Lomli

Privacy & Data Protection · English

Lomli Privacy Policy

Effective date: September 29, 2026

Last updated: September 29, 2026

This Privacy Policy explains how Lomli's operator, HYPERGAME TECHNOLOGY LIMITED (place of incorporation: Hong Kong, China; registered address in English: UNIT B604W ON 6/F., BLK B, CHUNG MEI CENTRE, 15 HING YIP STREET, KWUN TONG HONG KONG; the Chinese rendering of the address is for reference only, and the English registered address prevails; see Section 24 for other registration information), referred to as “Lomli,” “we,” “us” or the “Company,” collects, uses, discloses, retains and protects your personal information when you access or use the Lomli mobile applications, websites and related products, features and services (collectively, the “Services”), and how you may exercise your rights.

Lomli is an artificial intelligence companionship service for adults. You interact with an AI system or AI characters, not human support staff or human companions. AI responses are generated automatically by models and may be inaccurate, incomplete or inappropriate. The Services may offer AI character interactions, text chat, image interactions, voice features, character creation or customization, subscriptions and virtual goods purchases. AI-generated content does not represent a real person's opinion and should not be treated as medical, mental-health, legal, financial or other professional advice.

Important: Chat, image and voice content may contain highly private or sensitive information. Do not submit information you do not want processed, such as government-issued identification numbers, account passwords, full payment-card numbers, precise financial-account details, medical diagnoses, other people's private information or unlawful content. Do not upload someone else's personal information without appropriate authorization.

If you do not agree with this Privacy Policy, stop using the Services. For processing that legally requires separate consent, we will provide a separate notice and obtain your consent before processing. You may withdraw consent as permitted by law, without affecting the lawfulness of earlier processing.

1. Scope and Data Controller

This Privacy Policy applies to Services provided by Lomli that link to it, including:

  • Lomli mobile applications;
  • The official Lomli website and user center;
  • AI character, chat, image and voice interaction features;
  • Subscriptions, virtual goods and other in-app purchases;
  • Customer support, safety appeals, surveys and activities;
  • Other pages or features directly related to the Services that link to this Policy.

It does not apply to:

  • Third-party websites, applications, sign-in services, payment channels or platforms with their own privacy policies;
  • Activities for which Apple, Google, app stores, payment providers or other third parties independently determine processing purposes and means as separate controllers;
  • Processing of information about our employees, job applicants or personnel of business partners, except when they use the Services as ordinary users.

For the processing described here, the same company acts as data controller, Lomli service provider, user contracting party and charging entity. Its full legal name, place of incorporation and registered address have been confirmed: HYPERGAME TECHNOLOGY LIMITED, incorporated in Hong Kong, China, with the English registered address UNIT B604W ON 6/F., BLK B, CHUNG MEI CENTRE, 15 HING YIP STREET, KWUN TONG HONG KONG (the Chinese rendering is for reference only; the English registered address prevails). If other affiliated companies later jointly determine the purposes and means of processing for particular features, we will explain the joint-controller arrangements and allocation of responsibilities through feature pages, supplementary notices or an updated Policy.

2. Personal Information We Collect

The information we collect depends on the features you use, device settings, account type, region and your choices. If you decline to provide information necessary for a feature, we may be unable to provide it.

2.1 Account and Identity Information

When you register, sign in or manage your account, we may collect:

  • Email address, user ID, display name, profile image and encrypted password-verification information;
  • Account creation and sign-in times, sign-in method (Apple, Google, email or Guest mode), account status and subscription status;
  • Email-verification status and time, for email sign-in only;
  • Profile information you choose to provide, such as a nickname, biography, gender or pronouns, birthday or age-declaration information;
  • Account settings, privacy choices, notification preferences, language and region;
  • Information submitted for age assurance, identity verification or data-rights requests.

We do not offer sign-in by telephone number or SMS verification code, so we do not collect your telephone number for registration or sign-in.

We store passwords as encrypted verification information, not plaintext. Information collected through third-party sign-in is described in Section 2.2.

Age assurance is the overall framework we use to determine age eligibility: age declaration is self-reporting of age or date of birth; age estimation uses technology or behavioral signals to infer an age range; age verification uses more reliable declarations, documents or third-party services to confirm age; human review involves a person reviewing automated outcomes or challenges.

We currently use age declaration, meaning that at registration you report your date of birth or confirm that you are at least 18. This step occurs only once, at registration; we do not repeatedly ask you to declare your age during later use.

Under the current product design, Lomli does not require images of identity documents or passports, selfies, video or liveness checks; does not create voiceprint or facial-feature templates for age decisions; and does not use third-party age-verification services or automated age-estimation technology. Accordingly, we do not currently collect or process biometric information for age verification.

If changes in applicable law or regulatory requirements in launch or target markets require changes to age assurance, we will update this Policy in advance, provide legally required notice and obtain additional consent where necessary.

2.2 Third-Party Sign-In Information

Lomli currently offers four access methods: Apple sign-in, Google sign-in, email sign-in and Guest mode. This section describes information received through third-party sign-in (Apple and Google). Email sign-in information is covered in Section 2.1 and Guest mode in Section 2.3.

If you choose Apple or Google sign-in, we receive information that the provider supplies with your authorization, such as:

  • A unique identifier for the third-party account;
  • Your name, nickname, profile image or email address;
  • A relay email address generated by Apple's “Hide My Email” feature;
  • Sign-in tokens, token status and necessary security-verification information.

Under Apple's mechanism, your name and email address are normally supplied when you first authorize access. If you choose “Hide My Email,” we receive a relay address rather than your actual email address.

We do not receive your Apple ID or Google account password from these providers. Their processing is governed by their own terms and privacy policies. Where they determine processing purposes and means for their own activities, they act as independent controllers; see Section 11.3.

If you later link multiple sign-in methods to one account, where the app offers this feature, we associate the relevant identifiers, such as third-party unique identifiers and email addresses, with that account to maintain consistency and prevent duplicate registration. Handling on unlinking is explained in the app. See Section 4.5 of the Lomli Terms of Service for the availability of this feature.

2.3 Guest Mode Information

The Services offer Guest mode. We may use device identifiers, randomly generated guest IDs, local storage or similar technologies to maintain sessions, save limited preferences and prevent abuse.

Guest chat histories and related content are stored on our servers. When a guest registers a full account, we merge and migrate their guest chat history, characters and preferences into that account so that they can continue their experience. After merging, data associated with the former guest identifier are handled under Section 13.

Guest accounts may not support data recovery across devices. Clearing app data, uninstalling the app or changing devices may prevent recovery of content or purchase status, as explained in the product.

When you upgrade from Guest mode to a registered account, your guest chat history, characters and preferences are migrated to that account to preserve continuity.

2.4 Chat, Image and Voice Content

When you use AI interaction features, we process content you voluntarily submit, generate or receive, including:

  • Text, prompts, feedback and chat history sent to AI characters;
  • Images you upload or generate, image descriptions and necessary file metadata;
  • Voice input, audio files, transcribed text, speech-synthesis requests and related technical parameters;
  • AI-generated text, images, speech and other replies;
  • Content timestamps, conversation identifiers, associated characters and safety-classification results;
  • Your likes, dislikes, reports, hiding, deletion or regeneration of content.

Voice Features

The Services offer voice input (converting your speech to text for AI understanding), voice output (reading AI replies using synthesized speech) and real-time voice calls (two-way live voice conversations with an AI character).

Voice features require access to the device microphone, which is used only when you grant permission and actively use the relevant feature. You may withdraw microphone permission in device settings. This disables voice input and real-time calls but does not affect text interactions.

Voice interactions process your audio and transcribed text to deliver voice features and the voice experience. We do not create voiceprint templates, recognize voiceprints or uniquely identify people by voiceprint. This does not change Section 7's explanation of using voice audio and transcripts for model training. Security measures are described in Section 14.

