Privacy Policy

AI情騙子 — AI Love Scammer: Spot Fraud

Effective date: 2026-05-24  ·  Last updated: 2026-05-24

Quick summary

We built AI情騙子 to teach people how to recognize romance scams. To do that, the app sends your chat messages to an AI service so the AI characters can respond. Beyond that, we collect as little as possible:

The longer version below explains exactly what does flow through our systems, who processes it, and how you can delete it.


1. Who we are

This app and this Privacy Policy are operated by:

JN App Studio
Kuala Lumpur, Malaysia
Contact: jeffrey.ng.op@gmail.com

For purposes of the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), Malaysia's Personal Data Protection Act 2010, and similar laws, JN App Studio is the "data controller" of any personal data described in this policy.

2. What information we collect

2.1 Information you provide directly

We do not ask for and do not store: your real name, real email, real phone number, real address, real photos, real payment information, or your contacts.

2.2 Information collected automatically

When the app talks to our server, our server automatically receives:

2.3 Information we do NOT collect

To be explicit, AI情騙子 does not request or use the following permissions:

If a future version of the app adds any of these, this policy will be updated before the feature ships, and we'll prompt you for explicit permission inside the app.

3. Third parties we share data with

We rely on three categories of third-party service providers. Each one only receives the minimum data required for its specific function.

3.1 BytePlus (AI chat and image generation)

We use BytePlus — a cloud AI platform operated by Beijing Volcano Engine Technology Co., Ltd., an affiliate of ByteDance — for:

BytePlus is based in the People's Republic of China. Chat content you type may be processed and temporarily stored on servers located in China. BytePlus's own privacy and security terms apply to that processing; see their policy at byteplus.com/en/legal/privacy-policy.

What this means for you: if you live in a jurisdiction with strict cross-border data transfer rules (the EU, the UK, Switzerland, etc.), please weigh this disclosure when deciding whether to use the app. We do not send your real name, email, or any direct identifier to BytePlus — only the in-game nickname you chose and the messages you typed.

3.2 Fly.io (application hosting)

Our server, which sits between the app on your device and the BytePlus API, is hosted on Fly.io (Fly.io, Inc., a Delaware corporation). Fly.io processes incoming requests on our behalf. Our chosen Fly.io region is sin (Singapore), which means request metadata is handled at that data center.

Fly.io's privacy practices: fly.io/legal/privacy-policy.

3.3 App stores (Apple and Google)

When you install the app from the Apple App Store or Google Play Store, those platforms collect their own data (downloads, crashes if you opted in, in-app purchase metadata if applicable). We receive aggregate, anonymized reports from them — we do not receive your Apple ID, Google account email, or any directly identifying information.

3.4 No advertisers, no analytics SDKs, no data brokers

We do not embed any third-party advertising, analytics, or data-broker SDKs in the app. If we ever add a crash reporter (e.g., Firebase Crashlytics or Sentry), we'll update this policy first and the reporter will only receive crash stack traces, not chat content.

5. How long we keep your data

Data typeWhere it livesRetention
Player nickname, character nicknames, settingsYour device only (local storage)Until you uninstall or clear app data
Chat historyYour device only (local storage)Until you delete it in Settings or uninstall
Session ID and invitation-code mappingOur server (Fly.io, SQLite)Up to 90 days after last activity, then purged
Usage logs and rate-limiting countersOur server30 days, then rotated out
Chat messages forwarded to BytePlusBytePlus serversPer BytePlus's retention policy; we do not retain server-side copies beyond the request-response cycle
Generated imagesBytePlus TOS or our server's diskUp to 90 days, then purged
Diagnostic logsOur server14 days, then rotated out

We keep these periods as short as we can while still being able to debug issues and prevent abuse.

6. Your rights

6.1 The right to access and delete your data (everyone)

6.2 GDPR (EU/EEA/UK residents)

You have the right to:

To exercise any of these rights, email jeffrey.ng.op@gmail.com. We respond within 30 days.

6.3 CCPA / CPRA (California residents)

California residents have the right to:

6.4 PDPA (Malaysia residents)

Malaysia's Personal Data Protection Act 2010 gives you the right to access and correct the personal data we hold about you, to withdraw consent to processing, and to limit the processing of your personal data. To exercise these rights, email jeffrey.ng.op@gmail.com. We will respond within 21 days as required under the Act.

6.5 PIPA / 個人資料保護法 (Taiwan residents)

Taiwan's Personal Data Protection Act gives you the right to inquire, request copies of, supplement, correct, or delete the personal data we hold about you. To exercise these rights, email jeffrey.ng.op@gmail.com.

7. Children's privacy

AI情騙子 is rated 17+ on the App Store and Mature 17+ on Google Play. The app is intended for adults and is not directed to children.

We do not knowingly collect personal information from anyone under 18. If you are a parent or guardian and believe your child has used the app, please email jeffrey.ng.op@gmail.com and we will delete any associated session data promptly.

8. International data transfers

Because BytePlus is based in China and Fly.io is based in the United States (with our server instance in Singapore), your data may be transferred outside your country of residence. For users in the EU/EEA/UK, we rely on:

If you have concerns about cross-border transfers — particularly transfers to China — please consider whether AI情騙子 is the right product for you. We disclose this clearly so you can make an informed choice.

9. Security

We take reasonable steps to protect data, including:

No system is perfectly secure. If a breach occurs that materially affects you, we will notify you (where required by law) within the timelines applicable to your jurisdiction (e.g., 72 hours under GDPR for high-risk breaches).

10. Cookies and similar technologies

The app itself does not use cookies. Our server uses a session identifier transmitted in API requests (not a browser cookie). Our privacy policy webpage (if you're reading this on the web) may use a minimal first-party localStorage entry to remember a language preference; we do not use third-party tracking cookies.

11. Changes to this policy

If we make material changes to this policy — for example, adding a new third-party service or changing what data we collect — we will:

  1. Update the Last updated date at the top.
  2. Show an in-app notice on the next launch describing the change.
  3. For significant changes affecting EU/EEA/UK users, give 30 days' notice before the changes take effect.

You can review prior versions on request by emailing jeffrey.ng.op@gmail.com.

12. Contact

For any privacy question, data request, or complaint:

Email: jeffrey.ng.op@gmail.com
Subject line convention: start with [Privacy] for fastest routing