Privacy Policy
Last updated: August 11, 2026
This Privacy Policy describes what personal data Daika collects, how we use it, who processes it on our behalf, and what control you have over it. We wrote this policy to describe what the Service actually does — not an idealized version of it.
Daika is operated by SodoLabs.ai LLC, a limited liability company registered in Wyoming, United States.
1. What we collect
Account data
- Email address, username, password hash (if using email signup) or Google OAuth identifier (if using Google sign-in).
- Account tier, usage counters, age verification timestamp, timezone.
Content you create
- Companion configurations: names, personalities, appearance choices, language preferences.
- Conversation messages (yours and the companion's replies), images you upload, images the companion generates, and memories extracted from your conversations.
Technical data
- IP address, user agent, and request logs for abuse prevention.
- A session cookie (httpOnly, SameSite=Lax) to keep you signed in.
2. How we use it
- To operate the Service — sending your messages to the AI infrastructure providers we use for inference, generating and storing images and replies, and delivering them to you in the web chat.
- To enforce usage limits per account tier and rate-limit abuse.
- To improve the Service — aggregated, anonymized usage analytics. We don't sell conversation content or share it for advertising.
- For billing (when applicable) — processing payments through our payment processor.
We process your data on the basis of your consent to this Policy and our Terms of Service, and because the processing is necessary to provide the Service you've signed up for.
We do not use your conversations to train AI models. Your messages are sent to the third-party AI providers listed in Section 3 for inference only — to generate a reply to you, not to fine-tune or train any model.
3. Third-party services & where your data goes
- AI inference (chat) — DeepInfra (primary) and Novita (fallback) generate your companion's text replies. Anthropic provides safety classification and renders follow-up replies in the window after a detected crisis; the crisis response itself is a fixed, pre-authored safety message. All three are US-based infrastructure providers.
- Image & video rendering — RunPod (GPU cloud infrastructure) generates the images and videos your companion sends you.
- Database — Neon hosts our Postgres database (your account, conversation, and companion data), currently located in Frankfurt, Germany.
- Media storage — Cloudflare R2 stores uploaded and AI-generated images and video files.
- Application hosting — our servers run on Hetzner infrastructure in Germany.
- Error monitoring — Sentry receives technical crash/error reports so we can fix bugs. We configure it to exclude personal data by default, though we don't manually audit every error payload for content.
- Cloudflare — DNS, TLS, and content delivery.
- Payment processor — only when you make a purchase. Receives billing information, not chat content.
- Google OAuth — only if you sign in with Google; we receive your email and Google ID.
Put plainly: your conversations are processed by third-party AI infrastructure providers under contract, as listed above — not self-hosted, and not processed only inside Brazil. We don't send your data to any provider beyond the ones named in this section, and we don't sell your data. See Section 6 for what this means as an international transfer.
4. How long we keep it
In plain terms: we keep personal data only for as long as it's needed to provide the Service, or as long as the law requires — not indefinitely by default. Specifics:
- Account data and conversations: kept while your account is active. Deleting a companion immediately and permanently removes its conversations, messages, and memories from our database — this isn't a delayed or scheduled process.
- Payment records: retained per tax law (typically 5-7 years) even after account deletion.
- Deleting a companion permanently removes its conversations, messages, and memories. Images and videos already delivered to you remain in your gallery and can be deleted individually.
- Internal operational and audit logs (things like abuse signals and system event logs, not your conversation content): short-lived, roughly 14 to 90 days depending on log type, then purged automatically. We don't yet have an automated time-based purge for conversation content itself beyond your own deletion actions.
- Access logs (records of who accessed the application and when, required by Brazilian law): kept for a minimum of 6 months, per the Marco Civil da Internet (Law 12,965/2014, Art. 15). This is a legal floor we don't shorten, not a target we're minimizing toward.
You can delete data yourself, any time: remove an individual companion — and all of its conversations, messages, and memories — from that companion's own settings; it's immediate and permanent. You can also delete your entire account any time from Account Settings — this is permanent (see Section 5 for the full list of your rights).
5. Your rights
Under LGPD (Brazil), GDPR (EU), CCPA (California), and equivalent regimes, you have rights over the personal data we hold about you. Here's what's available today, in the product, versus what requires contacting us directly:
- Access — email us and we'll send you a summary of the data we hold about you. We don't yet have a self-serve "view my data" page.
- Correct — edit your profile directly in Account Settings. Companion memories can be deleted (not edited) from the companion's memory panel. For anything else, email us.
- Delete — delete an individual companion (and all of its conversations, messages, and memories) any time from that companion's settings; it's immediate and permanent. You can also request deletion of your entire account from Account Settings — this is permanent; some payment-adjacent records are retained afterward as required by law, per the retention policy in Section 4.
- Export — you can request a copy of your data — a JSON bundle covering your profile, consents, and conversations — by contacting us at privacy@daika.ai.
- Object — email us to object to a specific use of your data described in this Policy.
Reach us at privacy@daika.ai. We aim to respond within 30 days.
6. International transfers
Daika's data is stored, and the application itself runs, in the European Union (Germany) — our database (Neon, Frankfurt) and application hosting (Hetzner) are both EU-resident. As described in Section 3, your chat and photo content is additionally processed TRANSIENTLY by our US-based AI infrastructure providers (DeepInfra, Novita, Anthropic, RunPod) to generate responses and images. These providers do not retain your data after they've finished processing it.
For users located in Brazil, storing your data in the EU is not, by itself, an international transfer under LGPD — data collected directly from you and stored abroad is treated as direct collection, not a cross-border transfer requiring a separate LGPD Art. 33 gateway. The transient processing by our US-based AI providers is covered by the specific, informed consent you give when you accept this Policy, together with our processors' own contractual safeguards (see below).
We rely on our processors' own contractual and security commitments to protect your data in transit and at their facilities.
7. Children
The Service is for users aged 18+ only (or the legal age of majority in your jurisdiction). We don't knowingly collect data from minors. If you believe a minor has created an account, contact privacy@daika.ai and we'll delete the account.
8. Security
We use TLS encryption for all data in transit. Passwords are hashed with bcrypt — we never store your password in plain text. We limit access to production systems to the people who operate them. We don't currently offer additional application-layer encryption of stored message content or integration credentials beyond our infrastructure providers' own protections — closing that gap is active work on our end. We make no guarantee of perfect security — breaches can happen.
If a security incident affecting your personal data occurs and could pose a relevant risk to you, we will notify both the ANPD (Brazil's data protection authority) and affected users within the period required by law — currently up to 3 business days after we become aware of the incident (Resolution CD/ANPD No. 15/2024), a period doubled for small operators like us. We also keep an internal register of security incidents, including ones that don't reach the notification threshold, for at least 5 years.
9. Changes
Material changes to this Policy will be notified in-app and by email where applicable.
10. Contact
Privacy questions: privacy@daika.ai