App: My · Last updated: 12 May 2026 · Effective: 12 May 2026
This Privacy Policy explains how Federico G. Ramos (“we”, “us”, “our”) processes personal data in connection with the iOS application My (the “App”). We are committed to protecting your privacy and to complying with the Argentine Personal Data Protection Law (Ley 25.326) and, where applicable to users located in the European Economic Area, the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”).
1. Data Controller
The data controller responsible for the processing of your personal data is:
Postal address available on written request to the email above.
2. Scope and Principles
My is an AI companion app that lets you create a single AI persona (such as a friend, partner, or mentor) that exchanges text messages with you. The App is designed with privacy by default: it does not require an email, name, phone number, or any other identifying account credential, and your conversations are stored only on your device. We process the minimum personal data necessary to operate the App, and we do not sell, rent, or trade personal data to any third party.
3. What Data We Process
3.1 Data stored on your device
The following information is stored locally on your iPhone or iPad using Apple's SwiftData and UserDefaults frameworks, and is not uploaded to any server we operate:
Your chat messages with the persona (both your messages and the assistant's replies).
Images generated during chat conversations.
The persona's keyword-indexed memory used to personalise replies.
A local copy of the persona descriptor (name, traits, voice selection, etc.).
App preferences such as theme accent and notification settings.
This data never leaves your device unless you explicitly choose to share it (for example, by sending a screenshot or by emailing us a transcript with a support request).
3.2 Data stored on our backend
To operate the persona-creation, persona-image, push-notification, and subscription features, the App stores a limited amount of data on a backend hosted on Google Firebase, scoped to an anonymous identifier described in §3.3:
Persona descriptor — the persona's name, traits, age group, voice ID, and similar configuration values you enter during onboarding. We need a server copy because some derived assets (for example a cloned voice) are produced and managed server-side.
Persona reference, portrait, and full-body images — used as a visual blueprint to keep the persona consistent across future image generations. These are images of a fictional persona that you co-design; they do not depict you.
A credit balance — a single integer used to meter premium features.
An Apple Push Notification (APNs) / Firebase Cloud Messaging token, paired with your anonymous identifier, used solely to send proactive in-app notifications when enabled.
A subscription entitlement record indicating whether your StoreKit subscription is currently active and, where available, when it expires.
Your device's IANA time-zone identifier (for example, America/New_York or Europe/Madrid) — read from iOS using the standard TimeZone.current.identifier API, with no use of GPS, Wi-Fi positioning, or the iOS location-services permission. We use it server-side to (a) decide whether the persona's "today" has rolled over for daily-image and daily-outfit budgets, and (b) include the local time of day in the prompt sent to the AI provider so the persona's tone matches your part of the day. The IANA identifier embeds the name of a nearby major city; this name is included in the model context. We treat this as approximate, city-level location information. We do not store finer-grained coordinates and do not derive your precise location from this value.
Your chat messages, your local persona memory, and any chat-time images are not uploaded to this backend.
3.3 Anonymous authentication
The App signs you in to the backend using Firebase Anonymous Authentication. This produces a random user identifier (a “UID”) that is generated on the device and bound to your install. We do not collect your email, name, phone number, Apple ID, or any social identity in connection with this UID. If you uninstall the App or invoke “Delete my data” from in-app Settings, the UID and all server-side data associated with it are removed.
3.4 Data sent to AI service providers via our cloud functions
To produce the persona's replies, generate persona and chat images, and run safety checks on text you send, our cloud functions forward certain data, on your behalf, to third-party AI providers as our processors:
Your chat input and a short, on-device-built context window (recent messages, persona traits, and your device's IANA time-zone identifier as described in §3.2) are sent to OpenAI to generate the assistant's reply, and to OpenAI's moderation endpoint to screen text for prohibited content. Because the IANA identifier embeds the name of a nearby major city, the persona may occasionally reference your general area in conversation. The persona is never given your street address, GPS coordinates, IP address, or any finer-grained location signal.
