Privacy Policy
AI情騙子 — AI Love Scammer: Spot Fraud
Effective date: 2026-05-24 · Last updated: 2026-05-24
Quick summary
We built AI情騙子 to teach people how to recognize romance scams. To do that, the app sends your chat messages to an AI service so the AI characters can respond. Beyond that, we collect as little as possible:
- We do not collect your name, email, phone number, contacts, location, photos, microphone, or camera.
- We do not show ads and we do not sell your data.
- We do not track you across other apps or websites.
- The "money" in the game is fake (a training wallet). We never process real payments.
The longer version below explains exactly what does flow through our systems, who processes it, and how you can delete it.
1. Who we are
This app and this Privacy Policy are operated by:
JN App Studio
Kuala Lumpur, Malaysia
Contact: jeffrey.ng.op@gmail.com
For purposes of the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), Malaysia's Personal Data Protection Act 2010, and similar laws, JN App Studio is the "data controller" of any personal data described in this policy.
2. What information we collect
2.1 Information you provide directly
- Player nickname. A name you type for yourself when starting a game. Stored only on your device (in local storage on the device running the app) so we can address you in chat. It is also included in the prompts sent to our AI provider so the AI character can use your nickname in responses.
- Character nicknames. Names you choose for the AI characters. Same handling as the player nickname.
- Chat messages. The words you type to AI characters during gameplay. These are sent to our server so we can forward them to our AI provider (see §3).
- Invitation code. If your install requires one, the code is sent to our server to verify access.
We do not ask for and do not store: your real name, real email, real phone number, real address, real photos, real payment information, or your contacts.
2.2 Information collected automatically
When the app talks to our server, our server automatically receives:
- Session identifier. A randomly generated ID that lets us associate your chat session with rate-limiting state. This ID is not linked to your real identity.
- IP address. Inherent in any internet request. Used only for rate limiting and abuse prevention; not stored long-term in association with chat content.
- Usage logs. Time of request, which endpoint was called, response status. Rotated out after 30 days unless we need to retain them longer to investigate abuse.
- Device and app technical metadata. App version, operating system family (iOS or Android), language setting. Used to debug crashes and serve correctly localized content.
2.3 Information we do NOT collect
To be explicit, AI情騙子 does not request or use the following permissions:
- Precise or coarse location
- Contacts
- Photo library / camera / microphone
- Phone state or call logs
- SMS or notifications access (beyond standard push, if added in a future version)
- Advertising identifiers (we do not show ads)
- Health data, biometrics, or financial account information
If a future version of the app adds any of these, this policy will be updated before the feature ships, and we'll prompt you for explicit permission inside the app.
3. Third parties we share data with
We rely on three categories of third-party service providers. Each one only receives the minimum data required for its specific function.
3.1 BytePlus (AI chat and image generation)
We use BytePlus — a cloud AI platform operated by Beijing Volcano Engine Technology Co., Ltd., an affiliate of ByteDance — for:
- Chat completions via the BytePlus Seed 2.0 Lite model (
seed-2-0-lite-260228). Your chat messages, the AI character's system prompt, and recent conversation history are sent to BytePlus to generate AI responses. - Image generation via the BytePlus Seedream 5.0 model (
seedream-5-0-260128), only when the game generates an image for you. - Image storage via BytePlus TOS (their object storage), with a local-disk fallback on our own server.
BytePlus is based in the People's Republic of China. Chat content you type may be processed and temporarily stored on servers located in China. BytePlus's own privacy and security terms apply to that processing; see their policy at byteplus.com/en/legal/privacy-policy.
What this means for you: if you live in a jurisdiction with strict cross-border data transfer rules (the EU, the UK, Switzerland, etc.), please weigh this disclosure when deciding whether to use the app. We do not send your real name, email, or any direct identifier to BytePlus — only the in-game nickname you chose and the messages you typed.
3.2 Fly.io (application hosting)
Our server, which sits between the app on your device and the BytePlus API, is hosted on Fly.io (Fly.io, Inc., a Delaware corporation). Fly.io processes incoming requests on our behalf. Our chosen Fly.io region is sin (Singapore), which means request metadata is handled at that data center.
Fly.io's privacy practices: fly.io/legal/privacy-policy.
3.3 App stores (Apple and Google)
When you install the app from the Apple App Store or Google Play Store, those platforms collect their own data (downloads, crashes if you opted in, in-app purchase metadata if applicable). We receive aggregate, anonymized reports from them — we do not receive your Apple ID, Google account email, or any directly identifying information.
- Apple: apple.com/legal/privacy
- Google: policies.google.com/privacy
3.4 No advertisers, no analytics SDKs, no data brokers
We do not embed any third-party advertising, analytics, or data-broker SDKs in the app. If we ever add a crash reporter (e.g., Firebase Crashlytics or Sentry), we'll update this policy first and the reporter will only receive crash stack traces, not chat content.
4. Why we process your data (legal bases)
Under GDPR and similar laws, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Letting you chat with AI characters (the core feature) | Performance of a contract (Art. 6(1)(b) GDPR) |
| Rate limiting and abuse prevention | Legitimate interests in keeping the service available (Art. 6(1)(f) GDPR) |
| Debugging crashes and improving the app | Legitimate interests in service quality (Art. 6(1)(f) GDPR) |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c) GDPR) |
We do not process personal data for marketing purposes, and we do not engage in automated decision-making or profiling that produces legal or significant effects on you.
5. How long we keep your data
| Data type | Where it lives | Retention |
|---|---|---|
| Player nickname, character nicknames, settings | Your device only (local storage) | Until you uninstall or clear app data |
| Chat history | Your device only (local storage) | Until you delete it in Settings or uninstall |
| Session ID and invitation-code mapping | Our server (Fly.io, SQLite) | Up to 90 days after last activity, then purged |
| Usage logs and rate-limiting counters | Our server | 30 days, then rotated out |
| Chat messages forwarded to BytePlus | BytePlus servers | Per BytePlus's retention policy; we do not retain server-side copies beyond the request-response cycle |
| Generated images | BytePlus TOS or our server's disk | Up to 90 days, then purged |
| Diagnostic logs | Our server | 14 days, then rotated out |
We keep these periods as short as we can while still being able to debug issues and prevent abuse.
6. Your rights
6.1 The right to access and delete your data (everyone)
- In-app deletion. Open Settings → Delete my data in the app. This wipes your local chat history, settings, and your server-side session record.
- Web-based deletion (so you don't need the app installed): visit ailovescammer.fly.dev/delete-data and paste your session ID.
- By email. Write to jeffrey.ng.op@gmail.com with the subject line "Data deletion request" and tell us your session ID (visible in Settings → About). We'll confirm deletion within 30 days.
6.2 GDPR (EU/EEA/UK residents)
You have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request erasure ("right to be forgotten")
- Restrict or object to processing
- Data portability (receive your data in a structured, machine-readable format)
- Withdraw consent at any time, where we rely on consent
- Lodge a complaint with your local data protection authority
To exercise any of these rights, email jeffrey.ng.op@gmail.com. We respond within 30 days.
6.3 CCPA / CPRA (California residents)
California residents have the right to:
- Know what categories of personal information we collect and the purposes
- Request a copy of the specific pieces of personal information collected
- Request deletion
- Opt out of "sale" or "sharing" of personal information — we do not sell or share personal information for cross-context behavioral advertising
- Not be discriminated against for exercising these rights
6.4 PDPA (Malaysia residents)
Malaysia's Personal Data Protection Act 2010 gives you the right to access and correct the personal data we hold about you, to withdraw consent to processing, and to limit the processing of your personal data. To exercise these rights, email jeffrey.ng.op@gmail.com. We will respond within 21 days as required under the Act.
6.5 PIPA / 個人資料保護法 (Taiwan residents)
Taiwan's Personal Data Protection Act gives you the right to inquire, request copies of, supplement, correct, or delete the personal data we hold about you. To exercise these rights, email jeffrey.ng.op@gmail.com.
7. Children's privacy
AI情騙子 is rated 17+ on the App Store and Mature 17+ on Google Play. The app is intended for adults and is not directed to children.
We do not knowingly collect personal information from anyone under 18. If you are a parent or guardian and believe your child has used the app, please email jeffrey.ng.op@gmail.com and we will delete any associated session data promptly.
8. International data transfers
Because BytePlus is based in China and Fly.io is based in the United States (with our server instance in Singapore), your data may be transferred outside your country of residence. For users in the EU/EEA/UK, we rely on:
- BytePlus's published security and contractual terms, including their data processing terms
- Fly.io's Standard Contractual Clauses (SCCs) for transfers out of the EU/EEA
If you have concerns about cross-border transfers — particularly transfers to China — please consider whether AI情騙子 is the right product for you. We disclose this clearly so you can make an informed choice.
9. Security
We take reasonable steps to protect data, including:
- All traffic between the app and our server is encrypted using HTTPS / TLS 1.2+.
- API keys for BytePlus are stored on our server only, never shipped in the app binary.
- Server access is restricted to authorized administrators.
- We rate-limit and log suspicious traffic.
No system is perfectly secure. If a breach occurs that materially affects you, we will notify you (where required by law) within the timelines applicable to your jurisdiction (e.g., 72 hours under GDPR for high-risk breaches).
11. Changes to this policy
If we make material changes to this policy — for example, adding a new third-party service or changing what data we collect — we will:
- Update the Last updated date at the top.
- Show an in-app notice on the next launch describing the change.
- For significant changes affecting EU/EEA/UK users, give 30 days' notice before the changes take effect.
You can review prior versions on request by emailing jeffrey.ng.op@gmail.com.
12. Contact
For any privacy question, data request, or complaint:
Email: jeffrey.ng.op@gmail.com
Subject line convention: start with[Privacy]for fastest routing