PRIVACY POLICY

Your conversations,
your privacy.

The full policy. A shorter plain-language summary lives at /privacy-summary — it is a companion to this document, not a substitute for it.

1. Introduction

Welcome to Calypso. Calypso ("Calypso," "we," "us," or "our") is operated by Calypso AI. We provide an AI-based emotional-support and conversation-decoding service available through our website at trycalypso.ai (the "Service").

This Privacy Policy describes how we collect, use, share, and protect your personal information when you use the Service. It applies to all visitors and registered users of Calypso.

We have written this policy to be as clear as a legal document can reasonably be. A shorter, plainer-language summary lives at trycalypso.ai/privacy-summary and is not a substitute for this document. A separate Consumer Health Data Privacy Policy, required by the laws of Washington and Nevada, lives at trycalypso.ai/consumer-health-data-privacy and is linked separately in the site footer.

By using the Service, you confirm that you have read and understood this Privacy Policy. If you do not agree with any part of it, please do not use Calypso.

2. Calypso is for adults (18+) — age requirements

The Service is available only to users who are 18 years of age or older. We ask for your age when you create an account, and you represent that the age you give us is accurate.

We do not knowingly collect personal information from anyone under 18. Calypso is not directed to children or teens, and we do not market the Service to minors.

If we learn that a user is under 18 — from any source, including the account itself, a support ticket, or the content of a report — we will close the account and delete its personal information as described in section 7.

If you believe a minor has created a Calypso account, contact privacy@trycalypso.ai and we will investigate, close the account, and delete its associated data.

Because the Service does not accept users under 13 (or under 18), we do not operate a parental-consent flow under COPPA or analogous laws; no account requiring one is knowingly accepted.

3. Calypso is an AI — required disclosures about the nature of the Service

Several jurisdictions (including California and New York) require services like Calypso to make clear disclosures about what an AI companion is and is not. We make them here, and inside the product:

Calypso is artificial intelligence, not a human. Every Calypso voice (persona) is a computer program. When you chat with Calypso, you are not communicating with a human being. The product displays a clear notification of this at the start of your interactions and at regular intervals (at least every three hours) during long sessions.

Calypso is not therapy, medical care, or a licensed professional service. Calypso does not provide psychotherapy, mental-health treatment, diagnosis, or medical advice, and no Calypso voice is, or will claim to be, a licensed professional of any kind.

Calypso is not a crisis service. If a conversation suggests you may be in crisis, the Service will show you a notification referring you to crisis resources such as the 988 Suicide & Crisis Lifeline and the Crisis Text Line. Our safety protocol — including how we detect and respond to expressions of suicidal ideation or self-harm — is published on our Safety page at trycalypso.ai/safety.

We maintain and publish this crisis-response protocol as required by, among others, California Business & Professions Code §22602 and New York General Business Law §1701, and we log crisis-referral notifications in aggregate (never the content of your conversation) to meet statutory reporting duties, such as annual reporting to the California Office of Suicide Prevention beginning July 2027.

4. The information we collect

We collect only the information we need to provide the Service. This section describes what we collect; section 5 explains why.

4.1 Information you provide to us.

Account information — email address, password (stored as a salted hash, never in plaintext), your confirmation that you are 18 or older (we ask you to attest to this at signup; we do not collect a date of birth for age verification), and your display name if you choose to set one. You can use a name other than your legal name; we do not require government-verified identity.

Profile information (optional) — date and time of birth, place of birth, and gender identity if you choose to provide them for the astrology / synastry feature on Pro. You can leave these blank, and you can edit or delete them at any time.

Conversation content — the text of your conversations with Calypso voices, the screenshots and other files you upload to the Decode feature, and the metadata associated with those conversations (timestamps, thread titles you set, voices used). Please note: conversation content may reveal information about your emotional state, relationships, or mental health. We treat all conversation content as sensitive data under the standards described in section 6.

Feedback and reports — messages you send to support, feedback you submit on a Calypso response, and abuse reports you file.

Payment information — if you subscribe to Pro, billing information is collected and processed by our payment processor, not by Calypso. We receive a transaction confirmation, the last four digits of the payment method, the expiry, and the billing country and postal code. We do not store full card numbers on our systems.

