Privacy Policy

Applies to: Users located in the United States Service: RyzaChat (“RyzaChat:AI Weave your own summer dream with Ryza”) (the “Service”) Operator: SpiralAI Inc. (“we,” “us,” or “the Company”) Age requirement: The Service is intended for users 18 years of age or older. It is not directed to, and we do not knowingly permit use by, anyone under 18. See Section 11 (“Children’s Privacy”) for details, including our COPPA-specific commitments regarding children under 13.


Introduction

SpiralAI Inc. provides the mobile application RyzaChat. This U.S. Privacy Policy (“Policy”) describes how we collect, use, disclose, and protect information about users of the Service who are located in the United States. It is written to comply with the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, “CCPA”), the CCPA’s implementing regulations issued by the California Privacy Protection Agency (“CCPA Regulations”), and the U.S. Children’s Online Privacy Protection Act (“COPPA”), together with other U.S. federal and state laws applicable to the Service.

This Policy is a separate, U.S.-specific document. It does not incorporate the EU General Data Protection Regulation (“GDPR”) or Japan’s Act on the Protection of Personal Information, which are addressed in other regional versions of our privacy policy.

Our Terms of Service generally discourage users from submitting their own or third parties’ personal information (name, address, phone number, etc.) through the Service. However, if a user chooses to enter such information in a free-text field, we may incidentally collect and process it as described below.


1. Information We Collect

1.1 Information You Provide

When you register, configure, or otherwise interact with the Service, we may collect:

  • Nickname or other display name
  • Date of birth
  • In-app settings and preferences
  • Alarm settings (time)
  • Content of inquiries you submit to customer support
  • User Messages — the text (or other input) you type to the AI character (see Section 1.2 for special handling)

We do not recommend entering your real name, home address, phone number, email address, employer, school, or other information that could directly identify you, given the nature of the Service. If you nonetheless enter such information in a free-text field, it may be incidentally processed as part of generating an AI response.

1.2 User Messages — Not Retained Long-Term by Design

The Service is designed so that the original text of your messages to the AI character (“User Messages”) is not retained by us as part of our stored personal information. User Messages are temporarily processed to generate the AI’s response and to perform automated safety review (see Section 1.5), but as a general matter we do not keep a persistent copy in our backend or logs.

Exception: User Messages are transmitted to third-party AI model providers to generate AI Responses (see Section 4). Those providers may retain or otherwise process the transmitted content under the applicable contract terms, product settings, and data-handling policies, including for abuse prevention, safety, and legal compliance, even though we do not retain it ourselves. See Section 4 for details.

We do not use the original text of User Messages for model retraining/fine-tuning, quality evaluation/analysis, personalization/profiling, or advertising.

1.3 AI Responses

“AI Responses” are the messages generated by the AI character. We store AI Responses as part of your conversation history and use them to provide, display, and voice the Service, and to improve response quality (which may include using AI Responses for model retraining/fine-tuning and quality evaluation). Because an AI Response may quote, summarize, or otherwise reflect part of a User Message, we treat AI Responses as personal information where they reflect information about you, and they are accessible/deletable as described in Section 9.

1.4 Conversation Summaries

To maintain continuity of the conversation and the accuracy of AI Responses, we generate and store “Conversation Summaries” based on your messages. Conversation Summaries are used only to maintain conversational continuity and response accuracy; we do not use them for model retraining/fine-tuning, quality evaluation/analysis, or advertising. Because Conversation Summaries may be derived from your User Messages, we treat them as personal information.

1.5 Safety Review (Moderation) Information

We perform automated safety review of User Messages and AI Responses, using filters and other mechanisms we operate, to help protect user safety, detect harmful content, and prevent misuse. At present, apart from the external AI services used for AI response generation, we do not use a separate external moderation API to which User Messages or AI Responses are sent solely for the purpose of safety review. Information that is sent to external AI services for AI response generation may, however, be processed by those providers in accordance with their terms, data-handling policies, and our settings, including for their own safety, abuse-prevention, and legal-compliance purposes. The information we retain from our safety review is intended to be limited to the outcome of the review, any action taken, and a timestamp; our safety-review logs are not intended to contain the full text of User Messages or AI Responses.

1.6 Information Collected Automatically

When you use the Service, we may automatically collect:

  • Device information (operating system, device model, language setting, app version)
  • IP address
  • Cookies, advertising identifiers, device identifiers, and similar tracking technologies
  • App usage data (launch times, screen navigation, interaction events)
  • Crash logs and error logs
  • Push-notification device tokens
  • Subscription, conversation-token, add-on character, and skin purchase/usage status
  • Billing status, purchase history, and information necessary to confirm payment

1.7 Information from Third Parties

We may receive limited information from the app stores (Apple App Store, Google Play) confirming a purchase or subscription transaction. If we begin using advertising-effectiveness measurement or attribution-analysis tools (see Section 7), we may also receive install/campaign attribution information from those providers, associated with your device or advertising identifier.

1.8 On-Device Storage and the Nature of Your Conversations with the AI Character

In addition to being stored on our servers as described above, Conversation Summaries and AI Responses (i.e., your conversation history) are also stored locally on your device. If you delete the app, the history stored on your device is deleted. Please understand that your conversations with the AI character are communications between you and us, and that we are involved in them as a party to the communication.


2. How We Use Information

We use the information described in Section 1 for the following purposes:

  1. To provide, maintain, and operate the Service
  2. For authentication, login management, and account management
  3. To generate and store Conversation Summaries and maintain conversational continuity and AI response accuracy
  4. To generate, display, and voice AI character responses
  5. To analyze AI Responses to improve Service quality, develop new features, and improve the display/response experience
  6. For billing, payment confirmation, and purchase management related to paid features (subscriptions, conversation tokens, add-on characters, skins, etc.)
  7. To respond to inquiries, verify identity, and provide necessary communications
  8. To notify you of maintenance, important notices, and changes to the Service
  9. To detect and prevent fraud, violations of our Terms of Service, harmful content, or dangerous conduct, and to keep the Service safe
  10. To analyze usage for feature improvement, incident response, and Service operation
  11. To create or use statistical data or de-identified/aggregated information that does not identify an individual
  12. To exercise rights, fulfill obligations, and respond to disputes under applicable law, our Terms of Service, or our guidelines
  13. To verify eligibility for the Service (age 18+), prevent use by individuals under 18, and take necessary action (including suspension/deletion) if underage use is discovered
  14. For purposes reasonably related to or incidental to the foregoing (see Section 7 regarding advertising-effectiveness measurement and attribution analysis, including their current scope and our California-specific commitments)

We do not use the original text of User Messages or Conversation Summaries for model retraining/fine-tuning, quality evaluation/analysis, personalization, or advertising (Section 1.2, 1.4). Only AI Responses may be used for model retraining/fine-tuning or quality evaluation/analysis, and where an AI Response reflects a User Message, we handle it carefully as personal information.


3. Cookies and Similar Technologies

We may use cookies and similar technologies to:

  1. Maintain login state and session management (core Service functionality)
  2. Analyze user attributes, interaction history, screen navigation, and error conditions to improve usability, performance, and safety

If we begin using cookies or similar technologies to measure advertising effectiveness, perform attribution analysis, or improve marketing, we will do so as described in Section 7.

You may be able to limit cookies, advertising identifiers, and other tracking through your device settings, OS privacy settings, advertising-identifier reset, or tracking-permission settings (e.g., Apple’s App Tracking Transparency). Limiting these settings may reduce the effectiveness of some analytics, and, if we begin conducting advertising-effectiveness measurement or attribution analysis in the future, limiting these settings may also reduce the effectiveness of that measurement or analysis, but generally will not affect your ability to use the Service’s core functionality.


4. How We Share Information — Service Providers and Third Parties

We do not disclose your personal information to third parties for their own independent use, except as described in this Policy or as required by law. We share information with the following categories of service providers/contractors and external service operators, solely to operate the Service:

PurposeRecipientInformation InvolvedPrimary Processing Location(s)
AI response generationMultiple AI service providersUser Messages, Conversation Summaries, character configuration settings, other context needed for response generationU.S., EU/EEA, and other locations depending on the provider
Cloud infrastructure / backendGoogle Cloud Platform (GCP)General backend data, Conversation Summaries. User Messages are not retained by design.U.S. and Google’s global infrastructure locations
AuthenticationFirebase AuthenticationLogin/authentication credentialsU.S.
Push notificationsFirebase Cloud MessagingDevice tokens necessary for notification deliveryU.S. and Google’s global locations
In-app purchasesApple App Store, Google PlayBilling/purchase informationU.S., among others
Subscription managementRevenueCatSubscription, purchase history, billing statusU.S.
Error/crash analysisSentryError logs, crash information. User Messages/AI Responses are not sent.U.S., Germany, Canada, and other locations in Europe
Usage analyticsGoogle LLC (Google Analytics, Google Analytics for Firebase)App usage events (launch times, screen transitions, operation history, event information, etc.), device and app information, app-instance and other analytics identifiers, and connection information such as IP address. We do not send the text of User Messages or AI Responses to Google Analytics, and we configure Google Analytics for usage analytics only, without enabling Google Signals, advertising personalization, Google Ads linking, or the “Google products and services” data-sharing option. Depending on its configuration and the applicable contract, Google may act as our service provider or, for any processing it performs for its own purposes, as a separate controller.U.S. and Google’s global infrastructure locations
Voice synthesisFish Audio (operated by Hanabi AI Inc., U.S.)Text of AI Responses and generated audio. Your User Messages themselves are not sent to the voice-synthesis provider.U.S.