We do not analyze voice characteristics to infer your emotions or mental state or make automated decisions based on such inferences. We do not use your voice content for advertising targeting, marketing profiles or purposes incompatible with those described above.

Content you submit may reveal sensitive information, including health, sex life or sexual orientation, religious or philosophical beliefs, political opinions, or race or ethnicity. Consider carefully whether to disclose it. We do not assume such information is necessarily true merely because it appears in an AI conversation, and we apply additional protections as required by law.

2.5 AI Characters, Preferences and Personalization

To align AI companionship with your choices, we may process:

  • Characters you create, select, favorite or block;
  • Character names, appearances, backgrounds, personality tags, voices and interaction styles;
  • Your chosen interests, relationship settings, forms of address, reply lengths and content preferences;
  • Recommendation signals, memory entries or conversation summaries derived from interactions;
  • “Memory” information you manually save, edit, disable or delete;
  • Feedback about model replies, character quality and feature experiences.

Long-Term Memory

The Services offer long-term memory, allowing AI characters to remember information about you across conversations and maintain continuity.

  • How memories are created: There are two sources: information the AI automatically extracts and saves during interactions, such as preferences, forms of address or important events you mention; and memory entries you manually add or edit.
  • Your controls: You may enable or disable long-term memory at any time in the app's privacy settings, and view, modify or delete individual memories or all memories.

Please note: Memories may contain sensitive information you voluntarily disclose, such as health, emotional experiences, sexual orientation or religion. Because AI may repeatedly use long-term memories in later conversations, consider carefully whether you want the Services to remember such information.

Long-term memory provides personalized replies. Like chat, images, voice, transcripts and feedback, it is within the scope of general model training and improvement; see Section 7 for opting out. You may view and delete individual or all memories in the app. Following deletion, we immediately stop using them for personalization and remove them from active systems within no more than 30 days.

2.6 Purchases and Transactions

When you purchase subscriptions, virtual goods or other paid services, we may process:

  • Purchased items, order numbers, transaction times, currencies, prices and subscription status;
  • Trials, renewals, cancellations, refunds, promotion eligibility and entitlement usage;
  • Transaction tokens, receipt-verification results and limited billing information from app stores or payment providers;
  • Information needed for tax, accounting, anti-fraud and dispute-handling obligations.

Confirmed payment and subscription arrangements:

  • Purchase channels: Apple App Store in-app purchases (iOS) and Google Play in-app purchases (Android);
  • Charging entity: For app-store purchases, the relevant app store is the Merchant of Record;
  • Subscription types: Monthly, quarterly and annual subscriptions, all renewing automatically; consumable credit or token packs are one-time in-app purchases and do not renew automatically;
  • Trials: We do not offer free trials, and there is no automatic conversion from a trial to a paid subscription;
  • Prices: Displayed prices are final prices including applicable taxes;
  • Cancellation: The app provides access to subscription management; the relevant store stops actual billing for store subscriptions;
  • Refunds: Unless required by channel rules or applicable law, we do not offer a voluntary no-reason refund window;
  • Billing address: We do not receive your billing address.

Full payment-card numbers are processed directly by Apple, Google or their payment providers. We do not obtain or store full card numbers or process your complete payment credentials. App-store processing is governed by the stores' own privacy policies.

2.7 Device, Network, Log and Usage Information

When you use the Services, we may automatically collect:

  • Device model, operating system and version, app version, browser type, language, time zone and display settings;
  • IP address, network type, mobile carrier, approximate location (usually inferred from IP) and connection information;
  • App instance ID, device or advertising identifiers depending on permissions and settings, and push tokens;
  • Page and feature visits, clicks, dwell time, session duration, searches, character interactions and feature usage;
  • Crash logs, diagnostics, performance data, error records and network-request logs;
  • Security incidents, unusual sign-ins, reports, signals of rule violations and anti-fraud information;
  • Information collected through cookies, SDKs, local storage and similar technologies.

We do not collect your precise geolocation. We may use approximate location inferred from IP addresses, generally at country or city level, for safety, compliance and content localization.

2.8 Customer Support, Reports and Research

When you contact us, make a complaint, report content, complete a survey or join an activity, we may collect:

  • Contact details, account information and communications;
  • Ticket numbers, issue descriptions, attachments, relevant chat excerpts and handling records;
  • Reported subjects, reasons for reports, investigation findings and appeal information;
  • Survey responses, user-interview records and opinions you voluntarily provide;
  • Limited information needed to verify a requester's identity and prevent fraud.

Support staff should access information only to the extent needed to resolve the issue. Do not include sensitive information unrelated to the issue in a support ticket.

2.9 Information from Other Sources

We may also obtain information from:

  • Apple, Google, app stores, payment providers and sign-in providers;
  • Analytics, attribution, anti-fraud, security, content-moderation and infrastructure providers;
  • Other users whom you invite or authorize to interact with us;
  • Public sources, regulators, law enforcement or third parties lawfully providing information;
  • Counterparties and their advisers in corporate transactions.

3. Sensitive Personal Information

Chat, images, voice, character preferences and reporting materials may contain sensitive personal information or special-category personal data as defined by applicable law, such as health, sex life or sexual orientation, religion, political views, race or ethnicity, biometrics, precise location or account credentials.

We apply these principles:

  • Process such information only as needed to provide features you actively request, protect safety, meet legal obligations or act on explicit consent required by law;
  • Do not require sensitive information unrelated to ordinary chat features as a condition of using them;
  • Do not infer sensitive characteristics from chat content for targeted advertising;
  • Do not give advertising partners identifiable private chat text, images or voice content;
  • Apply access restrictions, encryption, de-identification and retention controls where feasible;
  • Offer appropriate choices where separate consent or a right to limit processing is required.

Confirmed processing of sensitive information: Long-term memory may store sensitive information you voluntarily disclose, and voice and image content you provide may also contain sensitive information. We do not create voiceprint templates or infer emotions or mental states from voice characteristics. These activities are separately described in Sections 2.4 and 2.5. We do not use them for advertising targeting or marketing profiles.

In addition, sensitive information you voluntarily disclose may be processed together with chat, images, voice or memories when those are used for model training. Before you opt out of general model training, this information may therefore be used in training. You may opt out at any time; see Section 7.2. We reduce risks through measures such as separating identifiers, filtering and restricting access during training, and provide limits on use, separate choices or consent mechanisms where required by law.

Where the Washington My Health My Data Act or similar laws apply, we will assess whether processing chat content constitutes collection, sharing or sale of consumer health data or biometric information, and provide separate notices, consent and deletion mechanisms where applicable.

4. How We Use Personal Information

We may use personal information for the following purposes:

4.1 Providing and Maintaining the Services

  • Create, authenticate and maintain your account or guest session;
  • Provide text, image, voice and character interactions;
  • Store chat history, preferences, character settings and memories you enable;
  • Synchronize subscriptions, purchases and virtual entitlements;
  • Provide support, troubleshooting and account recovery;
  • Send service notices, security alerts and transaction information.

4.2 Personalizing Your Experience

  • Remember your language, settings, characters and interaction preferences;
  • Recommend characters or features that may interest you;
  • Adjust reply formats, content length or interaction order;
  • Create or use conversation memories when you enable the relevant features.

You can manage some personalization and memory options through privacy and personalization settings in the app.

4.3 Safety, Content Review and Abuse Prevention

  • Detect, prevent and investigate spam, fraud, account takeover, automated abuse and other security risks;
  • Identify content that may violate applicable law or community rules;
  • Protect the rights, safety and property of users, the public, the Company and third parties;
  • Handle reports, appeals and law-enforcement requests;
  • Maintain service integrity and test security controls.

4.4 Analytics, Performance and Product Improvement

  • Analyze feature usage, retention, crashes and performance;
  • Debug errors, conduct quality assurance and plan capacity;
  • Evaluate new features, interfaces and model versions;
  • Produce aggregate or de-identified statistics;
  • Understand feedback and improve the Services.