4.2 Information we collect automatically.

Device and connection information — IP address, browser type and version, operating system, device type, and language preference.

Usage information — which pages you view, which features you use (Decode, Chat, voice switches), session start and end, how long a decode takes, and which CTAs you click.

Error and performance data — anonymized crash reports and performance telemetry.

Cookies and similar technologies — see section 12.

4.3 Information from third parties.

Authentication providers — if you sign in using a third-party provider (such as Google or Apple), we receive the basic profile information that provider shares — typically an email address and a name.

Payment processor — transaction status and the limited billing information described in 4.1.

4.4 What we do not collect.

Government-issued ID, social security number, or driver's licence number.

Precise location beyond the coarse geolocation inferable from an IP address. We do not use geofencing of any kind.

Contacts from your phone or social networks.

Audio or video from your device, unless you explicitly choose to dictate or upload an image you have already captured. We do not create voiceprints and we do not run facial-recognition or face-geometry analysis on uploaded images.

Formal health records, prescriptions, or diagnostic information. You may write about your feelings, relationships, or wellbeing in conversations; how we handle that content is governed by section 6.

5. How we use the information we collect

For each use we state the legal basis under GDPR for users in the EU/UK; in other jurisdictions the same uses are permitted under equivalent provisions, subject to the sensitive-data rules in section 6.

Provide the Service — authenticate you, render your conversations, run the Decode feature, generate synastry reads, deliver responses from Calypso voices. Legal basis: performance of a contract (Art. 6(1)(b)).

Maintain the Service — diagnose errors, prevent abuse and fraud, secure accounts. Legal basis: legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) in fraud/security contexts.

Communicate with you — account-related emails (sign-in confirmations, password resets, billing receipts, security alerts). Legal basis: performance of a contract (Art. 6(1)(b)).

Process payments — bill you for Pro, refund you, manage your subscription. Legal basis: performance of a contract (Art. 6(1)(b)).

Improve the Service — analyze aggregated, anonymized usage data. Conversation content is not used for this purpose except under the opt-in below. Legal basis: legitimate interests (Art. 6(1)(f)).

Optional: AI model improvement — only with your explicit, opt-in consent, we may use a sampled and de-identified subset of your conversation content to improve our AI models. Off by default. Opt in or out at any time in account settings. Because conversation content can reveal health-related information, this processing is never performed for residents of jurisdictions whose law prohibits it regardless of consent (see section 6). Legal basis: consent (Art. 6(1)(a)).

Safety and crisis response — detect language patterns that may indicate a user is in crisis and surface the in-product Crisis Banner with crisis-resource referrals (see section 3). This is automated detection performed as part of delivering the Service you requested; no human reads your conversation unless you flag it or it is reported. We retain aggregate counts of crisis referrals (not conversation content) for statutory reporting. Legal basis: vital interests (Art. 6(1)(d)); legitimate interests (Art. 6(1)(f)).

Marketing communications — only if you opt in to a newsletter or product-update list. No marketing email by default. Legal basis: consent (Art. 6(1)(a)).

Comply with law — respond to lawful subpoenas, court orders, or other legal requests. Legal basis: legal obligation (Art. 6(1)(c)).

We do not engage in automated decision-making with legal or similarly significant effects on you. The Decode feature provides an editorial reading of a conversation; it does not make binding decisions about you. We do not use your data for targeted advertising, and we do not profile you for advertising purposes.

6. Sensitive data and consumer health data

Because Calypso is an emotional-support product, the content of your conversations may reveal — or allow inferences about — your emotional state or mental health. US state laws increasingly treat such information as sensitive data or consumer health data. Our commitments:

We treat all conversation content, and any inference our systems derive from it (including crisis-detection signals), as sensitive data, regardless of which state or province you live in.

We collect and process it only as necessary to provide the Service you have requested — rendering your conversations, generating responses, running Decode, and operating the in-product safety features. This is the "necessary to provide a requested product or service" processing recognized by the Washington My Health My Data Act, Nevada's consumer health data law, and the "strictly necessary" standard of the Maryland Online Data Privacy Act.

Any processing beyond that requires your separate, explicit opt-in consent (for example, the AI-model-improvement opt-in in section 5), which you can withdraw at any time.

