Privacy Policy
Last updated: October 11, 2026
Operator: GRASS Outdoor Co., Ltd.
Contact: fox@grass.camp
We use your data to help your AI twin get to know you and meet people on your behalf. You choose how much to make public. OpenAI's AI generates your twin's conversations, so your data is sent to OpenAI for processing. We do not use ad tracking. You can delete your account at any time.
For where AI is used in the game and where it isn't, see How we use AI.
What we store
Account information
We store your account name. We store only one-way hashes of your password and recovery code. Username-and-password registration does not require an email address or phone number. We save everyday photos after resizing them and removing metadata. You can export the photos and their text summaries or delete them with your account, as explained under “Everyday photos” below.
The website uses a cookie only for sign-in, starting when you first open it, including before you register as a guest. The mobile app stores sign-in credentials in your phone's secure storage. The server stores only hashes of those credentials, which expire after 30 days.
When available, Apple and Google sign-in store a hashed provider identifier linked to your account. We do not request your name, email, or profile photo from them or merge accounts by email. We encrypt the token needed to revoke Apple access and revoke it when you unlink Apple or delete your account. For phone sign-in, Google Firebase receives your phone number to send and verify a code and prevent abuse. OtherDay stores a one-way phone identifier and an encrypted Firebase user ID, not your phone number or verification code. Unlinking phone sign-in or deleting your account also deletes the Firebase Auth user. Provider security and legal records follow the provider's retention policies. What we keep of your sign-in after account deletion is listed below under records that remain after deletion.
Twin profile
We store your twin's name, your date of birth (used to calculate your age), country or region, language, appearance, interests, four personality scores, and your purpose for meeting people. Optional information includes gender, height, weight, MBTI, boundaries, a self-description, the people and age range you would like to meet, and the conversation times and time zone you enter in Settings.
Conversations with your twin
We store the full text of your chats. We do not store audio recordings of voice calls. However, when your twin needs to look something up, remember something, or change a setting, or when you mention wanting to hurt yourself, we transcribe what you have said since the last saved segment, up to 1,000 characters at a time. We save that text and your twin's reply in your chat history. During calls labeled “Help me get to know you through voice,” most of your answers are saved this way. For press-and-hold voice input, we delete the recording after transcribing it.
Transcripts of calls with your twin
Every type of voice call—the first call after registration, daily calls, “Call your twin,” and “Start a voice chat”—also transcribes and saves your own words for up to 180 days, then automatically deletes them. After the call, AI reviews the whole conversation to learn about you and how you speak from your words.
Your twin's words are also transcribed and stored for up to 30 days to check call quality, such as whether the twin was cut off mid-sentence. They also help the AI understand what you were responding to during that review, but are not treated as your words.
If you turn off “Automatically remember” in People › Memories, or the crisis process described below is triggered that day, we do not save these transcripts for the entire call. This is separate from the chat-history records described above, including records kept during a crisis.
If you forget a memory learned from a call in People › Memories, we also delete the transcript segment that was its source. We delete that segment even if it also supports other memories. Those other memories remain. For older memories without a saved source range, we delete the entire call transcript. Deleting your account deletes all of these transcripts.
Everyday photos (optional)
You may upload up to 10 photos at a time in Chat › Practice › Everyday photos and keep up to 30 photos per person. Selected photos are only previewed on your device until you confirm that you are at least 18, agree to the Terms, and select “Upload.” Before saving them in the database, we resize them to JPEGs with a longest edge of no more than 640 pixels and a size of no more than 80 KB each. We remove EXIF data, GPS location, and other metadata. We do not keep the original photos or write them to logs.
Photos and the observations about your everyday life derived from them are for you and your twin only. They are not shared with other players or their twins or included in your public profile. Their purpose is to help your twin understand your habits, interests, and lifestyle, for future analysis and improvements to matching. Currently, photo analysis produces at most five sentences of observations for use in your private chats and voice calls.
We keep photos and observations until you delete your account. You can download the photo content in your data export. Guest photos move into your new account when you register. If you do not register, guest photos expire 72 hours after upload and are removed by the next cleanup. Removing a photo from the upload screen also deletes its saved copy.
Observations are labeled as AI observations that you have not confirmed. We instruct your twin not to infer personality, activity frequency, or who owns an item from a photo, or to treat these observations as confirmed memories or samples of how you speak. We instruct the AI not to describe looks, body shape, age, or ethnicity. We also instruct it not to infer health, religion, politics, sexual orientation, or income, identify people or exact locations, or copy text, license plates, or addresses from photos. Removing location metadata does not remove landmarks or text visible in the image.
Things your twin remembers
We store memories, interaction principles and example scenarios derived from them, and summaries you import from other AI services. For each memory, we also record whether it came from typing or voice, whether it concerns you or someone else, its source message or call segment, and whether you said it yourself, confirmed it, or your twin inferred it.
The interests you enter (during registration or in Settings) and the MBTI you enter in Settings › My traits each become a memory labeled as something you told your twin. The MBTI memory is used only between you and your twin. You can edit or forget these memories in People › Memories. Changes to interests or MBTI in Settings update the corresponding memories. Automatic learning is on by default. You can pause it in People › Memories.
Background hypothesis notes
At most once a day, your twin uses AI to form hypotheses about why you make certain choices, based on things you have said and things you like. These cover two perspectives: personality and emotions, and values and daily life. Every note must cite your own words. Private matters and MBTI are excluded.
For now, these notes stay in the background. They are not used in your twin's conversations or actions and are not shown to other people. We will use them only after confirming that they help the twin better reflect you, and will update this page when that changes. Forgetting a cited memory in People › Memories also deletes the related notes. Pausing automatic learning stops this process.
“Don't tell anyone” instructions
If you tell your twin not to share something, by text or voice, we save your instruction and what it refers to. We mark related memories as private between you and your twin, so the twin will not bring them up in the world. We remove this restriction only after you say it can be shared and confirm that choice. The instruction record remains in your account after the restriction is lifted and is deleted when you delete your account.
Requests, rules, and habits you give your twin
We store these in your account to help your twin follow your wishes. They are not shown directly to other players.
For a request, such as “Go say hi to Manny,” we store your exact words (up to 12,000 characters), a one-sentence explanation written by your twin, progress, and the other person's response. You can have up to 3 requests at a time. Unfinished requests expire after 3 days. You can cancel an unfinished request in People › Requests. Your twin will then stop trying to carry it out. After a request expires, finishes, or is canceled, its record, including your words, stays in your account, appears in your data export, and is deleted with your account.
When your twin acts on a request, other players' twins receive only the interaction type, such as a greeting. AI locals receive only a short context summary written by your twin, without your original words. Your twin tells you the outcome in chat. The outcome reflects what actually happened. We do not calculate and store a separate score.
For rules, such as “Never agree if someone wants to hold your hand,” and habits, such as “Tell a joke when you meet someone wearing red,” we store your words and a one-sentence summary written by your twin. You can have up to 20 rules and 10 habits. You can view and forget them in People › Memories. As with other memories, chats containing that sentence are also deleted.
Summaries are included in the twin's conversation prompts sent to OpenAI and may also be used in encounters with other players' twins. Your twin decides what to do based on its personality. Lines that repeat your original wording or say that you instructed it are blocked. Your twin mentions a new rule once in your next call. If it is unclear whether a sentence expresses a habit, we ask OpenAI to interpret that sentence again, with storage disabled for the request. Each time you give a rule, we log only codes for where it came from, whether it was saved, and its category, without the content.
Your choices in moments and spending
When your twin runs into a small situation while you have the app open, such as the café cat eyeing your twin, a moment appears so you can pick how your twin handles it. Before you see it, your twin guesses how it would handle it on its own. If you pick a way, or use “Say it” to describe your own, we record which moment it was, the way you picked, whether you tapped or said it, whether your twin guessed right, and whether it was the first time that moment came up. When you use “Say it,” we match your words to a way in code and leave the way blank if none matches. Your words are saved in your regular chat history, as described above. This record holds codes, never your words. If you select “Let your twin decide,” or time runs out, nothing is recorded.
When you ask your twin to do something that costs money, such as treat an AI local to coffee or ride to another part of town, we also record whether its wallet was tight, fine, or plenty at the time, whether it had enough, and, as codes, which local and what treat, or which area. The wording of your request is kept only with the request, as described above. Your twin's own spending and saving are not recorded.
Your twin uses these records to handle the same situation the way you chose the next time it comes up, and to lean toward what you chose when it is near the café cat or the gull. The wallet records are not yet used to change what your twin does. We will update this page before they are. The records themselves are not sent to OpenAI and are not shared with other players or their twins. The one exception is an AI local's second act: there, the way you chose is added as a pre-written sentence to the story prompt sent to OpenAI when your twin meets that local. What your twin does based on your choices is visible in town, like the rest of its activity.
When you use “Say it” or ask for something that costs money, the record notes which chat message your words were in. In People › Memories, if you forget a memory learned from that message, the record is deleted too. A way you tap has no words behind it, so that record isn't linked to any memory, and the same is true when your words didn't become a memory. Those records stay until you delete your account. All of these records appear in your data export and are deleted with your account, or when an unregistered guest identity expires.
Interaction boundaries
We save the switches you choose in Settings in your account. They are not directly public. “Overnight invitations” defaults to off if you have not set it. Flirting, jokes about looks, taunts, comments about body shape, and verbal harassment default to on.
When overnight invitations are off, we instruct your twin not to initiate them. If an invitation is received and identified as an overnight invitation, your twin says a line and leaves, and will not meet that person again for 7 days. The identified invitation is hidden by default, including in previews, screen-reader text, and replays. Revealing one line shows only that line. Switching on Sexual invitations and confirming the dialog removes this filter and allows your twin to respond to these invitations. This does not filter private messages between players. Turning this setting on requires both using the switch and confirming in the explanation dialog. A chat rule cannot turn it on for you.
Saved rules remain as they are. The new defaults also apply to older accounts that never saved a setting, including accounts that turned the feature off and back on in an older version without leaving a saved choice. You can change these choices in Settings. Data exports include your saved choices and all six effective settings. They are deleted with your account.
What your twin can share
In Settings › What your twin can share, you can set how much your twin says about each topic, such as work, money, health or politics: Brings it up, If asked, or Keeps it private. Topics you don't set use the defaults. Keeps it private works like a lock: your twin never says it, however well the twins know each other. When your twin tells another player's twin about one of these topics, that line is marked in your own record of the meeting, such as “Shared your work.” The other player and bystanders can't see the mark. Tapping “That's fine” or “Don't share this” changes the same setting. It applies from then on, and what was already said can't be taken back. This setting is saved in your account, not shown to other players, included in your data export and deleted with your account. Each tap on “That's fine” or “Don't share this” also adds a record that isn't linked to anyone, with only the topic's code and your choice, never the line itself. These records don't expire automatically.
Your twin's life and contact with other players
We store encounters, dates, things your twin observes, its judgments about others, and your post-encounter choices: “I'd like to get to know them,” “Not now,” or “Let's see.” We also record those choices when you tell your twin in chat. We store private messages between you and other players, willingness to connect, blocks, and reports.
A player report includes the other person's account name, private messages between you, and conversations from the two twins' most recent encounters. A report about a single message from a twin or AI local includes only that message's original text, speaker, time, and the reason you provide. It does not include other private conversations or automatically block a player.
Your data export includes your twin's decision log: whether it went up to someone, how it answered a date, what it did in a scenario card, how a request turned out, and the coins it earned and spent and what on. An AI local appears under that local's ID. Another player always appears as “another player” with a code that only holds within that one export: the same player has the same code throughout it, and the next export uses a different one. The log never includes their account ID, their name, or what your twin wrote about them. The basis for a decision lists only the IDs of your own memories it relied on. For “I think you would…” questions, a scenario card's “What would you do?” question, and moments, your export also includes your twin's guess, your answer (including any answer you wrote yourself), and whether your twin guessed right. These are deleted with your account.
How you text other players (optional)
Off by default: we don't learn from your private messages. If you turn on “Let my twin learn how I text” yourself in Settings › Account & data, each private message you send to another player is counted by our code the moment you send it. Only the numbers needed for proportions are added to a running total: message length, which filler words you use, whether there's an emoji, whether the message ends with a period, whether you laugh (like “haha” or “lol”), and whether you mix in English.
This feature never stores or forwards your words, and it doesn't send them to AI for analysis. Your private messages themselves are stored as described above and shown only to the two of you. Messages other players send you are not counted, and neither is a message about harming yourself.
These numbers are kept but not yet used for anything your twin says. Later, they'll be combined with how you talk in chats and calls with your twin so your twin texts more like you. We'll update this page before we start using them. The counts are not shared with other players or their twins.
When you turn the switch off, the counts and the texting habits calculated from them are deleted right away. Turning it back on starts from zero. The counts are included in your data export and deleted with your account.
Coins and rides
We record each coin your twin earns by helping AI locals and each coin it spends on coffee, meals, the shuttle bus, or a treat you asked for: the amount, the reason, the local involved, and the time. We also store its choices about spending and whether to treat someone, the two numbers under each daily report (coins earned and spent that day), its wallet balance, the bus it is riding, and when it arrived in its current area. We also store when your twin last woke up or finished a coffee or a meal (to tell whether it is tired), and which areas you have found, such as Halcyon Lake, with when you first found each. When you ask your twin to treat someone, that request also records roughly how full the wallet was at the time, in one of three levels.
Coins are earned only with time in the game. They cannot be bought with real money, and they are spent only on locals, never given to other players. Only you see the balance and the ledger's numbers, and they are not included in prompts sent to OpenAI. When your twin treats someone, buys a coffee, or rides the bus, others in town can see what it is doing, as with its other actions. Coin and spending records are deleted automatically after 45 days. The daily numbers and the balance are kept until you delete your account. All of this appears in your data export, where the daily figures are numbers only, and is deleted with your account.
Where you heard about us (optional)
After you create your account, we ask once how you heard about OtherDay. You can skip it. We keep only the option you pick, use it only for totals across all players, and don't send it to outside analytics. It's included in your data export and deleted with your account.
Technical records
We store AI usage and our costs, voice-call duration in seconds, and counters used to prevent abuse, such as sign-in attempts. These counters include hashes of IP addresses and are cleared after 1 to 8 days. Cloudflare also samples a small portion of connection and error logs for troubleshooting.
Consent to AI use
After you select “Create my twin,” a small card at the bottom of the screen explains that your twin's conversations are generated by OpenAI's AI and that the information you enter is sent to OpenAI for processing, and confirms that you are at least 18 (with links to the Terms and this Privacy Policy). When you select “Agree and start,” we record the version you agreed to, the time, and whether you used the web or a mobile operating system. We keep this with your account. For guests, it moves into the account at registration. We do not ask again later in the game. When you create an account (with a username and password, or with Apple or Google), we also record that you are at least 18 and agree to the Terms.
Mobile notifications
Only after the app's push setup is complete and you choose to enable notifications do we obtain and store a push token, your phone's time zone and operating system, and the app version. We also record the permission prompt and your choice. The app doesn't ask when you open it. When your twin has met a real person in the last day, or a match card is waiting, a line on the main screen asks, and your phone's permission prompt appears only if you tap Sure. Once you tap Sure, tap ×, or change the switch in Settings › Notifications, this phone isn't asked again. The token is stored in your phone's secure storage too.
Before disabling notifications, signing out, switching accounts, or deleting your account, the app unregisters this phone. If the connection fails, it keeps the settings so you can try again and stops that operation. You can turn off notifications in your phone's system settings first. You can use the game without enabling notifications. If app setup is incomplete, we do not request notification permission or generate a token. Actual push delivery has not yet been enabled.
There are six kinds of notifications: daily recap, new encounters, match cards, connection requests, messages, and date updates. Once you allow notifications on your phone, all six are on by default. You can turn each one off in the app under Settings › Notifications. The website can't receive notifications, so that row there just says “Set up in the app.” Notifications use fixed wording and never show names or what anyone said. You'll get at most two a day, and none between 10:30 PM and 8:30 AM.
Usage events
We record interactions with the app and website, such as panels you open and shortcuts you select, to improve the interface. These records do not include what you type. They include:
- Which menu panel you open, such as Chat, People, or Settings.
- Which shortcut you select, such as “Call your twin,” “See today,” “Help your twin be more like you,” or “Ask Riley to…” on a card.
- Whether you open, dismiss, or respond to a town prompt card, such as a match, a first encounter, a short story, or the notification question, after it appears, and which type of small card you open.
- How the app was opened or brought to the foreground: directly, through a notification, or through a link.
- The previous and new graphics-quality levels when quality changes automatically or manually.
When a program error occurs on the web or in the app, we record its type, its location in the code (file name, line, and column), and an error message with personal content removed, up to 5 records per minute.
Ordinary events contain only fixed codes and numbers. Each record also includes the time and whether you are using the web, iOS, or Android. App records include the app version. We do not record which person or place you clicked (match cards are the exception described next), or store IP addresses in these events.
When a match is introduced, we record how close both twins were at that moment, and whether the two of you went on to talk. We use this only to measure overall results, and we never store message contents. After you have messaged someone for a while, the top of the chat asks you once whether the conversation was worth having. Your answer only goes into overall totals: the other person and both twins never see it, and it never changes anyone's matches.
The server also records several kinds of events using only codes and numbers:
- Each time your twin learns from your words, how many memories the AI proposed, how many were kept, and which rules caused proposals to be skipped, to check for missed learning.
- The question category and whether your twin guessed correctly, when it guesses in the background how you'd choose (it never quizzes you, for example it guesses before a moment appears) and when you actually choose.
- Plan and report-type codes when daily reports are available to you and you open one. A skip event and reason when a recent crisis-support process causes that day's report to be skipped.
- A code that is not linked to any person when a twin leaves a conversation because of a boundary.
- Milestones, such as your first private message to another player and the first message in a conversation with a real-person match when you are the one who sends it (if the other person writes first, it is recorded for them): a milestone code and the time, without message content.
The rule-instruction events, notification permission prompts, and AI-use consent records described above are stored in the same place, as will the type of each notification sent after push delivery is enabled. App crashes, phone overheating, and the type of notification you opened will start being recorded only when the relevant features are launched.
Once you create a twin, events are linked to your account. Guest events are initially linked to the guest identity and move into your account when you register. Events recorded before you have a twin are not linked to anyone, except for AI-use consent as described above.
These records currently have no automatic expiration and are kept while your account exists. After account deletion or guest-identity expiration, we unlink them from you and keep only codes, numbers, and the error information described above. “Export my data” currently does not include these records.
Usage analytics: on by default, with an opt-out
We use Google Analytics 4 (GA4) and Amplitude to understand how features such as creating a twin, heading into town, encounters, and contact are used. “Help improve OtherDay” is on by default for existing accounts without a recorded choice, new players, and guests. A previous explicit opt-out stays off. You can turn it off at any time in Settings. Registration does not ask about it separately: it is on by default, and you can turn it off in Settings once your twin is created. No separate analytics agreement is required to register. This setting does not affect gameplay or replace consent to AI processing. Providers without a configured ID are not loaded and receive no analytics events.
While enabled, events contain only allowlisted names, times, platform, permission levels or interaction types, and a pseudonymous identifier. Account properties also include your selected country or region, signup and twin-creation dates, and subscription status. They do not include names, photos, chat or call content, your instructions to your twin, precise location, email, phone numbers, or the other person's identifier. Pseudonymous data can still be personal data. It is not fully anonymous.
Google and Amplitude may process data in the United States and other countries and receive your connection's IP address because your browser or app connects directly to them. We do not put IP addresses in event fields. Amplitude's location inference is disabled. We do not use advertising tracking, automatic form capture, or session replay. GA4 may use analytics cookies. The app uses the same default-on setting and opt-out, without advertising identifiers.
Turning the switch off stops this device immediately. Server events stop once the choice is saved. Other open devices stop at their next synchronization. If offline, only this device stops immediately: reconnect and use “Turn off analytics” again to save the account choice. Turning analytics off or deleting your account cannot recall events already sent. Provider retention settings apply to those events. Contact us about deletion requests. Existing internal usage statistics, security records, and AI-consent records are separate and continue as described above.
Analytics choices are stored by OtherDay until account deletion. They are separate from the usage records above, which currently have no automatic expiration. Anonymous operational statistics (counts and codes that are not linked to any account, such as how many instructions were created in a day) are automatically deleted after 30 days. Exports do not include usage events, analytics choices, or events already sent to analytics providers.
Who can see your information
- Level 0 — Private: You choose your twin's permission level in Settings. At level 0, your twin does not appear in town, and players who have not met it cannot see it. There is an exception: if either you or the other player selected “Agree to real-person contact,” that player can still see your twin in People. What they see depends on how far their twin has gotten with yours, as at level 1. If their twin hasn't met yours, they see only its name, appearance, and current location. Once their twin has met yours once, they also see its country or region and language. Once their twin reaches Clicking with yours, they see its age and interests too. Private messaging that both players agreed to also continues. To cut off contact completely, block the other player.
- Level 1 and above — Explore: All signed-in players can see your twin's name, appearance, height, approximate body type calculated from height and weight (not actual weight), interaction style, and current location, activity, and speech. Your twin's country or region, language, age, and interests depend on how far another player's twin has gotten with yours. Players whose twins haven't met yours don't see these four. Players whose twins have met yours once see its country or region and language. Once their twin reaches Clicking with yours, they see its age and interests too. Any signed-in player who selects your twin on the map can see its latest line and the other speaker's response. The exception is an encounter between twins: questions one twin asks about the other's player, the answers, and lines about politics, faith, money, or health are shown only to the two players whose twins are talking. Everyone else just sees that the twins are chatting. Other players' twins can also remember what they saw your twin do.
- Level 2 — Socialize. Level 3 — Date: At level 2, your twin can meet other players' twins. The other player can see the twins' full conversation. Other signed-in players can see the latest one or two lines, except the kinds of lines described above. At level 3, your twin can decide whether to go on dates.
- Not displayed directly to others: Your account name, date of birth (others see only age), actual weight, gender, MBTI, boundaries, self-description, photos and text summaries, purpose for meeting people, the people you want to meet, and last-online time. When talking with other players' twins, your twin uses only a one-sentence summary of what you've said or written, including things it learned on its own, things you asked it to remember, and preferences you brought over from another AI. It doesn't get your exact words. The exceptions are things meant to be shared, such as your sign-up answers, options you tapped, the interaction style you approved for public use, and lines you showed it how to say. Before any line reaches another player, our server blocks it if it repeats a run of your own words (6 words in a row in English, 12 characters in Chinese), copies a whole private memory, names an MBTI type, or contains a phone number, email, social handle, address, ID, or card number. The exceptions above, and lines you practiced while creating your twin (answers you picked in its scenes, and lines you marked as like you or rewrote in your own words), aren't checked for repeated runs, so your twin may say them word for word. This check matches text, not meaning, so a paraphrase can get through. Your twin's speech is still generated by AI using your data and may reveal your preferences.
- Private messages between real people: Your twins must first have met, and both players must agree before private messaging can begin.
Public moments in the game, like twins meeting in town, may be used anonymously to promote OtherDay. To ask us not to use footage of your twin, email fox@grass.camp.
Services that process your data
All of the services below may process or store your data in the United States and other countries.
OpenAI (a U.S. company) generates twin conversations and actions, provides voice calls and speech-to-text, and organizes memories. During voice calls, your phone or browser connects directly to OpenAI to send audio, so OpenAI also sees your IP address. We configure requests so OpenAI does not store this content for later retrieval, but under OpenAI's policies, it may retain it for up to 30 days for abuse monitoring.
When you create a twin, its name, the gender selected for its appearance, age calculated from your date of birth, MBTI, interests, a self-introduction pasted from another AI, and up to five sentences summarizing photos are sent once to OpenAI to predict answers to the tutorial's three scenario questions. Storage is disabled for that request. The request does not include your original date of birth. Our server does not keep a separate copy of the request content. It records only a count and AI usage. The name, date of birth, MBTI, and interests are later saved with the twin profile as described above. The pasted self-introduction is not saved. The one- or two-sentence summary the AI also writes from that information (your twin's first guess about you, not your words) is kept in your account for up to 7 days, so your twin has a first impression before your first call with it, and is sent to OpenAI with your answers to the tutorial's three questions to organize them. It appears in your data export and is deleted when you delete your account, including an account deleted before its twin was created.
Later, your date of birth and MBTI are sent to OpenAI with other twin information for your private chats and voice calls, predictions of what you would choose, and reference material when writing stories about your twin meeting AI locals. Saved photo observations are used only in private chats and voice calls. None of this information is included in encounters between your twin and other players' twins.
Resized everyday photos with metadata removed are also sent to OpenAI for analysis, with storage disabled for the request. OpenAI's published API data policies govern its retention and use of that data.
Your twin continues to be active while you are offline. When its permissions are level 1 or above and it is active, the town advances every minute, and your twin's profile and memories continue to be sent to OpenAI. To stop its activity, let it rest or return to level 0 in Settings. To stop background memory processing, pause automatic learning in People › Memories.
Cloudflare hosts the website and database. It also keeps the sampled connection and error logs described above and automatically deletes them according to its retention periods. Database backups are kept for up to 30 days.
Google: The website loads fonts from Google Fonts, which exposes your IP address to Google. The app uses bundled fonts. Once mobile push notifications are added, they will be sent through Google Firebase.
When purchases are available, RevenueCat and Apple or Google process a random purchase identifier, store receipts, and transaction data to verify subscriptions and refunds. OtherDay does not send RevenueCat your account name, photos, or conversations and does not enable RevenueCat to collect advertising identifiers. We keep product, store, currency, amount, billing period, refund, and duplicate-event records to provide paid features and reconcile payments. Purchase verification is required for paid features and is separate from optional analytics.
Particularly sensitive information
Your optional “People I'd like to meet” preferences (gender and age range) may reveal sexual orientation. These are used only on our server to select people for encounters and matching. They are not public or sent to OpenAI. You can change them in Settings at any time.
Religious and political views: If you tell your twin your faith or your politics, it remembers them like any other preference. This is on by default, and we don't ask separately. If you haven't told it, it may infer them from things you've said and answer for you with confidence when someone asks. Inferred answers are marked as your twin's guesses. When another twin asks about something you haven't taught yours, a card appears in People that says “I said ‘…’ for now.” You can pick your real answer or keep it private.
When your twin talks with another player's twin, there's no set number of meetings before it shares something. Like a person would, it weighs whether they asked, how well the two twins know each other, whether the other twin shared something similar first, and your settings. When asked, it usually answers honestly, including which side you lean. You can read what your twin said in its recent conversations. You can lock these topics in Settings › My traits, or tell your twin not to tell anyone. After that, if someone asks, your twin changes the subject and doesn't guess or answer. Locked topics, anything you told it not to share, and your real name, address, phone number, contact info and IDs are never shared, however well the twins know each other. Players outside the conversation can't see these lines, as described in “Who can see your information.”
If you share health information, sex-life details, or other private matters in chat, those messages are stored and sent to OpenAI for processing as usual. Automatic learning doesn't save health details, sexual orientation, or ID numbers as preferences.
When you delete a memory in People › Memories, we also delete chats containing that memory's text, its original source message, interaction principles and background hypothesis notes derived from it, and the record in which your twin originally proposed remembering it. Other chats that mention the same subject currently can be removed only by deleting your account.
When deleting a memory, we keep a fingerprint calculated from its text that cannot be reversed into the text. We use it only to stop older call transcripts or retried background tasks from saving the memory again. If you later say it again yourself, your twin can remember it again. The fingerprint is deleted with your account.
Your twin infers your personality and preferences from conversations only to better reflect you, not for advertising.
Retention and deletion
In general, we keep data until you delete it. Exceptions include things your twin observes (only the latest 160), example scenarios (only the latest 12), and call transcripts (up to 180 days for your words and 30 days for your twin's words, as described above).
When you delete your account, we immediately delete the account, twin, and data listed above, including photos, text summaries, and call transcripts, except for the records below. Encounters and private messages involving you, and other twins' records of what they saw your twin do, are also deleted from other players' accounts. The same goes the other way: when another player deletes their account, your encounters and messages with them are deleted too. If you reported them, the copies attached to the report are kept as described below. The counts of how you text other players are deleted as soon as you turn the switch off, without waiting for account deletion.
The following records remain after deletion:
- AI usage and voice-call duration: Unlinked from your account so they no longer identify whose usage it was.
- Reports, including attached private messages, encounter conversations, or individual AI messages: Closing a report does not delete its evidence. Reports and moderation records, including case status, actions, audit history, and crisis-event identifiers, remain after account deletion and currently have no automatic expiration. Crisis records do not contain a separate copy of your conversation.
- Sign-in fingerprint: When you delete your account, we keep a one-way fingerprint of your Apple, Google, or phone sign-in. We use it only so that blocks and 'not for me' choices you made, or that others made about you, still apply if you sign up again with the same sign-in. We keep nothing else.
- Abuse-prevention counters: Cleared after 1 to 8 days.
- Database backups: Kept for up to 30 days.
- Cloudflare's sampled connection and error logs: Automatically deleted according to Cloudflare's retention periods.
- OpenAI's abuse-monitoring logs: Kept for up to 30 days.
- Usage events: Unlinked from your account, retaining only codes, numbers, error types, code locations, and error messages with personal content removed.
After account deletion, purchase and refund records have no automatic expiration. We remove the link to your OtherDay account but keep the random purchase identifier and transaction records for refunds, duplicate-event checks, and reconciliation. Apple, Google, and RevenueCat retain their own records under their policies. Deletion does not cancel a subscription or automatically delete those records.
See the account deletion instructions for how to delete an account.
Unregistered guest data is also stored on the server and moves into your new account when you register. A guest identity expires 30 days after the first visit, after which we automatically delete the guest data. As with account deletion, usage events remain only as statistics with the identity removed.
If you clear browser data, sign in through “Forgot password,” or switch to an account that already has a twin, the original guest twin and conversations do not move into that account. They will be deleted no later than the end of that 30-day period. When switching accounts, usage events do move over. Notifications for this phone are unregistered first and can be enabled again later.
Your choices
- Download your main data: Sign in on the website and select Settings › Account & data › Export my data. Downloads are not currently available inside the mobile app. The export doesn't include call transcripts, what your twin saw, the text of daily recaps (only each day's coin numbers), or usage events.
- Correct or forget memories: Open People › Memories.
- Stop your twin's activity: Open Settings.
- Delete your account: See the account deletion instructions.
For other requests, email fox@grass.camp.
Crisis response and age requirement
If you mention wanting to hurt yourself while chatting or on a voice call with your twin, the service shows a fixed crisis-support card based on your device time zone or a saved chat time zone, not your language. In the United States, it offers 988 (call or text the Suicide & Crisis Lifeline) and 911 for immediate danger. In Taiwan, it offers 1925 (free, 24-hour mental health support) and 119 or 110 for immediate danger. For English accounts with an unknown region, it lists U.S. resources and findahelpline.com for help elsewhere. Chinese accounts with an unknown region see both countries’ resources. The card does not depend on an AI-generated phone number. It also works for guests, when AI is disabled or its allowance is exhausted, and after a voice call is interrupted. In text chat, your twin stops the game interaction. A voice call ends, and what you just said is transcribed and saved in your chat history with your twin. This conversation is not used to teach your twin your speaking style.
If these kinds of words appear in a private message you send to another player, the system uses word matching, without AI, and the message is delivered as usual. The crisis-support reminder appears only in your chat with your twin. The other player does not see it.
OtherDay is for people age 18 and older. If we discover an account belonging to someone under 18, we will delete it.
Changes to this policy
When we make material changes, we will update the date on this page and post a notice on the website.