Privacy Policy

Last updated: September 7, 2026

This Privacy Policy describes how the operator of the Blush platform ("Operator," "we," "us," or "our") collects, uses, stores, discloses, and otherwise processes personal data in connection with Blush, including the website, Google Sign-In, gallery, member access controls, custom request tools, AI companion chat, character and set generation tools, the marketplace, the virtual economy, and related services (collectively, the "Service").

The Service is operated by Blush Companion SpA, a company incorporated in Chile, with registered office at Las Bellotas 199, office 62, Providencia, Región Metropolitana de Santiago, Chile. Blush Companion SpA is the data controller for the personal data described in this Policy and operates the Blush platform under the creator brand "Mati" (also referred to as "Mati AI"). Contact channels are described in Section 16 and our Patreon page.

This Policy is intended to reflect the Service as currently implemented in the reviewed codebase. It is written to support compliance with Regulation (EU) 2016/679 ("GDPR"), the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), and Chilean Law No. 19.628, as amended ("Ley 19.628"). This document does not constitute legal advice.

1. Scope and Eligibility

The Service is intended solely for adults eighteen (18) years of age or older. The Service is not directed to children, and we do not knowingly provide accounts to minors.

2. Categories of Personal Data We Process

Depending on how you use the Service, we may process the following categories of data:

2.1 Account, Google, and Patreon Data

You can create or access an account with an email address and password, Google Sign-In, or Patreon. If you register with email and password, we process your email address and a hashed form of your password through our authentication provider (Supabase Auth), together with password-reset requests you initiate.

Google Sign-In. When you choose Google Sign-In, Blush requests only the standard OpenID Connect scopes openid, email, and profile. From Google, the Service receives and processes:

We use this Google user data only to create, authenticate, secure, or link your Blush account and to initialize your Blush profile. Blush does not request access to Gmail messages, Google Drive files, Google Calendar events, contacts, or other Google Workspace content. The Blush application does not use Google provider tokens to call unrelated Google APIs.

Supabase Auth processes the Google OAuth exchange and maintains the resulting identity and session records on our behalf. Google provider access or refresh tokens may be included in the authentication session managed by Supabase and persisted in browser or device storage to keep you signed in. We do not sell Google user data, use it for advertising, provide it to data brokers, or use it to develop, improve, or train generalized or non-personalized artificial-intelligence or machine-learning models. Blush does not use Google Workspace APIs.

Limited Use. Blush's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used solely to provide and improve the user-facing sign-in and account features described above. It is not transferred to third parties except as strictly necessary to provide the Service, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to affected users. Google user data is retained only for as long as your account exists and is deleted as described in Sections 9 and 12; you may delete your account, and the associated Google user data, at any time.

When you authenticate through Patreon, we request Patreon OAuth scopes for:

Based on the current implementation, we retrieve and process:

We use this information to create or link your account, determine access entitlements, and administer member-only features.

2.2 Membership and Access Control Data

We process your current access tier (free, archon, or celestial), account status, and, where applicable, an internal administrator flag.

2.3 Authentication and Session Data

We use Supabase Authentication to maintain your login state. Based on the current code, session data is persisted in browser local storage. Temporary login-return routing information is stored in session storage during the Patreon callback flow.

2.4 Content Interaction Data

We process data relating to your use of the Service, including:

2.5 Custom Request Data

If you submit a custom set request, we process the text you provide, including character names, prompts, and status information associated with the request. The current user interface displays a placeholder for reference image upload, but the reviewed implementation does not presently show a completed upload flow for user-supplied reference images.

2.6 Technical, Preference, and Device-Side Data

We use browser-side storage, and in some cases cookies, to remember:

These are governed by your choices in the in-product Privacy Choices panel. Optional preference storage and optional analytics storage stay off until you choose otherwise.

2.7 Analytics and Approximate Location Data

When you have enabled optional analytics in the Privacy Choices panel, the Service sends analytics events to a database table and attempts to derive approximate country and city from a third-party geolocation service (ipapi.co). We do not intentionally store the end user's raw IP address in our own database; however, your IP address may be disclosed to third-party infrastructure providers when requests are made to Patreon, Supabase, Cloudflare R2, ipapi.co, and other network services involved in delivering the Service.