We never sell conversation content or health-related data, and we never use it for advertising. Several states (including Maryland) prohibit the sale of such data outright; our position is the same everywhere.

We do not use third-party advertising pixels, tracking SDKs, or cross-context behavioural advertising tools anywhere on the Service.

Washington and Nevada residents: a standalone Consumer Health Data Privacy Policy with the disclosures those laws require is at trycalypso.ai/consumer-health-data-privacy, linked separately in the site footer. The rights it describes (including deletion that propagates to processors and backups) are available to you as described there.

7. How we share information

We share personal information only as described here. We do not sell your personal information, and we do not "share" it for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA and similar laws. We have not sold or shared personal information in the preceding 12 months.

7.1 Service providers (processors). We use a small set of trusted third-party providers, each bound by a written contract limiting their use of personal information to providing services to us:

Cloud infrastructure — hosting for the application, database, and uploads.

AI inference providers — run the large-language-model inference powering the Calypso voices and Decode. They process conversation content to generate responses and are contractually prohibited from using it to train their own models or retaining it beyond what the inference service requires, except where law requires otherwise.

Payment processing — collects and processes your billing information when you subscribe; we do not store full card numbers on our systems.

Email delivery — transactional email only; processes your email address only.

Error and performance monitoring — anonymized error reports; no conversation content.

Analytics — aggregated usage data; no conversation content; configured to respect the Global Privacy Control signal.

This list of provider categories is maintained on this page and updated when providers change. You can request more detail about our current providers at privacy@trycalypso.ai.

7.2 Business transfers. If Calypso is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will notify you (by email and in-product) before your information becomes subject to a different privacy policy.

7.3 Legal requirements. We may disclose personal information when we believe in good faith that disclosure is necessary to comply with a subpoena, court order, or lawful government request; enforce our Terms of Service; detect, prevent, or address fraud, security, or technical issues; or protect the rights, property, or safety of Calypso, our users, or the public. We require legal process for non-emergency requests, and we notify users of legal requests for their data unless legally prohibited.

7.4 With your consent. We may share information for purposes not covered here with your explicit consent.

7.5 Aggregated and de-identified data. We may share aggregated or de-identified data that cannot reasonably be used to identify you. We commit to maintaining such data in de-identified form and not attempting to re-identify it, and we require the same of recipients.

8. How long we keep your information

Account information — retained while your account is active.

Conversation history — retained while your account is active. Incognito-mode conversations are not retained beyond the active session.

Decoded files (screenshots, exports) — retained while the associated decode report is on your account, unless you delete the decode.

Backup copies — system backups retain information for up to 90 days after deletion from active systems.

Billing records — retained for seven years after the last transaction, as required by financial regulations.

Abuse and safety records — retained for up to two years after the last related event.

Crisis-referral statistics — aggregate counts only (no conversation content, no user identities), retained as required for statutory safety reporting.

Marketing list membership — retained while subscribed; removed within 30 days of unsubscribing.

When we no longer need information for a permitted purpose, we delete or anonymize it. We do not retain personal information indefinitely.

9. Your rights — and how to exercise them

Wherever you live, we honour the following core rights:

Access / right to know — request a copy of, and information about, the personal information we hold about you.

Correction — ask us to correct inaccurate or incomplete information.

Deletion — ask us to delete your account and associated personal information (some records are retained as described in section 8, e.g. billing records required by tax law).

Portability — receive a machine-readable copy of your conversation history and account data.

Objection / opt-out — object to processing based on legitimate interests. We do not sell personal data or process it for targeted advertising, so there is nothing to opt out of on those fronts; where you use an opt-out preference signal such as Global Privacy Control, we honour it as a valid opt-out of sale/sharing in the states that require it.

Restriction — ask us to limit processing in certain circumstances.

Withdraw consent — for any consent-based processing (such as the AI-training opt-in), at any time, as easily as consent was given.

No discrimination / no retaliation — you will not lose access, pay more, or receive degraded service for exercising any right.

Appeal — if we decline a request, you may appeal by replying to our decision or emailing privacy@trycalypso.ai with the subject "Appeal." We respond to appeals within the timeline your state's law requires (typically 45–60 days). If your appeal is denied, you may contact your state Attorney General.

How to exercise your rights: inside the app, under Account settings → Data → Export, Delete, or Manage consent; or by email at privacy@trycalypso.ai.