4.5 AI Operations, Safety Evaluation and General Improvement

We distinguish the following purposes:

  • Providing the current response: Send your input, necessary context and relevant parameters to the AI models or infrastructure needed to generate the response, and perform retrieval, speech recognition, speech synthesis, image generation and necessary safety filtering;
  • Safety, moderation and quality evaluation: Automatically classify, test, sample or conduct limited human review of content or signals to identify abuse, investigate reports and assess reliability;
  • Service operations and personalization: Analyze usage, performance, preferences and enabled memories to maintain features, rank content or improve the experience;
  • General model training or improvement: Use eligible content for training, fine-tuning, evaluation sets or system improvements beyond the current conversation. Under the current product design, private chat history, uploaded images, voice audio and transcripts, long-term memories and user feedback are all used to train and improve Lomli's own models, and you may opt out of that training at any time. See Section 7.

Sending data to a third-party model to provide the current response does not automatically authorize that provider to use it for its own training or other independent purposes. Provider roles, contractual boundaries and independent processing are described in Sections 6 and 7.3.

4.6 Transactions, Marketing and Communications

  • Handle subscriptions, purchases, refunds and accounting records;
  • Send product messages you request and service announcements;
  • Send marketing messages as described below;
  • Measure campaign effectiveness and prevent duplicate delivery;
  • Manage offers, surveys, activities and rewards.

Confirmed marketing and notification practices:

ItemConfirmed position
Marketing channelsMarketing email, in-app marketing push notifications, and SMS or other messaging channels
Providing contact details to third parties for their marketingNo
Unsubscribe methodManual unsubscribe through customer-support email
Necessary service noticesTransaction, security, terms-change and similar notices are not affected by unsubscribing
Remarketing / lookalike audiencesNo: we do not currently conduct remarketing, audience matching or lookalike audience campaigns

Even if you unsubscribe from marketing, we may still send necessary transaction, security or service messages.

Marketing and unsubscribe arrangements. Consent requirements and unsubscribe mechanisms differ by market; we make arrangements according to local law:

  • Consent for electronic marketing: In the EEA and UK, marketing email or SMS to individuals generally requires prior consent under electronic-privacy rules. In Canada, the Canadian Anti-Spam Legislation (CASL) requires express or implied consent and applies strict standards outside an existing business relationship. Before marketing to those regions, we will obtain the consent required by local law;
  • SMS marketing: In the United States, marketing texts are regulated by the Telephone Consumer Protection Act (TCPA), which requires prior express written consent. Statutory damages are USD 500–1,500 per violation and may be pursued in class actions. We will not send marketing texts to US users before obtaining the required prior written consent;
  • Unsubscribe mechanism: US CAN-SPAM, Canadian CASL and electronic-privacy rules require a directly usable unsubscribe method in every marketing message. CASL also requires requests to take effect within 10 business days, and SMS must support keywords such as STOP. Before opening marketing communications in any market, we will provide a directly usable unsubscribe method in every message and support STOP or similar keywords for marketing texts. Until then, you may request unsubscribe at any time through support email;
  • Remarketing and lookalike audiences: We do not currently conduct remarketing, audience matching or lookalike audience campaigns, or provide personal information to third parties for those purposes.

4.7 Legal Compliance and Corporate Operations

  • Comply with applicable laws, regulatory requirements, court orders and lawful law-enforcement requests;
  • Establish, exercise or defend legal claims;
  • Enforce the Terms of Service, community rules and other policies;
  • Conduct audits, finance, tax, insurance, compliance and corporate governance;
  • Evaluate or complete mergers, financing, restructuring, asset transactions or similar corporate transactions.

5. Legal Bases in the EEA, UK and Other GDPR Jurisdictions

If the EU General Data Protection Regulation, UK GDPR or similar laws apply, we rely on the legal bases below. The specific basis depends on the processing context and type of information.

Processing purposeTypical informationMain legal basis
Registration, sign-in, chat, characters, voice, purchases and supportAccounts, content, preferences, transactions, necessary device informationPerformance of our contract with you; steps at your request before entering a contract
Account, service and user safety; fraud and abuse preventionLogs, safety signals, reports, necessary content excerptsOur and users' legitimate interests; legal obligations; protection of vital interests when necessary
Service analytics, diagnostics and basic product improvementUsage, device data, diagnostics, aggregate statisticsLegitimate interests in improving and maintaining the Services; consent for non-essential cookies or SDKs where required
Personalization, long-term memory and some recommendationsPreferences, interactions, memoriesContract performance or legitimate interests; consent where required
Marketing messagesContact details, marketing preferencesConsent where prior consent is required for electronic marketing, including the EEA, UK and Canada; elsewhere, the basis required by applicable law and convenient unsubscribe options
Remarketing, audience matching and lookalike campaigns—We do not currently conduct these activities
Purchases, tax, accounting and refundsOrders, transactions, limited accounting dataContract performance; legal obligations
Special-category dataSensitive content voluntarily submittedContract performance together with an applicable Article 9 condition; explicit consent where required; statutory conditions such as establishing, exercising or defending legal claims
Regulatory, judicial or law-enforcement requestsInformation relevant to the requestLegal obligations; public interest; establishing, exercising or defending legal claims
AI training or general improvement, covering chat, images, voice and transcripts, memories and feedbackThe content categories aboveLegitimate interests, consent or other bases under applicable law, with the required conditions for special-category data; all users can opt out as described in Section 7

Where we rely on legitimate interests, we balance those interests against your rights, reasonable expectations and possible impacts, and apply minimization, opt-outs or other safeguards. Contact us for more information about this balancing assessment.

6. AI Service Providers, Model Providers and Data Minimization

AI companionship uses our own models as well as third-party AI, cloud computing, speech recognition, speech synthesis, image generation, content-safety and data-storage services. Providers may process necessary data on our behalf, or in some circumstances as independent controllers.

Confirmed provider list:

Service typeConfirmed providersInformation potentially processedPurpose
Large language models: primary generation capabilitiesOpenAI (GPT), Anthropic (Claude), Google (Gemini)Prompts, necessary context, model outputs, safety metadataGenerate replies, understand context, control quality and safety
Image generation and understandingOpenAI (GPT)Uploaded images, prompts, generated images, necessary metadataImage interaction and content safety
Speech recognition and synthesisFish AudioAudio, transcripts, voice parametersVoice input and output
Cloud hosting and content deliveryAmazon Web Services (AWS), Singapore regionAccounts, content, logs, encrypted dataStorage, computing, transmission and backups
Content safety and abuse preventionDeveloped in-house; no third-party content-safety providerContent or features, safety classifications, device and network signalsIdentify unlawful or harmful activities

Providers' training and retention policies. At their enterprise or paid API tiers, all three listed language-model providers do not, by default, use API inputs or outputs to train their foundation models: OpenAI's policy has applied since March 2023, Anthropic's commercial terms expressly exclude such use, and Google's paid tier does not use data to improve products. Three qualifications matter:

  • The paid or enterprise tier must be confirmed. Google's free tier, for example, uses content to improve products, including model training; this conclusion does not hold if that tier is used;
  • Even without training use, providers retain requests and outputs for limited periods for safety and abuse monitoring. Default periods differ, on the order of approximately 7 to 60 days, and safety-flagged content may be kept longer. Content deleted in our Services may therefore remain with a provider during its retention period;
  • Zero Data Retention (ZDR) is not the default. It requires a separate application under an enterprise agreement and applies only to eligible endpoints.

Controller roles: Whether and to what extent a provider acts as an independent controller depends on its terms and use of data for its own purposes. Independent-controller processing should have its own legal basis and be explained in that provider's terms or privacy policy. Using a third-party model does not mean we control all of that provider's processing.

