Immersive Privacy Policy
Effective date: September 3, 2026
Last updated: September 3, 2026
This Privacy Policy explains how Swift Media Entertainment (“Immersive”, “we”, “us”, or “our”) collects, uses, shares, and protects your personal data when you use the Immersive mobile application, our website at immersive.osu.ai, and any related services that link to this policy (together, the “Services”).
Immersive is an AI companion and roleplay chat platform. Because conversations on Immersive can be personal, we have tried to write this policy in plain language and to be specific about what we do with your data.
Immersive is intended for users aged 17 and over. If you are under 17, do not create an account or send us any personal data. See Age Requirements and Children’s Data.
If you do not agree with this policy, please do not use the Services. Questions go to privacy@osu.ai.
Quick Summary
This summary is for convenience only; the full sections below control.
| Question | Short answer |
|---|---|
| What do you collect? | Account details, your chats and uploads, character and model settings, device and log data, purchase records. |
| Do you sell my data? | No. We do not sell personal data and do not share it for cross-context behavioral advertising. |
| Do you train AI on my chats? | We may use anonymized and aggregated data — including chat transcripts, character configurations, and feedback signals — to train and improve our models. See Model Training. |
| Can I delete my data? | Yes. Delete individual chats and uploads in-app at any time, or delete your whole account at immersive.osu.ai/settings/privacy. |
| Who is this for? | Users 17 and older. |
| Where do you operate? | Globally. Region-specific rights for the EEA/UK, US states, Canada, and Brazil are set out below. |
1. Who We Are and How to Reach Us
- Controller: Swift Media Entertainment
- Registered address: 1000 Brickell Plaza #4806 Miami, FL 33131
- General support: support@osu.ai
- Privacy and data rights: privacy@osu.ai
- Data Protection Officer: dpo@osu.ai
- Law enforcement requests: legal@osu.ai
- Security reports: security@osu.ai
- EU representative (Art. 27 GDPR): EU Team, 1000 Brickell Plaza #4806 Miami, FL 33131
- UK representative: UK Team, 1000 Brickell Plaza #4806 Miami, FL 33131
2. Personal Data We Collect
2.1 Data you give us directly
Account creation and login. Email address, username, and a hashed password. If you use single sign-on, see Section 2.3.
Profile. Display name, avatar, bio, date of birth (for age verification), and any other details you add. Anything you put in a public profile can be seen by other users.
Characters, roles, and model settings. The characters you create or customize, persona and scenario descriptions, memory notes, voice and model preferences, content filter settings, and tags.
Chat content. The messages you send to and receive from our AI characters, images and files you upload into a conversation, voice recordings if you use voice input, and any regenerations, edits, or ratings you apply to a response.
Your chats and uploads are stored on our servers so we can deliver the Service — conversation continuity, memory, and history across devices. You can delete individual messages, conversations, or uploads at any time from within the app.
Please do not upload other people’s personal data. If you upload images or information about identifiable third parties, you are responsible for having their permission. Do not upload sensitive data (health, biometric, financial, government ID numbers, or data about children) that you would not want stored.
Feedback, reports, and support. Bug reports, moderation reports, survey answers, and the contents of emails or support tickets you send us.
Community content. Public characters you publish, comments, reviews, and forum posts.
2.2 Data we collect automatically
Device and application data. Device name and model, operating system and version, app version, device identifiers (including advertising identifiers where permitted), device settings such as region, language, time zone, and font size, screen dimensions, and installation and activation timestamps.
Network data. IP address, mobile carrier and network type, and coarse location inferred from IP address. We do not collect precise GPS location.
Log and diagnostic data. Access timestamps, session duration, feature usage events, referring URLs, crash reports, error traces, restarts, and upgrade events.
Usage and interaction data. Which characters you open, message volume and cadence, session frequency, retention and churn signals, and in-app navigation events.
Cookies and similar technologies. See Section 7.
2.3 Data from third parties
Single sign-on. If you register or log in through Google or Apple, that provider shares a limited set of data with us under their own privacy policy:
- Google: your Google account email address, name, and (optionally) profile picture, plus an authentication token. You can review and revoke this at your Google account permissions page.
- Apple: your name and either your Apple ID email or Apple’s private relay address, plus an authentication token.
We do not receive your password from these providers. If you signed up through SSO by mistake, delete your account at immersive.osu.ai/settings/privacy or email support@osu.ai.
