Privacy Policy

Effective Date: May 11, 2026

Svila.io ("we," "our," "us") is committed to protecting your privacy. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and your rights regarding your data.

1. Information We Collect

a) Account Information

When you create an account, we collect your email address. This is used to create your account, send you secure magic link login emails, and communicate account-related information.

b) Persona & Conversation Data

We store the AI personas you create (name, tone, mood, description, and related settings) and the conversation history between you and your personas. This data is necessary to provide the Service and is stored in our secure database.

c) Payment Information

We do not store your payment card or wallet details. Payments are processed by our third-party payment providers, which handle card and wallet data under their own PCI-compliant security policies. See section 3 for what they handle. We receive and store only non-sensitive transaction metadata (such as subscription status, product type, and transaction identifiers) necessary to manage your account.

d) Usage Data

We may collect basic usage information such as when you log in and how features are used. This helps us maintain and improve the Service. We do not use third-party advertising trackers.

e) Guest Preview & IP Address

You can try a short preview conversation without creating an account. When you do, we store the messages exchanged in that preview together with your IP address.

The IP address is collected for one purpose: preventing abuse of the free preview. We limit the number of preview sessions that can be started from a single IP address in a day, and without the address that limit cannot be enforced. It is not used for advertising, profiling, or analytics, and it is not shared with third parties.

A preview session expires 24 hours after it starts. Expired sessions — including the stored messages and the IP address — are deleted automatically by a daily job, after a short grace period that exists so that a preview conversation can be carried over if you decide to create an account. If you create an account, the preview conversation is migrated to it and is then covered by section 5.

f) Safety and Moderation Records

Where a message or a generated reply is blocked by our safety controls, we record that the block occurred: the account (if any), the category, and the time. For a short period we also retain a fragment of the text involved, so that the decision can be reviewed or contested. After 30 days that text is replaced with a one-way hash and the readable content is destroyed; the record that the block happened is kept, because it is what allows us to identify repeated attempts.

2. How We Use Your Information

  • To create and manage your Svila.io account
  • To authenticate you via secure magic link login
  • To store your personas and conversation history so you can access them across sessions
  • To process payments and manage your subscription, credits, and day pass status
  • To generate AI responses to your messages (via our AI provider)
  • To generate voice audio from AI responses (via ElevenLabs), only for accounts that already hold voice credits and turn voice on — voice credits are not on sale at the moment
  • To send transactional emails related to your account (e.g. login links, billing notifications)
  • To detect and prevent abuse, fraud, or violations of our Terms of Service

3. Third-Party Service Providers

We use trusted third-party providers to operate Svila.io. These providers may process some of your data as necessary to deliver the Service. We list them by function so you can see exactly what each one handles.

Authentication and database

  • Supabase — Authentication and secure database storage for your account, personas, and conversations.

Payment processing

  • Our card payment provider — Card payments for subscriptions and day passes, including card details, billing and renewals. We never receive your full card number.
  • Our cryptocurrency payment provider — Cryptocurrency payments.

We may add or change payment providers over time. Payment providers handle wallet and transaction data under their own privacy and security policies; Svila.io does not store payment card numbers or wallet credentials.

AI and voice

  • Our AI language-model provider — The content of your messages is sent to the AI provider to generate responses. The provider processes this data under their own privacy policy.
  • ElevenLabs — Voice synthesis. Voice is not available to new accounts at the moment, because voice credits are not on sale. For an account that already holds voice credits and turns voice on, the text of AI responses is sent to ElevenLabs to generate audio; otherwise nothing is sent.

Hosting and infrastructure

  • Vercel — Cloud hosting for the Svila.io web application.
  • Sentry — Error monitoring, with data stored in the United States. When something breaks, Sentry receives a technical report: the type of error, where in our code it happened, which page or route was involved, your browser and device type, and a random account identifier (not your name or email). We strip message text, conversation content, request bodies, cookies and sign-in tokens from every report before it leaves our servers or your browser.

Email

  • We use a transactional email provider to send you account-related emails such as login links and purchase confirmations.

Payment-method interest list

Before card payments were available, you could ask us to notify you when they launched. If you did, we recorded:

  • the email address you enter;
  • optionally, which plan or product you were looking at and where on the site you asked from;
  • your account identifier, only if you were signed in at the time.

We use this solely to email you once to say card payments are available. It is not used for marketing, is not sold or shared, and it did not create an account. We keep it until we have sent that email, or until you ask us to remove it — whichever comes first. To have your address removed at any time, email support@svila.io and we will delete it.

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

4. Cookies & Sessions

Svila.io uses cookies and browser storage to maintain your login session. These are essential for the Service to function and are not used for advertising. By using Svila.io, you consent to this use of cookies.

5. Data Retention

We retain your account data, personas, and conversation history for as long as your account is active. If you request account deletion, we will remove your data within 30 days. Payment records may be retained for longer where required by law or for financial compliance purposes.

Two categories have their own, shorter periods:

  • Guest preview sessions (messages and IP address) — deleted automatically once the session has expired and a short migration grace period has passed. See section 1(e).
  • Readable text in safety records — replaced with a one-way hash after 30 days. The record of the event is retained; the text is not. See section 1(f).

6. Security

We implement industry-standard security measures including encrypted connections (HTTPS), row-level database security, and secure authentication. However, no system is completely secure, and we cannot guarantee absolute security of your data.

7. Children's Privacy

Svila.io is strictly for users aged 18 and over. We do not knowingly collect personal information from anyone under 18. If we become aware that a minor has created an account, we will terminate it and delete their data immediately.

8. Your Rights

Depending on your location, you may have rights under applicable data protection laws (such as GDPR or CCPA) including the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and associated data
  • Object to or restrict certain types of processing
  • Withdraw consent where processing is based on consent

To exercise any of these rights, please contact us at support@svila.io.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date at the top of this page. We encourage you to review this page periodically. Continued use of the Service after changes are posted constitutes acceptance of the updated policy.

10. Contact

For privacy-related questions, requests, or concerns, contact us at support@svila.io.

Updated 2026-09-16: Sentry added as our error-monitoring provider. Updated 2026-05-11: third-party-providers list restructured by function and updated to include additional payment providers.