Account and sign-in information
When you sign in with Google, we receive your account identifier, name, email, email verification status and avatar (if available) to create and recognize your momosama account. The identity service also stores the authorization credentials, sessions, IP address and browser information needed for sign-in.
We only request basic identity, email and profile permissions — never access to Gmail, Google Drive or contacts. Google’s consent screen and account services are provided by Google; see the Google Privacy Policy.
For email sign-in, Resend delivers the code and processes the recipient address, the code email and delivery records. Codes are valid for five minutes, and our database stores only a hash of each code.
Story content and cloud saving
We store your world setup and state, your input, completed story and chats, journals, character drafts, app installs and settings, saves and generation records so you can keep playing, roll back and pick up on another device.
Current content in different worlds is kept separate. Older saves, previous versions and shared copies may retain earlier content; loading a save or clearing current app content does not delete it from every historical copy.
Cookies and browser storage
A sign-in cookie identifies your session; sessions last up to thirty days and renew while you keep using the service. Browser storage is also used for language, reading preferences, page state and unsynced drafts.
Clearing browser data may lose drafts that haven’t synced, but won’t delete your cloud progress. The app doesn’t include third-party advertising or marketing trackers. When a session or code expires it can no longer be used; that doesn’t mean every related database record is deleted at the same moment.
Model, payment and infrastructure providers
The app and database run in California, USA, on Alibaba Cloud servers managed by Zeabur; Cloudflare provides the domain and DNS. Operators with restricted access may handle related records and backups for maintenance and recovery.
For live generation, the relevant input, world state, script rules and permitted history are sent to DeepSeek. The model context doesn’t include your sign-in email or Google credentials, but any personal information you write into the story may still be included.
DeepSeek’s public policy states that it processes data in China and may use it to improve its models. We don’t promise zero retention by the provider or that data won’t be used for model improvement. Please don’t put sensitive personal information in your stories; context is only sent to the model when you start a generation. See the DeepSeek Privacy Policy.
When you buy credits, Stripe handles the payment page. We send the pack, order and your platform account identifier, and store order status, payment references, refunds and the credit ledger. Our database never receives full card numbers or security codes. See the Stripe Privacy Policy.
Retention, deletion and data requests
In the app you can edit content that supports editing, export saves and control what you share. There isn’t a self-service page for deleting your whole account yet.
Account and story records are kept while the service operates until you request deletion and it’s completed. Email support to request access, correction, export or deletion, and describe the scope. We verify account ownership before acting. Necessary payment and audit records may be kept to prevent fraud, handle refunds and meet legal obligations. Backups and copies already shared don’t disappear immediately when current content is deleted; backups aren’t used for day-to-day service, and confirmed deletion requests are reapplied if a backup is restored.
Send privacy requests to affeisme@gmail.com. Operator details and how to reach us are on the contact page.