Legal
Privacy Policy
Effective September 9, 2026. Binding. Read it.
This Privacy Policy explains what GoBantr collects, why, and what we do not collect. It covers https://gobantr.com, the waitlist, and the iOS app. Version one of the app is local-first. That is not a promise that nothing ever leaves your phone.
1. Who we are
The operator of GoBantr is the controller for waitlist and website analytics data. Model providers are independent controllers or processors of the prompts they receive when you generate a reply. Kit processes waitlist signups. Google processes Analytics data.
Privacy requests: privacy@gobantr.com. Use the same email address you submitted on the waitlist so we can find you.
2. What the website collects
If you join the waitlist we collect your email address and, if you choose, an interest tag (for example friend, romance, adult roleplay, mentor, creative, or curious). That data goes to Kit so we can send alpha invites and occasional product notes. It is not a marketing sequence you did not sign up for, but it is still personal data.
Google Analytics 4 collects device and usage data such as pages viewed, approximate location from IP, browser type, and referral. We use it to see whether the site works and whether people join the waitlist. We do not use it to sell you third-party ads.
3. What the app stores on your device
Personalities, chats, memories, portraits, and settings are intended to live in an encrypted local database on your iPhone, with the encryption key in the device Keychain. Uninstalling the app, losing the phone, or failing Face ID recovery can make that data unreadable. We cannot remote-restore v1 local chats.
Installation credentials and similar secrets are stored in the Keychain. Backups you export are files you chose to create. Keep them private. They can contain conversation content.
4. What leaves the device when you chat
To generate a reply, the app sends a deliberately assembled context package to our backend and then to selected AI providers. That package can include personality description, recent messages or summaries, and safety instructions. It is not “the whole phone,” but it is enough of the conversation to produce the next line.
Providers may log prompts according to their own policies. We do not represent that providers will never train on data unless their current terms say so. If you cannot accept provider processing, do not send messages.
5. What we do not do
We do not sell your personal information. We do not run a public personality marketplace or social graph. We do not require a public profile. We do not want children’s data.
- No sale of waitlist emails to data brokers.
- No sharing of on-device chat logs with advertisers.
- No account password stored by us for v1 local-first installs beyond installation tokens we issue.
6. Legal bases and retention
We process waitlist data to take steps toward a possible contract (an invite) and for legitimate interests in running a private alpha. We keep waitlist records until you ask to be removed or we shut the list down, then for a short additional period if we must keep records of a request.
Analytics data is kept according to our Google Analytics retention setting. Server logs, if any, are kept only as long as needed for security and debugging.
7. Cookies and similar tech
The marketing site uses Google Analytics, which uses cookies or similar identifiers where the browser allows them. You can block them with browser controls. The waitlist form does not require an analytics cookie to submit.
8. Children
The Services are not directed to children under 18. We do not knowingly collect personal information from them. If you believe a minor submitted an email, write to privacy@gobantr.com and we will delete waitlist data we can identify.
9. Your choices
You may request access, correction, or deletion of waitlist data we hold, subject to law. California residents may request that we disclose categories of information collected and that we not “sell” or “share” personal information as those words are used in the CCPA; we do not sell or share for cross-context behavioral advertising.
EEA/UK users may have additional rights of access, erasure, restriction, and objection. We may decline requests that are unlawful, abusive, or would compromise others’ information.
On device, you can delete messages, chats, personalities, or all local data from the app. That does not automatically erase provider-side logs.
10. Security
We use HTTPS on the site. The app uses device encryption and biometric lock. No method is perfect. You are responsible for who can unlock your phone and who can open exported backup files.
11. International transfers
Kit, Google, our hosting providers, and model providers may process data in the United States or other countries. Those places may not have the same privacy laws as yours. By using the site or sending a message, you understand that transfer.
12. California notice at collection
We collect identifiers (email) and internet activity (analytics) for the business purposes described above. We do not sell personal information and we do not share it for cross-context behavioral advertising. We do not use sensitive personal information to infer characteristics for advertising.
13. Changes
We may update this policy. The effective date will change. Material waitlist changes will be posted on this page. Continued use of the site after an update is acceptance of the revised policy.