Skip to content
Andromeda
Log inJoin

Privacy Policy

Effective date: January 1, 2026 · Last updated: August 29, 2026

This Privacy Policy explains how Andromeda, operated by Persephone Reborn LLC (“Andromeda”, the “Service”, “we”, “us”, or “our”) collects, uses, discloses, and safeguards information in connection with your access to and use of our websites, applications, APIs, and related services. It should be read together with our Terms of Service.

By using the Service, you acknowledge that you have read and understood this Policy. Where required by applicable law, we rely on the legal bases described in Section 5 and obtain your consent before processing certain information.

1. Scope

This Policy applies to information we process about visitors and registered users of the Service. It does not apply to third-party products or services that we do not control, even if they link to or integrate with the Service.

2. Information We Collect

We collect information in the following ways:

  • Information you provide: account details (handle, display name, password, email address, date of birth, and a self-reported gender you may leave blank), profile information (bio, a free-text location, links, pronouns, avatar, and banner), the content you create (posts, replies, reposts, messages, polls, and media), and communications you send to us.
  • Precise location, only if you turn it on: your device’s coordinates, used to sort nearby events and — if you use Synergy — to apply a distance limit. This is off by default, it is never shown to other members, and switching it off deletes the stored coordinates. It is separate from the free-text location on your profile, which is simply text you wrote.
  • Matchmaking preferences, if you use Synergy: whether you are open to companionship or to something romantic, an age range, which genders you would be matched with, roughly when you are free, and an optional distance limit. See Section 19 — this is optional, it is the one place we ask for something that can reveal information about your private life, and it exists only to decide who you are shown.
  • Verification material, if you ask to be verified as a real person: a photograph taken to a pose we choose at that moment, which a human reviewer compares with the pictures already on your account and which is deleted the moment they decide. See Section 20.
  • Information collected automatically: usage and log data (such as posts viewed, features used, and interactions), device and connection information (such as IP address, browser type, and approximate location derived from IP), and identifiers stored via cookies or similar technologies.
  • Transaction and wallet information: your Stardust balance and a ledger of in-Service activity (such as tips, premium unlocks, subscriptions, gifts, and commissions). If you make a purchase, limited payment information is processed by our payment providers; we do not store full payment-card numbers.
  • Information from others: content and information other users provide about you (for example, when they mention, tag, message, or report you). Where somebody reports a conversation, that includes any excerpt of it they chose to attach to the report — see Section 21.
  • Connected third-party accounts: if you choose to link an external service (such as a music-streaming account), we receive the limited information that service returns to us with your authorization, as described in Section 13.

3. How We Use Information

We use information to:

  • provide, operate, maintain, and secure the Service and your account;
  • personalize your experience, including timelines, suggestions, and discovery features;
  • enable social features such as following, messaging, mentions, and notifications;
  • detect, prevent, and respond to fraud, abuse, security incidents, and policy violations;
  • communicate with you about the Service, including verification and security alerts;
  • develop new features and conduct research and analytics; and
  • comply with legal obligations and enforce our Terms.

4. How We Share Information

We do not sell your personal information. We share information only as follows:

  • With other users according to your settings (for example, your public profile and posts, or close-friends content limited to selected people);
  • With service providers who process information on our behalf under appropriate confidentiality and security obligations (such as hosting, email delivery, and analytics);
  • For legal and safety reasons, where we believe disclosure is reasonably necessary to comply with law, enforce our Terms, or protect the rights, property, or safety of users or the public;
  • In a business transfer, such as a merger, acquisition, or sale of assets, subject to this Policy; and
  • With your consent or at your direction.

5. Legal Bases for Processing

Where applicable data-protection law (such as the GDPR) requires it, we process personal information on the following legal bases: performance of our contract with you (providing the Service); your consent (which you may withdraw at any time); our legitimate interests (such as securing and improving the Service), balanced against your rights; and compliance with legal obligations.