We follow these principles:

  • Send suppliers only the data needed for the specific request or safety check;
  • Where technically and operationally feasible, remove direct identifiers and use random identifiers, truncation, summaries or other minimization measures;
  • Require appropriate confidentiality and security, and conduct due diligence on access, retention, reuse and international transfers;
  • Avoid sending account passwords, full payment-card numbers or account information unrelated to the request to model providers;
  • Conduct necessary data-protection and safety assessments for high-risk features;
  • Where a provider may use data for its own training, disclose the facts under Section 7.3 and assess whether additional notice, consent or choices are required by law.

We will publish and maintain an in-app list of third-party AI and infrastructure providers and their roles. If a new provider materially disadvantages your rights, we will notify you to the extent required by law.

7. Conversation Content, Model Training and Opting Out

We distinguish processing to generate the current response, processing for safety review or service operations, and using content for general model training or improvement. Generating a response is generally necessary for the AI feature you request. Safety review and operations have separate, limited purposes. General training or improvement may not be necessary for the current conversation.

7.1 Data Used for Training and Improvement: Confirmed Product Design

Lomli's training and improvement currently covers the following categories. All of them are used to train, fine-tune, evaluate or otherwise improve Lomli's own models:

Data typeUsed to train and improve our models?
Private chat history, including AI repliesYes
Uploaded or generated imagesYes
Voice audio and transcriptsYes
Long-term memoriesYes
Feedback, including likes, dislikes, reports and regenerationYes

Before processing, we apply necessary risk-based measures, including access controls, de-identification or separation of identifiers, sensitive-information filtering and the content-safety review described in Section 8. Training samples are limited to what is necessary for training and evaluation and are subject to tiered permissions, purpose restrictions and security audits.

7.2 Your Training Choices

You may opt out of general model training at any time. Through in-app settings or a request to us, you may ask that your relevant content no longer be used for general model training and improvement. After you opt out, we stop using that content for general training. This does not affect training results completed before your opt-out.

We recognize that this design affects your choices and clarify its implications:

  • Deletion requests submitted under Section 21 will still be accepted, and we will delete the relevant personal information as required by law and technically feasible;
  • Deleting personal information does not automatically retract model parameters already incorporating training, evaluation results or aggregate data that cannot reasonably be re-identified;
  • Therefore, deleting an account or content is not the same as removing its influence from an already trained model.

This opt-out is available to every user, regardless of region. See Section 17 for how to exercise it. Where applicable law imposes other training requirements or an equivalent mechanism, we will comply.

We assess training's legal basis, purpose limitations, special-category data conditions, rights to limit sensitive-data use and data-protection assessment obligations under applicable law. Where explicit consent or other additional conditions are required for a region or context, we will meet them before processing.

7.3 Third-Party Model Providers and Training Boundaries

We transmit necessary data to third-party model, speech-recognition and synthesis, image-generation and content-safety providers to deliver AI features. Whether those providers use data for their own model training is explained below:

ProviderTraining policy, based on public policies and subject to the terms actually agreedDefault retention
OpenAI (GPT)Paid API inputs and outputs are not used for training by defaultApproximately 30 days for safety and abuse monitoring
Anthropic (Claude)Commercial terms expressly provide no training useLess than 30 days, approximately a single-digit number of days
Google (Gemini)Paid tier: no training use. Free tier: used to improve products, including trainingApproximately 55 days for safety monitoring
Fish AudioIts default API terms; the relevant arrangements depend on our provider list and applicable termsAs provided in the applicable terms

The third-party training risk described in Section 7 therefore does not apply uniformly; it depends on each provider's actual tier and terms. The following confirmations remain necessary: we will publish an in-app list of third-party AI, voice and infrastructure providers and their roles, and continually confirm each provider's tier and terms. We will give legally required notice if a new provider materially disadvantages your rights.

Even where a provider does not train on the data, two facts remain relevant:

  • Short-term retention still occurs. Requests and outputs are retained by the provider for the periods above for safety and abuse monitoring; flagged content may be retained longer. Content you delete within our Services may therefore remain with the provider during its retention period;
  • Provider safety review is another route for human access. In addition to our in-house review described in Section 8, providers may conduct safety checks or human review under their own policies.

We will assess the legal classification of transmitting necessary data to these providers and meet notice and choice obligations where it constitutes sale, sharing or another activity requiring choices.

7.4 Our Express Statements

To avoid misunderstanding, we expressly state:

  • We do not claim that your conversation content is “never used for training” or “fully anonymous”;
  • We do not claim that we can completely remove your data or its influence from a model whose training is already complete;
  • These explanations do not limit mandatory rights of access, correction, deletion, objection or other rights under applicable law. If you are in the EEA, UK or Switzerland, your rights exercised under Section 18 are not reduced by this section;
  • If applicable law requires an opt-out, consent or limitation mechanism for particular processing, we will provide it and update this Policy accordingly.

8. Content-Safety Review and Human Access

To protect users and the Services, we may use automated tools and limited human review to identify suspected violations of law, the Terms of Service or community rules, such as child sexual exploitation material, nonconsensual intimate imagery, serious threats of violence, immediate self-harm risks, fraud, spam or other abuse.

Processing may include:

  • Automated classification, risk scoring, hash matching or keyword detection on inputs and outputs;
  • Blocking, restricting, blurring or removing content;
  • Suspending features, restricting accounts or terminating accounts;
  • Having authorized, trained personnel examine flagged content and context where necessary and appropriate;
  • Preserving evidence and handling reports and appeals;
  • Reporting to relevant authorities where required or permitted by law.

8.1 Triggers for Human Review: Confirmed

We trigger human review only in these circumstances:

  1. An automated classification system identifies high risk;
  2. A user report;
  3. A risk involving minors;
  4. Signals of self-harm or suicide;
  5. A law-enforcement or regulatory requirement.

8.2 Scope and Location of Human Review: Confirmed

Human reviewers read only flagged content excerpts after the system flags them. As a general rule, we do not proactively or routinely read entire private conversations. Review is conducted by our own review team, currently located entirely in mainland China.

Please note: Our data are stored in Singapore, but reviewers are in mainland China. Flagged content, potentially including sensitive information about health, sexual orientation, religion or political opinions, is accessed by that team from mainland China. This is cross-jurisdictional access. Before launch, we will implement the necessary transfer mechanisms, impact assessments and supplementary safeguards, and provide further notice or obtain consent where required by law.

We will explain possible human access in the interface and apply necessary, proportionate measures when reviewing sensitive content.

8.3 Review Processes and Safeguards

Human access follows least-privilege, confidentiality, logging and purpose-limitation requirements. Reviewers may see only excerpts necessary to handle a particular flag and may not use them for other purposes, disclose them externally or use them personally. Reviewers are subject to tiered permissions, training and audits.

Our content-safety capability is developed in-house, and we do not currently use a third-party content-safety provider. We continually assess automated classification accuracy, bias, false positives and false negatives, and configure human review and escalation according to risk.

We do not promise real-time human monitoring of all content and cannot guarantee detection of all harmful or unlawful content.

High-risk self-harm and suicide signals (confirmed). When the system identifies such signals, we trigger human review and escalation and proactively send intervention information in the conversation. Crisis resources are dynamically matched to the user's region. Human review is currently available only during working hours, not around the clock, so escalations outside working hours may experience delayed human intervention. See also Section 6.5 of the Lomli Terms of Service.

Child sexual exploitation content. We prohibit any sexualized content involving minors. We have internal detection and handling mechanisms for suspected child sexual abuse material (CSAM). Where reporting is legally required, we report to competent authorities or equivalent bodies in accordance with applicable law.

If automated or human review leads to blocking, hiding or deleting content, or restricting, suspending or terminating features or accounts, we will provide the main reasons, the categories of rules applied and available appeal methods, provided this does not compromise safety, fraud prevention, third-party rights or legal investigations. We may withhold details that would endanger others, reveal ways to evade review or be restricted by law.