Image-generation prompts (and, for persona images, the persona reference sheet stored on our backend) are sent to Replicate and/or OpenAI to produce the resulting image.
These providers process data only to perform the requested operation. Generated outputs are returned to our cloud functions, then to your device. Where supported, we configure these providers to not use your data to train their models.
3.5 Device permissions
Camera (optional): if you choose to send a photo to your persona from within a chat, iOS will prompt for camera permission. Photos taken this way are used to compose the chat message; they are stored locally with the rest of your conversation and are not uploaded to our servers.
Notifications (optional): if you allow notifications, the App registers a push token with our backend so the persona can send proactive messages. You can revoke this permission at any time in iOS Settings.
3.6 Data we do not collect
We do not require an email, name, phone number, social login, or any personally identifying account.
We do not use third-party analytics, telemetry, advertising, or attribution SDKs.
We do not use cookies, tracking pixels, or similar technologies.
We do not collect the IDFA, do not show the App Tracking Transparency prompt, and do not perform cross-app or cross-site tracking.
We do not request the iOS location-services permission (no GPS, no Wi-Fi positioning, no Significant Location Change). The only location-adjacent signal we read is your device's IANA time-zone identifier, which is treated as approximate, city-level information and is described in §3.2 and §3.4.
We do not access your contacts, calendar, microphone, photo library, or files outside the App's sandbox.
We do not synchronise your conversations through iCloud or any other cloud service operated by us. (If you have enabled iCloud Backup on your device, iOS itself may include the App's local data in your personal device backup; that backup is governed by Apple's privacy practices, not ours.)
4. Legal Basis for Processing
Under Article 5 of the Argentine Personal Data Protection Law (Ley 25.326) and, where applicable to users in the EU/EEA, Article 6(1) GDPR, we rely on the following legal bases:
Performance of a contract (Art. 6(1)(b) GDPR / consent to use the App under Ley 25.326): processing necessary to provide the core persona-creation, conversational, image-generation, push-notification, and subscription features that you have chosen to install and use.
Legitimate interests (Art. 6(1)(f) GDPR): maintaining minimal server-side state (anonymous UID, credit counter, subscription entitlement) needed to meter usage, prevent abuse, and run safety / content moderation checks on text submitted to the App.
Legal obligations (Art. 6(1)(c) GDPR / Art. 5 Ley 25.326): where applicable, to comply with our obligations under Argentine and, where relevant, EU law.
5. How We Use Information
Any data processed in connection with the App is used exclusively to:
Provide and maintain the App's features (persona creation, persona image generation, conversational replies, in-context image generation, content moderation, push notifications, subscription metering).
Preserve your conversations, persona, and preferences between sessions on your device.
Diagnose and resolve technical issues strictly based on information you choose to share with us by email.
6. Data Sharing and Third Parties
We do not sell or share personal data for advertising or profiling. The App relies on the following third-party services, acting either as our processors or as independent controllers as indicated:
Apple Inc. / Apple Distribution International Ltd. — operator of the App Store, the iOS platform on which the App runs, the Apple Push Notification service, and StoreKit in-app purchase processing. Apple acts as an independent controller for the services it provides to you. Its handling of this data is governed by the Apple Privacy Policy.
Google LLC / Google Cloud EMEA Ltd. (Firebase) — provides Anonymous Authentication, Cloud Firestore, Cloud Functions, Cloud Storage, and Firebase Cloud Messaging used to host the limited backend described in §3.2 and §3.3. Acts as our processor. Governed by the Firebase Privacy and Security documentation.
OpenAI, L.L.C. — invoked from our cloud functions to generate the persona's text replies and to perform content-moderation safety checks; also used for image generation in some flows. Acts as our processor. Governed by the OpenAI Privacy Policy.
Replicate, Inc. — invoked from our cloud functions to generate persona and in-chat images. Acts as our processor. Governed by the Replicate Privacy Policy.
