Privacy Policy

Effective September 2026 · Last updated 9 September 2026

1. Who is responsible for your data

Nevika Innovations Private Limited, 1st Floor, Mapkhan Nagar, Opp. Municipal School, Marol, Marol Naka, Andheri (East), Mumbai – 400059, Maharashtra, India, is the data fiduciary and controller for Syfra. This policy explains what we collect when you use the Syfrawebsites and apps, why we collect it, who processes it for us, and the choices you have. It should be read with our Terms of Service and Cookie Policy.

Privacy contact: privacy@nevika.ai.

2. What we collect

  • Account data — your verified email address from the sign-in provider you choose, your display name and avatar, and your mobile number if you sign in with a one-time SMS code.
  • Conversation data — the messages you send, images you attach, the replies characters generate, and the AI-written summaries, remembered facts and semantic memory vectors that give a character continuity with you.
  • Creations — characters, personas, worlds, roleplay sessions, group chats and uploaded artwork, along with whether you published them.
  • Preferences — theme, mature-content and safety settings, notification choices, voice settings, and any model preferences or API key you choose to store.
  • Usage and technical data — model and token counts with estimated cost, feature usage, sign-in attempts, IP address, device and browser information, and error diagnostics.
  • Safety and moderation data — reports you file or that concern your content, the excerpt reported, moderator decisions and review notes.
  • Billing data — plan, order and payment status from our payment gateway. We never see or store your full card details.

3. Why we use it, and on what basis

We process your data to perform our contract with you (running your account, generating replies, keeping character memory, billing), on the basis of our legitimate interests and legal obligations (security, abuse prevention, fair-use limits, moderation, accounting), and on the basis of your consent where consent is required (SMS sign-in, marketing or push notifications, storing your own model API key, unlocking mature content). Where the Digital Personal Data Protection Act, 2023 applies, we rely on the consent you give at sign-up and on legitimate uses permitted by that Act; you may withdraw consent at any time as described in section 7.

We do not sell your personal data, do not use your private conversations for advertising, and do not run behavioural ad tracking on Syfra.

4. AI models and training

To generate a reply we send the relevant part of your conversation — the character definition, recent messages, retrieved memory and your current message or image — to the AI model provider routed for that request. We instruct our providers to process this data only to return a response to us. We do not train our own foundation models on your conversations, and we do not hand your conversations to third parties for their own model training. If you supply your own provider API key, requests made with it are additionally subject to that provider’s terms.

5. Who processes data for us

We use service providers (processors), not data brokers. Each is bound by contract to confidentiality and to using the data only for the service it provides to us:

  • cloud hosting, database, authentication and file storage providers;
  • AI model and embedding providers, for generating replies, memory and discovery;
  • an SMS provider, for one-time sign-in codes;
  • an email provider, for account and transactional email;
  • a push-notification provider, if you enable notifications;
  • a voice-synthesis provider, if you use read-aloud;
  • a payment gateway, for plan purchases and refunds.

We may also disclose data where legally compelled, to protect the safety of a person, to enforce our terms, or in connection with a merger or reorganisation (in which case this policy continues to apply to the transferred data).

6. Safety screening and human review

Messages and published characters are screened automatically for prohibited categories — most importantly any sexualisation of minors, credible threats of violence, and signs of immediate self-harm risk, where we surface crisis resources. Screening is automated by default. A person on our moderation team reads a specific excerpt only when it is reported, when an automated flag needs adjudication, or when the law requires it. Moderation decisions and notes are kept as a record of enforcement.

7. Your rights and choices

You may access and correct your profile, export or request a copy of your data, delete individual conversations, characters or personas, delete your account, withdraw consent for notifications or mature content, and object to or ask us to restrict a particular processing activity. You may also nominate another person to exercise your rights in the event of death or incapacity. Write to privacy@nevika.ai from your registered address; we respond within 30 days and may ask you to verify your identity. If you are unhappy with the outcome you may escalate to our Grievance Officer at grievance@nevika.ai and, in India, to the Data Protection Board.

8. How long we keep it

Conversations, memory and creations are kept while your account is open, so characters can remember you, and are deleted when you delete them or close your account. One-time SMS codes expire within minutes and sign-in audit records are kept for up to 90 days for abuse prevention. Moderation records and records needed for tax, accounting or legal-defence purposes are kept for as long as the applicable law requires. Encrypted backups roll off within 30 days of deletion.

9. Children

Syfra is an adults-only service. We do not knowingly collect personal data from anyone under 18, we do not profile children, and we do not direct advertising at them. If you believe a minor has created an account, email privacy@nevika.ai and we will verify and remove it.

10. Security

Data is encrypted in transit, access to production data is restricted to staff who need it and logged, database rules confine your rows to your account, and secrets are held in managed secret storage rather than in code. No system is perfectly secure: please avoid sharing financial details, government identifiers or other sensitive personal information in chats. If a breach affects your personal data we will notify you and the competent authority as required by law.

11. International transfers

Some of our providers operate outside India, including in the United States and the European Union. Where data leaves your country we rely on contractual safeguards such as standard contractual clauses and on provider commitments to equivalent protection.

12. Cookies and local storage

We use only what is needed to keep you signed in and to remember your settings. The details are in our Cookie Policy.

13. Changes to this policy

If we change how we handle your data we will update this page, change the effective date and, for material changes, tell you in the app or by email before the change takes effect.