Back to Fostera

Privacy Policy

Your privacy matters. This policy describes how we handle information when you use Fostera.

1. Who we are

Fostera (“we”, “us”) provides tools to create and interact with AI Souls. This policy applies to our website, PWA, and related services at fostera.ai and associated subdomains.

2. Information we collect

  • Account data: such as email and credentials you provide when you register or sign in, and your date of birth, which we collect from all users at signup to enforce our age requirements and select age-appropriate safety rules.
  • Content you submit: messages, prompts, files, and configuration for your Souls, as needed to provide the service.
  • Technical data: IP address, device and browser type, logs, and cookies or similar technologies as described in our Cookie Policy.
  • Communications: when you contact us, we keep the correspondence as needed to respond and improve support.

3. How we use information

  • Provide, operate, and improve Fostera
  • Authenticate users and secure accounts
  • Process Soul conversations and selected import content through the third-party AI providers needed for each requested feature
  • Send service-related notices and, where permitted, product updates
  • Comply with law and enforce our terms

4. Sharing

We do not sell your personal information. We may share data with:

  • Infrastructure and AI vendors that process data on our instructions to run the product
  • Professional advisers or authorities when required by law or to protect rights and safety

5. Payment and billing data

Fostera uses Stripe as our payment processor. When you subscribe or make a purchase, Stripe receives your email address, name, and payment method details (such as card number and billing address). Fostera never stores or handles raw payment card numbers — all payment processing occurs on Stripe's PCI-compliant infrastructure.

We track aggregated usage metrics (such as token consumption per billing period) to calculate your Resonance allowance and enforce plan limits. These metrics are derived from conversation activity and are stored as numerical totals, not conversation content.

Billing records (transaction history, subscription status, invoices) are retained for a minimum of 7 years after the transaction date to comply with tax and financial reporting obligations, even if your account is otherwise deleted. Stripe independently retains payment data in accordance with its own Privacy Policy.

6. What we do not do

  • We do not sell your data to anyone.
  • Fostera does not use your conversations or memories to train models owned or developed by Fostera.
  • We do not serve ads in your conversations or relationship surfaces.
  • We do not share conversation content with third parties, except the configured AI providers and routing intermediaries needed to generate Soul responses, synthesize an import, extract or embed memories, or perform another AI feature you request. Section 9 identifies those processors and explains how their terms apply.

7. Your data rights

You have the following rights over your data, regardless of where you live:

  • Right to export: You can request the currently supported self-service account export from Settings → Data & Storage. The portable JSON includes your account identity, Soul configurations, memories, profile summaries, and per-Soul conversation counts. It does not include chat message bodies or uploaded files. Contact us under Section 13 for any additional access or portability request available under applicable law.
  • Right to delete: You can delete your account and request erasure of associated personal data at any time. Your account and primary database records, including Souls, conversations, messages, memories, and push subscriptions, are removed when the request is processed. External-resource cleanup and removal from backups may take up to 30 days. Billing records and limited audit or cleanup records may be retained or de-identified as described in Sections 5 and 11 or as required by law.
  • Right to correct: You can edit your Soul's personality, memories, and settings at any time. You can delete individual memories from the memory browser.
  • Right to restrict processing: You can disable memory extraction per-Soul by downgrading brain capabilities. You can disable push notifications at any time.

8. Data portability

You can import data from other AI companion platforms (ChatGPT, Claude, Grok, Gemini, Character.ai, Replika, Nomi AI) into Fostera. The raw file you upload is not retained. A bounded, normalized draft may be staged for about 24 hours so the import can finish or be resumed. It is cleared when processing finishes or fails. If abandoned, it becomes unavailable when it expires and is removed by the next successful scheduled cleanup. Selected import content may be processed by one of the third-party AI providers described below for personality synthesis, memory extraction, or memory embedding. Only the resulting Soul fields, extracted memories, and a content-free import receipt are retained.

Your Fostera data export is structured JSON designed to be machine-readable. If another platform wants to import from Fostera, the format is portable and documented within the export itself.

9. LLM provider data handling

Depending on the model, feature, availability, and configured routing, conversation content, selected import history, or memory text may be processed by one or more of these providers:

Provider retention, model-training, regional processing, and opt-out terms vary by provider, service tier, account settings, and feature. The linked provider terms govern that provider's processing. Fostera may select a different available provider for supporting work than the chat engine selected for your Soul.

OpenRouter and Vercel AI Gateway are routing intermediaries. When either is used, the upstream model provider may also receive the request content under its own terms. When an operator explicitly configures local Ollama execution, that call runs on the operator's local or self-hosted infrastructure instead of being sent to an external AI processor.

