Controller: [2WAI, Inc.] ("2WAI", "we"). Privacy contact / DPO: privacy@2wai.ai. EU/UK representative (if required): [appoint under GDPR Art. 27].
1. Overview
2WAI is a social app with a vertical-video feed of AI avatars, direct messages, an avatar marketplace, on-device and cloud AI chat, per-avatar memory, virtual coins, and creator subscriptions. This Policy covers our app and website. Key points: avatars are AI, not real people (Section 9); some features run on-device, others use cloud AI providers; we support in-app data export and in-app account deletion; we do not sell your personal information and do not track you across other companies' apps and sites for advertising.
2. Information we collect
2.1 You provide
- Account data: name/display name, email (or Apple relay ID), hashed password, date of birth, profile details.
- User content (UGC): videos, photos, text posts, avatar packages, prompts.
- Direct messages: message content you send.
- Camera face-capture: face images/video captured to create an avatar.
- Voice & audio: voice notes and audio processed for voice features.
- Support & reports: what you send us.
2.2 Generated through use
- Per-avatar "memory": personalization data per avatar (viewable, exportable, deletable).
- Wallet & transactions: coin balances and purchase/subscription records (payment processed by Apple; we don't receive full card details).
- AI interaction data: prompts, outputs, and safety/compliance signals (e.g., crisis-detection).
- Usage & diagnostics: app interactions, feature usage, crash/diagnostic data [to the extent analytics/crash SDKs are actually implemented — see Section 15].
2.3 Collected automatically
- Device/technical: device model, OS/app version, language, IP, coarse IP-based location.
- Identifiers: account/user ID, device identifiers for app functionality, push tokens.
- Required-reason APIs: limited UserDefaults, file timestamps, system-boot time for functionality — not for tracking.
We do not intentionally collect precise GPS location.
2.4 Biometric-adjacent data
Face-capture and voice may be considered biometric/sensitive (e.g., Illinois BIPA, GDPR Art. 9, CCPA sensitive PI). We use them only to provide the features you request, do not sell them, and retain per Section 6. [Counsel: assess BIPA written-consent + retention-schedule if face/voice templates are stored.]
3. How we use information
- Provide the Service: account, feed, avatar chat/DMs, per-avatar memory, marketplace, wallet.
- AI processing: generate avatar responses/media on-device and via cloud providers.
- Safety, moderation & legal duties: filter/review content; report/block; detect and act on objectionable content and CSAE; meet legal reporting/preservation duties (Section 8).
- Transactions: coins and subscriptions (via Apple).
- Communications: service messages, push notifications, support.
- Improve & secure: diagnostics, fraud/abuse prevention.
- Legal compliance and enforcing our Terms.
GDPR/UK legal bases: contract (providing the Service), legitimate interests (security, abuse prevention, improvement), legal obligation (CSAM reporting/preservation, records), and consent (device permissions, optional analytics, any biometric processing — withdrawable anytime).
4. Who we share with
We share only as described here. We do not sell personal information, and we do not "share" it for cross-context behavioral advertising (CCPA/CPRA).
- AI model/inference providers: [OpenAI, Google (Gemini), OpenRouter, ElevenLabs (voice), Deepgram (speech-to-text)] — process inputs to generate outputs, under contract.
- Real-time communications: LiveKit.
- Hosting & database: [Azure, AWS, Neon].
- Analytics/crash: [only if implemented — list actual SDKs, see Section 15].
- Payments: Apple (in-app purchases/subscriptions).
- Push: Apple Push Notification service.
- Safety & legal recipients: NCMEC and law enforcement, where required for CSAM reporting or lawful requests.
- Corporate transactions: a successor in a merger/acquisition/asset sale (with notice as required).
Providers act as processors/service providers under contract. [Counsel/Eng: confirm each AI provider's data-use/training terms — e.g., whether inputs are excluded from model training — and reflect accurately.]
5. International transfers
We may process data in the U.S. and other countries. For EEA/UK/Swiss transfers we rely on appropriate safeguards such as EU Standard Contractual Clauses (+ UK Addendum) and/or applicable data-privacy frameworks. Details: privacy@2wai.ai.
6. Data retention
| Data | Indicative retention [confirm] |
|---|---|
| Account data | Life of account; deleted/anonymized on deletion |
| Posts / UGC | Until deleted; residual backups purged within [30–90 days] |
| Direct messages | Until deleted or on account deletion; backups per above |
| Face-capture / avatar source media | Retained to operate your avatar; deletable in-app; deleted on account deletion |
| Voice/audio | Transient audio purged after processing; saved voice notes until deleted |
| Per-avatar memory | Until you delete it or delete your account |
| Wallet/transaction records | As required for tax/accounting/audit (typically [7 years]) |
| Diagnostics/logs | [30–180 days] |
| CSAM-related preserved data | ≥ 1 year where a CyberTipline report is made (REPORT Act / 18 U.S.C. § 2258A(h)), in a restricted legal-hold store |
7. Your rights & choices
7.1 In-app controls (everyone)
- Export your data (JSON) via the in-app Privacy Dashboard.
- Delete your account in-app — deletes/anonymizes your account and data (subject to legal-hold/backup exceptions in Section 6).
- Delete memory — view, export, or atomically purge per-avatar memory.
- Permissions — control camera, mic, photos, speech, notifications, tracking in iOS Settings.
7.2 GDPR/UK rights (EEA/UK/Switzerland)
Access, rectification, erasure, restriction, portability, objection (incl. to legitimate-interests processing), consent withdrawal, and complaint to your supervisory authority (e.g., the ICO). We do not use solely automated decision-making with legal/similarly significant effects.
7.3 CCPA/CPRA rights (California)
Know/access, delete, correct, opt out of "sale"/"sharing" (we do neither), and limit use of sensitive PI (used only to provide the Service). No discrimination for exercising rights; authorized agents accepted. We do not sell or share personal information and have not in the preceding 12 months.
7.4 Exercising rights
Use in-app controls or email privacy@2wai.ai. We verify against your account and respond within the required time (generally 30 days GDPR / 45 days CCPA, extendable).
8. Content moderation & child-safety data
We process reports, apply automated filtering and hash-matching on upload paths, and conduct human review. On actual knowledge of apparent CSAM we remove it, report to NCMEC, and preserve related data ≥ 1 year (18 U.S.C. § 2258A / REPORT Act), and may disclose to law enforcement. See Terms, Section 7.
9. AI, avatars & likeness disclosures
- Avatars are AI, labeled as AI, may be inaccurate, and are not real people or a substitute for professional/emergency help.
- Your inputs power AI features — prompts, messages, and captured media may go to AI providers (Section 4; retention Section 6).
- Licensed public-figure avatars recreate figures who licensed their name/likeness/voice; a consent record is referenced at
https://2wai.ai/licenses/{avatarId}. We do not train likeness models of real people without a license. - On-device processing keeps some data on your device (protected at rest); social features still sync to our servers.
10. Security
Encryption in transit (HTTPS/TLS), on-device file protection at rest, hashed passwords, access controls, and a restricted legal-hold store for preserved safety data. No system is perfectly secure; report concerns to security@2wai.ai.
11. Children's privacy
The Service is for users 13+ (or higher where required), is not directed to children under 13, and we do not knowingly collect their data. We apply age-appropriate restrictions to minor accounts (including the coin wallet and certain topics). Believe a child under the applicable age provided data? Contact privacy@2wai.ai and we will delete it. [Counsel: assess COPPA, UK Age-Appropriate Design Code, EU minimum-age rules per market.]
12. Push notifications & communications
If enabled, we use your APNs token to send notifications (disable in iOS Settings). We may send necessary service messages regardless of marketing preferences.
13. Do Not Track / Global Privacy Control
We do not track you across third-party apps/sites for advertising and honor recognized opt-out signals (e.g., Global Privacy Control) where legally required.
14. Changes
We may update this Policy (new "Last updated" date; additional notice for material changes; continued use = acceptance).
PrivacyInfo.xcprivacy / App Store labels — in particular, the manifest declares Analytics (ProductInteraction/CrashData) but no analytics/crash SDK is implemented; either implement and list the SDKs accurately, or remove the Analytics claims. Do not publish the account-deletion claim until the real server-side erasure endpoint is live.15. Contact
Privacy questions or requests: privacy@2wai.ai. EEA/UK residents may also contact our representative or lodge a complaint with their supervisory authority.