Trust
How Fostera handles encryption, vendor risk, incident response, and data deletion, with the limits of each claim stated plainly.
Fostera uses HTTPS/TLS for browser↔server traffic and encrypted connections for service-to-service traffic. The exact protocol version is negotiated and managed by each infrastructure provider rather than fixed by this page.
Primary application data is stored in managed Neon Postgres infrastructure, with application compute on Vercel. Their current encryption, backup, and regional controls are governed by the respective vendor documentation and service configuration.
Stripe handles payment cards directly — Fostera never sees or stores raw card numbers. Subscription state and billing identifiers are stored, but PAN data is not.
Authentication is handled by NextAuth v5 with Google OAuth and verified email/password credentials. Passwords are hashed with bcrypt and never stored in plain text.
Sessions use JWT-backed cookies configured as httpOnly and secure in production.
Fostera does not currently offer app-based two-factor authentication. Protect the email or Google account used to sign in with its available security controls.
Fostera does not use your conversations or memories to train models owned or developed by Fostera.
Features you request may send relevant content to a configured AI provider or routing intermediary. Provider retention, model-training, regional processing, and opt-out terms vary by provider, service tier, account settings, and feature; the current processor list and policy links are maintained in Privacy Policy section 9.
Aggregated, non-identifying usage telemetry is collected to improve product reliability. You can opt out via the consent banner.
Compute: Vercel (Node.js + Edge functions on Fluid Compute).
Database: Neon Postgres on Vercel Marketplace.
Authentication: NextAuth v5 + OAuth providers.
AI processing: direct model APIs, inference platforms, and routing gateways listed in Privacy Policy section 9. Their data-handling terms are not identical.
Payments: Stripe (PCI DSS Level 1 compliant).
Email: SMTP via configured provider.
We choose vendors with mature security postures and document them here so you can evaluate the supply chain.
If we discover a security incident affecting user data, we will assess it and notify affected users or regulators when and as required by applicable law. Regulatory reporting deadlines and affected-user notice duties are separate and depend on the incident and jurisdiction.
If you discover a security issue, please email security@fostera.ai with details and reproduction steps. We triage verified reports promptly and treat coordinated disclosure as the standard.
We do not currently run a paid bug bounty. We do credit researchers who report verified issues.
The current self-service export provides portable JSON containing account identity, Soul configurations, memories, profile summaries, and per-Soul conversation counts. It does not include chat message bodies or uploaded files; additional access rights may be available under applicable law.
You can edit what your Soul remembers. Each Soul has a memory browser showing extracted memories; you can delete individual memories at any time.
When an account-deletion request is processed, Fostera removes the account and primary database records, including Souls, conversations, messages, memories, and push subscriptions. External-resource cleanup and removal from backups may take up to 30 days.
Billing records and limited audit or cleanup records may be retained or de-identified where required for legal, accounting, security, or deletion-integrity purposes. Deleted primary records are not offered as a user recovery mechanism.
Fostera is operated from the United States. We aim for GDPR, CCPA, and equivalent compliance.
Fostera is for ages 13 and up. We do not knowingly collect data from children under 13, and 13–17 accounts require confirmed parent or guardian consent. If you believe a child under 13 has created an account, contact us via /contact and we will remove the account and associated data.
Fostera is not a HIPAA-covered entity. Fostera is not a therapist, therapy app, or substitute for licensed mental-health care. Do not use Fostera as a substitute for clinical care; if in crisis, contact 988 (US) or local emergency services.
/privacy — full privacy policy.
/terms — terms of service.
/cookies — cookie usage and consent controls.
/companions/safe-ai-companion — broader trust posture for AI companion users.
Report a security issue: email security@fostera.ai. For everything else, /contact.
Continue with context
Start with one project. Or one companion. Either way, your Soul takes it from there and remembers the rest.
Start with one projectFree to start · No credit card required
Necessary cookies power sign-in and core settings. If you allow, optional cookies support product analytics, enhanced preferences, and personalized marketing. Read our Cookie Policy or Privacy Policy.