Effective Date: September 6, 2026
Genframe LLC (“we”, “us”, or “our”) deeply understands the importance of personal information to you. We will take appropriate security measures as required by applicable laws to keep your personal information secure and under your control. This policy applies to all products and services provided through the iChat mobile application and related websites (ichat365.app, collectively the “Product”), and such services are collectively referred to as the “Services”.
Please read this policy carefully and fully understand it, especially the content in bold, before using the Product. By checking your consent to this policy or starting to use the Product, you signify that you have read and agreed to this policy in its entirety. This policy, together with the iChat Terms of Service, forms the complete agreement between you and us.
Summary (for convenience only; the full text prevails):
Account information: the email address you provide when registering or logging in; if you sign in with Apple or Google, we receive the verified user identifier (ID) from that platform. We do not collect your name, avatar, or other profile data from those platforms unless you separately authorize it.
Profile information: the nickname, age, and gender you provide when completing your profile, and the avatar you upload. We recommend that you do not use your real name or other identifying information in your nickname.
Content generated in your use of the Service:
Payment-related information: order and receipt information generated when you purchase memberships or credits (e.g., transaction IDs, products, timestamps, platform). We do not collect or store your full payment instrument details such as bank card numbers; payments are processed by the App Store / Google Play and their payment providers.
To provide the following features, we request device permissions when you use the corresponding features; you may revoke them at any time in your device’s system settings:
| Permission | Purpose |
|---|---|
| Camera | Taking photos for your avatar and chats |
| Microphone | Voice messages and voice calls |
| Photo library (read/write) | Selecting images to upload; saving generated content |
| Notifications | Push message notifications |
We do not request location, contacts, Bluetooth, or other permissions.
For any purpose beyond those listed above, we will seek your separate consent.
In accordance with applicable law, we may process your personal information without your consent in the following circumstances: where necessary for the performance of a contract to which you are a party; where necessary to comply with legal obligations; where necessary in response to a public health emergency or to protect vital interests; where within a reasonable scope we process information you have made public or that has been lawfully made public; and other circumstances provided by law.
We do not sell your personal information. Solely for the purpose of providing the Service, we share the information necessary for each function with the following processors/partners, and require them to process the data in accordance with this policy and our contracts:
| Provider | Purpose | Information Shared | Processing Location |
|---|---|---|---|
| Tencent Cloud (messaging cloud, international edition) | Message transport and offline channels | Account identifiers, message content | United States (Silicon Valley) |
| Large-language-model providers (third-party AI providers we integrate, including xAI (Grok), OpenRouter, DeepSeek, Google (Gemini), OpenAI (GPT Image), Seedream, Seedance, MiniMax, and others; see the app for the current configuration) | Generating conversational replies, images, and video | Conversation context, retrieved memories, character settings, links to images you send | As deployed by each provider |
| SiliconFlow | Vectorizing memory text (AI memory retrieval) | Memory / message text | China |
| Linode (Akamai) Object Storage | Storing your uploaded images, voice, and files | Avatars, wallpapers, conversation images, voice, character-card files | United States |
| Brevo | Sending verification-code emails | Email address, verification code | European Union |
| RevenueCat | In-app purchase verification | User identifiers, transaction receipts | United States |
| Apple / APNs; Google / Firebase Cloud Messaging | Login identity verification, push notifications | Login credentials, push tokens | As applicable |
| PostHog (self-hosted by us) | Product analytics | Anonymized aggregate events (no message content) | Servers under our control |
Beyond the above, we share your personal information only when: (1) we have obtained your explicit consent; (2) necessary to comply with legal obligations or lawful requests from judicial or administrative authorities under statutory procedures; or (3) otherwise provided by law.
In the event of a merger, acquisition, or asset transfer requiring the transfer of your personal information, we will require the successor to remain bound by this policy; otherwise we will require it to obtain your fresh consent.
In the unfortunate event of a personal information security incident, we will, as required by law, promptly inform you of the basic facts of the incident, its possible impact, and the remedial measures taken or to be taken, via push notifications, email, or (where individual notification is impracticable) reasonable and effective public announcements.
Subject to the data protection laws applicable in your jurisdiction (where applicable), you have the following rights over your personal information:
After verifying your identity, we will respond to your request within 15 business days (or a shorter period required by applicable law). For requests that are unreasonably repetitive or require disproportionate technical means, we may decline and explain why.
We may revise this policy from time to time. Without your explicit consent, we will not reduce your rights under this policy. When this policy is updated, we will notify you of the changes via in-app announcements, pop-ups, or other appropriate means, and give you reasonable time to review the updated version before it takes effect.
If you have any questions, comments, or suggestions about this policy or about personal information protection, or wish to exercise your rights, please contact us:
We will generally respond within 15 business days. If you are not satisfied with our response, you may also lodge a complaint with the competent data protection authority in your jurisdiction.