Legal
Privacy Policy
This policy explains what VelvetTK processes when you visit the website, connect a membership account, use managed companion AI, or store companion memory on your own computer.
Effective and last updated: August 3, 2026
Plain-language summary
- The Services are for adults only and are not directed to minors.
- The website does not use advertising trackers in its source code.
- With your authorization, Patreon provides your account email, display name, account IDs, and membership details. It does not provide your password, payment-card number, or shipping address.
- Companion prompts and generated speech pass through Firebase to Replicate. Prompt content is not stored in VelvetTK's Firestore prediction records.
- Local journals, character notes, consent settings, and cached generated audio remain on your computer until you remove them.
- We do not sell personal information or use it for targeted advertising.
1. Controller and contact
The independent creator publishing under the name VelvetTK is the controller of personal data described in this policy. Privacy, access, correction, deletion, objection, and consent-withdrawal requests may be sent to [email protected].
2. Scope
This policy applies to velvettk.com, VelvetTK games, membership authentication, AI credit administration, and managed companion AI features that link to it. Third-party websites and platforms have their own policies.
3. Information processed
| Context | Data | Source and purpose |
|---|---|---|
| Website and security | IP address, request time, requested URL, browser or device data, and security events | Processed automatically by Cloudflare to deliver, secure, and operate the static website |
| Adult preference | A device-local yes/no confirmation, without a birth date | Stored in your browser so the age notice is not repeated on every visit |
| Membership connection | Patreon account email, provider user and member IDs, display name, campaign, eligible tier, entitlement and charge status, gifted status, membership dates, and billing-period boundaries | Received with your OAuth authorization to authenticate you, verify access, and maintain a long-lived Firebase membership and support record |
| Firebase authentication | Pseudonymous Firebase user ID, session tokens, IP address, and user-agent data | Used to create and secure the current authenticated game session |
| AI requests | Character prompt, your companion guidance or message, selected recent dialogue and gameplay events, optional journal summary, generated reply, voice text, character and reference IDs | Sent from the game through Firebase to Replicate to generate dialogue and speech |
| Usage and credits | Firebase user ID, operation and model, request and character counts, input-character counts, status, safe performance metrics, estimated provider cost, tier, and credit-period dates | Generated by the managed service to enforce limits, display credits, prevent abuse, and operate the service |
| Local companion memory | Character guidance, recent dialogue and gameplay events, daily journals, rolling summaries, consent version, and cached generated audio | Created and stored on your Windows computer for continuity and faster playback |
| Support and legal requests | Your email address, request content, and information reasonably needed to verify and answer the request | Provided directly by you when you contact us |
4. Information not requested through the membership connection
The current Patreon connection requests identity, identity[email], and identity.memberships. With your authorization, this provides the account email used as a long-lived identifier in the Firebase membership record, along with the identity and entitlement details listed above. We do not ask the OAuth connection for your membership-provider password, payment-card number, shipping address, payout data, or creator-wide payment records. The planned SubscribeStar connection is limited to subscriber and user-subscription read access and is not enabled until its separate integration is deployed.
The game does not request or store your personal Replicate or other model-provider API credential. Provider access is managed on the server.
5. Companion AI and potentially sensitive input
Companion dialogue and speech are generated by AI, not by a human. Prompt content may reflect adult gameplay, preferences, sex-life information, or other information that some laws treat as sensitive. Do not include a real person's confidential information or unnecessary identifying, financial, health, or other sensitive information.
Before the managed AI is enabled, the game presents a separate disclosure and asks for your explicit consent to process the listed inputs and transfer them to service providers in the United States. You may decline and play without the managed feature. You may stop future cloud processing by disconnecting the membership session. Contact us to request deletion of server-side records associated with your Firebase identity.
6. Purposes and legal bases
Depending on your location, we rely on the following grounds:
- Contract: authenticate an eligible membership, maintain the associated account and support record, provide requested AI output, administer credits, and operate requested features.
- Explicit consent: process AI prompt content that may contain sensitive adult preference or sex-life information and transfer it to the identified providers. Consent may be withdrawn for future processing.
- Legitimate interests: secure the Services, prevent fraud and abuse, enforce limits, diagnose failures, and maintain reliable operations, balanced against user rights.
- Legal obligation and claims: comply with valid law, protect rights, and establish, exercise, or defend legal claims.
We do not use companion content to make decisions producing legal or similarly significant effects about you, build advertising profiles, or train a VelvetTK model.
7. Recipients and service providers
- Cloudflare: DNS, content delivery, website hosting, network security, and limited request telemetry.
- Google Firebase and Google Cloud: authentication, Cloud Functions, Firestore, token security, and managed service infrastructure.