If you believe a moderation decision is incorrect, appeal through the in-app appeal channel or lomli-service@outlook.com. We commit to responding within 7 days of receiving your appeal. Review is handled by someone uninvolved in the original decision or through an appropriately independent process. If complexity, a need for more materials from you or law requires an extension, we will explain why and provide an expected response time.

9. Analytics, Advertising and Boundaries for Chat Content

9.1 Analytics

Under the current product design, we do not integrate third-party analytics SDKs. We may use our own first-party statistics to understand performance, errors and feature usage. Before enabling those statistics, we will update this Policy or the privacy-preference center to explain their scope and implementation.

If we later integrate a third-party analytics SDK, we will update this Policy before enabling it and obtain prior consent where required by law.

9.2 Advertising

We do not currently display third-party advertisements or conduct cross-context behavioral advertising: advertising based on your activities on other websites or apps. We do not use advertising SDKs, mobile advertising identifiers or similar technologies to track across apps or websites, and do not disclose personal information to advertising partners for advertising purposes. We commit not to use private chats, voice, images, transcripts or long-term memories for any advertising purpose.

9.3 Classification as Sale or Sharing

We do not sell your personal information to third parties. Because we do not currently conduct cross-context behavioral advertising or use behavioral data for remarketing, audience matching or lookalike campaigns, we currently have no activities constituting “sale” or “sharing” as defined by applicable law. If our business changes, we will assess that classification and, where applicable, update this Policy in advance and provide the required notices and opt-outs.

Global Privacy Control (GPC): Since we do not currently conduct cross-context behavioral advertising or sell or share personal information, we do not consider that we currently have sale or sharing activities requiring recognition of a universal opt-out mechanism such as GPC. If our business changes, we will recognize and honor GPC and other opt-out preference signals as required by law and support account-level opt-outs.

9.4 Separation from Private Content

Regardless of technological or business changes, we commit not to use private chat, voice, images, transcripts or memories for advertising or marketing, or provide them to third parties for those purposes.

10. Cookies, SDKs and Similar Technologies

We and our partners may use cookies, software development kits, pixels, local storage, mobile identifiers and similar technologies to:

  • Maintain sign-in, sessions and security;
  • Remember language, privacy and feature preferences;
  • Measure performance, errors and usage;
  • Perform attribution and measure marketing effectiveness;
  • Prevent fraud and abuse.

These technologies fall into these categories:

  • Strictly necessary: Essential for sign-in, security, networking and features you request;
  • Functional: Remember preferences and support enhanced features;
  • Analytics: Help us understand performance and usage. We do not currently use third-party analytics SDKs; statistics use our own first-party capabilities, with scope described in Section 9.1;
  • Advertising or marketing: We do not currently display third-party ads or use advertising SDKs, mobile advertising identifiers or similar technologies for cross-context behavioral advertising; see Section 9.2.

Where consent is required, non-essential technologies are not enabled before you agree. Manage choices through the cookie banner or privacy-preference center in the app or on the website, or use browser or device settings to restrict some technologies. Disabling certain technologies may affect functionality.

A detailed list will be available on our Cookie Policy page or the in-app SDK list, including names, providers, purposes, durations and types.

11. How We Disclose Personal Information

We may disclose personal information in the following circumstances:

11.1 Service Providers and Processors

We may disclose necessary information to suppliers providing cloud hosting, AI inference, voice, images, content safety, analytics, support, email, payment support, fraud prevention, auditing or legal services on our behalf. We limit their processing through contracts and management controls.

11.2 Advertising

We do not currently display third-party advertisements, conduct cross-context behavioral advertising or disclose personal information to advertising partners. If our business changes, we will update this Policy and provide the required choices before such use.

11.3 Third-Party Sign-In, App Stores and Payment Providers

When you choose their services, we exchange with Apple, Google, app stores or payment providers the information necessary for sign-in, subscriptions, purchases, refunds, entitlement synchronization and fraud prevention. They may act as independent controllers for their own activities.

11.4 Affiliates

We may disclose information to affiliated companies as necessary for this Policy's purposes, internal management, safety and technical support, and require protections consistent with this Policy.

11.5 Law, Safety and Protection of Rights

Where we believe in good faith that it is necessary and appropriate, we may disclose information to courts, law enforcement, regulators, government bodies, rights holders or others to:

  • Comply with law, subpoenas, court orders or other valid legal process;
  • Handle emergencies and protect life or personal safety;
  • Investigate fraud, unlawful activity, infringement or rule violations;
  • Establish, exercise or defend legal claims;
  • Protect the rights, safety and property of users, the Company or the public.

We review the legal validity and scope of requests and, where permitted, limit excessive requests or notify users.

11.6 At Your Direction or with Your Consent

When you voluntarily share content, use third-party integrations, join public activities or expressly ask us to disclose information, we act on your instructions. Publicly posted information may be viewed, saved or redistributed by others. Even if we delete public content within the Services at your request, deletion may not cover copies previously downloaded, forwarded, quoted, screenshotted, cached or created on third-party services. Appropriate temporary storage, legal preservation, public interest, freedom of expression or a third-party platform's continuing anti-abuse needs may also limit immediate deletion of all copies. Deleting content or an account does not automatically revoke copies others previously obtained lawfully.

11.7 Aggregate and De-Identified Information

We may disclose aggregate or de-identified information that cannot reasonably identify a person for research, analytics, business and safety purposes. We take reasonable measures against re-identification and require recipients not to attempt it, unless applicable law requires otherwise.

12. Statement on Sale, Sharing and Targeted Advertising

We do not sell personal information for money or share it for cross-context behavioral advertising, remarketing, audience matching or lookalike campaigns. We do not currently display third-party ads, conduct cross-context behavioral advertising, or use user lists or behavioral data for remarketing or lookalike campaigns.

Using user content for promotion: we do not use your user content, including chats, uploaded images or voice, for marketing, promotion or display; see Section 9.3 of the Lomli Terms of Service. If we need to do so in the future, we will obtain separate consent before use.

Global Privacy Control (GPC): Because we do not currently conduct cross-context behavioral advertising or sell or share personal information, we do not consider that there are current sale or sharing activities requiring recognition of GPC. If our business changes, we will recognize and honor GPC and other opt-out preference signals as required by law and support account-level choices.

The Services are only for people aged 18 or older; no minor may use them. We will not sell or share information when we know the person is below the applicable legal age of consent, and will comply with relevant opt-out or prior-consent requirements.

13. Data Retention

We retain personal information only as long as needed for collection purposes, service delivery, user choices, dispute resolution, enforcement of agreements, and legal, safety, tax and audit obligations. Periods depend on the nature of the information, processing purposes, sensitivity, risks and legal requirements.

Retention arrangements are as follows:

Information categoryProposed or applicable retention periodExplanation
Accounts and profilesDuring the account's existence; deleted immediately after account deletionNo recovery window; limited information required by law may be retained
Inactive accountsWhile the account exists, or no longer than necessary for collection purposesContinued retention is periodically assessed under applicable law, account status and safety needs
Chat history and AI-generated contentWhile the user keeps it; 30 days after user deletion or account deletionA grace period for deletion execution and cross-system synchronization, not continued use; any temporary-chat feature should have a separately stated shorter period
Image and voice filesAs needed for the feature; 30 days after user deletion or account deletion, consistent with chat historyThe same period applies to original audio, image files and caches, as well as transcripts and generated results
Characters, preferences and long-term memoriesWhile the account exists or feature is enabled; deleted immediately, in near real time, after user deletionIndividual viewing, editing and deletion are available; disabling long-term memory stops new memories
Safety review, reports and abuse records3 years from case closureSerious illegality, security incidents or repeated violations may justify lawful extensions
Transaction, tax and accounting recordsPeriods required by applicable lawExcludes full payment-card numbers held separately by payment providers
Customer-support records3 years from ticket closureComplex disputes or legal claims may justify lawful extensions
Device, usage and diagnostic logs24 monthsDifferent logs may have tiered retention for security, diagnostic and compliance purposes
Marketing preferences and unsubscribe recordsDuring the relationship and as needed to demonstrate complianceSuppression lists may retain minimal necessary information for an extended period
Data-rights request recordsNo longer than necessary for compliance, fraud prevention and dispute handlingDepends on applicable law and the request
BackupsOverwritten within 180 days on a rolling cycleValid deletion flags are reapplied after restoration
Training data or evaluation sets, including chat, images, voice, transcripts, memories and feedbackNo longer than necessary for training, evaluation, safety validation and legal obligationsDistinguish raw content, de-identified samples, checkpoints and evaluation records; deleting personal information does not automatically retract completed model parameters

When information is no longer needed, we delete, de-identify or isolate it. If immediate deletion is not feasible because of backups, legal preservation or technical limitations, we restrict use and delete it when feasible.