Payment and subscription data. Purchases are processed by the Apple App Store, Google Play, or our web payment processor. We never receive or store your full card number. We receive transaction identifiers, subscription tier and status, purchase and renewal dates, amounts, currency, partial card details (last four digits and card brand, for web purchases), refund and chargeback records, and billing country for tax purposes.
Analytics, attribution, and anti-fraud providers. Aggregated performance metrics, install attribution data, and abuse or fraud signals. See Section 8.
Publicly available and compliance sources. Where required by law, sanctions and age-assurance checks.
We do not purchase personal data from data brokers.
2.4 Sensitive data
We do not ask for sensitive personal data. However, conversations on an AI companion platform can naturally touch on health, sexuality, religion, political views, or other sensitive topics. Anything you choose to type into a chat is stored as chat content under Section 2.1. Where local law treats such content as a special category of data, we rely on your explicit consent, given when you accept this policy and choose to send that content. You can withdraw that consent by deleting the content or your account.
3. Permissions We Request
We ask for the minimum permissions needed for each feature. You can grant, refuse, or revoke each one at any time in your device settings; refusing a permission only disables the related feature.
| Permission | Why we ask | What happens if you decline |
|---|---|---|
| Photos / media library | To let you upload images into chats or set an avatar | Image upload and avatar change are unavailable |
| Camera | To take a photo to send in a chat | You can still upload from your library |
| Microphone | For voice input and voice messages | Voice features are unavailable; text still works |
| Notifications | Character replies, reminders, security and billing alerts | You will not receive push notifications |
| Network state | To detect connectivity and adapt streaming quality | Reduced reliability |
| Storage (Android) | To cache media and save exports | Downloads and caching are unavailable |
We do not request contacts, calendar, SMS, call logs, or precise location.
4. How We Use Your Personal Data
4.1 Purposes and legal bases
For users in the EEA, UK, and other regions requiring a legal basis, the table below sets out why we process each category and on what basis.
| Purpose | Data used | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Create and operate your account; authenticate you | Account, SSO, device data | Performance of a contract |
| Deliver AI chat, memory, and character features | Chat content, character settings, model preferences | Performance of a contract |
| Process subscriptions and purchases | Payment and subscription data | Performance of a contract; legal obligation (tax, accounting) |
| Send service and transactional messages | Account, contact data | Performance of a contract |
| Content moderation, trust and safety, fraud prevention | Chat content, device, log, usage data | Legitimate interests (platform safety); legal obligation |
| Age assurance and 17+ enforcement | Date of birth, account, device data | Legal obligation; legitimate interests |
| Debugging, performance monitoring, security | Log, device, diagnostic data | Legitimate interests (secure, reliable service) |
| Product analytics and feature development | Usage, device, aggregated data | Legitimate interests; consent where required by local cookie law |
| Model training and service improvement | Anonymized and aggregated chat, character, and feedback data | Legitimate interests; consent where required |
| Marketing emails and push notifications | Contact data, usage and preference data | Consent, or legitimate interests for existing customers where permitted (soft opt-in) |
| Advertising and measurement cookies | Cookie and device identifiers | Consent |
| Responding to legal claims and requests | Any relevant data | Legal obligation; legitimate interests (establishing or defending claims) |
Where we rely on legitimate interests, we have assessed that our interest does not override your rights. You can ask us for a summary of that assessment at privacy@osu.ai, and you can object at any time (see Section 11.2).
4.2 Model training and service improvement
To improve the quality, safety, and personality of Immersive’s AI characters, we may use anonymized and aggregated user data to train, fine-tune, and evaluate our models. This includes:
- chat transcripts and message pairs,
- character configurations, persona and scenario text, and prompt settings,
- feedback signals such as regenerations, thumbs up/down, edits, and reported responses,
- moderation outcomes and safety classifications.
Before data enters a training set, we apply a de-identification pipeline that strips direct identifiers — account IDs, usernames, email addresses, and detected names, phone numbers, addresses, and payment identifiers within message text — and separates content from the account it came from.
Your controls:
- Opt out of training. Turn off “Improve Immersive with my chats” at immersive.osu.ai/settings/privacy or in the app under Settings → Privacy. This applies going forward. Opting out does not degrade the Service you receive.
- Delete your data. Deleting a conversation or your account removes it from future training sets. Models that were already trained on de-identified data cannot practically be un-trained, but the underlying data is deleted from our systems on the schedule in Section 10.
- See whether it happened. You can ask us whether your data was used for model training in the past 12 months (see Section 11).