6. Cookies and Similar Technologies

We use cookies and similar technologies to keep you signed in, remember your preferences, maintain security, and understand how the Service is used. We do not use third-party advertising or cross-site tracking cookies. You can control cookies through your browser settings; disabling certain cookies may affect functionality such as staying logged in. For details, see our Cookie Policy.

Embedded media. Some posts and pages can embed media hosted elsewhere — most often YouTube (operated by Google), and the music services described in Section 13. An embedded player is a connection between you and that provider: loading one lets them see your IP address and may let them set their own cookies, under their privacy policy rather than ours.

Two things limit that. No third-party player loads until you choose to play it — until then you are looking at a still image served by us, and the provider has not been contacted at all. And where the provider offers a privacy-preserving embed domain, we use it: YouTube videos load from youtube-nocookie.com.

7. Data Retention

We retain information for as long as your account is active or as needed to provide the Service, and thereafter as necessary to comply with legal obligations, resolve disputes, and enforce our agreements. When you delete content or your account, we delete or de-identify the associated information within a commercially reasonable period, except for copies retained in routine backups or as required by law, and except for content others have reshared.

8. Your Rights and Choices

Depending on your location, you may have rights to access, correct, delete, port, or restrict the processing of your personal information, and to object to certain processing. You can exercise many of these directly in the Service:

  • review and edit your profile and privacy & safety settings;
  • control who can message, tag, or quote you, who can see who you follow, and your discoverability;
  • download an archive of your data from Account settings;
  • deactivate (a reversible pause) or permanently delete your account.

To make a request that cannot be completed in-product, contact us using the details in Changes and Contact at the end of this Policy. We will respond consistent with applicable law and may need to verify your identity.

9. Security

We use administrative, technical, and organizational measures designed to protect information, including encrypted credentials, optional two-factor authentication, rate-limiting, and access controls. Direct messages are additionally end-to-end encrypted in the ordinary case, which means we cannot read them at all; Section 21 explains exactly what that does and does not cover. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. You are responsible for keeping your password and devices secure.

10. Children's Privacy and Supervised Accounts

The Service is not directed to children under 16 (or the minimum age of digital consent in your jurisdiction, if higher), and we do not knowingly collect personal information from them. If we learn that we have collected such information without appropriate consent, we will take steps to delete it.

Supervised accounts. A member between 16 and the age of majority may link their account to a parent or guardian, who can then set limits — for example, who may message them, and whether disappearing messages are available. A guardian’s setting can only make a member’s own setting narrower, never wider, and where a limit comes from a guardian the member is told so.

A guardian does not read their messages. Linking an account gives a guardian controls, not a window: no feature shows a guardian the contents of a member’s conversations, and direct messages are end-to-end encrypted, so there is nothing for us to show them even if we wanted to. What a guardian receives is the fact that a limit is in force, not the conversations it applies to.

Some features are closed to minors entirely regardless of any setting, including Synergy and anything that arranges a meeting in person. Those are available only to members whose date of birth shows they are 18 or over, and they are closed to any account with an active guardian link whatever that date says.

We should be plain about the limit of that: the date of birth is one you told us, and we do not verify it against a document. It is the same check every general-audience service of this kind performs, and it is a floor rather than a guarantee.

11. International Data Transfers

We may process and store information in countries other than your own. Where we transfer personal information across borders, we implement safeguards designed to provide an adequate level of protection consistent with applicable law.

12. Artificial Intelligence and Automated Processing

The Service includes features powered by artificial intelligence and automated systems — for example, content summaries (Clouds), writing and image tools, recommendations and discovery, search, and safety and moderation systems. To provide some of these features, we share the relevant inputs (such as the text or image you submit) with third-party AI providers that process them on our behalf under confidentiality and security obligations.