Inactive accounts: During an account's existence, we handle data under the table above and periodically assess continued retention against applicable law, account status, safety needs and minimization. If we intend to delete or irreversibly de-identify data from long-inactive accounts, we give advance notice where required.

The 30-day deletion grace period. Chat history, AI-generated content, image and voice files remain in active systems for no more than 30 days after a user deletes them. This period is solely for deletion execution and retries, synchronization across systems including caches, content delivery and search indexes, safety auditing and tracing accidental deletions. It is not a window for continued business use or model training.

Please note: The 30-day grace period does not apply to completed model-training results. As Section 7 explains, content may have trained Lomli's own models before deletion, and you may opt out of training at any time. A deletion request cannot remove its influence from already completed model parameters.

We align deletion in active systems, caches, content delivery, search indexes, backups and third-party processors with these periods. Where technical or legal reasons prevent immediate deletion, we restrict use and complete deletion when feasible.

14. Information Security

We use technical and organizational safeguards appropriate to the nature and risks of the information.

Confirmed storage environment: Users' personal data, including backups, voice and images, are stored in the Amazon Web Services (AWS) Singapore region, not in mainland China. See Section 15 for cross-border flows.

Confirmed controls:

MeasureConfirmed status
Field-level / column-level encryption for sensitive fieldsImplemented, with separate encryption for sensitive fields
Least privilege and role-based access controlImplemented
Access loggingImplemented
Confidentiality agreements for employees and contractorsSigned
Security and privacy training for employees and contractorsImplemented
Data-breach response processWritten procedures in place, including deadlines for notifying regulators and users
Penetration testing or third-party security auditPlanned, not yet completed
Security certifications, such as ISO/IEC 27001 or SOC 2Planned, not yet obtained

Other measures we may use include authentication, approval for sensitive operations and anomaly monitoring, secure development and vulnerability management, dependency and infrastructure updates, supplier security assessments and contractual protections, backups and business continuity, and minimization, isolation, pseudonymization or de-identification.

We continually assess and improve transmission, storage, access controls, vulnerability management, security testing and supplier management according to risk. This Policy does not mean we hold a particular certification or have completed a particular third-party audit.

No system guarantees absolute security. Use a unique, sufficiently strong password, protect sign-in devices and third-party accounts, and watch for phishing or impersonation. If you suspect unauthorized access to your account or information, contact us immediately through Section 24.

For a personal-data breach requiring notice by law, we will notify affected people and regulators in accordance with applicable law. Our written response procedures include the relevant notification deadlines.

15. International and Cross-Border Data Transfers

Lomli's launch markets are the United States and Canada, excluding Quebec. Quebec and Mexico are not included at launch; opening them will be assessed after French or Spanish versions and local legal reviews are complete. Later expansion will be gradual and global, but mainland China is not currently open.

Your personal information may be transferred to, stored in or processed outside your country or region.

Confirmed data locations and flows:

ItemConfirmed position
User-data storageSingapore, not mainland China
Large language models and image generationOpenAI (GPT), Anthropic (Claude), Google (Gemini): all US providers; requests and outputs are generally processed in the United States
Speech recognition and synthesisFish Audio: operated by a US-incorporated company, Hanabi AI Inc., with an international team; processing locations are specified in our provider list
Cloud providerAmazon Web Services (AWS), Singapore region
Human content reviewTeam in mainland China; see Section 8.2
Transfer instruments, such as standard contractual clauses or a UK addendumNot yet signed
Transfer impact assessment (TIA) or other local assessmentsNot yet started
Representatives and data-protection responsibilities for the EEA, UK or SwitzerlandNone currently designated

Data-protection laws in these locations may differ from those where you live.

Applicable law for cross-border processing: We continually assess the laws governing cross-border transfers and access from abroad, including destination-market rules on outbound data and access by foreign entities. Where required, we implement appropriate measures, including transfer mechanisms, technical and organizational safeguards and compliance procedures. Assessment outcomes and the application of particular measures depend on applicable law and the mechanisms in this section.

15.1 Applicable Transfer Mechanisms

For transfers from the EEA, UK or Switzerland to countries or regions not recognized as providing adequate protection, we select one or more of the following mechanisms where applicable and their conditions are met, based on the data flow, recipient, destination and law:

  • European Commission standard contractual clauses;
  • The UK International Data Transfer Addendum or International Data Transfer Agreement;
  • Adequacy decisions;
  • Applicable certification frameworks or other statutory mechanisms;
  • Necessary supplementary technical and organizational measures, including encryption, minimization and access restrictions.

Confirmed main flows include storage in AWS Singapore; possible processing of language-model and image-generation requests by US providers; voice-service processing at locations specified in the provider list; and access to flagged content by the review team in mainland China. We apply appropriate mechanisms, assessments and supplementary measures according to each flow, destination and applicable law. These instruments are used only where the relevant law applies and their specific conditions are met; not every instrument applies to every cross-border activity.

You may request a copy of applicable transfer safeguards using the contact details in Section 24. Necessary redactions may be made for trade secrets or security.

16. Adults Aged 18 and Older Only

The Services are for people aged 18 or older, not children or minors. You must not create an account or use the Services if under 18, or create an account for a minor.

We do not knowingly collect personal information from anyone under 18. If we become aware of it, we take reasonable steps to investigate and delete the account and information, except limited records needed for safety, legal obligations or proof of deletion.

If you believe someone under 18 has supplied personal information, contact us through the support email or in-app reporting form listed in Section 24, providing enough information to locate the account. We may apply proportionate verification.

We currently use age declaration, once at registration, without documents, selfies, biometrics or third-party age-verification services. Guests may be allowed to browse character or content overviews, but must complete an age declaration before chat, voice or other AI interactions. If we later add assurance measures for legal or risk-management reasons, we will update this Policy in advance and provide legally required notice.

If you believe age-related processing wrongly denied access or restricted your account, request human review through the support email or in-app reporting form in Section 24. We will verify necessary information according to risk and applicable law and explain the outcome within statutory deadlines.

17. Your Global Privacy Choices and Rights

Depending on your location and applicable law, you may have some or all of these rights:

  • Information: Understand how we collect, use and disclose personal information;
  • Access: Obtain your personal information and explanations of processing;
  • Correction: Correct inaccurate or incomplete information;
  • Deletion: Request deletion of your personal information;
  • Restriction: Limit use in particular circumstances;
  • Objection: Object to processing based on legitimate interests, direct marketing or certain automated activities;
  • Portability: Receive information you provided in a structured, commonly used, machine-readable format and, where feasible, transmit it to another controller;
  • Withdrawal of consent: Withdraw consent-based processing at any time;
  • Opt-out: Opt out of legally defined sale, sharing or targeted advertising, and general model training, as described in Section 7.2;
  • Limits on sensitive information: Limit use and disclosure as provided by applicable law;
  • Appeal: Challenge our denial or limitation of a request;
  • Complaint: Complain to a competent data-protection or regulatory authority;
  • Nondiscrimination: Be free from unlawful discrimination or unfair treatment for lawfully exercising privacy rights.

