile
- Email address — for account identification and service communications
- Profile picture — to display as your avatar within the application
- OpenID identifier — a unique ID for secure authentication
We do NOT access: your Google contacts, calendar, Google Drive files, Gmail messages, location data, or any other Google services data.
2. Data Usage
Your Google data is used exclusively for the following purposes:
- Creating and authenticating your Feliona account
- Displaying your name and profile picture within the application
- Sending important service-related communications to your email (e.g., account security alerts)
- Providing customer support when you contact us
We do NOT use your Google data for: advertising, marketing to third parties, selling to data brokers, training AI/ML models, credit assessment, or any purpose other than providing the Feliona service.
3. Data Sharing
We do NOT sell, rent, or trade your Google user data.
Your Google data may only be shared with the following service providers who help us operate Feliona:
- Clerk — authentication provider that processes your Google Sign-In securely
- Supabase — database provider that stores your account information
These service providers are contractually bound to protect your data and may only use it to provide their services to us. They cannot use your data for their own purposes.
We NEVER share your data with: advertising platforms, data brokers, information resellers, or any third parties for marketing purposes.
4. Data Storage & Protection
Your Google data is protected using industry-standard security measures:
- Encryption in transit: All data is transmitted using TLS 1.3 encryption
- Encryption at rest: Data is encrypted using AES-256 encryption
- Secure infrastructure: Data is stored on SOC 2 compliant cloud providers (Supabase, Clerk)
- Access controls: Strict role-based access limiting employee access to personal data
- No human access: We do not allow employees to read your data unless you provide explicit consent for specific support requests
5. Data Retention & Deletion
Retention Period:
Your Google data is retained for as long as your account remains active. We do not retain your data longer than necessary to provide our services.
Deletion Options:
You can request deletion of your data at any time through:
- The "Delete Account" button in your Account Settings
- Sending an email to privacy@feliona.app
Deletion Timeline:
Upon receiving a deletion request, all your Google-sourced data will be permanently and irreversibly deleted within 30 days.
Revoke Access: You can also revoke Feliona's access to your Google account at any time by visiting Google Account Permissions. This will prevent future sign-ins but will not automatically delete existing data.
4. How We Use Your Information
We use the collected information to:
- Provide, maintain, and improve the Service
- Authenticate your identity and manage your account
- Personalize your experience with the AI companion
- Communicate with you about service updates and support
- Monitor and analyze usage patterns to improve the Service
- Detect and prevent fraud, abuse, and security issues
- Comply with legal obligations
5. How We Share Your Information
We do not sell your personal information. We may share your information only in the following circumstances:
- Service Providers: With third-party vendors who assist us in operating the Service (hosting, analytics, authentication)
- AI Processing: Conversation data may be processed by AI infrastructure providers to generate responses
- Legal Requirements: When required by law, subpoena, or other legal process
- Safety: To protect the rights, property, or safety of our users, the Company, or others
- Business Transfers: In connection with a merger, acquisition, or sale of assets
We do not use your data for advertising purposes or share it with advertising platforms, data brokers, or information resellers.
6. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption of data in transit (TLS/SSL)
- Encryption of sensitive data at rest
- Regular security assessments and updates
- Access controls limiting employee access to personal data
- Secure authentication mechanisms
While we strive to protect your information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
7. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you services. You may request deletion of your data at any time by contacting us or using the account deletion feature in your settings.
Upon account deletion, we will delete or anonymize your personal information within 30 days, except where we are required to retain certain information for legal or legitimate business purposes.
8. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your personal data
- Portability: Request transfer of your data in a portable format
- Opt-Out: Opt out of certain data processing activities
- Withdraw Consent: Withdraw previously given consent
California Residents (CCPA/CPRA)
California residents have the right to know what personal information is collected, request deletion, and opt-out of the sale or sharing of personal information. We honor Global Privacy Control (GPC) signals. To exercise your rights, contact us at privacy@feliona.app.
European Users (GDPR)
If you are in the European Economic Area, you have additional rights under the GDPR, including the right to lodge a complaint with a supervisory authority.
9. Mental Health & Crisis Resources
Our Service includes protocols to detect expressions of self-harm or crisis situations. If such content is detected, we may provide referrals to crisis support services. Our AI companion is not a substitute for professional mental health care.
If you or someone you know is in crisis, please contact a crisis helpline:
- United States: 988 Suicide & Crisis Lifeline (call or text 988)
- International: findahelpline.com
10. Children's Privacy
Our Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
Users between 13 and 18 years of age should review this Privacy Policy with a parent or guardian before using the Service.
11. Third-Party Services
Our Service uses the following third-party services:
- Clerk: Authentication and user management
- Supabase: Database and backend services
- Sentry: Error tracking and monitoring
- Cloudflare: Content delivery and security
- AI Providers: Language model inference for generating responses
Each of these services has its own privacy policy governing their use of data.
12. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers, including Standard Contractual Clauses where applicable.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last Updated" date. For significant changes, we will provide additional notice, such as an email notification.
Your continued use of the Service after any changes indicates your acceptance of the updated Privacy Policy.
14. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us: