Heyya — Privacy Policy

Privacy Policy — Heyya

Effective date: August 12, 2026
Last updated: August 12, 2026
Controller / Operator: CRONCODE LLC (“Croncode”, “we”, “us”, or “our”)
App: Heyya (iOS mobile application) and related websites, APIs, and services (collectively, the “Service”)

Contact
Email: [email protected]
Phone: +1 (505) 460-4765
Head Office (USA): CRONCODE LLC, 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, USA

This Privacy Policy explains how we collect, use, disclose, store, and protect personal information when you use Heyya. It is designed to support transparency expectations under Apple App Store Review Guidelines (including Guideline 5.1 Privacy), applicable U.S. state privacy laws (including CCPA/CPRA where applicable), and GDPR/UK GDPR where those laws apply.

By downloading, accessing, or using the Service, you acknowledge this Privacy Policy. If you do not agree, do not use the Service.


1. Important summary

  • Heyya is an adult (18+) AI entertainment app featuring fictional AI characters / companions. Characters are not real people.
  • We process account/profile data, chat content, voice audio for realtime calls, photos you upload or capture, AI-generated outputs, purchase records (via Apple), device/usage data, reports, and advertising/measurement data where permitted.
  • User-generated content (UGC) and photos you provide may be sent to AI processors (including Google Gemini for image generation/processing and OpenAI for chat/voice-related processing) so we can return AI-generated text, voice, and images to you.
  • We do not sell your personal information for money. We may use advertising and analytics partners as described below, subject to your device settings and consent choices (including App Tracking Transparency where required).
  • You can request access/deletion and delete your account as described in Section 12.

2. Scope

This Policy applies to personal information processed in connection with:

  • the Heyya iOS app;
  • our websites and support channels (including email);
  • backend infrastructure used to operate Heyya (authentication, databases, file storage, edge functions / proxies);
  • AI model providers and other subprocessors engaged to deliver features you request.

This Policy does not apply to third-party websites, apps, or services that we do not control (for example, Apple App Store pages, Apple ID settings, or third-party privacy choices screens).


3. Who we are

The data controller for Heyya is:

CRONCODE LLC
1209 Mountain Road Pl NE, Ste N
Albuquerque, NM 87110, USA
Email: [email protected]
Phone: +1 (505) 460-4765


4. Categories of information we collect

4.1 Information you provide

  • Account & authentication data: email/credentials (if used), Sign in with Apple identifiers/tokens (when enabled), session tokens, account IDs.
  • Profile data: display name, age/birthday (for 18+ age gate), gender or preferences you select, bio/about text, language settings, interest preferences, and similar profile fields.
  • User content (UGC): text messages/prompts you send to AI characters; photos or images you upload or capture (including profile photos and couple/selfie inputs); captions/instructions for “take/create a photo” style requests; reports, feedback, and support messages.
  • Voice inputs: microphone audio streamed for realtime AI voice conversations while a call feature is active.
  • Communications: emails or messages you send to [email protected] or other support channels.

4.2 Information created by the Service (including AI outputs)

  • AI-generated character replies (text).
  • AI-generated or AI-processed images (including character photos, requested scenes, and composite/couple-style outputs).
  • Transcripts or derived text used to operate voice features (where applicable).
  • Relationship/progress metadata (for example match status, relationship level, in-app economy balances) needed to run the experience.

AI image processing disclosure: When you use photo-related features, we may transmit your uploaded/captured image(s), prompt text, and necessary context to AI image systems (including Google Gemini) so the Service can generate, transform, combine, or return an image output to you. That processing is performed to provide the feature you requested.

4.3 Information collected automatically

  • Device and app information (device model, OS version, app version, language/locale, time zone).
  • Identifiers used for security, anti-abuse, analytics, and (where allowed) advertising (for example device/install identifiers; IDFA only if you authorize tracking via ATT).
  • Usage and diagnostics (feature usage, screen views, crash logs, performance metrics, approximate network info needed to deliver the Service).
  • Log data related to authentication, API calls, moderation/report tooling, and fraud prevention.

4.4 Purchases and subscriptions

In-app purchases and subscriptions are processed by Apple. We typically receive transaction identifiers, product identifiers, purchase/restore status, and entitlement information needed to unlock VIP, gems/virtual currency, or other paid features. We do not receive your full payment card number from Apple.

4.5 Advertising / measurement (if enabled)

Where the app includes ads (for example rewarded ads via Google AdMob) or measurement SDKs, those partners may collect device/ad identifiers, coarse location (if provided by the platform), interaction data, and similar signals according to your consent and OS settings. You can limit ad tracking via iOS settings and ATT prompts.


5. AI providers and how your content is processed

Heyya uses artificial intelligence to generate conversational replies, realtime voice interactions, and images. To operate these features, relevant inputs are sent to trusted processors acting on our instructions, including:

  • Google (Gemini) — primarily for AI image generation and image processing/transformation features (including generating character/scene images and processing user-provided images when you request photo creation/editing/composite outputs).
  • OpenAI — primarily for AI chat/completions and realtime voice conversation features.
  • Our backend / hosting providers (including infrastructure such as Supabase for authentication, database, storage, and server-side proxying of AI requests) so API keys can be kept server-side and requests can be authenticated, rate-limited, logged for security, and moderated.

Depending on the feature, processors may receive:

  • your prompt / message text;
  • character/system context needed for consistent roleplay;
  • language preference;
  • reference or user photos you upload/capture for image features;
  • short-lived audio streams for voice calls;
  • safety/moderation signals.

We configure providers as service providers/processors to the extent practicable. Provider processing is also subject to their terms and privacy policies. Do not submit content you are not allowed to share (for example, others’ intimate images without consent, illegal content, or personal data of minors).

No guarantee of perfect safety filters: We apply technical and policy safeguards, but AI systems can produce unexpected, inaccurate, or undesired outputs. See also our Terms of Use.


6. Why we use personal information (purposes)

We process personal information to:

  • create and manage accounts and sessions;
  • provide core features (onboarding, swipe/explore, matching, chat, voice calls, photo request/generation, couple selfie, store, VIP/gems);
  • personalize language and experience settings;
  • process payments/entitlements through Apple;
  • operate AI features you request and return outputs to you;
  • host, cache, and deliver media (including generated images) as part of the Service;
  • enable safety tooling: content reporting, abuse prevention, spam/fraud reduction, rate limiting;
  • send service-related notices (security, account, legal);
  • send optional push notifications if you enable them;
  • measure performance, debug, and improve the Service;
  • show ads or offer rewarded ads where implemented and permitted;
  • comply with law, enforce Terms, and protect rights, safety, and property;
  • respond to support and privacy requests.

7. Legal bases (EEA/UK and similar regimes)

Where GDPR/UK GDPR (or similar) applies, we rely on:

  • Contract — to provide the Service you request;
  • Consent — for optional permissions (microphone, camera, photos, notifications), tracking/ATT where required, and certain marketing/analytics uses;
  • Legitimate interests — security, fraud prevention, product improvement, service analytics that are not consent-required, and protecting the Service (balanced against your rights);
  • Legal obligation — where we must retain or disclose information to comply with law.

You may withdraw consent at any time in iOS Settings and/or by contacting us, without affecting the lawfulness of processing before withdrawal.


8. How we share information

We share personal information only as needed to operate the Service:

  • Apple — App Store distribution, In-App Purchases/subscriptions, Sign in with Apple (if used), push notification infrastructure, and related platform services.
  • Cloud / backend providers — hosting, authentication, databases, object storage, edge functions (e.g., Supabase and similar infrastructure).
  • AI subprocessors — Google Gemini; OpenAI; and any successor/additional model providers we engage to deliver the same categories of features (we will update this Policy when material provider changes occur).
  • Advertising / measurement partners — e.g., Google AdMob and related Google advertising services, subject to consent/ATT and your settings.
  • Professional advisors — lawyers, auditors, insurers under confidentiality obligations.
  • Authorities / legal — if required by law, legal process, or to protect users, the public, or Croncode from harm, fraud, or liability.
  • Business transfers — in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate protections.

We do not sell personal information as “sale” is commonly understood (exchange for money). If a jurisdiction defines “sale” or “sharing” more broadly for cross-context behavioral advertising, we honor applicable opt-out rights (see Section 12).


9. User-generated content, reporting, and safety

Heyya includes interactive AI experiences and may allow users to upload photos/text (UGC). Consistent with Apple’s expectations for UGC-capable apps:

  • You are responsible for content you submit.
  • We provide in-app reporting mechanisms for objectionable content/conduct.
  • We may review reports, remove content, restrict features, suspend or terminate accounts, and preserve records needed for safety/legal compliance.
  • Illegal content (including any sexual content involving minors) is strictly prohibited and may be reported to authorities.

See our Terms of Use for acceptable-use rules.


10. Retention

We retain personal information only as long as reasonably necessary for the purposes described in this Policy, including:

  • Account/profile data: for the life of the account, then deleted or anonymized after account deletion (subject to legal holds and backup cycles).
  • Chat, prompts, and generated media: while needed to provide the Service, moderation, and restore/continuity features; deleted or anonymized after account deletion subject to residual backups and legal requirements.
  • Voice audio: processed to provide realtime calls; we do not intend to permanently store raw call recordings unless a specific feature clearly offers saving/export and you choose it (in which case retention follows that feature’s notice).
  • Purchase/entitlement records: retained as needed for accounting, fraud prevention, chargebacks, and legal compliance.
  • Security/report logs: retained for a reasonable period for safety, abuse prevention, and dispute resolution.

11. Security

We use administrative, technical, and organizational measures designed to protect personal information, including encryption in transit (HTTPS/TLS), access controls, server-side handling of AI API credentials (via backend proxies where implemented), and monitoring for abuse. No method of transmission or storage is 100% secure; you use the Service at your own risk regarding residual security risk.


12. Your rights and choices

12.1 Account controls

  • Update profile information in the app where available.
  • Delete your account via in-app Settings (or contact us if unavailable).
  • Manage iOS permissions: Microphone, Camera, Photos, Notifications, Tracking.
  • Manage subscriptions/purchases in Apple ID → Subscriptions.

12.2 Privacy rights (region-dependent)

Depending on your location, you may have rights to access, correct, delete, port/export, restrict or object to certain processing, withdraw consent, and appeal a denial. To exercise rights, email [email protected] with the subject line “Privacy Request” and enough information to verify your request.

12.3 California / similar U.S. state notices (summary)

If you are a California resident (or resident of a state with similar laws), you may have rights to know/access, delete, correct, and opt out of “sale”/“sharing” of personal information for cross-context behavioral advertising. We do not knowingly sell personal information for money. To opt out of advertising-related sharing to the extent applicable, use ATT/iOS Limited Ad Tracking controls and contact us. We will not discriminate against you for exercising privacy rights.

12.4 EEA/UK

You may lodge a complaint with your local supervisory authority. You may also contact us first so we can try to resolve your concern.


13. Children and age restriction

Heyya is intended solely for users 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from a minor, we will delete it promptly. Parents/guardians who believe a minor has used the Service should contact [email protected] immediately.

This Service is not directed to children under 13 and is not intended to be COPPA-covered children’s content.


14. International transfers

Croncode is based in the United States. Your information may be processed in the United States and other countries where we or our processors operate. Those countries may have data-protection laws different from your home country. Where required, we use appropriate transfer safeguards (such as standard contractual clauses or equivalent mechanisms offered by processors).


15. Device permissions (iOS)

Depending on features you use, the app may request:

  • Microphone — realtime AI voice calls;
  • Camera — capture photos for profile or couple/selfie / photo-request features;
  • Photo Library — select images to upload for those features;
  • Notifications — optional alerts (matches, messages, reminders);
  • App Tracking Transparency — only if we request permission for cross-app tracking / personalized ads.

You can deny or later revoke permissions in iOS Settings. Some features will not work without the related permission.


16. Do Not Track / global privacy controls

Mobile apps do not uniformly support browser “Do Not Track” signals. We respond to applicable platform privacy signals and legal opt-out mechanisms as described above.


17. Third-party links and SDKs

The Service may contain links to third-party sites or embed third-party SDKs (Apple, Google, cloud providers). Their privacy practices are governed by their own policies. We encourage you to review them.


18. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date at our privacy URL and/or provide in-app notice for material changes. Continued use after the effective date constitutes acknowledgment of the updated Policy, except where additional consent is required by law.


19. Contact

For privacy questions, requests, or complaints:

CRONCODE LLC
1209 Mountain Road Pl NE, Ste N
Albuquerque, NM 87110, USA
Email: [email protected]
Phone: +1 (505) 460-4765
Privacy URL: https://croncode.com/privacy

This Privacy Policy is provided for transparency and compliance support. It is not legal advice. You should have counsel review jurisdiction-specific requirements before launch in new markets.