PRV / 02 · PUBLIC DOCUMENT
Privacy Policy
How Otome App handles account, gameplay, creator, payment, and technical data.
Last updated: August 14, 2026
Scope and data controller
This Privacy Policy explains how 符源, the operator of Otome App (“Otome App”, “we”, “us”, or “our”), collects, uses, stores, and shares personal information when you use our websites, AI interactive stories, creator tools, accounts, and payment features (the “Service”).
Controller: 符源
Registered/contact address: China — individual operator; correspondence by email
Country/region: People's Republic of China
Privacy contact: fuy7455@gmail.com
Data Protection Officer: Not appointed at this stage.
Information we collect
2.1 Information you provide
- Account data: email address, optional display name, age-verification status, and account timestamps.
- Gameplay data: story choices, messages, save files, relationship state, progress, endings, and safety signals.
- Creator data: briefs, prompts, game definitions, characters, uploaded images or other assets, submissions, and publication history.
- Purchase data: product, Starlight quantity, transaction identifiers, amount, currency, status, and subscription state. We do not receive or store full card numbers.
- Communications: support, privacy, billing, moderation, refund, and security correspondence.
2.2 Information collected automatically
- Device and request data: IP address, browser, operating system, language, time zone, request time, and security headers.
- Service logs: authentication events, errors, performance data, fraud signals, and API activity.
- Pseudonymous usage events: program, scene, save identifier, progress, duration, and safety outcome. Our gameplay analytics intentionally excludes user IDs.
- Cookies: strictly necessary session and security cookies used to keep you signed in and protect requests.
How and why we use information
- Provide the Service / contract: authenticate accounts, run stories, save progress, generate AI responses, operate creator tools, and deliver Starlight.
- Payments / contract and legal duty: create checkout sessions, reconcile payments, manage subscriptions, refunds, taxes, and accounting records.
- Safety and security / legitimate interests and legal duty: prevent abuse, screen content, enforce age gates, investigate incidents, and protect users and systems.
- Support / contract and legitimate interests: answer requests, resolve errors, and handle complaints.
- Improve the Service / legitimate interests: understand aggregate usage, reliability, and feature performance. We balance these interests against your rights.
- Legal compliance: meet tax, accounting, consumer-protection, fraud-prevention, regulatory, and lawful-request obligations.
- Marketing / consent: only if we introduce optional marketing and you affirmatively opt in. Service, billing, security, and policy notices are not marketing.
We may aggregate or de-identify information so it can no longer reasonably identify you.
AI processing
Story messages, relevant game state, character instructions, and creator briefs may be sent to third-party AI processors to generate dialogue, summaries, classifications, drafts, or safety decisions. Current processing may involve a GeekAI-compatible model gateway and Alibaba Qwen-family models, with Cloudflare infrastructure used elsewhere in the request path.
Do not include sensitive personal data or confidential third-party information in prompts. We do not use private gameplay messages to train our own general-purpose AI model without separate, explicit consent. Automated game-state and safety outputs affect entertainment content or platform moderation; they do not make decisions producing legal or similarly significant effects about you. You may request human review of a moderation outcome by contacting support.
Cookies and tracking
We currently use only strictly necessary cookies and similar storage for sign-in, session continuity, security, and core preferences. These cannot be disabled through a consent panel because the Service cannot operate securely without them; you can block them in your browser, but sign-in and saved play may stop working.
We do not currently use third-party advertising cookies or cross-site marketing pixels. If we add optional analytics or marketing tracking, we will update this Policy and provide consent controls where required before activating it.
When we share information
We do not sell personal information or share it for cross-context behavioural advertising. We disclose only what is needed to:
- Cloudflare: website delivery, Workers, databases and storage, security, transactional email, aggregate analytics, and related infrastructure.
- Waffo Pancake: merchant-of-record services, checkout, card processing, tax, fraud prevention, receipts, subscriptions, and refunds. Full card data is handled by Waffo Pancake and does not reside on our servers.
- AI processors: process the limited prompts and context needed to generate or moderate content, currently including a GeekAI-compatible gateway and Alibaba Qwen-family models.
- Professional advisers and authorities: comply with law, court orders, valid government requests, audits, or defend legal rights.
- Business transfers: support a merger, financing, acquisition, reorganization, or sale, subject to continued protection and notice where required.
- Public and other users: display creator profiles, published games, credited authorship, and content you intentionally make public.
Security
We use HTTPS/TLS, HTTP-only signed session cookies, hashed login codes and refresh tokens, access controls, environment-separated payment verification, signed Waffo webhooks, and restricted storage bindings. No system is completely secure. If a breach is likely to risk your rights, we will notify affected users and regulators within the periods required by applicable law, including 72 hours where that rule applies.
Retention
- Account profile and saves: while the account is active, then up to 90 days after a verified deletion request, unless a longer period is required.
- Published creator content: until unpublished or deleted, plus versioned records needed for integrity, disputes, and legal obligations.
- Payment and transaction records: 7 years, or the period required by tax, accounting, fraud, and consumer law.
- Support and moderation records: 2 years after closure, unless needed for an active dispute or safety matter.
- Authentication, security, and diagnostic logs: normally up to 12 months.
- Aggregated or de-identified analytics: may be retained longer because they no longer reasonably identify a person.
Backups may retain deleted information for a limited rotation period and are isolated from ordinary use.
Your privacy rights
Depending on where you live, you may request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or information about processing and disclosures. You may also appeal certain decisions and complain to your local data-protection authority. We do not discriminate against you for exercising a legal right.
Send requests to fuy7455@gmail.com from your registered email. We may verify identity and authority before responding. We aim to respond within 30 calendar days, or the shorter period required by law. Some records may be retained where law permits or requires it.
International transfers
We and our providers may process data in countries other than yours, including the United States and locations used by our AI and infrastructure providers. Where required, we rely on adequacy decisions, Standard Contractual Clauses, contractual safeguards, or another lawful transfer mechanism, together with technical and organizational protections.
Adults only
The Service is intended only for people aged 18 or older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided information, contact fuy7455@gmail.com so we can investigate and delete it as appropriate.
Third-party services and links
Our Service may link to or integrate third-party sites and services. Their privacy practices are governed by their own policies. This Policy describes information controlled by us and does not replace Waffo Pancake’s or another provider’s notices for data they independently control.
Changes to this Policy
We may update this Policy as the Service, providers, or laws change. For material changes, we will provide at least 15 days’ advance notice by email or a prominent in-Service notice unless urgent legal or security reasons require faster action. The current effective date will always appear at the top of this page.
Contact us
Privacy requests: fuy7455@gmail.com
General support: fuy7455@gmail.com
Security reports: fuy7455@gmail.com
Controller: 符源
Address: China — individual operator; correspondence by email
Website: https://otomeapp.com