Slowburn – Privacy Policy
This policy explains how we handle personal data when you use Slowburn. We write it in plain language because the data involved, your private conversations with fictional characters, is about as personal as data gets.
1. Who is responsible
1.1 The data controller is PowerQuant ApS, trading as ONEWORD Entertainment, Denmark. Registered address and CVR number are available on request at hello@onewordentertainment.com. Email: hello@onewordentertainment.com.
1.2 We have not appointed a Data Protection Officer because we are not legally required to at our current size. Privacy questions go to the address above.
2. What data we collect
2.1 Account data: your email address, account ID, sign-in timestamps, and magic-link tokens (short-lived).
2.2 Age declaration: your confirmation that you are 18 or older, with timestamp, browser user agent and a shortened keyed hash (HMAC-SHA-256) of your IP address. The key exists only on our server, so the stored value cannot be turned back into your IP by anyone who obtains it. Declarations recorded before 21 September 2026 used a fixed, public prefix instead of a secret key and are weaker; we cannot recalculate them, because the raw addresses were never kept. We do not store the raw IP with the declaration.
2.3 Conversation content: the messages you write, the characters' replies, the settings and preferences you choose for characters, and any voice notes or portraits generated for you.
2.4 Safety data: content flagged by automated filters, filter scores, reviewer decisions and enforcement history.
2.5 Usage data: first-party analytics events such as page visits, signups, message counts and feature use, stored in our own database. In the app they are tied to your account ID. On our website they are not tied to an account; if you say yes to visit counting there, page-view events carry a random visitor ID that is kept in your browser (see the Cookies and Local Storage Notice). We use no third-party analytics or advertising trackers.
2.6 Payment data: subscription status, plan, renewal date and a payment-processor reference. Card details go directly to the payment processor (Stripe); we never receive your full card number.
2.7 Support data: emails you send us and our replies.
3. Conversation content is treated as sensitive
3.1 Your conversations may reveal information about your sex life or sexual orientation, which the GDPR classes as special-category data (Article 9). Even where they do not, we treat all conversation content as if they did.
3.2 We process this content only on the basis of your explicit consent (GDPR Art. 6(1)(a) and Art. 9(2)(a)), which you give by ticking the consent statement before your first story. We keep the version of the statement you agreed to and the time you agreed. You can withdraw your consent at any time under Your account in the app, without deleting your account. Withdrawing ends the processing at once and removes your stories and any voice files made from them; your account remains, and you may consent again later if you wish. Deleting your account also withdraws your consent. We keep a record that consent was given and withdrawn, and when, because we are required to be able to demonstrate it; withdrawal does not make earlier processing unlawful.
3.3 No human reads your conversations except (a) when our safety filter flags content for review, (b) when you ask us for support and share it, or (c) when the law requires it.
3.4 We never use your conversations, voice notes or portraits to train AI models, and we contractually require our providers not to either.
4. Why we process data and on what legal basis
4.1 To provide the service, including character memory: contract (Art. 6(1)(b)) for account and usage data; explicit consent (Art. 9(2)(a)) for conversation content.
4.2 To record your declaration that you are an adult, and to keep evidence of that declaration: legal obligation and legitimate interest (Art. 6(1)(c) and (f)), since operating an adult service lawfully requires it. What we keep is listed in 2.2. This is a declaration you make, not an identity check: we do not ask for identification and we cannot confirm anyone's age.
4.3 To keep the service safe and enforce our rules, including automated filtering and human review: legitimate interest (Art. 6(1)(f)) and, for red-line content, substantial public interest in preventing abuse (Art. 9(2)(g) with Danish Data Protection Act §7).
4.4 To bill you and keep accounting records: contract and legal obligation under the Danish Bookkeeping Act.
4.5 To improve the product using aggregated, non-identifying statistics: legitimate interest.
4.6 To send service emails about your account, security or changes to terms: contract. We do not send marketing emails without separate consent.
4.7 To count website visitors with a random visitor ID: your consent (Art. 6(1)(a)), which you give on our front page and can withdraw at any time on the Cookies page.
5. Automated decisions
5.1 Automated safety filters may block or rewrite a message in real time. Blocking a message is not a decision with legal or similarly significant effect. Suspensions and bans are always confirmed by a human before they apply, and you can appeal under the Acceptable Use Policy.
6. Who we share data with
We do not sell personal data. We share it only with processors who act on our instructions under a data processing agreement, or where the law requires.
| Processor | Purpose | Data | Location | Transfer mechanism |
|---|---|---|---|---|
| Supabase Inc. | Authentication, database, file storage | All account, conversation, safety and usage data | EU (Frankfurt, Germany) | Data stays in the EU; DPA with SCCs as fallback |
| Vercel Inc. | Hosting of the web front-end | Request metadata, IP address in transit | EU edge and US | EU–US Data Privacy Framework and SCCs |
| OpenRouter, Inc. (routing to Parasail; for some steps to other model hosts such as NextBit and a content-moderation model) | Generating character replies, memory summaries and content moderation | Conversation content sent per request, pseudonymised (no email or name) | United States | SCCs; we request zero-retention processing where the provider offers it |
| Featherless.ai | Generating character replies (second host for the same model) | Conversation content sent per request, pseudonymised (no email or name) | United States | SCCs; the host states that it does not store prompts or completions |
| fal.ai | Generating voice notes and portraits | Text prompts and character descriptions, no account identifiers | United States | SCCs; we request zero-retention processing where the provider offers it |
| Stripe Payments Europe, Ltd. (Ireland), with Stripe, Inc. (US) as sub-processor | Payment processing (subscriptions) | Email, subscription reference, payment details you enter with Stripe | EU (Ireland); some support processing in the US | EU–US Data Privacy Framework and SCCs |
| Resend (EU region) and Simply.com (Denmark) | Sending magic links and service emails | Email address, email content | EU (Resend EU region; Simply.com, Denmark) | Data stays in the EU; DPA with SCCs as fallback |
6.1 Conversation content sent to the LLM provider is not linked to your email address or name. The provider receives only what is needed to generate the next reply and must not retain or train on it.
6.2 We may disclose data to Danish police, courts or supervisory authorities where legally required, and to professional advisers under confidentiality. If Slowburn is sold, data transfers to the buyer under the same rules; you will be informed.
7. International transfers
7.1 Where a processor is in the USA, transfers rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework. We have assessed the transfers and minimise what is sent: US providers never receive your email address or your age declaration. Our hosting provider necessarily handles your IP address in transit while it serves you a page, as the table above says; it is not stored for analytics.
8. How long we keep data
| Data | Retention |
|---|---|
| Conversations, characters, voice notes, portraits | Until you delete them or your account; fully erased within 30 days of deletion |
| Account data | Until account deletion, then 30 days |
| Age-declaration evidence | 5 years after account deletion, to demonstrate compliance |
| Safety logs and enforcement records | 12 months, or until a related claim or investigation ends |
| Analytics events | 24 months, then aggregated or deleted |
| Billing records | 5 years after the financial year ends (Danish Bookkeeping Act) |
| Support emails | 2 years |
| Backups | Rolling backups are overwritten within 30 days |
9. Your rights
9.1 You can ask for access to your data, correction, deletion, restriction, a portable copy of your conversations, and you can object to processing based on legitimate interest. You can withdraw consent at any time.
9.2 You can delete your account and all data in the app or by emailing hello@onewordentertainment.com from your account email. We confirm deletion by email.
9.2a You can change your display name and your persona yourself in the app. For anything else — a correction to other data we hold about you (art. 16), or a request that we keep your data but stop using it while a dispute is settled (restriction, art. 18) — email hello@onewordentertainment.com from your account email and say which of the two you want. Restriction takes effect on the account the same day: the story stops, nothing is deleted, and you can still read everything you have written. We do not alter your age declaration or your consent record, because those are the record of why we may process anything at all; if you dispute them, ask for restriction instead.
9.3 We respond within one month. We may ask you to verify your identity via your account email.
9.4 You can complain to the Danish Data Protection Agency: Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, dt@datatilsynet.dk, datatilsynet.dk. We would appreciate the chance to resolve your concern first.
10. Security
10.1 Data is encrypted in transit (TLS) and at rest. Access to the production database is restricted to the minimum staff needed and logged. Sign-in uses single-use magic links rather than passwords. Conversation content sent to AI providers is stripped of account identifiers.
10.2 No system is perfectly secure. If a breach affects you, we notify you and Datatilsynet as the GDPR requires.
11. Children
11.1 Slowburn is for adults only. We do not knowingly collect data from anyone under 18. If we discover we have, we delete the account and its data.
12. Changes
12.1 We will notify you by email or in the app before material changes take effect. The current version is always available in the app.