2.8 Companion Chat and Memory Data

If you use the AI companion chat features, we process:

Chat messages and companion memories are retained until you delete a conversation, use the "forget character" or "delete all companion data" controls, or delete your account.

2.9 Character and Set Generation Data

If you use the character or set generation tools, we process the prompts and settings you submit (freeform character descriptions, names, pronouns, style choices, NSFW-capability flags), generation job records and their intermediate steps, automated safety-screening events associated with your jobs, and your generation quota usage. Generated images are stored in our media storage (Cloudflare R2). Characters you create default to private visibility; you control whether a character becomes unlisted or publicly discoverable.

2.10 Marketplace and Virtual Economy Data

If you use the marketplace or virtual economy features, we process:

When a listing you created is live, its content — including your public display name, avatar, and aggregate creator statistics — is visible to other users. Buyer identities are not shown to creators; creators see aggregate sales metrics only.

2.11 Age Attestation Data

Before explicit chat features can be enabled, you must attest that you are an adult. We process the date of birth you provide and record the attestation in an append-only verification ledger. Self-attested verifications expire after 365 days, after which re-verification is required.

2.12 Voice and Audio Data

Where companion voice features are enabled, character dialogue text is sent to a third-party text-to-speech provider (Fish Audio) to generate audio. We process your voice-preference settings and TTS quota usage.

3. Sources of Personal Data

We collect personal data:

4. How We Use Personal Data

We use personal data for the following purposes:

5. Login and Payment Information

The Service supports login with email and password, Google Sign-In (through Supabase Auth), and Patreon. Google Sign-In is optional and is used only for account authentication, account linking, profile initialization, and related account security. It is not used to obtain access to Google Workspace services. Patreon is currently the membership and billing provider for paid tiers. We do not directly collect or store your payment card details or bank information; the billing provider remains responsible for processing subscription billing and payment instruments.

We do, however, process membership-related information received from Patreon, including whether you are entitled to a membership tier that unlocks specific content or features. We may also store Patreon access and refresh tokens on our backend in order to refresh membership status.

The codebase contains an integration with the payment processor CCBill for tier subscriptions; that integration is disabled, does not accept signups, and there are no plans to enable it. If we adopt a payment processor in the future, we will update this Policy before it goes live. Where a third-party payment processor is used, it processes your payment data under its own privacy policy; we receive subscription-status events (not card details) and store them to administer your entitlement.

The virtual currency "Devotion" is earned only through in-app activity, cannot be bought for money, and cannot be redeemed for money. The virtual currency "Ardor" is obtained only by purchase and likewise cannot be redeemed for money.

Ardor is purchased by cryptocurrency transfer to a deposit address shown for your account. There is no payment gateway in that path and we do not collect card or bank details for it. We do process, and are required to retain, records of the on-chain transaction, your consent to immediate delivery, and evidence of the country you are purchasing from; Section 2.10 lists these in full and Section 9 gives the retention periods. A deposit address associated with your account is visible on a public blockchain; anyone who learns it can observe transfers to it.

6. Legal Bases for Processing

Where GDPR applies, we rely on one or more of the following legal bases:

Where Ley 19.628 applies, we process data on the basis of consent, necessity to provide the requested service, legitimate legal grounds, and other bases recognized by applicable Chilean law.

Where CCPA/CPRA applies, this Policy is intended to provide notice of collection, categories of processing, and consumer rights.

7. Disclosure of Personal Data

We may disclose personal data to the following categories of recipients:

We do not "sell" personal information. Based on the reviewed code, we do not engage in cross-context behavioral advertising. Google user data is not disclosed for advertising, retargeting, credit or lending decisions, data brokerage, information resale, or generalized AI or ML model training. If our data practices materially change, we will update this Policy accordingly.

8. International Transfers

The Operator, Blush Companion SpA, is established in Chile. The Service uses providers that may process data in multiple jurisdictions, including the United States and the European Union, so your personal data may be transferred to, stored in, or accessed from countries outside your country of residence. Where required, we will use appropriate safeguards for such transfers.

9. Data Retention

We retain personal data only for so long as reasonably necessary for the purposes described in this Policy, including account administration, entitlement verification, security, recordkeeping, dispute resolution, and legal compliance.