We do not use your chat content to train third parties’ foundation models, and our model provider agreements prohibit those providers from training on data we send them.
4.3 Automated decision-making
Our AI generates responses automatically, and automated systems screen content for safety violations. Automated moderation can restrict features or suspend an account. Suspensions for serious violations are reviewed by a human before they become permanent, and you can contest any decision by emailing appeals@osu.ai. We do not use automated profiling to make decisions with legal or similarly significant effects such as credit or employment.
4.4 Marketing communications
We may use your email address and information about how you use Immersive — the characters you interact with, your genre and language preferences, and your activity level — to send you product updates, character recommendations, promotions, and re-engagement reminders.
Unsubscribe at any time using the link in any marketing email, your email client’s unsubscribe option, or immersive.osu.ai/settings/notifications. Push notifications can be turned off in your device settings.
Unsubscribing from marketing does not stop essential service messages — security alerts, payment and receipt notices, and changes to our terms or this policy.
4.5 New purposes
We will not use your personal data for materially different purposes than those described here without giving you notice and, where required, obtaining your consent.
5. How We Share Your Personal Data
We do not sell your personal data. We do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months.
We disclose personal data in these circumstances:
Through your own choices. Anything in your public profile, published characters, or public comments is visible to other users. Content you share to social networks is governed by those networks’ terms.
Service providers (processors). We use vendors to run the Service, each bound by contract to process data only on our instructions:
| Category | What they receive |
|---|---|
| Cloud hosting and storage | Account data, chat content, logs |
| AI model providers and inference infrastructure | Prompt and conversation content needed to generate a reply |
| Payment processors and app stores | Transaction and subscription data |
| Content moderation and safety vendors | Content flagged for review, associated account identifiers |
| Analytics and crash reporting | Device, usage, and diagnostic data |
| Push notification and email delivery | Device tokens, email address, message content |
| Customer support tooling | Ticket contents, account identifiers |
| Fraud and abuse prevention | Device and network signals |
A current list of subprocessors is at immersive.osu.ai/subprocessors.
Corporate group. Affiliates of Swift Media Entertainment, for the purposes described in this policy.
Legal and safety disclosures. We may disclose data to courts, regulators, and law enforcement to comply with legal obligations or valid legal process; to respond to claims; to investigate suspected illegal activity or terms violations; to enforce our Terms of Service; or to protect the rights, property, or safety of Immersive, our users, or the public — including reporting child sexual abuse material to the National Center for Missing & Exploited Children as required by law. Where permitted, we notify affected users of government requests.
Business transfers. In a merger, acquisition, financing, reorganization, or bankruptcy, personal data may transfer to the acquiring party. We will make reasonable efforts to notify you before your data becomes subject to a different privacy policy.
With your consent. Any other sharing you specifically authorize.
6. International Data Transfers
We operate globally and process data in the United States and other countries where our providers operate. These countries may not offer the same level of protection as your home country.
Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on:
- the European Commission’s Standard Contractual Clauses, plus the UK International Data Transfer Addendum where relevant,
- adequacy decisions, where the destination country has one,
- supplementary technical and organizational measures, including encryption in transit and at rest.
Transfers from Canada and Brazil rely on equivalent contractual safeguards. To request a copy of the relevant transfer mechanism, email dpo@osu.ai.
7. Cookies and Similar Technologies
On immersive.osu.ai and in our emails we use cookies, pixels, web beacons, and local storage (including HTML5 local storage). Our mobile apps use equivalent SDK-based identifiers rather than browser cookies.
| Type | Purpose | Can you refuse? |
|---|---|---|
| Strictly necessary | Login sessions, authentication, security, load balancing, saving language and font preferences | No — the site will not function without them |
| Analytical | Understanding which features are used, measuring performance, diagnosing errors | Yes |
| Advertising and measurement | Measuring campaign performance and delivering relevant promotions | Yes |
Where required by law (including in the EEA and UK), we ask for consent before setting non-essential cookies and you can change your choices at any time via the “Cookie Settings” link in our site footer or at immersive.osu.ai/cookie-policy. You can also block or delete cookies in your browser, though doing so may require you to re-enter preferences on each visit and may break some features.
Some identifiers — IP addresses in particular — are treated as personal data under some laws. Where that applies, or where we combine cookie data with account data, we treat the combined data as personal data under this policy.