- Replicate: processing of companion prompts, generated text, speech text, and server-selected voice reference data.
- Patreon: the current optional source of the authorized account email, identity, and membership entitlement data.
- SubscribeStar: an optional future membership OAuth and entitlement source after the integration is enabled.
- Vimeo: automatic delivery of the featured embedded video using Vimeo's Do Not Track player parameter.
- Authorities or advisers: only when reasonably necessary to comply with valid law, protect users or the Services, or handle legal claims.
Providers process data under their own terms and, where applicable, as processors or service providers acting for VelvetTK. We do not sell personal information, share it for cross-context behavioral advertising, or exchange it for targeted advertising.
Provider notices are available from Cloudflare, Firebase, Replicate, Patreon, SubscribeStar, and Vimeo.
8. International processing
VelvetTK's Firebase Authentication service processes data in the United States. The configured Cloud Functions and Firestore deployment is in us-central1(Iowa), and Replicate is a United States provider. Data may also be processed where Cloudflare and other providers maintain infrastructure.
Where required, international transfers are handled using provider data-processing terms, contractual safeguards such as standard contractual clauses, consent where legally valid, or another lawful transfer mechanism. You may contact us for information relevant to a transfer from your jurisdiction.
9. Retention
| Record | Retention approach |
|---|---|
| OAuth login and rate-limit records | Short-lived records expire after approximately 5 and 10 minutes, respectively, subject to scheduled deletion timing. |
| Replicate API prediction inputs, outputs, files, and logs | Replicate states that API prediction data is removed after one hour by default. |
| VelvetTK prediction ownership metadata | Scheduled to expire 48 hours after creation; it does not contain the prompt or generated output. |
| Daily usage and one-use credit grants | Daily counters are scheduled to expire after 40 days; grants expire after the shorter of 15 minutes or the membership-period end. |
| Membership identity and billing-period credit counters | The Patreon email and related identifiers are kept as a long-lived account record while needed to provide membership access and support, administer credits, prevent abuse, resolve disputes, or comply with law. They are then deleted or de-identified, including after a valid deletion request unless continued retention is legally permitted or required. |
| Firebase Authentication identity | Kept until the account record is deleted. Disconnecting revokes the current refresh session but is not by itself a deletion request. |
| Local memory and audio cache | Kept on your computer until you inspect, edit, back up, or delete the files. |
| Legal or support records | Kept only as long as reasonably needed to answer the request, meet legal duties, and protect legal rights. |
10. Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or a copy of personal data; object to certain processing; withdraw consent for future processing; and appeal or complain to a competent privacy authority. We will respond within the period required by applicable law and may ask for information needed to verify the request.
California and other covered U.S. residents may request to know, correct, or delete covered personal information and may exercise applicable opt-out and non-discrimination rights. VelvetTK does not sell personal information, share it for cross-context behavioral advertising, or offer a financial incentive for personal information.
The game lets you open the local companion memory folder. You can edit or delete those files directly. Disconnecting the membership provider prevents new authenticated AI requests until you connect again, but does not by itself delete the long-lived Patreon email or Firebase membership record. Logging in again updates the record with the email currently returned by Patreon. To request server-side access, correction, or deletion, email [email protected].
11. Website storage, cookies, and Do Not Track
The website stores only the adult-confirmation preference in browser local storage from its own source code. It does not use that preference to identify you. Cloudflare may use strictly necessary security mechanisms. The featured Vimeo player loads automatically and sends your IP address and device or request information to Vimeo. It uses Vimeo's Do Not Track parameter, although Vimeo states that essential security cookies may still operate.
VelvetTK does not track your browsing over time across unrelated websites, so browser Do Not Track signals do not change our own practices. Third parties may respond according to their policies and technical settings.
12. Security
We use HTTPS, restricted server-side secrets, hashed one-time login credentials, short session windows, Firebase token verification, deny-by-default Firestore client rules, access controls, usage limits, and provider-managed encryption. No system is perfectly secure, and you should avoid submitting unnecessary personal information.
13. Adults only and children's privacy
The Services are not directed to children or minors and must not be used by anyone under 18 or under the legal age of majority where they live. We do not knowingly collect data from minors. If you believe a minor has provided data, contact us so we can investigate and delete it as required.
14. Changes and notice
We may update this policy when the Services, providers, data practices, or laws change. The date above will be updated. Material changes may be announced on the website or in the game and may require a new acknowledgment or consent before further processing.
15. Contact and complaints
Contact [email protected] for privacy questions or rights requests. You may also lodge a complaint with the privacy regulator where you live, including an EU or EEA supervisory authority, the California Privacy Protection Agency where applicable, or Japan's Personal Information Protection Commission.
Use of the Services is also subject to the Terms of Use.