Based on the reviewed implementation:

The full written retention schedule, including triggers and legal-hold handling, is published at docs/data-retention.md in the project repository.

10. Cookies, Local Storage, and Similar Technologies

The Service uses local storage, session storage, and certain cookie-based preference mechanisms. These technologies support:

The in-product Privacy Choices panel lets you accept or reject optional preference storage and optional analytics storage independently. Essential storage required to keep the site secure and working cannot be disabled, because the Service would not function without it.

11. Security

We use administrative, technical, and organizational measures designed to protect personal data. Based on the reviewed codebase, these measures include HTTPS/TLS encryption in transit, authentication and session controls, row-level access controls in the database, signed media URLs for protected assets, and entitlement checks before tier-gated assets are served. Access to Google identity data is limited to the systems and personnel that need it to operate authentication, account support, and security.

No method of transmission or storage is completely secure. You acknowledge that the security of information transmitted over the internet cannot be guaranteed absolutely.

12. Your Privacy Rights

Depending on your location, you may have the right to:

California residents may also exercise rights under CCPA/CPRA, including the rights to know, delete, and correct, subject to statutory limitations. Chilean data subjects may exercise rights recognized under Ley 19.628 as amended.

Most rights are available as self-service controls inside the Service: the Account & Data panel lets you export a copy of your data and delete your account, the Connected Accounts panel lets you unlink Google when another login method remains available, and the Privacy Choices panel lets you withdraw consent for optional analytics and preference storage. Deleting your Blush account removes the Google identity linkage and associated Blush profile data, subject to the limited legal-retention exceptions described in Section 9; you may also revoke Blush access from your Google Account settings. The export bundle includes your profile, interaction history, chat messages and companion memory summaries, personas, characters and worlds you created, generation job records, marketplace listings and your own purchases, virtual-economy history (Devotion ledger, inventory, shop and gacha records), subscription records, and aggregate counts from internal moderation tables; it deliberately excludes authentication provider tokens, encrypted Patreon tokens, other users' identities (for example, buyers of your listings), and raw memory embeddings (the embeddings exist only in the vector store and are deleted in full when you use the forget or delete controls). Within chat, the forget character and delete all companion data controls delete conversation history and companion memories, including the associated vector-store namespaces. To exercise rights that are not covered by a self-service control, contact us through the channels described on the Contact page. We may request information reasonably necessary to verify your identity before acting on your request. Our internal handling procedure (including target response times) is published at docs/dsr-playbook.md in the project repository.

If you are in the European Economic Area or United Kingdom, you may also have the right to lodge a complaint with a competent supervisory authority. If you are in Chile, you may have rights to seek review before the competent authority or tribunal as provided by law.

13. Sensitive and Adult Content

The Service is designed for adult audiences and includes erotic or NSFW fictional art and, where you opt in, explicit AI chat. Your use of the Service may therefore reveal, infer, or be associated with an interest in adult-oriented content. Chat content, companion memories, intimacy-preference settings, and wellbeing or crisis-screening signals can be particularly sensitive; we treat such information as sensitive in context, restrict access to it through row-level access controls, and do not use it for advertising. Access to explicit chat additionally requires the age attestation described in Section 2.11. Additional age-verification controls may be rolled out as part of ongoing compliance work.

13a. Image Metadata and Provenance

Operator-curated gallery content is uploaded to storage with EXIF, IPTC, XMP, GPS, and similar non-pixel metadata stripped or absent. AI-generated content is disclosed in the user interface via an explicit "AI" badge driven by a per-set flag (gallery_sets.is_ai_generated) and an optional admin-supplied provenance note. Where user-supplied uploads are introduced in the future, they will be re-encoded client-side to drop metadata before being sent to storage. See docs/data-handling.md for operational detail.

14. Third-Party Services

The Service may contain links to, or rely on integrations with, third-party services, including Google, Patreon, Supabase, Cloudflare, Anthropic, OpenAI, DeepSeek, xAI, OpenRouter, Pinecone, RunPod, Fish Audio, and ipapi.co. Their privacy practices are governed by their own policies and terms. We encourage you to review those policies before using third-party services.

15. Changes to This Policy

We may amend this Privacy Policy from time to time. When we do, we will update the "Last updated" date above and, where required by law, provide additional notice.

16. Contact Information