Back to Fostera

Privacy Policy

Your privacy matters. This policy describes how we handle information when you use Fostera.

1. Who we are

Fostera (“we”, “us”) provides tools to create and interact with AI Souls. This policy applies to our website, PWA, and related services at fostera.ai and associated subdomains.

2. Information we collect

  • Account data: such as email and credentials you provide when you register or sign in.
  • Content you submit: messages, prompts, files, and configuration for your Souls, as needed to provide the service.
  • Technical data: IP address, device and browser type, logs, and cookies or similar technologies as described in our Cookie Policy.
  • Communications: when you contact us, we keep the correspondence as needed to respond and improve support.

3. How we use information

  • Provide, operate, and improve Fostera
  • Authenticate users and secure accounts
  • Process conversations with Souls through our and, where you configure them, third-party AI providers
  • Send service-related notices and, where permitted, product updates
  • Comply with law and enforce our terms

4. Sharing

We do not sell your personal information. We may share data with:

  • Infrastructure and AI vendors that process data on our instructions to run the product
  • Professional advisers or authorities when required by law or to protect rights and safety

5. Payment and billing data

Fostera uses Stripe as our payment processor. When you subscribe or make a purchase, Stripe receives your email address, name, and payment method details (such as card number and billing address). Fostera never stores or handles raw payment card numbers — all payment processing occurs on Stripe's PCI-compliant infrastructure.

We track aggregated usage metrics (such as token consumption per billing period) to calculate your Resonance allowance and enforce plan limits. These metrics are derived from conversation activity and are stored as numerical totals, not conversation content.

Billing records (transaction history, subscription status, invoices) are retained for a minimum of 7 years after the transaction date to comply with tax and financial reporting obligations, even if your account is otherwise deleted. Stripe independently retains payment data in accordance with its own Privacy Policy.

6. What we do not do

  • We do not sell your data to anyone.
  • We do not use your conversations to train AI models.
  • We do not serve ads in your conversations or relationship surfaces.
  • We do not share conversation content with third parties, except the LLM providers that process your messages to generate Soul responses (Google/Gemini, OpenAI, Anthropic, xAI/Grok — depending on your engine configuration). Each provider's API data usage policy states that API inputs are not used for model training.

7. Your data rights

You have the following rights over your data, regardless of where you live:

  • Right to export: You can download all your data at any time from Settings → Data & Storage. The export includes all Souls, conversations, memories, and account metadata in a portable JSON format.
  • Right to delete: You can permanently delete your account and all associated data at any time. Deletion cascades to all Souls, conversations, messages, memories, and push subscriptions. All data is removed from our systems within 30 days, including backups.
  • Right to correct: You can edit your Soul's personality, memories, and settings at any time. You can delete individual memories from the memory browser.
  • Right to restrict processing: You can disable memory extraction per-Soul by downgrading brain capabilities. You can disable push notifications at any time.

8. Data portability

You can import data from other AI companion platforms (ChatGPT, Claude, Grok, Gemini, Character.ai, Replika, Nomi AI) into Fostera. Imported data from other platforms is processed in memory during import and not stored in raw form — only synthesized personality fields and extracted memories are persisted.

Your Fostera data export is structured JSON designed to be machine-readable. If another platform wants to import from Fostera, the format is portable and documented within the export itself.

9. LLM provider data handling

Conversations are processed by third-party LLM providers to generate Soul responses. The providers we may use include:

  • Google (Gemini) — API inputs are not used for model training
  • OpenAI — API data is not used for training by default
  • Anthropic (Claude) — API inputs are not used for model training
  • xAI (Grok) — subject to their API data usage policy

Memory extraction uses the same providers with the same data handling policies. Your engine configuration determines which provider processes your conversations.

10. Third-party integrations (OAuth)

Fostera lets you connect optional third-party accounts so your Souls can sense parts of your real life. Connecting is always explicit, always read-only where possible, and you can disconnect at any time from Settings → Integrations.

Available integrations

  • Spotify — we read your profile (/v1/me), currently-playing and recently-played tracks, and your top tracks/artists so your Soul can reference what you're listening to and your musical taste. We no longer request the audio-features endpoint (valence, energy, tempo, danceability); mood cues are inferred from track + artist + genre metadata instead.
  • Google Calendar (calendar.readonly scope) — we read your primary calendar events to surface what's on your schedule now or next, and to build a 90-day baseline of who you meet with most often and your typical meeting load.
  • Gmail (gmail.readonly scope, Google-designated sensitive scope) — we read message headers (From, Subject, Date) and Gmail-provided snippets for up to 50 recent inbox messages at a time. We use these to show unread count and recent senders in chat, and to build a baseline of who you correspond with most. We do not read, store, transmit, or train on email bodies or attachments. Access is read-only — Fostera cannot send, delete, or modify any email.

What we store for each connection

  • A long-lived refresh token (used to fetch fresh access tokens on demand) and the provider's stable account id.
  • The OAuth scopes you granted, for auditability.
  • Connection timestamps. No passwords.

For Google integrations (Calendar + Gmail), Fostera stores a single connection per user — one refresh token that covers the union of capabilities you've enabled. Toggling Calendar or Gmail on or off updates the granted-scopes list on that connection rather than creating separate records. Disconnecting Google entirely revokes the token and removes the row; toggling a single capability off removes only that scope.

Derived memories your Souls may retain

When you explicitly share integration context in chat, or when your Soul is in the Familiar phase with the Limbic/Semantic brain subsystems enabled, Fostera may persist derived summaries — e.g. “user corresponds often with X, Y, Z” or “busiest meeting day is Thursday.” These are short text summaries, not copies of source records. Each integration can be gated per-Soul via the Integrations tab, and shared memories appear in your Soul's memory log where you can delete them individually.

Your controls

Use of Google user data transferred to Fostera complies with the Google API Services User Data Policy, including the Limited Use requirements. Fostera does not transfer Gmail data to third parties other than the LLM providers listed above when you explicitly share inbox context into a chat, and we do not use Gmail data for advertising or sell it.

11. Retention

We retain information as long as your account is active or as needed to provide the service, comply with legal obligations, resolve disputes, and enforce agreements. You may request deletion subject to applicable law and legitimate retention needs.

12. Security

We use industry-standard measures to protect data. No method of transmission or storage is completely secure; we encourage strong passwords and careful sharing of access to your account.

13. Additional rights

Depending on where you live, you may have rights to access, correct, delete, or export your personal data, or to object to or restrict certain processing. Contact us at the email below to exercise these rights. You may also lodge a complaint with a supervisory authority where applicable.

14. Age restriction and minors

Fostera is restricted to users who are 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If we become aware that a user is under 18, we will terminate their account and delete their personal data.

If you believe a minor is using Fostera, please contact us at the email below so we can take appropriate action.

15. International transfers

We may process data in countries other than your own. Where required, we use appropriate safeguards for cross-border transfers.

16. Changes

We may update this Privacy Policy periodically. Continued use after changes constitutes acceptance of the updated policy where permitted by law.

17. Contact

Privacy questions or requests: reach out on our contact page.