This Privacy Policy explains what data ButterCupp collects when you use ButterCupp, how we use it, and the rights you have over it.
1. Data we collect
- Account: email, hashed password, sign-in provider (if Google).
- Age and compliance: date of birth, jurisdiction, terms/privacy acceptance timestamps, and, when applicable, the age-verification vendor result.
- Product use: characters you interact with, messages you send, memory records extracted from those conversations, subscription/token history, and audit logs required for safety review.
- Device and network metadata used for abuse prevention and analytics.
2. How we use it
- Operate the service (chat, voice, image, memory).
- Enforce our Terms and Content Policy, including crisis-detection under California SB 243.
- Bill you and reconcile with our payment processors.
- Detect fraud and abuse.
- Communicate service and legal notices.
3. Processors we share data with
- LLM providers (OpenRouter, Anthropic, OpenAI) receive your prompts and character context to generate replies.
- Voice providers (ElevenLabs, Cartesia, Google) receive text for TTS.
- Image providers (Fal, Replicate) receive prompts and appearance references.
- Mature-friendly payment processors (CCBill, Verotel, SegPay, crypto) receive billing data. We do NOT use Stripe or PayPal.
- Age-verification vendor (when required by jurisdiction).
- Hosting: AWS (RDS, ECS, S3, CloudFront, Amplify).
- Error monitoring: Sentry.
4. Retention
We retain account data for the life of your account. Messages and memory records persist until you delete them from Settings or delete the account. Audit logs required for SB 243 or DMCA obligations are anonymized on account deletion but not erased.
5. Your rights
You may export your data (Settings → Export data) or delete your account (Settings → Delete account). If you are in a jurisdiction with GDPR or CCPA rights, contact us at admin@buttercupp.fun to exercise them.
6. Contact
Data controller: ButterCupp, the United States. admin@buttercupp.fun.