Additional notes:

  • We use commercially reasonable efforts to design our transmissions so that they do not include information that could directly identify you (real name, address, phone number, etc.); however, if you enter such information into a free-text field, it may incidentally be included in data sent to an AI provider.
  • Whether a given AI provider’s API uses transmitted data for model training/improvement, and how long that provider retains logs, varies by provider, API, contract terms, and configuration. We seek to select settings/contracts under which transmitted data is not used for model training/improvement where feasible, but for reasons such as abuse monitoring, safety assurance, and legal compliance, some providers may retain transmitted data as logs for a limited period. Please also refer to each provider’s own published privacy policy and data-handling policy.
  • We disclose personal information to the recipients above as our service providers or contractors (as those terms are defined under the CCPA) acting on our behalf for the business purposes described in this Policy — not as an independent sale or sharing of your information for the recipient’s own purposes. See Section 9 for our CCPA-specific representations regarding “selling” and “sharing.”

We may also disclose information: (a) to comply with law, legal process, or governmental request; (b) to protect the rights, property, or safety of SpiralAI, our users, or others; (c) in connection with a merger, acquisition, financing, or sale of business assets; or (d) with your consent.


5. AI Model Improvement and Opt-Out

  1. To improve Service quality, AI character response quality, new feature development, and the conversational experience, we may use AI Responses for model retraining/fine-tuning and quality evaluation/analysis.
  2. The only category of information we use for these purposes is AI Responses. We do not retain the original text of User Messages as part of our stored personal information, and we do not use User Messages or Conversation Summaries for these purposes.
  3. An AI Response may quote, summarize, or otherwise reflect part of a User Message. In that case, we treat the AI Response as personal information.
  4. If an AI Response reflects information that could constitute sensitive personal information (see Section 9.1), we handle it appropriately, within the scope of our stated purposes and consistent with applicable law.
  5. If you do not want your AI Responses used for quality-improvement purposes, you may request to opt out by contacting us at the address in the “Contact Us” section. We will act on reasonable opt-out requests promptly.
  6. Certain information may fall outside the scope of this opt-out where retention is legally required, necessary for monitoring/preventing misuse, necessary for system integrity, consists of moderation determination records, or consists of statistical information derived from AI Responses that does not itself constitute personal information. It may also not be technically feasible to fully remove information already reflected in a trained model.

6. Data Retention

We retain personal information only for as long as reasonably necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law. When information is no longer needed, we delete it or render it anonymous within a reasonable period, except where retention is legally required. The specific retention period we apply depends on the category of information, as set out below and elsewhere in this Policy:

  • User Messages: Not retained as stored personal information by design (Section 1.2); they are temporarily transmitted to AI model providers for response generation and may be retained or processed by those providers as described in Section 4.
  • Conversation Summaries: Retained for as long as necessary to maintain conversational continuity and AI response accuracy.
  • AI Responses: Retained for as long as necessary for Service provision, history management, quality improvement, and misuse prevention.
  • Billing/accounting/tax/legal-compliance records; fraud, violation, and dispute-related records; backup, incident-response, and security logs; and safety-review determination records (determination results, actions, timestamps): Retained for the periods necessary for those specific purposes, which may exceed the retention period for other categories.

7. Advertising and Analytics — California-Specific Commitments

  1. We use Google Analytics and Google Analytics for Firebase solely to analyze use of the Service. We do not enable Google Signals, advertising personalization, remarketing, Google Ads linking, or the “Google products and services” data-sharing option that would permit Analytics data to be used for Google’s own advertising or product-improvement purposes. This does not prevent Google from carrying out processing strictly necessary to provide, maintain, and secure the analytics service itself under the applicable terms.
  2. As of the effective date of this Policy, we do not conduct advertising-effectiveness measurement or attribution analysis, and we do not transmit advertising identifiers or other user information to any third party for those purposes. Our app includes a bundled software development kit (Adjust) capable of supporting this type of measurement, but it is not configured to transmit data, and no data is currently sent through it. If we begin conducting advertising-effectiveness measurement or attribution analysis, we will amend this Policy before doing so and identify the external service(s) used, the purpose, and the scope of information involved.
  3. If we begin advertising-effectiveness measurement or attribution analysis in the future, that processing may involve advertising identifiers, device information, campaign information, and app usage data. We do not use, and will not use, User Messages or Conversation Summaries for ad delivery, ad-effectiveness measurement, or ad targeting.
  4. We do not provide personal information to advertising platforms for custom-audience matching. Any SKAdNetwork-based measurement we may use in the future would rely on anonymized, aggregated data rather than data tied to an individual device.
  5. We do not sell or share (as those terms are defined under the CCPA) California consumers’ personal information for cross-context behavioral advertising, and we have not sold or shared California consumers’ personal information in the preceding 12 months. To the extent we engage measurement or analytics providers such as Google Analytics, we do so as our service providers or contractors, for our business purposes, under contractual terms that restrict their use of the information.
  6. Because we do not sell or share personal information, we do not operate a “Do Not Sell or Share My Personal Information” link or process at this time. We recognize and will honor Global Privacy Control (“GPC”) and other opt-out preference signals as a valid request that we not sell or share your personal information — however, since we do not sell or share personal information, receiving such a signal does not currently change our processing.

8. Data Security

We maintain administrative, technical, and organizational safeguards designed to protect personal information from unauthorized access, disclosure, alteration, and destruction, including:

  • Access-privilege management
  • Protection of communications (encryption in transit, where applicable)
  • Monitoring of handling status through logs
  • Oversight of service providers/contractors
  • Employee training and awareness
  • Data minimization
  • Deletion or de-identification of information that is no longer needed

No security measure is perfect, and we cannot guarantee absolute security. If you have questions about our security practices, please contact us using the information below.


9. Your California Privacy Rights (CCPA/CPRA)

This section applies to California residents and is provided to satisfy the disclosure requirements of CCPA Regulations § 7011(e).

9.1 Categories of Personal Information We Collect (Preceding 12 Months)

Using the statutory categories in California Civil Code § 1798.140(v)(1)(A)–(K):

CCPA CategoryExamples from RyzaChat
(A) IdentifiersNickname/display name, account/login identifiers, device identifiers, advertising identifiers (e.g., IDFA/GAID), IP address, push-notification tokens
(D) Commercial informationSubscription, conversation-token, add-on character, and skin purchase/usage records; billing status; purchase history
(F) Internet or other electronic network activityApp usage data (launch times, screen navigation, interaction events), cookies, crash/error logs
(K) InferencesConversation Summaries and AI Response history, to the extent they reflect inferences supporting conversational continuity and response personalization
(L) Sensitive personal informationAccount log-in credentials (in combination with password); date of birth, collected solely to verify Service eligibility (age 18+)

We do not intentionally collect Social Security numbers, government ID numbers, financial account/card numbers, precise geolocation, racial/ethnic origin or other protected-classification data, genetic or biometric data used for unique identification, health information, or information about sex life/sexual orientation. If a user voluntarily enters such information into a free-text field, it may be incidentally processed as described in Section 1.1 and Section 4.

We have not collected any category of personal information about consumers that is not disclosed in this Policy.

9.2 Categories of Sources

We collect personal information from:

  • Directly from you (account setup, in-app settings, messages you send, support inquiries)
  • Automatically from your device as you use the Service (technical/usage data, cookies, identifiers)
  • From our service providers/contractors described in Section 4 (e.g., purchase confirmations from Apple App Store/Google Play)

9.3 Business or Commercial Purpose for Collection

See Section 2 (“How We Use Information”) for the specific business/commercial purposes for which we collect each category of personal information.

9.4 Personal Information Sold or Shared

We have not sold or shared any category of California consumers’ personal information in the preceding 12 months, and we do not sell or share personal information for cross-context behavioral advertising. See Section 7 for details.

9.5 Actual Knowledge of Selling/Sharing Information of Consumers Under 16

The Service is intended for users age 18 and older, and we do not knowingly permit use by anyone under 18. Consistent with Section 9.4, we do not sell or share personal information at all, and we have no actual knowledge that we sell or share the personal information of consumers under 16 years of age.

9.6 Categories Disclosed to Service Providers/Contractors for a Business Purpose (Preceding 12 Months)

We currently disclose, or may disclose, personal information to the service providers/contractors and for the business purposes listed in Section 4 (AI response generation, cloud infrastructure, authentication, push notifications, in-app purchase and subscription processing, error/crash analysis, usage analytics, and voice synthesis). The categories involved include Identifiers; Commercial information; Internet or other electronic network activity information; Audio, electronic, visual, or similar information; Inferences; and, to the extent described in Section 9.1, Sensitive personal information.