We will verify your identity before fulfilling a request (typically by confirmation link to the email on file). An authorized agent may submit requests on your behalf with written authorization we may verify. We respond within 30 days in most cases (45 days under most US state laws, extendable once; 45 days extendable to 90 under CCPA). We do not charge for the first request in a 12-month period; for excessive or manifestly unfounded requests we may charge a reasonable fee or decline, as permitted by law.

10. US state-specific rights and disclosures

10.1 California (CCPA/CPRA). California residents have the rights to know, delete, correct, opt out of sale/sharing, limit use of sensitive personal information, and non-discrimination. We do not sell or share personal information and have not done so in the preceding 12 months; we do not use or disclose sensitive personal information for purposes other than providing the Service, so there is nothing to opt out of or limit — a "Your Privacy Choices" link is provided in the footer for completeness, and we honour Global Privacy Control.

Categories of personal information collected (CPRA categories): identifiers (email, account ID); customer records (name, billing data); internet or other electronic network activity (usage data, IP address); commercial information (subscription history); sensitive personal information (conversation content that may reveal health-related information; account log-in credentials); inferences (crisis-detection signals used only for in-product safety). Sources, purposes, and recipients are described in sections 4, 5, and 7. Retention criteria are in section 8.

Shine the Light (Civ. Code §1798.83): we do not disclose personal information to third parties for their direct marketing purposes.

California SB 243 (companion chatbots): the disclosures and crisis protocol described in section 3 are provided pursuant to Business & Professions Code §§22601–22605. Our published crisis protocol is at trycalypso.ai/safety.

10.2 Other US states. If you are a resident of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Florida, Montana, Iowa, Delaware, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, or Rhode Island — each of which has a comprehensive privacy law in effect as of August 2026 — you have rights substantially similar to those in section 9, including access, correction, deletion, portability, opt-out of sale/targeted advertising/profiling (we do none of these), and appeal. Residents of Oklahoma and Louisiana (laws effective January 1, 2027), Alabama (May 1, 2027), and Vermont (January 1, 2028) will have equivalent rights when those laws take effect.

Sensitive data. Every state law listed treats health-related information — in several states including anything used to infer mental health status — as sensitive data. Our handling is described in section 6: processing only as necessary to provide the Service, opt-in consent for anything more, and no sale ever.

Universal opt-out signals. We honour the Global Privacy Control signal as an opt-out of sale/sharing/targeted advertising in every state that requires it (including California, Colorado, Connecticut, Texas, Montana, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Delaware, and Oregon).

Maryland. We comply with MODPA's data-minimization standard: we collect personal data only as reasonably necessary and proportionate to provide the Service you request, we process sensitive data only where strictly necessary, and we do not sell sensitive data (we sell no personal data at all).

Washington and Nevada. See the standalone Consumer Health Data Privacy Policy at trycalypso.ai/consumer-health-data-privacy.

New York. The AI-companion disclosures and crisis-referral protocol described in section 3 are provided pursuant to General Business Law Article 47.

Texas. Calypso does not accept users under 18 (section 2); the Service is not directed to minors.

10.3 European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR). You have the rights in section 9. Legal bases are in the table in section 5. Data Controller: the entity in section 1; contact details in section 14. Data Protection Officer: we have not appointed a DPO; you can reach our privacy team at privacy@trycalypso.ai. Complaints: your local supervisory authority (edpb.europa.eu; ico.org.uk). International transfers: where personal information leaves the EEA/UK/Switzerland for a country without an adequacy decision, we rely on the EU Standard Contractual Clauses (with UK Addendum / Swiss equivalent), supplemented by technical and organizational measures.

11. Canada (PIPEDA and Quebec Law 25)

If you are in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) governs our handling of your personal information; if you are in Quebec, the Act respecting the protection of personal information in the private sector (as modernized by Law 25) also applies.

Accountability / Privacy Officer. Our person in charge of the protection of personal information is our Privacy Officer, reachable at privacy@trycalypso.ai.

Express consent for sensitive information. Conversation content that reveals emotional or intimate information is sensitive; we obtain express consent at signup for the processing needed to provide the Service, and separate express consent for anything beyond it (such as the AI-training opt-in, which is off by default).