We do not engage any other processor, analytics provider, advertising network, or attribution service.
7. International Transfers
Our backend providers (Google, OpenAI, Replicate, Apple) are based in the United States and may process data in the United States and other jurisdictions outside Argentina and the European Economic Area. Where required, transfers of personal data from the EEA are protected by the Standard Contractual Clauses adopted by the European Commission (Decision (EU) 2021/914), and by additional safeguards offered by each provider. Argentina has been recognised by the European Commission as providing an adequate level of data protection (Decision 2003/490/EC). Apple's, Google's, OpenAI's, and Replicate's own handling of the data is further governed by their respective privacy policies and safeguards.
8. Data Retention
Data stored locally on your device (chat messages, generated chat images, persona memory, persona descriptor, preferences) is retained for as long as you keep the App installed or choose to keep that data. You can delete it from within the App at any time, or remove all of it by uninstalling the App.
Server-side data (anonymous UID, persona descriptor, persona images, credit counter, push token, subscription entitlement) is retained for as long as your install is active. When you invoke “Delete my data” from in-app Settings, all server-side data scoped to your UID is removed and the App's local store is wiped.
Data sent to OpenAI and Replicate to fulfil a single request is processed transiently to produce the response. Where these providers retain short-term operational logs (for example for abuse prevention), retention is governed by their own policies.
Correspondence you send to us (for example, support emails) is retained only for as long as necessary to handle your request, and typically no longer than 24 months.
9. Security
We apply appropriate technical and organisational measures to protect personal data, including iOS app sandboxing, TLS / HTTPS encryption in transit between the App and our backend and between our backend and our AI processors, encryption at rest in Firebase, scoping of all server-side reads and writes to your anonymous UID via Firebase Security Rules and per-call authentication of cloud-function invocations, and storage of third-party API credentials only in Google Secret Manager (never in the iOS App). No method of electronic storage or transmission is entirely secure; however, we continuously work to apply industry-standard safeguards.
10. Your Rights
Subject to the conditions set out in the Argentine Personal Data Protection Law (Ley 25.326) and, where applicable, the GDPR, you have the right to:
Access the personal data we hold about you (Art. 14 Ley 25.326 / Art. 15 GDPR).
Request rectification of inaccurate or incomplete data (Art. 16 Ley 25.326 / Art. 16 GDPR).
Request erasure of your personal data (Art. 16 Ley 25.326 / Art. 17 GDPR).
Object to or request restriction of processing (Art. 27 Ley 25.326 / Arts. 18, 21 GDPR).
Data portability, where applicable (Art. 20 GDPR).
Withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of prior processing.
Because most of the data processed by My is stored on your device, exercising these rights in practice often means using the App's own controls (clear individual messages, clear all conversations, regenerate persona images, or invoke “Delete my data” from Settings) or simply uninstalling the App. For any request concerning data we may hold directly (for example, your support correspondence or any residual server-side records), please contact us using the details in Section 13.
11. Supervisory Authority
If you believe that our processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with a supervisory authority. The competent authority in Argentina is:
Agencia de Acceso a la Información Pública (AAIP)
Av. Pte. Gral. Julio A. Roca 710, Piso 2
C1067ABP, Ciudad Autónoma de Buenos Aires, Argentina
Users in the EU/EEA may also lodge a complaint with the national supervisory authority of their place of residence, place of work, or place of the alleged infringement.
12. Children's Privacy
My is intended for users aged 18 and over. The App enforces an age gate during onboarding and is not directed at children under 18. We do not knowingly process personal data from anyone under 18. If you believe a person under 18 has provided personal data to us (for example, by email), please contact us so we can take appropriate action, including deletion of that data.
13. Contact Us
For any questions, requests, or complaints regarding this Privacy Policy or the processing of your personal data, please contact:
We may update this Privacy Policy from time to time to reflect changes in the App, our practices, or applicable law. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice within the App. We encourage you to review this page periodically.