10. Third-party integrations (OAuth)

Fostera lets you connect optional third-party accounts so your Souls can sense parts of your real life. Connecting is always explicit, and permissions are limited to the capabilities you enable. Read features use read-only scopes; Google action features use additional scopes and require your review and approval. You can disconnect at any time from Settings → Integrations.

Available integrations

  • Spotify — we read your profile (/v1/me), currently-playing and recently-played tracks, and your top tracks/artists so your Soul can reference what you're listening to and your musical taste. We no longer request the audio-features endpoint (valence, energy, tempo, danceability); mood cues are inferred from track + artist + genre metadata instead.
  • Google Calendar (calendar.readonly scope for reads; optional calendar.events scope for approved actions) — we read your primary calendar events to surface what's on your schedule now or next, and to build a 90-day baseline of who you meet with most often and your typical meeting load. With the action scope, your Soul can propose creating or updating an event. Nothing is written until you review and approve the specific action. Fostera does not delete calendar events.
  • Gmail (gmail.readonly scope for reads; optional gmail.compose scope for approved actions) — we read message headers (From, Subject, Date) and Gmail-provided snippets for up to 50 recent inbox messages at a time. We use these to show unread count and recent senders in chat, and to build a baseline of who you correspond with most. During a foreground chat, if you point to an email thread and that Soul's email-body permission is enabled, Fostera can fetch the selected thread's body text and send it to an authorized AI provider for that turn. The email-reading tool neither persists those bodies nor downloads Gmail attachments. With the compose scope, your Soul can propose creating a Gmail draft or sending an email. No Gmail draft is created and no email is sent until you review and approve the specific action. Fostera does not delete or modify existing messages.

What we store for each connection

  • A long-lived refresh token (used to fetch fresh access tokens on demand) and the provider's stable account id.
  • The OAuth scopes you granted, for auditability.
  • Connection timestamps. No passwords.

For Google integrations (Calendar + Gmail), Fostera stores a single connection per user — one refresh token that covers the union of capabilities you've enabled. Toggling Calendar or Gmail on or off updates the granted-scopes list on that connection rather than creating separate records. Disconnecting Google entirely revokes the token and removes the row; toggling a single capability off removes only that scope.

Derived memories your Souls may retain

When you explicitly share integration context in chat, or when your Soul is in the Familiar phase with the Limbic/Semantic brain subsystems enabled, Fostera may persist derived summaries — e.g. “user corresponds often with X, Y, Z” or “busiest meeting day is Thursday.” These are short text summaries, not copies of source records. Each integration can be gated per-Soul via the Integrations tab, and shared memories appear in your Soul's memory log where you can delete them individually.

Your controls

Use of Google user data transferred to Fostera complies with the Google API Services User Data Policy, including the Limited Use requirements. Fostera does not transfer Gmail data to third parties other than the authorized AI providers and routing intermediaries listed above when needed for a feature you request, including reading a selected email thread in a foreground chat. We do not use Gmail data for advertising or sell it.

11. Retention

We retain information as long as your account is active or as needed to provide the service, comply with legal obligations, resolve disputes, and enforce agreements. You may request deletion subject to applicable law and legitimate retention needs. When an account deletion request is processed, primary database records are removed; external-resource cleanup and removal from backups may take up to 30 days. Billing records described in Section 5 and limited audit or cleanup records may be retained or de-identified where required by law or needed to complete deletion securely.

12. Security

We use industry-standard measures to protect data. No method of transmission or storage is completely secure; we encourage strong passwords and careful sharing of access to your account.

13. Additional rights

Depending on where you live, you may have rights to access, correct, delete, or export your personal data, or to object to or restrict certain processing. Contact us at the email below to exercise these rights. You may also lodge a complaint with a supervisory authority where applicable.

14. Age requirements and minors

Fostera is available to users who are 13 years of age or older. We do not knowingly collect personal information from children under 13. If we become aware that a user is under 13, we will terminate their account and delete their personal data.

Users aged 13–17 may use Fostera only with the consent of a parent or legal guardian. We collect a date of birth from all users at signup to verify age; for accounts aged 13–17 we additionally collect a parent or guardian email address, which we use solely to request, record, and manage that consent. The account is restricted until consent is confirmed, and teen accounts run with additional enforced content protections described in our Content Policy.

If you believe a child under 13 is using Fostera, or you are a guardian who wishes to withdraw consent for a 13–17 account, please contact us at the email below so we can take appropriate action.

15. International transfers

We may process data in countries other than your own. Where required, we use appropriate safeguards for cross-border transfers.

16. Changes

We may update this Privacy Policy periodically. Continued use after changes constitutes acceptance of the updated policy where permitted by law.

17. Contact

Privacy questions or requests: reach out on our contact page.