Who processes your inputs. We use two AI processing providers. Anthropic handles reading and writing — content summaries, the writing and image studios, discovery, safety systems, and the reading the Lens returns for a frame you capture. fal handles generative media and speech-to-text: it receives the still image you choose when you create a Living Portrait, the audio of a track or video you have uploaded at the point captions or a transcript are produced for it, and — where everyone present has agreed to it — the short clip recorded when you use the Lens's Listen control. That clip is sent to be turned into words, the words come back, and the recording is not kept by us. The Lens never asks for sound unless every person covered by the permission has separately agreed to sound, which is asked for apart from permission to be described. We may engage additional providers to perform the same function — returning a result for something you submit — and where we do, we will name them in this Policy before they are used. We will not use a provider to do something of a different kind than is described in this Section without telling you first.

Training. Your content is never used to train an AI provider’s models. This applies to everything you submit — not only to the private content of your direct messages. We will not engage a provider whose terms permit training on what you send.

Retention. Providers process your inputs to return a result, and we ask for the shortest retention each service offers. We want to be precise rather than reassuring here, because the honest answer has exceptions:

  • For most requests to Anthropic, your prompt and the result are not stored by the provider after the response is returned.
  • Some of the models we use for writing and narrative features are, under our provider’s policy, subject to a 30-day retention requirement, and that requirement cannot be waived for those models. Where we use them, the input and the result may be held by the provider for up to 30 days and are then deleted.
  • fal, which handles generative media and speech-to-text, does not promise in its published terms that each request is deleted as it completes. The still you submit for a Living Portrait, and audio submitted for captions, may therefore be held while our account with fal remains open. We are seeking written confirmation of the shortest retention they will commit to, and will state it here once we have it.
  • If a request is flagged by a provider’s automated safety systems, or where retention is required by law, it may be held for longer — up to two years under Anthropic’s published policy — so that abuse can be investigated.

What happens on your device instead. A substantial part of the Service’s intelligence never reaches us or anyone else, because it runs inside your browser. In the Lens, the live camera view is analysed on your device by models downloaded to it, and that live view is never transmitted to us or to any provider. Only a frame you deliberately capture is sent to be identified. The same is true of the Lens’s optional listening feature, which classifies sound on your device and never records or transmits audio; of on-device text reading; and of transcription in the Vigil. Where a feature summarises what those on-device models concluded, it sends the resulting words and never the images or audio they came from, and it says so at the point you press the button.

We also use automated systems to help detect spam, fraud, abuse, and policy violations and to operate and secure the Service. Where these systems produce a decision with a legal or similarly significant effect, you may have the right to request human review; you can reach us using the contact section below, and many enforcement decisions can be appealed in-product.

One of those decisions is automatic, and we should name it. Andromeda is for people, and we run automated checks for accounts that are not. Where those checks are confident enough, an account can be restricted automatically — limited in what it can do — and queued for a person to look at. Nothing is ever deleted automatically, the restriction is reviewed by a human, and you can appeal it in the Service and have it lifted. We would rather tell you that the restriction can come before the review than describe it as though a person had decided first.

13. Connected Music Services

You may optionally connect a third-party music-streaming account—currently Spotify and Apple Music—to display your listening activity on your profile. This connection is entirely at your election and is off unless you enable it.

  • Authorization. Spotify is connected through its OAuth authorization flow, after which we store an access token and a refresh token on your account. Apple Music is connected in your browser through Apple’s MusicKit, which returns a “music user token” that we store on your account. You must have an active subscription with the relevant service to authorize it.
  • Information we access. Using these tokens, we access, on a read-only basis, a limited set of your listening data—such as your currently playing track (Spotify only), recently played tracks, top tracks, and associated genre information. We do not access your payment details, and we do not modify your music account or play, purchase, or save content on your behalf.
  • What we store and display. We derive and cache a limited “listening profile”—for example, recently played and top tracks, a “most played” list, and a colour theme derived from your most-listened genres—which is refreshed periodically and stored in association with your account so that it can appear on your profile. If you choose, you may also share an individual track as a post, which publishes that track’s title, artist, and a link.
  • Your control. You control whether this information is shown and can disconnect at any time in your settings. Disconnecting deletes the stored tokens and the cached listening profile. You may also revoke our access directly from within the third-party service’s account settings.
  • Third-party terms. Your use of Spotify and Apple Music is governed by those providers’ own terms and privacy policies, which we do not control. Apple Music functionality is provided through Apple’s MusicKit and is additionally subject to Apple’s applicable terms.

14. Live Audio, Video, and Calls

Parts of the Service carry live audio and video: direct-message calls, live streams, and Spheres (live rooms). Your microphone and camera are used only after you turn them on for a specific call or room, and you can mute or switch them off at any time. We do not access your microphone or camera in the background, and we do not record calls on our own initiative.

How the media travels. Live audio and video is sent between participants over WebRTC. To connect participants whose networks cannot reach each other directly, media may be relayed through a third-party relay (TURN) service acting on our behalf. In larger rooms, media may instead be routed through a third-party real-time media server (an SFU) that forwards it to the other participants. These providers carry the stream to deliver the call; live call audio and video is not stored by us in the ordinary course.

Recording. The host of a Sphere decides whether recording is allowed at all. When recording is disallowed, the Service refuses to record. When somebody is recording, everyone in the room is shown a notice naming who is recording and what will become of the recording, which the host also chooses when the room is created: kept by the host only, replayable by people who were in the room, or publishable. A recording made by a participant captures that participant’s own microphone. You are responsible for complying with the recording and consent laws that apply where you are and where the other participants are.

Live captions. Captions are optional and off by default. When a speaker has captions running, the speech recognition is performed by the speaker’s own web browser, and some browsers perform that recognition by sending audio to the browser vendor’s servers — a transfer between you and your browser vendor, governed by their privacy policy, not ours. Only the resulting text reaches us. Caption text is held in memory to display it live and to write the room’s summary when it ends; it is discarded when the room closes, and it is excluded from the summary entirely if the host disallowed recording.

What we do keep. We keep the ordinary operational record of a room — who joined and when, and whether a room was live — along with anything you deliberately create in it, such as questions, poll votes, or a recording that was saved. Deleting a room deletes that record.

15. Region-Specific Disclosures

California (CCPA/CPRA). If you are a California resident, you have rights to know the categories and specific pieces of personal information we collect, to delete and correct your information, and to opt out of “sales” or “sharing” of personal information and certain targeted advertising. We do not sell your personal information, and we honor recognized opt-out preference signals (such as Global Privacy Control) where required. We do not discriminate against you for exercising your rights. You may exercise rights as described in Section 8 or by contacting us.

European Economic Area, United Kingdom, and Switzerland. If you are in these regions, our legal bases for processing are described in Section 5, and you have the rights described in Section 8, including the right to lodge a complaint with your local data-protection authority. Where we rely on consent, you may withdraw it at any time without affecting prior processing. For international transfers, see Section 11.

Other jurisdictions may provide additional rights; we honor applicable local requirements.

16. The Lens: Camera, Location, and On-Device Processing

The camera. The camera is active only while the Lens is open, and we do not record continuously. The work of finding and labelling what is in front of you runs on your device — the models are downloaded to your phone and the video frames they read never leave it. When you ask for a written description of what you are pointing at, a single still image is sent to be described, used to produce that description, and not retained afterwards. We do not build a record of what you point a camera at.

Faces. We do not run face recognition. Nothing in the Service attempts to identify a person from their face, and we do not create, collect, or store faceprints, voiceprints, or other biometric identifiers.

Location, and how coarse it is kept. Location is read only with your permission and only while a feature that needs it is open. Features that describe your surroundings — weather, daylight, what is overhead, what has been recorded nearby — work from a rounded cell of roughly eleven kilometres rather than from your position, and it is that cell, not your coordinates, that is used to look anything up. Map tiles are fetched through us rather than directly by your browser, so the sequence of places you look at on a map is not disclosed to the organisations that publish the imagery.

Sensors. Compass, motion, and light readings are used to draw the view and to tell whether the device is still. They are processed on your device and are not stored as a record of your movements.

Sound is asked for separately. The Lens never listens because you allowed it to describe something. Permission to record sound is a distinct question, asked of every person it would cover, and recorded per person — because a great many places, including New Hampshire, require everyone present to agree before an oral conversation may be recorded. Agreeing to be described is not agreeing to be recorded, and we do not treat it as though it were. Nothing derives a voiceprint.

Subjects you return to. If you name something and come back to it — a plant, a building site, a piece of work in progress — we keep the name you gave it, a short written note of what was there on each visit, and what had changed since the last one, so that the Lens can tell you. It holds no images and no location, and each visit is dated to the day rather than the moment — deliberately, because a sequence of places at minute resolution is a reconstruction of where you went, which is not something we will hold. Deleting a subject removes it and its notes.

17. Federation: Data That Leaves Our Control

Where federation is enabled and you have not opted out, your public posts — and the profile information attached to them, such as your handle, display name, avatar, and the text and media of the post — may be delivered to independent servers operated by other people, so that members there can follow and read you. Accounts set to private are never federated.

⚠ Once data has reached another server we cannot retrieve or erase it. When you delete a post or your account, we send a deletion request to the servers that received it. Honouring that request is entirely at their discretion, and some will not. This is a property of the open protocol rather than a choice we have made, and it means your rights of erasure, as against those operators, are exercised with them and not with us. We will tell you what we sent and where, so far as our records allow, to help you make those requests.

You can switch federation off in your settings. Doing so stops future delivery; it cannot recall what has already been sent.

18. The Psyche

If you use the Psyche, we store what you enter — the intentions you set, the entries you write, and a record of what you marked as done — so that the feature can show it back to you over time. It is yours. It is not shown to other members, it is not used to rank you against anyone, and it is not sold or shared for advertising.

Entries may contain information that is sensitive in nature because of what you choose to write. We do not ask you for special-category data, and you should not enter anything you would not want stored. You can delete individual entries, and deleting your account removes them along with the rest of your data as described in Retention above.

Where the Psyche uses automated processing to assemble a prompt or a reflection, it acts only on your own entries. It does not profile you for advertising, it does not make decisions producing legal or similarly significant effects about you, and it is not a mental-health assessment of any kind — see the corresponding section of our Terms of Service.

19. Synergy: Matchmaking and Meeting in Person

Synergy introduces members to each other and, where both agree, helps them arrange to meet at a public event. It is optional, it is off until you enrol, and it is available only to members whose date of birth shows they are 18 or over.

What we store, and why it is sensitive. If you enrol you may set whether you are open to companionship, to something romantic, or to either; an age range; which genders you would be matched with; roughly when you are free; and an optional distance limit. We ask you to notice what the first two of those amount to together: an openness to romance combined with a gender preference can reveal your sexual orientation, which the law of several places — including the UK and the EEA — treats as a special category needing your explicit consent. That is why these are blank until you set them, why nothing is inferred from them beyond deciding who you are shown, and why you can clear them or leave Synergy at any time, which deletes them.

Who sees it. Your preferences are not shown to other members. They are used to decide who is proposed to you and who you are proposed to, and — because the rule is applied in both directions — somebody is shown to you only if you also fall inside what they asked for.

Distance. A distance limit works only if you have turned on precise location, and it compares the two positions to produce an answer to “is this within the limit”. Neither member is shown the other’s location, and a member whose location is unknown is treated as outside the limit rather than inside it.

Arranging to meet. A meeting is attached to a public event already listed on Andromeda; there is no free-text address, and we do not hold one. Checking in sends the word “here” and no coordinates, cell, or IP-derived guess — neither person’s card is shown until both have checked in, and what that proves is that you both said you were somewhere you both named, never where either of you is. Short notes for finding each other in a building (“by the window”) exist only while you are looking and are deleted once you have met.

Photographs from a meeting. A photograph taken at a meeting almost always contains the other person, so it is private to the two of you unless they say otherwise: publishing one requires their explicit agreement to that file going to that place, and withdrawing that agreement takes the post down with it.

What we do not do. We do not run background checks or identity checks on members, and we say so where it matters rather than only here — see the safety policy, which also explains what to do if something goes wrong. We do not sell or share any of this, and we do not use it for advertising.

20. Confirming Somebody Is Real

A recurring harm on any social service is one person’s photographs used to run somebody else’s account. Two things address it, and both are deliberately narrow.

A photograph taken to a pose. If you ask to be verified, we choose a pose at that moment and ask you to copy it. A human reviewer compares that photograph with the pictures already on your account and answers one question: is this the same person. No software measures your face at any point — nothing extracts face geometry, computes an embedding, or compares a template, and we do not create or store faceprints, voiceprints, or any other biometric identifier. The photograph is deleted the moment the reviewer decides; what remains is the date, and a fingerprint of the picture URLs the check vouched for, so that the mark lapses by itself if the pictures are later swapped.

A summary of a profile picture. We compute a short perceptual summary of profile pictures — a description of light and dark regions of the whole image — so that the same picture appearing on many accounts can be noticed. It works identically on a photograph of a dog, it does not locate or measure a face, and it cannot be compared against anything outside Andromeda. It is visible only to moderators: telling a member which accounts share a picture would be a way to look up somebody’s other accounts by uploading their avatar, which is exactly the harm this is meant to reduce.

We have built, and have not switched on, a check for where else a profile picture appears on the public web. It would send the picture to a third party, so it stays off until this Policy names that provider. If you are reading this sentence, it is off.

21. Direct Messages: What End-to-End Encryption Does and Does Not Cover

Direct messages are end-to-end encrypted whenever both devices hold a key, which is the ordinary case and the default. The message is encrypted in your browser before it reaches us and can be opened only by you and the person you sent it to. We cannot read it. That is not a promise about our conduct — it is a statement about what we are able to do.

When it is not encrypted, we say so at the time. If the other person has never set up a key, or this device does not hold yours, the message is stored in a form we can read. The composer tells you before you send rather than falling back quietly.

What we can still see. Encryption protects the contents, not the fact of the conversation. We hold who sent a message to whom and when, whether it has been read, how large it is, any emoji reaction, and the storage addresses of attachments — the attachment’s name, type, and key stay inside the encrypted part, and the address is in the clear only so that unused files can be cleaned up. We also hold the settings you chose for a message, such as whether it disappears, whether it is sealed until a date, or whether it needs both of you to open it. We do not hold the words.

What that means for reporting. Because we cannot read a conversation, we cannot examine one because it was reported. Reporting a conversation sends us the reason you wrote and any excerpt you chose to attach, taken from your own device — nothing else. That excerpt is evidence you supplied, it names the account it came from, and it is retained with the report.

Losing a key. A key that exists only on one device is lost with that device, and messages encrypted to it cannot be recovered by anybody, us included. You may store an encrypted backup of your key with us, protected by a phrase only you know; the sealing happens in your browser and the phrase never reaches us, so without it the backup is useless to us and to anyone who takes it.

One consequence worth stating plainly, because it is a real trade rather than a detail: a key that can be restored is a key that can open everything ever sent with it. These messages are therefore not forward-secret — recovering your history after losing a phone and having old messages become permanently unreadable are the same property seen from two sides, and we chose recoverability.

Disappearing and Incognito messages. These delete the message from our systems on the schedule you chose. They cannot control what the other person does — they can photograph the screen with another device, and no website can reliably detect a screenshot. Where a device tells us one may have been taken we pass that on, and we do not present it as a guarantee, because it is not one.

22. Changes and Contact

We may update this Policy from time to time. If we make material changes, we will provide reasonable notice, such as by posting the updated Policy with a new effective date or notifying you within the Service. Questions or requests may be sent to privacy@andromedasphere.com.

© 2026 Andromeda · Created by Persephone Reborn LLC in 2026

← Legal & copyrightCreditsHome