Back to home

Privacy Policy

Last updated: June 4, 2026

This Privacy Policy describes how CharacterOS ("we", "us", or "our") collects, uses, stores, and shares information when you use our website and services at CharacterOS (the "Service"). This policy applies to all users and is designed to meet Google's requirements for applications that use Google Sign-In and other Google API Services.

1. Who We Are

CharacterOS is an AI character consistency platform for anime, manga, and creative storytelling. The Service is operated by the CharacterOS development team. When this policy refers to "Google user data", it means personal data we receive from Google when you sign in with Google or link a Google account.

2. Information We Collect (Non-Google)

In addition to Google user data described below, we may collect:

  • Account information you provide directly, such as email address, password (stored only as a secure hash), and optional display name.
  • Email verification codes when you sign in with a one-time code.
  • Content you upload or generate, including character images, DNA metadata, expressions, scenes, and related creative assets tied to your account.
  • Usage and technical data, such as IP address, browser type, device information, API request logs, and subscription or quota usage.
  • Cookies and similar technologies as described in our Cookie Policy.

3. Google User Data We Collect

When you choose "Continue with Google" or link Google in Settings, we use Google Identity Services (Google Sign-In). Google shares an ID token with our application after you authenticate with Google. From that token we verify and may store the following Google user data:

  • Google account ID (subject identifier / "sub") — to identify your Google account and link it to your CharacterOS account.
  • Email address — to create or match your CharacterOS account and for account-related communications.
  • Display name — to populate your profile nickname when you first sign up.
  • Profile picture URL — to populate your avatar when you first sign up.

We request only the scopes required for Google Sign-In (typically openid, email, and profile). We do not request access to Gmail, Google Drive, Calendar, Contacts, or other Google Workspace data.

We do not access Google user data until you complete Google's sign-in flow and our Service receives a valid ID token.

4. How We Use Google User Data

We use Google user data solely to provide and improve user-facing features of CharacterOS, including:

  • Authenticating you and maintaining your session.
  • Creating a new CharacterOS account or signing you into an existing account.
  • Linking a Google sign-in method to an account that uses the same email address.
  • Displaying your profile name and avatar within the Service.
  • Protecting the Service against fraud, abuse, and unauthorized access.
  • Complying with applicable law and enforcing our terms.

We do not use Google user data for advertising, interest-based or retargeted ads, creditworthiness, lending, selling to data brokers, creating advertising profiles, or training generalized machine learning models unrelated to your use of CharacterOS.

5. How We Share, Transfer, or Disclose Google User Data

We do not sell Google user data. We do not share, transfer, or disclose Google user data to third parties except in the limited circumstances below, and only as needed to provide or improve the Service or for permitted purposes under Google's policies:

  • Infrastructure and hosting providers that process data on our behalf under contractual confidentiality and security obligations (for example, cloud servers, databases, and object storage).
  • Email delivery providers when we send account-related messages to the email address associated with your account.
  • Professional advisors or authorities when required by law, legal process, or to protect rights, safety, and security.
  • A successor entity in connection with a merger, acquisition, or sale of assets, only after providing notice and, where required, obtaining your consent.

We do not share Google user data with third parties for their independent marketing, advertising, or data brokerage purposes.

6. Data Protection and Security

We implement reasonable technical and organizational measures designed to protect all personal data, including Google user data, against unauthorized access, alteration, disclosure, or destruction. Measures include, where appropriate:

  • HTTPS/TLS encryption for data in transit between your browser and our servers.
  • Access controls and authentication for production systems.
  • Hashed storage of passwords (we do not store plaintext passwords).
  • Validation of Google ID tokens with Google before trusting sign-in credentials.
  • Restricted internal access to production databases on a need-to-know basis.

No method of transmission or storage is completely secure. If you believe your account has been compromised, contact us promptly using the details in Section 12.

7. Data Retention and Deletion

We retain personal data, including Google user data, for as long as your account is active and as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements.

  • Account and profile data (including Google-linked identifiers, email, name, and avatar) are kept while your account exists.
  • Creative content and usage records may be retained according to our backup and operational schedules unless you request deletion.
  • When you delete your account or request deletion of your data, we will delete or anonymize personal data within a reasonable period, except where retention is required by law or for legitimate security purposes.

To request access, correction, export, or deletion of your data, email us at [email protected] from the address associated with your account. We may ask you to verify your identity before fulfilling the request. Disconnecting Google in Google Account settings stops new Google sign-ins but does not by itself delete data already stored in CharacterOS — contact us for account deletion.

8. Google API Services — Limited Use Disclosure

CharacterOS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In summary:

  • We only use Google user data to provide and improve user-facing features that are prominent in the CharacterOS interface.
  • We do not sell Google user data.
  • We do not use Google user data for serving advertisements.
  • We do not allow humans to read Google user data except with your affirmative agreement for specific support requests, for security investigations, to comply with law, or when data is aggregated and anonymized for internal operations.
  • If we change how we use Google user data in a way that is materially different from what is described here, we will update this policy, notify users, and obtain your consent where required before using the data for the new purpose.

9. Your Choices and Rights

You can choose not to use Google Sign-In and instead register or sign in with email. You can sign out at any time. Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal data. We will respond to valid requests in accordance with applicable law.

10. Children's Privacy

CharacterOS is not directed at children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has provided us personal data, contact us and we will take steps to delete such information.

11. International Users

We may process and store information on servers located in countries other than your own. By using the Service, you understand that your information may be transferred to jurisdictions that may have different data protection laws than your country.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the "Last updated" date. If we materially change how we handle Google user data, we will provide additional notice (for example, in the app or by email) and obtain consent where required by Google or applicable law.

13. Contact Us

For privacy questions, Google user data requests, or account deletion, contact: