2WAI

Privacy Policy

Last updated: 2026-07-23 · Effective: [to be set on publication]
DRAFT — for counsel review. Working draft to accelerate legal review; not legal advice; not binding until approved and published. Data-practice statements must be reconciled against the app's actual behavior and its privacy manifest before publication.

Controller: [2WAI, Inc.] ("2WAI", "we"). Privacy contact / DPO: privacy@2wai.ai. EU/UK representative (if required): [appoint under GDPR Art. 27].

1. Overview

2WAI is a social app with a vertical-video feed of AI avatars, direct messages, an avatar marketplace, on-device and cloud AI chat, per-avatar memory, virtual coins, and creator subscriptions. This Policy covers our app and website. Key points: avatars are AI, not real people (Section 9); some features run on-device, others use cloud AI providers; we support in-app data export and in-app account deletion; we do not sell your personal information and do not track you across other companies' apps and sites for advertising.

2. Information we collect

2.1 You provide

2.2 Generated through use

2.3 Collected automatically

We do not intentionally collect precise GPS location.

2.4 Biometric-adjacent data

Face-capture and voice may be considered biometric/sensitive (e.g., Illinois BIPA, GDPR Art. 9, CCPA sensitive PI). We use them only to provide the features you request, do not sell them, and retain per Section 6. [Counsel: assess BIPA written-consent + retention-schedule if face/voice templates are stored.]

3. How we use information

GDPR/UK legal bases: contract (providing the Service), legitimate interests (security, abuse prevention, improvement), legal obligation (CSAM reporting/preservation, records), and consent (device permissions, optional analytics, any biometric processing — withdrawable anytime).

4. Who we share with

We share only as described here. We do not sell personal information, and we do not "share" it for cross-context behavioral advertising (CCPA/CPRA).

Providers act as processors/service providers under contract. [Counsel/Eng: confirm each AI provider's data-use/training terms — e.g., whether inputs are excluded from model training — and reflect accurately.]

5. International transfers

We may process data in the U.S. and other countries. For EEA/UK/Swiss transfers we rely on appropriate safeguards such as EU Standard Contractual Clauses (+ UK Addendum) and/or applicable data-privacy frameworks. Details: privacy@2wai.ai.

6. Data retention

DataIndicative retention [confirm]
Account dataLife of account; deleted/anonymized on deletion
Posts / UGCUntil deleted; residual backups purged within [30–90 days]
Direct messagesUntil deleted or on account deletion; backups per above
Face-capture / avatar source mediaRetained to operate your avatar; deletable in-app; deleted on account deletion
Voice/audioTransient audio purged after processing; saved voice notes until deleted
Per-avatar memoryUntil you delete it or delete your account
Wallet/transaction recordsAs required for tax/accounting/audit (typically [7 years])
Diagnostics/logs[30–180 days]
CSAM-related preserved data≥ 1 year where a CyberTipline report is made (REPORT Act / 18 U.S.C. § 2258A(h)), in a restricted legal-hold store

7. Your rights & choices

7.1 In-app controls (everyone)

7.2 GDPR/UK rights (EEA/UK/Switzerland)

Access, rectification, erasure, restriction, portability, objection (incl. to legitimate-interests processing), consent withdrawal, and complaint to your supervisory authority (e.g., the ICO). We do not use solely automated decision-making with legal/similarly significant effects.

7.3 CCPA/CPRA rights (California)

Know/access, delete, correct, opt out of "sale"/"sharing" (we do neither), and limit use of sensitive PI (used only to provide the Service). No discrimination for exercising rights; authorized agents accepted. We do not sell or share personal information and have not in the preceding 12 months.

7.4 Exercising rights

Use in-app controls or email privacy@2wai.ai. We verify against your account and respond within the required time (generally 30 days GDPR / 45 days CCPA, extendable).

8. Content moderation & child-safety data

We process reports, apply automated filtering and hash-matching on upload paths, and conduct human review. On actual knowledge of apparent CSAM we remove it, report to NCMEC, and preserve related data ≥ 1 year (18 U.S.C. § 2258A / REPORT Act), and may disclose to law enforcement. See Terms, Section 7.

9. AI, avatars & likeness disclosures

10. Security

Encryption in transit (HTTPS/TLS), on-device file protection at rest, hashed passwords, access controls, and a restricted legal-hold store for preserved safety data. No system is perfectly secure; report concerns to security@2wai.ai.

11. Children's privacy

The Service is for users 13+ (or higher where required), is not directed to children under 13, and we do not knowingly collect their data. We apply age-appropriate restrictions to minor accounts (including the coin wallet and certain topics). Believe a child under the applicable age provided data? Contact privacy@2wai.ai and we will delete it. [Counsel: assess COPPA, UK Age-Appropriate Design Code, EU minimum-age rules per market.]

12. Push notifications & communications

If enabled, we use your APNs token to send notifications (disable in iOS Settings). We may send necessary service messages regardless of marketing preferences.

13. Do Not Track / Global Privacy Control

We do not track you across third-party apps/sites for advertising and honor recognized opt-out signals (e.g., Global Privacy Control) where legally required.

14. Changes

We may update this Policy (new "Last updated" date; additional notice for material changes; continued use = acceptance).

Internal note (do not publish to users as-is, or keep as an internal appendix): Before publishing, verify each statement matches the app and PrivacyInfo.xcprivacy / App Store labels — in particular, the manifest declares Analytics (ProductInteraction/CrashData) but no analytics/crash SDK is implemented; either implement and list the SDKs accurately, or remove the Analytics claims. Do not publish the account-deletion claim until the real server-side erasure endpoint is live.

15. Contact

Privacy questions or requests: privacy@2wai.ai. EEA/UK residents may also contact our representative or lodge a complaint with their supervisory authority.