Privacy Policy
Last updated: October 11, 2026 · Draft pending legal review
Contact-routing amendment (October 11, 2026): privacy requests, security reports, and all other email communications to Affective go to founder@affective-llc.site.
Plain language, because a policy you cannot read is a policy you did not agree to. This Privacy Policy explains what personal data Affective LLC ("Affective," "we," "us," or "our") collects, how we use and share it, and the choices you have. It covers our website (the "Site") and, once they launch, our API, console, and other products (the "Services").
The short version
- Today the Site collects almost nothing: the standard request logs any web host keeps, and whatever you choose to email us.
- When the Services launch, the conversations you send us stay yours. We train on raw conversation content only if you opt in, never by default.
- The appraisal state data our models derive is ours, and we train on it only after de-identifying it.
- We do not sell your data, we do not run ads, and we do not track you across other sites.
- Persistent emotional memory is opt-in and clearable. Crisis content is the most protected data we hold.
Who this covers
This policy applies to visitors to the Site and to our customers and their users when they deal with us directly. When a company builds a product on the Services, that company decides how its users' data is used, and its own privacy policy governs; we process that data on its behalf under our Data Processing Addendum. If you use a product built on Affective, contact that company first about your data.
The Services are not live yet. The sections below that describe the Services say what will apply when they launch, and this policy will be updated, with a dated note, before they do.
What we collect today
- Request logs. Our hosting provider records standard information about each request to the Site, such as IP address, browser type, the page requested, and the time. We use these logs to operate and secure the Site.
- Your theme preference. If you switch between light and dark mode, the Site saves that choice in your own browser's local storage. It is never sent to us.
- What you send us. If you email us, apply for a job, or join our mailing list when it opens, we receive your name, email address, and whatever else you choose to include, such as a resume.
The Site does not use analytics that profile you, advertising cookies, tracking pixels, or third-party trackers.
What the Services will collect
- Account information: your name, email address, organization, and login details.
- Payment information: collected and processed by our payment processor. We receive confirmation of payment and limited details such as the last four digits of a card, never the full card number.
- Content: the text, audio, images, and transcripts you or your users submit (Input) and what the Services return (Output).
- State data: the appraisal states, emotional trajectories, and persistent memory our models derive from Input.
- Usage data: logs, request metadata, performance metrics, and billing records about how the Services are used.
- Device and location data: IP address, device and browser type, and general location inferred from IP address.
How we use personal data
- To provide, operate, maintain, and support the Site and the Services.
- To remember context across sessions, where persistent memory is turned on.
- To secure the Services, and to detect and prevent fraud, abuse, and violations of our Acceptable Use Policy.
- To improve and train our models, only as Section 5 describes.
- To process payments and communicate with you about your account, the Services, and updates you asked for.
- To review job applications.
- To comply with the law, enforce our agreements, and protect the rights and safety of our users, the public, and Affective.
- For any other purpose we tell you about when we collect the data, with your consent where the law requires it.
Training: what we train on and what we do not
- Raw conversation content: opt-in only. We do not train or fine-tune models on the content of conversations unless the customer has opted in and the person whose content it is has given explicit, separately revocable consent.
- Appraisal state data: de-identified only. We own the appraisal state data our models derive, and we use it to train, improve, and benchmark our models only after de-identifying it so it cannot reasonably be linked to you. We never try to re-identify it.
- Aggregate findings we publish cover at least 50 people and never identify a customer or a person.
- Crisis content is excluded. We do not train on crisis-path content beyond the minimal record of the risk event and the action taken.
Deleting your data removes it from future training runs. Models already trained on de-identified patterns cannot unlearn them individually.
Crisis content
If a conversation triggers the crisis response, the content of that response is not logged beyond what safety review requires, and safety events are handled as incidents with restricted, logged access. The state system goes silent on the crisis surface. We treat that content as the most sensitive data we will ever hold.