9.7 Use/Disclosure of Sensitive Personal Information

To the limited extent we process sensitive personal information (Section 9.1), we use and disclose it only for the purposes permitted under CCPA Regulations § 7027(m) (e.g., to provide the Service you requested, for security and safety purposes, and to comply with law) — not for purposes requiring an opt-in or a “Limit the Use of My Sensitive Personal Information” option beyond those permitted purposes.

9.8 Your CCPA Rights

Subject to certain exceptions and verification requirements, California residents have the right to:

  • Know what personal information we have collected about you, including the categories of personal information, categories of sources, business/commercial purposes for collecting, selling, or sharing personal information, categories of third parties to whom we disclose personal information, and the specific pieces of personal information we hold about you
  • Delete personal information we have collected from you, subject to certain exceptions
  • Correct inaccurate personal information we maintain about you
  • Opt out of the sale or sharing of your personal information — currently not applicable, as we do not sell or share personal information (see Section 9.4)
  • Limit the use or disclosure of sensitive personal information — currently not applicable beyond the permitted purposes described in Section 9.7
  • Rights related to Automated Decision-Making Technology (“ADMT”) (access to, and opt-out of, ADMT used for a significant decision) — not currently applicable, as we do not use technology that meets the CCPA Regulations’ definition of ADMT for a significant decision concerning you
  • Non-retaliation — we will not discriminate or retaliate against you for exercising any of the above rights, including if you are an applicant to an educational program, a job applicant, a student, an employee, or an independent contractor of ours

9.9 How to Exercise Your Rights

You may submit a request to know, delete, or correct by contacting us at the email address in the “Contact Us” section below.

  • We will verify your identity before responding to a request, which may require you to provide information matching what we have on file. If we cannot reasonably verify your identity, we may deny the request as required or permitted by law.
  • Authorized agents: You may designate an authorized agent to submit a request on your behalf. We may require proof of the agent’s authority to act on your behalf and may still require you to verify your own identity directly with us.
  • Global Privacy Control: See Section 7.6 for how we currently process GPC and other opt-out preference signals.
  • We will respond to verifiable requests within the time periods required by the CCPA.
  • There is generally no fee to exercise your CCPA rights.

9.10 Data Broker Status

SpiralAI Inc. is not, to our knowledge, a “data broker” as defined under California law, and this Policy does not include data-broker registration disclosures.


10. State Privacy Law Disclosures Beyond California

Other U.S. states have enacted comprehensive privacy laws (e.g., Virginia, Colorado, Connecticut, Utah, and others) that may grant residents of those states rights similar to those described in Section 9. If you are a resident of one of these states and believe you are entitled to rights under your state’s law, please contact us using the information below and we will address your request consistent with applicable law.


11. Children’s Privacy (COPPA)

  1. The Service is intended for use by individuals 18 years of age or older and is not directed to children.
  2. If we learn that a user under 18 is using the Service, we will take appropriate action, which may include suspending or terminating the account, deleting associated personal information, and other necessary measures. We may retain a limited amount of information for a limited period where necessary for legal compliance, fraud prevention, or dispute resolution.
  3. The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will delete that information promptly, except to the limited extent COPPA permits retention (e.g., for safety or legal-compliance purposes).
  4. If you are a parent or guardian and believe your child under 13 has provided us with personal information, please contact us using the information below so we can investigate and, where appropriate, delete the information.

12. International Data Transfers

Some of our service providers (Section 4) process information outside the United States, including in Germany and other locations in the EU/EEA (e.g., Sentry) and other jurisdictions where our AI providers operate. Where we transfer personal information internationally, we take steps designed to ensure appropriate protection consistent with applicable U.S. law and our contracts with those providers.


13. Changes to This Policy

We may revise this Policy from time to time to reflect changes in law, changes to the Service, changes in the third-party services we use, or other operational needs. We will post the updated Policy in the app or on our website and update the “Last Updated” date below. Where a change is material, we will provide notice or seek consent to the extent required by applicable law.


Contact Us

If you have questions about this Policy, or wish to submit a request to know, delete, correct, or otherwise exercise your rights described above, please contact us:

SpiralAI Inc. 2-2-5 Higashi-Kanda, Chiyoda-ku, Tokyo 101-0031, Japan (PMO Akihabara III, 5F) Representative Director: Yuichi Sasaki Email: contact_ryzachat@go-spiral.ai


Last Updated: August 18, 2026