Global Privacy Control. We honor the Global Privacy Control (GPC) signal as a valid opt-out of sale/sharing where required by law. We do not currently respond to browser “Do Not Track” headers, because no common standard for them exists.
8. Third-Party SDKs
We integrate third-party SDKs to deliver core functionality. For each, we limit the data shared to what the SDK needs.
| SDK category | Data accessed | Purpose |
|---|---|---|
| Push notifications (Firebase Cloud Messaging, APNs) | Device push token, app instance ID, display name for message personalization | Deliver replies, reminders, and alerts |
| Analytics (Clickhouse, Metabase) | Device and usage events, pseudonymous IDs | Product analytics |
| Crash reporting (Sentry) | Stack traces, device state, app version | Stability |
| Payments and billing (Google Pay, Apple Pay) | Transaction and subscription identifiers | Manage subscriptions |
| Attribution (AppsFlyer) | Install events, advertising identifier (with permission) | Measure campaigns |
| Authentication (Google, Apple, SuperTokens) | SSO tokens, email, profile basics | Sign-in |
Each provider’s own privacy policy applies to data it processes for its own purposes. On iOS, we only access the advertising identifier if you allow tracking through the App Tracking Transparency prompt. The current SDK list is maintained at immersive.osu.ai/subprocessors.
9. Security
We maintain technical, administrative, and physical safeguards appropriate to the risk, including:
- encryption of data in transit (TLS) and at rest,
- hashed and salted password storage,
- role-based access controls and least-privilege access for staff,
- logging and monitoring of access to production systems,
- vulnerability scanning, periodic penetration testing, and a security review process for new features,
- vendor security assessments before onboarding.
Support for you: choose a strong, unique password, enable two-factor authentication at immersive.osu.ai/settings/security, keep your device locked, and sign out on shared devices.
No method of transmission or storage over the internet is completely secure, and we cannot guarantee absolute security. You use the Services and provide data at your own discretion. If a breach affects your personal data, we will notify you and the relevant regulators as required by law — for GDPR, within 72 hours of becoming aware where feasible.
Report a suspected vulnerability to security@osu.ai.
10. Data Retention
We keep personal data only as long as we need it.
| Data | Retention |
|---|---|
| Account and profile data | While your account is open |
| Chat content and uploads | While your account is open, or until you delete it |
| Deleted chats and uploads | Removed from live systems immediately; purged from backups within 30 days |
| Deleted accounts | Purged within 30 days of the deletion request; backups within 90 days |
| Payment and transaction records | 7 years, or as required by tax and accounting law |
| Trust and safety records (bans, serious violations) | Up to 3 years, to prevent ban evasion and repeat harm |
| Server and security logs | 12 months |
| Marketing preferences and suppression lists | Until you ask us to delete, and a minimal record thereafter to honor your unsubscribe |
| Anonymized and aggregated data | Indefinitely — this data no longer identifies you |
We may retain data longer where necessary to comply with legal obligations, resolve disputes, collect fees owed, or defend legal claims.
11. Your Privacy Rights
11.1 Rights available everywhere
Wherever you live, you can:
- access and download a copy of your data at immersive.osu.ai/settings/privacy,
- correct your profile and account details in-app,
- delete individual messages, conversations, uploads, or your entire account,
- opt out of model training,
- unsubscribe from marketing.
11.2 EEA, UK, and Switzerland (GDPR)
You have the right to: access your data; rectify inaccurate data; erase data (“right to be forgotten”); restrict processing; object to processing based on legitimate interests, including profiling; data portability in a machine-readable format; withdraw consent at any time without affecting prior processing; and not be subject to solely automated decisions with legal or similarly significant effects.
You may also lodge a complaint with your local supervisory authority. A list is available at edpb.europa.eu; in the UK, contact the Information Commissioner’s Office at ico.org.uk. We would appreciate the chance to address your concern first at dpo@osu.ai.
11.3 United States — California
Categories collected in the past 12 months, under the CCPA/CPRA:
| CCPA category | Collected? | Source | Purpose | Disclosed to |
|---|---|---|---|---|
| Identifiers (email, username, IP, device ID) | Yes | You, your device, SSO | Account, security, analytics | Service providers |
| Customer records (billing info) | Yes | You, payment processors | Purchases | Payment processors |
| Commercial information (subscriptions, purchases) | Yes | You, app stores | Billing, support | Service providers |
| Internet activity (usage, interactions) | Yes | Your device | Analytics, safety | Service providers |
| Geolocation (coarse, IP-derived) | Yes | Your device | Security, localization | Service providers |
| Audio/visual (uploaded images, voice input) | Yes | You | Deliver the Service | Service providers |
| Inferences (preferences, recommendations) | Yes | Derived | Personalization | Service providers |
| Sensitive personal information (content you choose to share in chats; account credentials) | Yes | You | Deliver the Service | Service providers |
We do not use sensitive personal information for purposes beyond those permitted by CCPA §7027(m), and therefore do not offer a separate “limit the use of my sensitive personal information” right — though you can delete this content at any time.
