HiYou.AI ← Back to home

Privacy Policy

Last updated: February 14, 2026

1. Who We Are

HiYou.AI is operated by Rahaiz, a sole proprietorship registered in the Netherlands.

Company: Rahaiz

KVK number: 99728567

Contact: support@hiyou.app

In this policy, "we", "us", and "our" refer to Rahaiz. "You" refers to you, the user of HiYou.AI.

2. What HiYou.AI Is

HiYou.AI is a mobile application that lets you interact with AI-generated characters. All characters are fictional — no real people are depicted or involved in conversations. You must be 18 or older to use HiYou.

3. Data We Collect

Account Data

When you create an account, we collect:

  • Email address
  • Username
  • Password (stored as a secure hash — we never see your actual password)

Conversation Data

We store the messages you send and receive within the app. This includes text messages and any media exchanged. This data is necessary for the app to function — it allows characters to remember your conversations and build a relationship over time.

Relationship Data

We store data related to your interactions with characters, including relationship scores, emotional states, milestones, memories, and inside jokes. This data powers the relationship mechanics of the app.

Purchase Data

If you make in-app purchases, we store transaction records (coin balances, gift history, subscription status). Actual payment processing is handled by Apple (App Store) or Google (Play Store) — we never see your credit card or payment details.

Device Data

We may collect device identifiers and push notification tokens to deliver notifications. We do not track your location.

Creator Data

If you participate in the Creator Program, we additionally collect your PayPal email address for payouts and store your earnings history, payout requests, and transaction records. This data is necessary to process your creator earnings.

Usage Data

We collect anonymized usage data and error reports to improve the app. This includes crash logs and performance metrics.

4. How We Use Your Data

We use your data for the following purposes, each with a legal basis under the GDPR:

Purpose Legal Basis
Provide the core service — AI conversations, relationship progression, character interactions Performance of contract (Art. 6(1)(b))
Generate AI responses tailored to your conversation history and relationship context Performance of contract (Art. 6(1)(b))
Process in-app purchases and manage your coin balance Performance of contract (Art. 6(1)(b))
Send push notifications (proactive messages from characters, system alerts) Consent (Art. 6(1)(a)) — you can disable notifications at any time
Improve the app through anonymized analytics and error tracking Legitimate interest (Art. 6(1)(f))
Enforce our Terms of Service and ensure platform safety Legitimate interest (Art. 6(1)(f))
Process creator payouts (PayPal email, earnings data) Performance of contract (Art. 6(1)(b))

5. AI Processing

Your messages are processed by AI models (provided by Anthropic) to generate character responses. This means your conversation content is sent to Anthropic's API for processing. Anthropic does not use your data to train their models. The processing happens in real-time and conversation data is not retained by Anthropic beyond what is needed to generate a response.

6. Third-Party Services

We use the following third-party services to operate HiYou.AI:

Service Purpose Data Shared
Supabase Database & authentication All user data (stored in EU)
Anthropic (Claude AI) AI character conversations Message content for response generation
fal.ai AI image generation Character descriptions for photo generation
RevenueCat Subscription & purchase management User ID, purchase status
Sentry Error tracking & monitoring Anonymized crash reports
Expo App infrastructure & push notifications Device tokens
Apple / Google Payment processing Purchase transactions (handled by their platforms)

All third-party services are selected for their compliance with data protection standards. Your primary data is stored on servers located in the European Union (Supabase EU).

International Data Transfers

Some of our third-party services process data outside the European Economic Area (EEA):

  • Anthropic (Claude AI) — Message content is sent to US-based servers for AI response generation. Anthropic operates under Standard Contractual Clauses (SCCs) and their API terms include zero data retention for API usage.
  • fal.ai — Character descriptions are sent to US-based servers for image generation. Data is processed only for the duration of generation and not retained.
  • RevenueCat, Sentry, Expo — May process limited data on US-based infrastructure under Standard Contractual Clauses.

Where data is transferred outside the EEA, we ensure appropriate safeguards are in place in accordance with GDPR Article 46.

7. Data Retention

We retain your data for as long as your account is active. If you delete your account, we will delete all your personal data within 30 days. Some anonymized data may be retained for analytics purposes.

8. Your Rights (GDPR)

Under the General Data Protection Regulation (GDPR), you have the following rights:

  • Right of access — Request a copy of all data we hold about you
  • Right to rectification — Correct inaccurate personal data
  • Right to erasure — Request deletion of your account and all associated data
  • Right to data portability — Receive your data in a machine-readable format
  • Right to restrict processing — Limit how we use your data
  • Right to object — Object to certain types of data processing
  • Right to withdraw consent — Withdraw consent at any time

To exercise any of these rights, contact us at support@hiyou.app. We will respond within 30 days.

If you believe we have not handled your request adequately, you have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.

9. Data Security

We take the security of your data seriously. We implement the following measures:

  • All data is transmitted over HTTPS (encrypted in transit)
  • Passwords are hashed using bcrypt (never stored in plain text)
  • Database access is restricted and authenticated
  • API endpoints are protected by rate limiting and input validation
  • Content moderation systems are in place to detect harmful content

10. Children's Privacy

HiYou.AI is intended for users aged 18 and older. We do not knowingly collect data from anyone under 18. If we discover that a minor has created an account, we will delete it and all associated data immediately.

11. Cookies

The HiYou.AI mobile app does not use cookies. Our website may use essential cookies for basic functionality only.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes through the app or via email. The "Last updated" date at the top of this page indicates when this policy was last revised.

13. Contact Us

If you have any question