← Back to Airtrek AI
Privacy Policy
Last updated: July 20, 2026 | Effective: July 20, 2026
1. AI Disclosure & You're Talking with AI
You are talking with AI characters, not real people. The
characters Marcus Aurelius, Livia, Gaius, Chiyo, Nami, and Tetsuro are AI
language models trained to respond in historical and cultural voices. They
do not have personal beliefs, feelings, or continuity of memory across
your conversations, though Airtrek AI preserves your conversation history so
they remember you across sessions.
This is required transparency under EU AI Act Article 50. We take it
seriously: we mean it, and we want you to know it clearly.
2. Information We Collect
Authentication & Account
- Email address (for login via Supabase)
- Session tokens (stored securely in your browser)
Your Interactions
-
Conversations: Every message you send and every
response you receive from our AI characters
-
Selfies & Portrait Photos: Your self-portrait
images, used to generate personalized in-scene imagery
-
Location & Era Choices: Which historical location
and time period you choose to visit
-
Usage Events: How long you chat, which features you
use, latency measurements (aggregate only, never message content)
Device & Browser
- Browser type, device type, language, timezone
- IP address (for rate-limiting and abuse prevention)
3. Where Your Data Lives (July 2026)
Current State: Airtrek AI uses a device-first storage model
for sensitive media (selfies, portraits) and US-based cloud infrastructure
for conversation memory and account data. Under US law, including the
CLOUD Act, we cannot guarantee that US authorities cannot access
cloud-stored data if compelled.
Infrastructure Breakdown
-
Selfies & Generated Portraits: Device-only. Your
raw selfie and the AI-generated historical portrait are processed
in-session and stored encrypted in your browser's IndexedDB (via the
IdentityVault). They are never uploaded to or retained
on our servers. The server uses your selfie transiently to run the AI
transformation and discards it immediately.
-
Generated Character Images: Returned to your browser
as base64 image data and cached locally. They are not currently stored
in cloud storage. Your Passport Gallery metadata (character, era,
timestamp, and a reference to the image) is stored in your browser's
localStorage and synced to Firestore so your gallery can be restored
across devices. The image bytes themselves stay on your device unless
you choose to download them.
-
Conversation History (Local): Your full chat history is
stored in your browser's localStorage on your device. You control it.
Clear your browser data and it's gone.
-
Conversation Memory (Cloud): To let characters remember
you across sessions, conversation turns are persisted to Google Cloud
Firestore (US region) as memory records. These records power character
recall (e.g., a character remembering what you discussed last time). See
§4 below for retention and deletion.
-
Account Data: Email, auth credentials (managed by
Supabase), coin balance, and usage stats are stored in Google Cloud
Firestore (US region).
-
LLM API: Mistral Cloud API (US-based, with data
retention disabled where available)
-
Image Generation: Google Gemini 2.5 Flash Image (Nano
Banana) API (US-based). All generated images include an invisible
SynthID watermark identifying them as AI-generated.
-
Voice Synthesis: Cartesia Sonic TTS (US-based, no
content retention)
AI-Generated Content Disclosure
Airtrek AI characters are AI-generated personas, not real historical persons.
You are always informed when you are interacting with an AI character
(visible indicator in the chat interface and onboarding). All AI-generated
images carry a SynthID watermark (machine-detectable). AI-generated voice
audio and portraits are labeled as AI-generated in the UI.
4. Conversation Memory: Retention & Deletion
How long do we keep your conversation memory?
Conversation turns are retained in Firestore as memory records for as long
as your account is active. This retention is functional,
not for analytics or monetization. It is what allows characters to
remember you across sessions. We do not monetize
conversation data, and our team does not routinely read
individual conversations.
You are in control:
-
Delete a conversation locally (in the chat UI) → it's removed from your
device immediately.
-
Delete your account (in the Account page) → all cloud-stored
conversation memory, account data, and associated records are
permanently deleted across Firestore and Supabase. See §5.
Selfies and generated portraits are never stored on our
servers. They live only on your device, encrypted, and are
deleted when you clear your browser data or delete them from your Passport
Gallery.
5. Your Rights: Deletion, Access, Portability
You can exercise these rights instantly, in-app, no email
request required.
Right to Delete (GDPR Art. 17)
You can permanently delete your account and all associated cloud data at
any time from the Account page in the app. This triggers
a cascading deletion across:
-
Conversation memory: All your records in Firestore
(Stella memory) are permanently deleted
-
Supabase auth: Your auth account and credentials are
deleted
-
Account data: Coin balance, usage stats, passport
gallery metadata, all deleted
-
Local data: Browser localStorage and IndexedDB are
cleared on your device
This action cannot be undone. Deletion is immediate for
cloud data; your characters will no longer remember you.
Prefer email? You can also request deletion by emailing
kelly@airtrek.ai with the subject "Delete My Account."
Right to Data Export (GDPR Art. 20)
You can download a complete copy of your data in machine-readable JSON
format from the Account page in the app. The export
includes your conversation memory, profile, coin history, and metadata.
The download is generated instantly, no waiting period.
Prefer email? You can also request an export by emailing
kelly@airtrek.ai with the subject "Export My Data."
Right to Portability
Your conversation history lives on your device (in browser localStorage)
and can be exported via the Account page. Your selfies and generated
portraits are device-only. You own them entirely. You can back them up,
move them, or delete them at any time without asking us.
6. Analytics & Usage Metrics
We track aggregate usage to improve the service:
- Session length (how long you chat)
-
Features used (which characters you talk to, which
locations)
-
Latency & performance (to identify slow code)
- Error rates (to catch bugs)
We do NOT track: message content, selfie data,
personalized conversation themes, or any identifiable details. All
analytics are aggregate and anonymized.
Consent-gated: Google Analytics and Sentry (error
monitoring) load only after you click "Accept all" in the cookie
banner. If you choose "Essential only," no analytics or error-reporting
scripts run and no usage/error data is sent to third parties. You can
change your choice anytime in the Account page.
7. How We Protect Your Data
-
In Transit: All data travels over HTTPS (TLS 1.2+)
-
In Storage (Cloud): Firestore data is encrypted at rest
by Google Cloud's managed encryption
-
In Storage (Device): Selfies and generated portraits
are encrypted in your browser's IndexedDB using AES-GCM (via
IdentityVault)
-
Access Control: Our team does not have routine access
to individual conversation content. All authenticated endpoints verify
a Supabase JWT. No client can read another user's data.
-
Content Security Policy: The app enforces a strict CSP
(no external scripts, no inline scripts) to prevent cross-site scripting
attacks.
8. Third-Party Services
Airtrek AI uses the following third-party services. Each has its own privacy
policy:
-
Supabase: Authentication (your email + password hash).
Auth only. No app data is stored in Supabase.
-
Google Cloud (Firebase, Firestore, Cloud Functions,
Hosting): Infrastructure and database
-
Google Gemini 2.5 Flash Image (Nano Banana): Image
generation API. All outputs include a SynthID watermark.
-
Mistral AI: Large language model inference (chat
characters)
-
Cartesia: Text-to-speech voice synthesis (Sonic TTS)
-
Stripe: Payment processing for token pack purchases
-
Sentry: Error monitoring (crash reports and performance
data). Loads only after "Accept all" consent. Email and IP address are
stripped from error reports before sending.
For questions about how these services handle your data, refer to their
respective privacy policies.
9. GDPR & EU Compliance
If you are in the EU, you have rights under GDPR including access,
rectification, erasure, and data portability. Airtrek AI commits to:
-
Data Minimization: We collect only what is necessary to
provide the service. Selfies and portraits are device-only, never
uploaded to our servers.
-
Purpose Limitation: Your data is used only to provide
the service and power character recall, not for marketing or secondary
purposes.
-
Storage Limitation: Conversation memory is retained for
as long as your account is active (to power character recall). You can
delete it at any time via the Account page. Selfies and portraits are
device-only.
-
Deletion (Art. 17): Instant, in-app account deletion
cascades across all cloud stores. No waiting period, no strings attached.
-
Portability (Art. 20): Instant, in-app JSON export of
all your cloud-stored data.
-
Biometric Data (Art. 9): Selfie processing requires
explicit, informed consent via a biometric consent modal before any
selfie is processed. Selfies are processed transiently and never stored
server-side.
-
AI Transparency (AI Act Art. 50): A standing indicator
in every chat tells you the characters are AI, not real historical
persons. Generated images carry an invisible SynthID watermark
(machine-readable) and an AirTrek logo watermark when exported or
downloaded. Generated scenes and synthetic voice are labeled
"AI-generated" / "AI voice" at the point of viewing and listening, and
passport images that composite your photo are marked as AI composites —
not real historical records. Each generated asset carries a provenance
record (model, timestamp, user-prompted vs system-generated).
CLOUD Act Notice: Because cloud data is stored on US-based
infrastructure (Google Cloud), we cannot guarantee that US authorities
cannot access it if compelled. Device-only data (selfies, portraits, local
chat history) is not subject to this exposure.
International Data Transfers (GDPR Chapter V)
Airtrek AI is operated from and its service providers are located in the
United States. If you are in the EU/EEA or UK, using the
app means your personal data is transferred to and processed in the United
States. The United States is not covered by an EU adequacy decision for
all transfers, so we rely on Standard Contractual Clauses
(SCCs) adopted by the European Commission (Decision (EU) 2021/914)
as the transfer safeguard for our cloud providers (Google Cloud/Firebase,
Supabase, Mistral AI, Cartesia, Sentry, Stripe), each of which offers SCCs
or an equivalent transfer mechanism under their Data Processing Agreements.
Wherever possible, data is kept on your device (selfies, portraits, local
chat history) and encrypted, minimizing what is transferred. You may
exercise your rights (access, erasure, portability, objection) at any time
via the Account page.
Cookies, Local Storage & Consent (ePrivacy Directive)
When you first visit, a cookie consent banner lets you choose
"Accept all" or "Essential only." We store
information on your device (localStorage/IndexedDB) in two categories:
-
Strictly necessary (no consent required): your
authentication token, your consent choices, age verification, and the
app-state needed to provide the service you requested (scoped chat
history, met characters, language and preferences). The app cannot
function without these.
-
Non-essential (consent required): Google Analytics
(usage statistics) and Sentry (error monitoring). These load
only after you click "Accept all." Choosing "Essential only"
or withdrawing consent removes/stops them — no analytics or error data
is then sent to third parties.
You can change or withdraw your consent at any time in the
Account page. Withdrawing consent stops Google Analytics
and Sentry immediately and is recorded in our consent audit trail
(GDPR Art. 7).
10. Contact Us
Questions about this privacy policy? The fastest way to exercise your
deletion or export rights is in the Account page in the
app. For policy questions, email us:
Email:
kelly@airtrek.ai
Subject line examples:
- "Privacy Policy Question"
- "Delete My Account" (or use the in-app Account page)
- "Export My Data" (or use the in-app Account page)
11. Changes to This Policy
This privacy policy will evolve as Airtrek AI grows. Major changes will be
announced in-app and via email. By continuing to use Airtrek AI, you accept
the current policy; if you disagree with changes, you can delete your
account anytime via the Account page.
Last Updated: August 14, 2026
Version: 3.2 (Beta 2.0, Device-First, In-App GDPR
Rights, AI Act Transparency + Point-of-Use Labels + Provenance Records,
Consent-Gated Monitoring, International Transfer Disclosure)
This privacy policy supersedes all prior versions. If you are an existing
user from before this update, your data is now covered by the terms
above, including instant in-app deletion and export. The prior 30-day
safety retention window is no longer in effect; conversation memory is
retained for character recall and is deletable at any time via the
Account page.