Cross-border transfers. Personal information about Canadian users is transferred to, stored, and processed in the United States (and the countries where our service providers operate). While there, it is subject to the laws of those jurisdictions and may be accessible to their courts, law enforcement, and national security authorities. We use contractual and technical safeguards to ensure a comparable level of protection. For Quebec residents, we conduct the privacy impact assessment Law 25 requires before communicating personal information outside Quebec.

Profiling and technology disclosures (Quebec). The Service personalizes conversations using your conversation history and profile, and uses automated detection of crisis-related language to show the in-product Crisis Banner. These functions operate as described in sections 3 and 5; the AI-training use is off by default and activated only by you.

Portability (Quebec). You may request your conversation history and account data in a structured, commonly used technological format (section 9).

Breach notification. We report breaches of security safeguards presenting a real risk of significant harm to the Office of the Privacy Commissioner of Canada and affected individuals, maintain the 24-month breach register PIPEDA requires, and notify the Commission d'accès à l'information for Quebec incidents presenting a risk of serious injury.

Complaints. Office of the Privacy Commissioner of Canada (priv.gc.ca); in Quebec, the Commission d'accès à l'information (cai.gouv.qc.ca).

Minors. The Service is 18+ everywhere, including Canada (section 2).

12. Cookies and similar technologies

Calypso uses cookies and similar technologies (local storage, session storage) for three purposes:

Strictly necessary — keeping you signed in, remembering your privacy choices, protecting against fraud.

Functional — remembering preferences such as selected voice and theme; can be disabled in account settings.

Analytics — anonymous, aggregated usage analytics, honouring the Global Privacy Control signal.

We do not use cookies for advertising, and we do not use cookies to track you across third-party websites.

13. Security

Encryption in transit (TLS 1.2+) and encryption at rest for conversation content, account data, and uploads.

Access controls — least-privilege staff access; most roles have no access to conversation content; access events logged and reviewed.

Authentication — sign-in uses a one-time code sent to your email address, and passwords, where set, are stored as salted hashes (bcrypt).

Vulnerability management — automated scans, prompt patching, responsible-disclosure programme (security@trycalypso.ai).

Backups and disaster recovery — encrypted backups, tested restores, regional redundancy.

No system is perfectly secure. If a breach creates meaningful risk to you, we will notify you and the relevant authorities as required by applicable law (72 hours under GDPR; state-specific timelines, generally 30–60 days, in the US; PIPEDA's "as soon as feasible" standard in Canada). Because conversation content may be treated as health-related information under several state breach-notification laws, our incident-response plan classifies it accordingly.

14. Contact us

General privacy questions and requests: privacy@trycalypso.ai.

Security: security@trycalypso.ai.

Safety and abuse: safety@trycalypso.ai.

California requests: privacy@trycalypso.ai (subject "California Request").

Privacy Officer (Canada/Quebec): privacy@trycalypso.ai (subject "Privacy Officer").

We aim to respond to every privacy request within 30 days (extendable as permitted by applicable law).

15. Changes to this Policy

When we make a material change, we will update the effective date, notify you by email and in-product notice at least 30 days before the change takes effect, and, where required by law, obtain renewed consent. Past versions are archived and available on request at privacy@trycalypso.ai.

16. The plain-language summary

Calypso is for adults — you must be 18 or older to use it.

Calypso is an AI, not a human, and not therapy or a crisis service. If you're in crisis, our Safety page connects you to real people (988, Crisis Text Line) — and the product will point you there too.

We collect what we need to run Calypso for you — your account, your conversations, your usage, your billing info — and as little else as we can.

Your conversations are private to your account, and we treat them as sensitive data everywhere, because what you share here is personal. Incognito mode doesn't save them at all.

We never sell your personal information and never use your conversations for advertising. No ad pixels, no trackers.

We don't use your conversations to train our AI unless you explicitly opt in. The opt-in is off by default.

We share information only with the small set of providers needed to run the Service, under strict contracts, or when the law requires.

You can access, correct, export, or delete your data any time, from settings or by emailing privacy@trycalypso.ai. We honour Global Privacy Control, and we'll never penalize you for exercising your rights.

Questions about your data?

Email privacy@trycalypso.ai. A real person reads it.

Read the plain-language summary