Privacy Policy — Myra
Effective: 13 September 2026
Contact: boonyboonapp@gmail.com
Myra is an AI companion app. This policy describes what we collect, why, and what you can do about it. It describes the app as built — every retention period and deletion behaviour below is enforced in code, not aspiration.
1. Who we are
Myra is operated by boonwiz. Contact: boonyboonapp@gmail.com
2. Age requirement
Myra is for adults (18+). We ask for your date of birth once, at signup, and the server refuses to create an account for anyone under 18. We keep the declared date of birth so a blocked account cannot simply re-declare a different age. You cannot change it yourself afterwards.
3. What we collect
Account
• A user identifier. You may use the app without giving us an email address — "Start chatting" creates an anonymous account.
• Your display name (whatever you choose to be called).
• Your date of birth (see above).
• Your device timezone and device language setting. We use them to avoid messaging you at night, to set your daily message allowance for your region, and to choose the language a companion first greets you in.
• The app version you are running, so we only send features your version can display.
Conversations
• The messages you send and the replies you receive.
• Memories: short factual notes the app extracts from your conversations so a companion can remember things about you. You can see every one of these and delete any of them at any time.
• A short style note per companion describing how you like to talk (for example, brief or detailed, playful or serious). It contains no facts about you and never covers health, politics, religion, sexuality or finances. It is deleted with the relationship and with your account.
Purchases
• Subscription and in-app purchase records, processed by Google Play and RevenueCat. We never see or store your card details.
• A ledger of in-app currency granted and spent, including diamonds and messages granted for watching a rewarded ad.
Technical
• Token counts and latency for the AI service, used to monitor cost.
• A push notification token, if you enable notifications.
• App usage events (for example, which screens were opened and whether an ad loaded), collected through Google Firebase Analytics to understand how the app is used. These do not include your messages.
Voice input uses your phone's built-in speech recogniser. Myra does not request microphone access and never receives audio.
We do not collect your contacts, location or photos.
4. Advertising
Myra is free to use and is paid for by advertising. If you do not have a subscription or trial, the app shows ads: banners, native ads in the chat and companion list, full-screen ads between screens and after a number of messages, ads when you return to the app, and rewarded video ads that you choose to watch in exchange for messages or diamonds. Subscribers and trial users do not see ads, except rewarded ads they choose to watch.
Ads are served by Google AdMob, which may also request ads from Unity Ads. To serve and measure ads, these companies receive standard ad-serving data from your device, which can include your device's advertising ID, IP address, device model, operating system, app version and general location derived from your IP address. Google's use of this data is described at https://policies.google.com/technologies/partner-sites.
What ads never receive: your messages, your memories, your companion conversations, your name, your date of birth or your email address.
Consent (UK, EEA and Switzerland). If you are in the UK, the European Economic Area or Switzerland, the app asks for your consent before personalised ads are shown, using Google's certified consent message. If you do not consent, you may still see non-personalised or limited ads. To withdraw consent, turn off personalised ads in your phone's ad settings (below), or email us.
Everywhere. You can opt out of personalised ads on Android at Settings → Google → Ads (or Settings → Privacy → Ads, depending on your phone), and you can reset or delete your advertising ID there.
5. What we do NOT do
• We do not sell your data. To anyone, ever.
• We do not use your conversations to train AI models.
• We do not share your conversations with advertisers.
• We do not condition what a companion says on what you have paid. The conversation system is technically prevented from seeing your balance, subscription tier, or spending — this is enforced by automated tests, not policy.
• We do not use notifications to pressure you into spending. Frequency is based on how long you have been using the app, never on whether you pay.
6. Who we share it with
Only the processors needed to run the service:
• Supabase — database and authentication — receives account data, messages and memories.
• DeepSeek — generates companion replies — receives recent conversation context.
• Google Play and RevenueCat — purchases — receive purchase records; we never see card details.
• Google Firebase — push notifications and app usage analytics — receives the notification token, notification text and app usage events.
• Google AdMob and Unity Ads — advertising — receive standard ad-serving data (see section 4).
• Render — hosting — handles traffic to our servers.
7. How long we keep it
• While your account is active: your conversations and memories are kept so a companion can remember you.
• When you delete your account: it becomes unusable immediately. Your data is permanently erased 30 days later by an automated job.
• After erasure, financial records are retained with your identity removed — they are accounting records and contain no personal data once anonymised.
• Crisis-support records: we record only that support resources were shown and when. We never store the message text in those records.
• Advertising data held by Google and Unity is kept under their own policies, not ours.
8. Your rights
• See your memories. Every memory a companion holds is visible in the app.
• Delete a memory. One tap. It is excluded from future conversations and cannot be re-learned from the same message.
• Delete your account. Settings → Delete account. No retention offer, no survey, no obstacle.
• Withdraw ad consent. Turn off personalised ads or delete your advertising ID in your phone's ad settings, or email us.
• Get a copy of your data, or ask us to correct it: boonyboonapp@gmail.com
If you are in the UK or EU you have the usual GDPR rights (access, rectification, erasure, restriction, portability, objection) and the right to complain to your data protection authority. Our legal basis for running the service is the contract you enter when you use it; for personalised advertising it is your consent; for app usage analytics and fraud prevention it is our legitimate interest in running and improving the app.
9. AI disclosure
Companions are AI characters, not real people. The app says so before you create an account, shows a persistent "AI" indicator in every conversation, and reminds you periodically during long sessions. If you sincerely ask a companion whether it is human, it will tell you the truth.
10. Crisis situations
If a message suggests you may be at risk of suicide or self-harm, the app responds directly — not the AI character — with crisis support resources for your region. This is never charged, never counted against any limit, and cannot be switched off. Full protocol: https://sites.google.com/view/myra-privacy-policy/home/crisis-resource
Myra is not a counselling service, a crisis service, or a substitute for professional care.
11. Security
Data is encrypted in transit. Access to production data is limited to the operator. We are a small operation and do not claim certifications we do not hold.
12. Changes
If we change this policy materially we will say so in the app before the change takes effect.
13. Contact
boonyboonapp@gmail.com