These rights are not absolute. Legal exceptions may allow retention of necessary information, for example to complete transactions, maintain safety, prevent fraud, comply with law or establish, exercise or defend legal claims.

This Policy does not diminish statutory rights. The rights above and other mandatory rights under applicable law are not reduced by this Policy or any contractual arrangement with us. If statutory rights or remedies conflict with contractual or commercial arrangements, mandatory applicable law prevails.

You may also:

  • Change profile, chat and communication preferences, view, edit or delete long-term memories, and disable long-term memory in in-app account settings;
  • Disable microphone, photo, notification, advertising-tracking or other permissions in device settings;
  • Manage non-essential technologies through the cookie or privacy-preference center;
  • Unsubscribe from marketing: Request unsubscribe by support email at any time; see Section 24. Before opening marketing communications in any market, we will provide a directly usable unsubscribe method in each message and support STOP or similar keywords for marketing texts. You may also disable marketing communications in the app's privacy settings;
  • Opt out of general model training: Use in-app settings or contact lomli-service@outlook.com; see Section 7.2.

Materials needed to exercise rights: To protect your information, we may ask for enough information to locate the account and verify the requester. We will not require materials beyond what is necessary.

18. Additional US State Privacy Rights

This section applies to residents granted rights by US state privacy laws. Rights, exceptions, definitions and response deadlines vary by state.

18.1 Categories and Disclosure Overview

In the past 12 months, we may have collected the information in Section 2 within these statutory categories:

  • Identifiers and account information;
  • Customer records and transaction information;
  • Protected characteristics, generally only when voluntarily disclosed;
  • Commercial information;
  • Internet or other electronic-network activity;
  • Approximate geolocation;
  • Audio, electronic or visual information;
  • Professional or education information, generally only when voluntarily disclosed;
  • Preferences or inferences derived from the above;
  • Sensitive personal information, including information private chats may contain.

Sources, uses and recipient categories are described in Sections 2, 4, 6, 8, 9, 11 and 12.

Sale and sharing: We do not sell personal information for money, conduct cross-context behavioral advertising, use behavioral data for remarketing, audience matching or lookalike campaigns, or disclose personal information to advertising partners for those purposes. If our business changes, we will update this Policy and provide the required notices and choices.

18.2 California Residents

To the extent the California Consumer Privacy Act, as amended, applies, California residents may have the right to:

  • Know the categories, sources, purposes and third-party categories involved in collection, use, disclosure, sale or sharing;

  • Request access to specific personal information;

  • Request deletion or correction;

  • Opt out of sale or sharing;

  • Limit certain uses and disclosures of sensitive personal information;

  • Be free from unlawful discrimination for exercising rights.

We will not deny service, charge a different price or provide a different quality of service because you exercise rights, unless a difference is lawfully and reasonably related to the value of your information. If we offer financial incentives or loyalty programs, we will provide a separate processing notice with material terms and obtain applicable consent.

18.3 Residents of Other States

Residents of Colorado, Connecticut, Delaware, Iowa, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Texas, Utah, Virginia and other jurisdictions with effective laws may have rights of access, correction, deletion, portability, opt-out of sale, targeted advertising or profiling with legal or similarly significant effects, and appeal.

We handle requests under the law effective and applicable to us when the request is made. Applicability thresholds and rights differ by state.

18.4 Authorized Agents

Where allowed, you may designate an authorized agent to make a request. We may require proof of authority and ask you to verify your identity or confirm authorization directly. Requests expressed through universal opt-out preference signals are handled under applicable law only where required and the relevant technology is implemented; see Section 12 for technical support.

19. Automated Decisions and Profiling

We may use automated systems to:

  • Recommend characters, reply styles or features;
  • Generate AI content;
  • Detect spam, fraud, safety risks or rule violations;
  • Score risks involving accounts, content or transactions;
  • Decide whether to show particular prompts, restrict features or refer matters for human review.

AI generation and ordinary recommendations generally provide entertainment and personalization, not decisions with legal or similarly significant effects on you.

If we use solely automated processing to make a decision with such effects, we will, where required:

  • Provide meaningful information about the logic, significant factors and potential consequences;
  • Offer human intervention and ways to express your views and challenge the decision;
  • Provide opt-outs from particular profiling;
  • Conduct necessary data-protection or algorithmic impact assessments.

19.1 Confirmed Automated Processing: Product Facts

ScenarioDegree of automationExplanation
Account bans or terminationNot solely automatedAutomated systems may impose only temporary restrictions; final action requires human confirmation
Payment risk controlsAutomatedThe system may identify abnormal transactions and reject, block or require verification
Content restrictionsMay take effect entirely automaticallyThe system may block, hide, downrank or remove content, or restrict particular features
Recommendations and personalizationAutomatedUsed for character recommendations, reply styles and feature presentation

19.2 Explanation of Automation

AI generation and ordinary recommendations generally provide entertainment and personalization, not decisions with legal or similarly significant effects.

Automated decisions: We may use automated systems for content-safety classification and payment-risk controls. Content may therefore be removed, hidden or restricted before human intervention, and a transaction may be declined or require extra verification. For decisions with potentially significant effects, such as account termination, we retain human confirmation and provide explanations and appeal routes.

19.3 Human Review

If you challenge an automated action, request human review through the in-app appeal channel or lomli-service@outlook.com.

Independent review: For content restrictions, account actions and age-related decisions, we commit to using personnel not involved in the original decision or an appropriately independent process and explaining escalation routes. Where required, we will also provide external dispute-resolution channels.

Where required by law, we provide human intervention, opportunities to express your views and challenge solely automated decisions with significant effects, and rights to opt out of certain profiling.

20. Deleting an Account or Making a Data Request

20.1 Account Deletion

Deleting an account or personal information and opting out of general model training under Section 7 are separate mechanisms. Account deletion does not automatically replace a training opt-out; opting out does not automatically delete the account, past conversations or other information. You may make both requests separately.

You may request deletion by:

  1. Using Delete Account in the app's account settings; or
  2. Emailing the support address in Section 24, which also accepts privacy requests; or
  3. Using the in-app reporting form.

Account deletion normally starts deletion of associated personal information, but we may lawfully retain limited information needed to complete transactions, process refunds, meet financial or legal obligations, protect safety, prevent fraud or resolve disputes. Uninstalling the app does not itself delete your account or server-side data.

Deletion timing: accounts and profiles are deleted immediately after account deletion, without a recovery window or cooling-off period; see Section 13. Characters, preferences and long-term memories are deleted immediately, in near real time, after user deletion. Chat history, AI-generated content, image and voice files remain in active systems for no more than 30 days after user deletion, solely for deletion execution, cross-system synchronization and safety auditing. Backup copies are overwritten within a rolling cycle of no more than 180 days.

Store subscriptions must be canceled through the original purchase channel. Deleting a Lomli account does not automatically cancel subscriptions managed by the Apple App Store or Google Play.

20.2 Other Data Requests

For access, correction, deletion, portability, restriction, objection, opt-out or appeal requests, provide:

  • The right you wish to exercise;
  • The email address, user ID or other information sufficient to locate the account;
  • Your country, state or region;
  • Other limited information necessary to handle the request.

Do not send identity documents by ordinary email unless we expressly request them and provide a secure upload method.

20.3 Data Export and Portability: Confirmed

Self-service export is available in the app. You can export account data without contacting support. Confirmed arrangements are:

ItemConfirmed position
Export methodIn-app self-service export
FormatCSV
ScopeAccount details and preferences; chats and AI-generated content; long-term memories; uploaded images; voice files and transcripts; transaction records

When exporting:

  • Exports may contain highly sensitive information, such as voice files, transcripts and sensitive disclosures. Keep files secure and avoid storing or forwarding them in uncontrolled environments;
  • Exports include only data under your own account. If other users' content is present, we make necessary redactions or exclusions;
  • CSV is tabular and suitable for structured fields. We use encoding that supports multiple languages and reasonably separate nested content such as chat history and memories into tables. Images and voice files may be supplied separately or in an archive to ensure complete, readable exports.

