← Back to home

Legal

Privacy Policy

Last updated: July 2026

1. Who we are

withSolène ("we", "us", "our") is an AI companion application operated by:

Willy Lu Wang
Hermann-Müller-Würtz-Straße 36, 76189 Karlsruhe, Germany
privacy@withsolene.com

We are the data controller for all personal data processed through the withSolène app and website.

2. What we collect

  • Account data: Email address, authentication provider (Google, Apple), account creation date.
  • Conversation data: Messages you send and receive, stored encrypted with AES-256-GCM on your device. We cannot read the content of your messages.
  • Relationship memory data: withSolène builds a structured memory model of the people, events, and patterns you share with us, to provide contextually aware responses across sessions. This is a form of automated profiling and is described further in Section 4.
  • Usage telemetry: Anonymised session data (turn count, response latency). No message content is included in telemetry.
  • Subscription data: Subscription status and payment dates. Card details are held by our payment processor, not us.

3. How we use your data

We process your data on the following legal bases under GDPR Article 6:

  • Account data — performance of contract (Art. 6(1)(b)): necessary to provide the withSolène service.
  • Conversation data — performance of contract (Art. 6(1)(b)): processed by AI models to generate responses. See Section 5 for how this is transmitted to third-party providers.
  • Relationship memory data — performance of contract (Art. 6(1)(b)): core functionality of the service.
  • Usage telemetry — legitimate interests (Art. 6(1)(f)): improving service performance and reliability.
  • Legal compliance — legal obligation (Art. 6(1)(c)): where required by applicable law.

We never sell your data. We never use your conversations to train AI models.

4. Automated profiling

withSolène uses automated processing to build a contextual memory model from your conversations. This model stores structured information about the people, relationships, and patterns you describe, and is used to provide more relevant and personalised responses over time.

In accordance with GDPR Articles 13 and 22, we disclose that:

  • This processing constitutes automated profiling of your personal data.
  • It does not produce legal or similarly significant effects on you — it is used solely to improve conversational relevance.
  • You may request deletion of your memory model at any time via the app menu (···) → Delete my account, or by contacting privacy@withsolene.com.
  • You may also request a copy of your memory data under your right of access (Section 7).

5. Third-party services and data transfers

The following third-party services process your data on our behalf:

  • Supabase — database and authentication. US-based servers. Data transfers to Supabase are covered by Standard Contractual Clauses (SCCs) approved by the European Commission, and where applicable the EU-US Data Privacy Framework (DPF).
  • Anthropic / OpenAI — AI model providers. Your conversation messages are transmitted to these providers solely to generate AI responses. These providers do not retain your messages beyond the session and do not use them to train their models under our agreements with them. Data transfers are covered by Standard Contractual Clauses (SCCs). These providers are US-based and subject to their own EU AI Act obligations as general-purpose AI (GPAI) model providers.
  • ElevenLabs — voice synthesis (optional feature, only if you enable voice). Data transfers covered by SCCs.
  • RevenueCat — subscription and entitlement management for App Store and Google Play subscribers. RevenueCat receives subscription status and transaction data from Apple and Google to sync your access entitlement across devices. We do not store payment card details; these are held by Apple, Google, or Dodo Payments depending on your subscription path. Data transfers are covered by RevenueCat's Data Processing Agreement.
  • Dodo Payments — subscription and payment processing for web subscribers. We do not store card details. Dodo Payments operates as merchant of record for web purchases.

All transfers of personal data from the EU/EEA to third countries are governed by appropriate safeguards under GDPR Chapter V, primarily Standard Contractual Clauses. Where providers are certified under the EU-US Data Privacy Framework, we may additionally rely on that mechanism.

Note: The EU-US Data Privacy Framework was upheld by the European General Court in September 2025 but remains subject to potential future legal challenge. We maintain SCCs as a fallback transfer mechanism in all cases.

6. Data retention

You may delete your account and all associated data at any time from within the app (the app menu (···) → Delete my account). Deletion is processed within 30 days. Anonymised telemetry may be retained for up to 90 days after deletion.

Conversation data encrypted on your device is deleted when you delete the app or your account. We do not retain decrypted conversation content on our servers.

7. Your rights

Regardless of your location, you may request:

  • Access — a copy of the personal data we hold about you, including your memory model.
  • Deletion — removal of your account and all associated data.
  • Correction — correction of inaccurate data.
  • Restriction — restriction of processing in certain circumstances.
  • Portability — your data in a structured, machine-readable format.
  • Objection — objection to processing based on legitimate interests.

To exercise any of these rights, contact us at privacy@withsolene.com. We will respond within 30 days.

8. Data breach notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the competent supervisory authority (Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg) within 72 hours of becoming aware of the breach.
  • Notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

9. Supervisory authority

You have the right to lodge a complaint with the data protection supervisory authority in your country of residence. In Germany, the competent authority for withSolène is:

Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Königstraße 10a, 70173 Stuttgart, Germany
www.baden-wuerttemberg.datenschutz.de

If you are located in another EU member state, you may alternatively lodge a complaint with the supervisory authority in your country of residence.

10. Children

withSolène is not directed at children under 13. We do not knowingly collect personal data from anyone under 13. If you believe a child under 13 has created an account, please contact us immediately at privacy@withsolene.com and we will delete the account promptly.

Users between 13 and 15 in the European Union should have parental or guardian consent before using the service, in accordance with GDPR Article 8 and applicable national law.

11. Changes to this policy

We may update this policy from time to time. Significant changes will be communicated in the app or by email. Continued use constitutes acceptance. The date at the top of this page reflects the most recent revision.

12. Contact

Questions about this policy or your data?
Email: privacy@withsolene.com
Post: Willy Lu Wang, Hermann-Müller-Würtz-Straße 36, 76189 Karlsruhe, Germany