BINETSU Privacy Policy
BINETSU is an iOS romance story app featuring two fictional adult AI characters.
Current App Boundary
The current app does not create accounts within BINETSU, call external AI providers, integrate online age-verification providers, or generate runtime images or videos. Character replies, memories, relationship progress, and bundled character voices are processed on the user's device.
The version currently submitted as Build 27 does not bundle Firebase Analytics. A later BINETSU version may use Firebase Analytics for consent-gated aggregate product measurement as described below; it does not add an account, a server-side conversation service, or a live AI provider.
StoreKit 2 offers the optional BINETSU Plus, BINETSU Gold, and BINETSU Premium auto-renewable subscriptions. Apple processes purchases and payment details; BINETSU does not receive or store full payment-card information. TestFlight purchases use Apple's Sandbox and do not create a live charge.
Google Mobile Ads SDK and Google's User Messaging Platform are included for optional rewarded ads and native or interstitial ads on the free plan. Unity Ads and AppLovin MAX SDKs, along with the Meta Audience Network SDK, are embedded only as Google Mobile Ads mediation adapters; they do not create a separate BINETSU ad placement. The App Store build uses the app's production advertising identifiers. Ad requests are made only when the SDK reports that ads may be requested after the applicable consent flow. Publisher first-party ID is disabled.
The current build does not use real-person likenesses, SNS photos, voice clones, or deepfake features.
Data Stored On Device
The app stores profile, chat, memory, usage, safety reports, local voice metadata, and relationship state only on the user's device using app-local storage. The current build writes the same local JSON snapshot to app-local defaults and an Application Support file for reliable relaunch restore.
When optional paid photo tickets or member benefits are available, the unspent paid-ticket and member-benefit ticket balances, grant and consumption totals, completed purchase transaction IDs, completed subscription-benefit IDs, and photo-draw recovery records are stored in the signed-in user's iCloud Private Database so that unspent tickets can be recovered after reinstalling the app or on another device signed in to the same iCloud account. A photo-draw recovery record contains a random operation ID, ticket type, a hash identifying the iCloud account scope, and a cryptographic commitment that binds the operation to the photo selected on the device. It prevents a retry from spending another ticket. The photo itself, its asset ID, character ID, chat, memories, voices, profile, relationship state, subscription receipts, and payment-card data are not stored in this iCloud record. Photos remain saved on each device; this balance recovery does not restore every photo after reinstalling the app. When an older device balance differs from iCloud, the app keeps the first and latest before-and-after ledger observations locally for recovery diagnosis. These observations are cleared by the local-data reset; resetting local data does not refund spent tickets or delete the iCloud ledger. If iCloud is unavailable, paid-ticket purchase and member-ticket recovery wait until iCloud is available; Story or rewarded-ad tickets remain usable.
- 18+ confirmation and AI-character disclosure acknowledgment.
- Display name, conversation messages, user-visible memories, and relationship/intimacy state.
- Usage counters, estimated local cost ledger, local safety reports, and local voice metadata.
Product Analytics
When the applicable consent flow permits aggregate measurement, BINETSU uses Firebase Analytics and Google Analytics to understand app reliability and aggregate product flows. The SDK may process app-instance, device/app/OS, diagnostics, approximate region derived from masked IP, lifecycle/session/engagement, screen activity, and StoreKit product metadata such as product ID, name, and price. BINETSU's own custom events are limited to Story scene/chapter/outcome, photo-draw source/rank/duplicate, optional rewarded-ad placement/result, StoreKit catalog availability, purchase product ID/result, and free-talk success/failure.
BINETSU does not set a Firebase user ID and does not send display name, conversation text, character replies, memories, profile, relationship or emotional state, photos, image or audio asset URLs, voice data, free-form user input, receipt, StoreKit transaction ID, or payment-card data to Firebase. Analytics collection stays off while consent is required, unknown, denied for GDPR Purpose 1, or cannot be refreshed. Firebase advertising storage, ad user data, and ad personalization are denied for this product measurement.
See Firebase Privacy and Security, Firebase's Apple disclosure guidance, and Google's Privacy Policy for information about Google's processing. App Store privacy disclosures are updated for the version that includes this measurement.
Advertising And Data Sent To Third Parties
BINETSU does not send chat, memories, safety reports, local voice metadata, display name, relationship state, audio, images, user input, or payment details to Google, Unity, AppLovin, Meta, or an external AI provider. The limited Firebase product analytics data is described separately above. BINETSU does not add custom ad targeting.
When the app checks advertising consent or requests an eligible rewarded, native, or interstitial ad, Google Mobile Ads and User Messaging Platform may process advertising-related data such as IP address or approximate location, device or advertising identifiers, product and ad interactions, advertising data, crash data, performance data, and other diagnostics. When enabled as Google-mediated bidders, Unity and AppLovin may also process advertising-related data under their own SDK policies. The same applies to Meta Audience Network when it is selected as the mediated ad source; embedding an adapter does not mean that source is currently serving ads. The exact data depends on device settings, region, consent, the selected ad source, and each SDK's behavior. Device identifiers may be used for tracking or advertising depending on those factors. See Google Mobile Ads data disclosure, Unity Privacy Policy, AppLovin Privacy Policy, Meta Privacy Policy, and Google's Privacy Policy.
Rewarded ads are optional. Declining or closing an ad does not remove story content; the same main story remains available by returning on a later day.
Memory And Deletion
Users can delete individual visible memories from the Memory screen. Users can reset the app from the Memory or Settings screen. Reset clears profile, messages, safety reports, local voice metadata, memories, usage counters, relationship state, and returns the app to the 18+ gate. Reset does not erase unspent paid tickets held in iCloud, because those purchases must remain recoverable on the same iCloud account. Advertising consent choices can be reviewed through the advertising privacy options when required and may also be governed by device or Google settings.
AI Character And Safety Disclosure
C1 and C3 are fictional AI characters. BINETSU does not claim to provide medical, psychological, or crisis support.
Changes To This Policy
Before account creation, server-side conversation storage, analytics beyond the Firebase and advertising uses disclosed above, a live AI or TTS provider, online age verification, runtime generation, or another material data practice is enabled, this policy and the App Store privacy disclosures will be updated to match the changed behavior.
Support
For support, purchase restoration help, feedback, or safety concerns, see the BINETSU Support page. TestFlight testers may also use TestFlight feedback.