Privacy policy
Last updated 05 August 2026. This describes what Fenris Labs Companions, operated by Fenris Labs, collects and what happens to it.
1. What we collect
From Discord, when you sign in. We request the
identify scope only: your Discord user ID, username, and avatar.
We do not request your email, your server list, or your messages elsewhere.
What you give us. A preferred name, pronouns, timezone, anything you write in “about you”, anything you write as a hard limit, and anything you tell a companion she should already know.
Your conversations. Message history with each companion, the notes she keeps about you, her long-term summaries, and her scheduled reminders. Each companion has its own separate database; memory never merges between companions or between users.
Technical and billing records. A session identifier, the IP address and browser string at sign-in, the IP address at age confirmation, your Stripe customer and subscription identifiers, amounts, and dates. Also per-request AI usage counts (tokens and timings) used to calculate operating cost.
We never receive your card details. Payment happens on Stripe's own hosted page; card numbers never reach our servers.
2. Who else sees it
AI model providers. To generate a reply, the relevant part of your conversation — including her memory of you and your profile text — is sent to a third-party model provider. Currently these are DeepSeek and Google (Gemini). Which one handles a given message depends on the character's configuration. Their handling of that data is governed by their own terms, not ours.
Discord. Every message is also a Discord message and is subject to Discord's privacy policy.
Stripe. Payments and billing records.
Amazon Web Services. Hosting, and a copy of billing records (subscriptions, payments, operating costs) held in DynamoDB. That copy contains identifiers and amounts — not conversations.
We do not sell your data, and we do not use it for advertising.
3. What the operator can see
The operator has administrative access to all instance memory and message history, and uses it for support, moderation, and debugging. Your conversations are private from other users, not from us.
4. How long we keep it
- Sessions — 14 days, then expired and deleted.
- Routine backups — rolling, kept 72 hours; one promoted copy per week kept a fortnight.
- Billing-cycle backups — one per payment, kept indefinitely.
- Farewell backups — taken when a subscription ends and kept indefinitely, so a companion can be restored if you come back. See §5: this limits how completely we can delete your data unless you ask.
- Billing records — kept as long as required for tax and accounting. The DynamoDB copy is append-only by design and cannot be edited or deleted by the server.
5. Your controls, and their limits
From your dashboard, without asking us:
- Export everything a companion holds about you, as JSON or as a plain-text transcript.
- Wipe what she remembers about you, her adult-content memory, or reset her to her original state.
- Edit your profile, your hard limits, and — depending on what the character's owner permits — her memory of you directly.
- Cancel your subscription, and manage cards and invoices through Stripe's own portal.
An important limit. Wiping memory clears the live instance; it does not reach into backups already taken, and billing-cycle and farewell backups are kept indefinitely. If you want your data erased from backups as well, contact us and say so explicitly — we will delete the archives and confirm. Billing records we are legally required to retain are the exception.
Depending on where you live you may have rights to access, correction, erasure, portability, and objection. Contact us and we will comply within 30 days.
6. Cookies
A session cookie so you stay signed in, and a short-lived cookie during the Discord sign-in round trip. No analytics, no tracking, no third-party cookies, no advertising pixels.
7. Security
Traffic is encrypted in transit. Credentials and API keys are encrypted at rest. Access to the server is restricted to the operator.
We are a small operation on a single server, not an enterprise with a security team. We do not claim to be unbreachable. If there is a breach affecting your data we will tell you in The Warren and by whatever contact details we hold, promptly and without minimising it.
8. Children
The Service is 18+. We do not knowingly collect data from anyone under 18; if we learn that we have, we delete it and terminate the account.
9. Changes
Material changes will be announced in The Warren before taking effect, and the date at the top of this page will change.
10. Contact
For any data request: saakra.fenrislabs@gmail.com
See also the terms of service.