See Section 17 for export and portability methods, formats and scope. If export is unavailable or fails, request assistance through Section 24.

20.4 Identity Verification

To protect your information, we verify identity proportionately to the request's risks, for example by:

  • Asking you to confirm from a verified email address;
  • Requiring account sign-in or confirmation of a one-time code;
  • Comparing limited account information we already hold;
  • Requesting additional evidence for high-risk requests.

Verification materials are used only for verification and fraud prevention, and deleted or retained on a restricted basis under applicable law. If we cannot reasonably verify identity, we may request more information or deny the request with reasons.

20.5 Response Times

  • For EEA and UK requests, we normally respond within one month of receiving a valid request. For complexity or volume, we may lawfully extend by two months and explain the extension within the first month.
  • For US state requests, we normally respond within 45 days. Extensions may be made where permitted, with an explanation. If a state sets a different period, that law governs.
  • Elsewhere, we respond within applicable statutory deadlines.

Requests are normally free. For manifestly unfounded, repetitive or excessive requests, we may charge a reasonable fee or refuse handling where lawful.

20.6 Appeals

If we deny your request, appeal after receiving the decision through the support email or in-app reporting form in Section 24, stating the original request number and reasons. We respond within statutory deadlines. If the appeal is also denied, we provide ways to complain to a state attorney general, data-protection authority or other regulator where required.

21. Business Transfers

If the Company is involved in or considers a merger, acquisition, financing, restructuring, bankruptcy, asset sale, change of control or similar transaction, personal information may be disclosed or transferred in due diligence or as part of transaction assets.

We take reasonable steps to require recipients to handle it under this Policy and applicable law. If they plan materially different processing, we provide notice and obtain consent or offer choices where required. If the transaction does not proceed, potential counterparties and advisers remain bound by confidentiality and use restrictions.

22. Changes to This Policy

We may update this Policy to reflect product, technology, legal or business changes. We change the “Last updated” date and notify you appropriately, for example through in-app notices, website announcements, email or other prominent messages.

For changes with significant effects on your rights or how we process information, we provide more prominent notice before they take effect and obtain consent where required. Unless law permits, we do not retroactively apply material changes to previously collected information.

Notice period and acceptance: Material changes are also subject to the 30-day advance notice period in Section 21.2 of the Lomli Terms of Service. For consent-based processing, such as future new marketing communications, continued use after notice does not constitute consent to the new processing. If changes introduce or expand that processing, we obtain separate explicit consent and do not begin it beforehand.

We recommend reviewing this Policy periodically.

23. Contact Us

For questions, complaints or requests about this Policy, our processing or your privacy rights, contact:

  • Data controller: HYPERGAME TECHNOLOGY LIMITED
  • Registered address: UNIT B604W ON 6/F., BLK B, CHUNG MEI CENTRE, 15 HING YIP STREET, KWUN TONG HONG KONG (the Chinese rendering is for reference only; the English registered address prevails)
  • Support email, also accepting privacy requests: lomli-service@outlook.com
  • In-app reporting: An in-app reporting form is available alongside the email channel
  • Written notices: We primarily receive notices and requests electronically, using the support email above. If you need to serve legal documents by post, you may request a postal address that accepts legal service through that email.

Request channels (confirmed): Support email is our common intake channel for privacy requests and legal notices: lomli-service@outlook.com. Include “Privacy Request” or “Legal Notice” in the subject and specify the request type. Do not send unrelated sensitive information.

How to submit: Send privacy requests, legal notices and complaints to lomli-service@outlook.com or through the in-app reporting/request form. We respond within statutory deadlines, generally no more than 30 days. For complex or numerous requests, we may extend as permitted by law and tell you the new deadline.

24. Other Contact and Applicability Notes

Read this Policy together with supplementary privacy notices for particular features or regions. If a supplement differs about the same processing activity, the more specific notice governs unless applicable law requires otherwise.

For Canadian users outside Quebec, we may provide a regional supplement explaining notice, consent, international transfers, rights and regulatory complaints under PIPEDA and provincial privacy rules. Quebec and Mexico are not included at launch. Before opening them, we will separately assess and provide required local-language versions and regional supplementary notices.

Existing compliance gaps in launch markets (confirmed). Data are stored in Singapore, while human reviewers are located in mainland China. The following matters therefore require completion before launch in the United States and Canada, excluding Quebec:

  • Canadian PIPEDA, applying to Canada outside Quebec in the launch scope: Cross-border transfers must still receive comparable protection, and a privacy officer accountable for compliance must be designated. No such person has yet been designated.
  • Quebec Law 25, a prerequisite for later opening Quebec, which is excluded from launch: A privacy impact assessment must be completed before transferring personal information outside Quebec. It must consider sensitivity, purposes, safeguards and protection under the destination's legal framework, with storage in Singapore and reviewers in mainland China. Users must be told the transfer destination, Singapore, and the location of foreign access, mainland China. Quebec also requires a person responsible for personal-information protection whose role and contact details are public. This work has not yet started.

These obligations have legal bases distinct from EEA, UK or Swiss transfer mechanisms and cannot replace one another. Opening Quebec and Mexico also requires local legal review and the relevant French and Spanish versions; see Section 25.1.

25.1 Language Versions and Localization: Confirmed

The confirmed language arrangements for this Policy and supporting documents are:

ItemConfirmed position
Planned languagesSimplified Chinese and English, two languages
Languages at launchChinese and English only
Translation methodCommissioned translation only; no back-translation verification
Local counsel reviewNot planned
Interface languagesInconsistent: the app currently offers English and Chinese only

Language requirements for launch and later markets; facts updated September 28, 2026. The launch markets are the United States and Canada, excluding Quebec, covered by Chinese and English launch texts. Quebec and Mexico have been removed from the launch scope. Both have mandatory language requirements that are prerequisites for later opening:

  • Quebec, a prerequisite for later opening: Quebec's Charter of the French Language requires privacy policies and related notices for Quebec consumers in French, with Law 25 further reinforcing French-language use and transparency. Without a French version, this Policy may be considered insufficient to fulfill statutory notice obligations to Quebec users, affecting the effectiveness of transfer notices and privacy impact assessments. This must be completed together with the Quebec privacy impact assessment in Section 25.
  • Mexico, a prerequisite for later opening: Privacy notices and international-transfer notices under the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) and its regulations generally must be provided in Spanish. English-only notices may not be recognized as effective, affecting the commencement of ARCO rights and the basis for consent.
  • United States and Canada, the launch scope: English can cover the launch markets. However, if Chinese controls as stated in Section 25 of the Terms of Service, differences in meaning between versions may be alleged to be inconsistent disclosure. The issue of Chinese as the controlling language affecting transparency and valid consent in English-speaking markets remains despite removing Quebec and Mexico from launch. It is a residual issue requiring US/Canadian counsel confirmation and must not be omitted.

Unaddressed mitigations, confirmed: Without back-translation, translation accuracy lacks independent verification. Without local legal review, the adequacy of disclosures in launch markets, the United States and Canada outside Quebec, and later markets, Quebec and Mexico, has not been locally validated.

Conclusion: Chinese and English cover the launch markets, the United States and Canada outside Quebec, without a territorial requirement for French or Spanish there. Before reintroducing Quebec or Mexico, the required languages (French for Quebec, Spanish for Mexico), back-translation verification and local legal review must be completed. Until then, this Policy should not be launched in Quebec or Mexico.

For an accessible format, past versions or questions about processing in a specific feature, contact us using Section 24. We update these explanations with product, technology and legal changes and provide prominent notices where required.