Response-variation research
To learn which safe responses help people most, we may deliberately vary responses among options a safety review has already approved and record the effect. We do this only for people who have affirmatively opted in, never on crisis or clinical-risk paths, and anyone in the program can see and delete what was recorded about them.
How we share personal data
We do not sell personal data, and we do not share it for cross-context behavioral advertising. We share it only:
- With service providers that host, process, or support the Site and the Services for us, such as cloud hosting, payment, and email providers, under contracts that limit their use of it. Our subprocessor list will be published on our Security page before the Services launch.
- With the customer whose product you use, for data processed on that customer's behalf.
- For legal reasons, when we believe in good faith that the law, a court order, or a valid legal process requires it, or that it is needed to protect the rights, property, or safety of our users, the public, or Affective, or to investigate fraud or other unlawful activity.
- In a business transaction, such as a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections. Any successor must honor this policy for data already collected.
- With your consent or at your direction.
Your choices and controls
- Persistent memory is opt-in, and a Clear control ships with it: if the product remembers, you can make it forget, in the same place, without emailing anyone.
- Mailing list: unsubscribe at any time with the link in every email.
- Deletion: ask us to delete your account and its stored state by writing to founder@affective-llc.site.
- Do Not Track: we do not track you across sites, so there is nothing for a Do Not Track or Global Privacy Control signal to switch off.
Your privacy rights
Depending on where you live, including in Texas, California, and other US states, the European Economic Area, the United Kingdom, and Switzerland, you may have the right to:
- know what personal data we hold about you and get a copy of it in a portable format;
- correct inaccurate personal data;
- delete your personal data;
- opt out of the sale of personal data, targeted advertising, and profiling that produces legal or similarly significant effects (we do none of these);
- withdraw consent you have given, without affecting processing that already happened; and
- object to or restrict certain processing.
To exercise a right, write to founder@affective-llc.site. We will verify your request, respond within the time the law requires, and never discriminate against you for using your rights. You may use an authorized agent where the law allows. If we decline your request, you may appeal by replying to our decision, and if we deny your appeal, you may contact your state attorney general or your local data protection authority.
Legal bases (EEA, UK, and Switzerland). We process personal data to perform our contract with you, for our legitimate interests in operating, securing, and improving the Site and the Services where those interests are not overridden by your rights, to comply with legal obligations, and with your consent for persistent memory, content training, and response-variation research.
How long we keep data
- Site request logs: for the retention period our hosting provider applies.
- Emails and job applications: as long as needed to respond and for a reasonable period afterward, or as the law requires.
- Identifiable state data: up to 90 days by default, unless persistent memory is on, in which case it is kept until you clear it.
- Account and billing records: for the life of the account and afterward as required for tax, accounting, and legal purposes.
- De-identified data: may be kept indefinitely, because it no longer identifies you.
Backups are deleted on their regular cycle.
Security
Data is encrypted in transit and at rest, and emotional state data gets field-level encryption, a tier above everything else we store. Access to stored user content is restricted to roles that need it, and every access to crisis-related content is logged. No system is perfectly secure. If something breaks, we will tell affected people what happened, what data was involved, and what we did, in plain language. Our Security page has more detail.
Children
The Site is not directed to children under 13, and the Services are for people 18 and older or the age of majority where they live. We do not knowingly collect personal data from children under 13. Persistent emotional memory for minors is allowed only with a verified parental consent process run by the customer offering the product. If you believe a child has given us personal data, write to founder@affective-llc.site and we will delete it.
International transfers
We are based in the United States and process data there. If you are outside the United States, your personal data will be transferred to the United States, where privacy laws may differ from those where you live. For customer data from the EEA, the UK, and Switzerland, we rely on the standard contractual clauses in our Data Processing Addendum.
Changes to this policy
Material changes ship with a dated note at the top of this page and, where we have a way to reach you, a direct notice. We do not retroactively change the deal on data already collected.
Contact
Privacy questions, requests, and security disclosures: founder@affective-llc.site. Mail: Affective LLC, [NOTICE ADDRESS].