Your rights: know/access (including the specific pieces of data and whether your data was used for model training in the past 12 months), delete, correct, opt out of sale/sharing (we do neither), and non-discrimination. We will not deny service, charge different prices, or provide lower quality because you exercised a right. We may offer different service tiers at different prices as permitted by law.
Shine the Light. Under California Civil Code §§1798.83–1798.84 you may request information about disclosures to third parties for their direct marketing purposes. We do not make such disclosures; requests may be sent to privacy@osu.ai.
11.4 United States — other states
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, and other states with comprehensive privacy laws have rights to access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling. Where your state provides an appeal process, you may appeal a denied request by emailing appeals@osu.ai; we will respond within 45 days (or 60 where permitted), and you may contact your state Attorney General if unsatisfied.
Nevada. Nevada residents may opt out of the sale of covered information. We do not sell it. Send questions to privacy@osu.ai with the subject line “Nevada Do Not Sell Request”.
11.5 Canada (PIPEDA and provincial law)
You may access and correct your personal information and withdraw consent, subject to legal and contractual restrictions. Complaints can be directed to the Office of the Privacy Commissioner of Canada, or to the Quebec, Alberta, or British Columbia commissioner as applicable.
11.6 Brazil (LGPD)
You have the rights to confirmation of processing, access, correction, anonymization or deletion of unnecessary or excessive data, portability, information about data sharing, information about the consequences of refusing consent, and revocation of consent. Contact dpo@osu.ai; you may also petition the ANPD.
11.7 How to exercise your rights
Most rights are self-service at immersive.osu.ai/settings/privacy. Otherwise, submit a request at immersive.osu.ai/data-request or email privacy@osu.ai.
A valid request must (1) give us enough information to verify that you are the person whose data we hold — typically confirmation of control over the account email — and (2) describe what you want in enough detail for us to act. We use the information you provide only to verify identity and fulfill the request. You do not need an account to submit a request.
We respond within 30 days (EEA/UK/Brazil, extendable by two months for complex requests) or 45 days (US states, extendable by a further 45 days with notice). Requests are free unless excessive, repetitive, or manifestly unfounded, in which case we will tell you the fee and why before proceeding.
Authorized agents. You may appoint an agent to act for you. We will ask for written permission signed by you and may still ask you to verify your identity directly.
12. Age Requirements and Children’s Data
Immersive is rated 17+ and is not intended for anyone under 17. We do not knowingly collect personal data from anyone under 17, and we do not allow users who identify as under 17 to register.
We ask for date of birth at sign-up and block registration below the age threshold. Where required by app store rules or local law, we apply additional age assurance measures.
If we learn that a user is under 17, we will terminate the account and delete the associated personal data promptly. In line with COPPA, we do not knowingly collect personal information from children under 13 under any circumstances.
If you believe a minor has provided us with personal data, contact privacy@osu.ai and we will act quickly.
13. Third-Party Links and Features
The Services may link to or embed features from third parties. Their handling of your data is governed by their own privacy policies and terms, not this one. Please review them before engaging.
14. Changes to This Policy
We may update this policy as our Services evolve. When we make material changes, we will notify you by in-app notice, email, or another prominent means before the changes take effect, and we will update the “Last updated” date above. Previous versions are archived at immersive.osu.ai/privacy-policy/archive.
Continued use of the Services after changes take effect means you accept the updated policy. Data we collected previously remains subject to the policy in effect when it was collected, unless you consent otherwise.
15. Contact
| Purpose | Contact |
|---|---|
| General support | support@osu.ai |
| Privacy questions and data requests | privacy@osu.ai |
| Data Protection Officer | dpo@osu.ai |
| Appeals of denied requests | appeals@osu.ai |
| Legal and law enforcement | legal@osu.ai |
| Security vulnerabilities | security@osu.ai |
Swift Media Entertainment | 1000 Brickell Plaza #4806 Miami, FL 33131 | immersive.osu.ai