Talyni information
Privacy policy
This policy explains what data the Talyni website processes, why, which providers are involved and what you can control.
Last updated: 7 September 2026
1. Data controller
D'ABOVILLE VENTURES, a French SAS registered with the Nanterre Trade and Companies Register under number 109 162 016, 92400 Courbevoie, France. The publisher’s identification details are provided in the legal notice. For any question or request: support@talyni.com.
2. Data processed
- email address and account identifier, display name, language and secure session; references to a previous account only if you request that it be linked;
- messages, selected character, conversation summary and memories you can erase;
- media requests, generated files, delivery status and technical cost;
- confirmed offers, orders, access rights and credits, transaction identifiers, subscriptions, cancellations, refunds and support requests;
- pseudonymous general operational metrics, incidents, reports and security logs;
- for access requiring an age check: result, method, required threshold, verification dates and references; country or region needed to apply the access rule;
3. Purposes and legal bases
If you choose Google sign-in, Google sends Supabase Auth your Google identifier, email address and the basic profile information provided, including your name and profile picture. This identity is used to create or retrieve your Talyni account; you can confirm your first name in Talyni. This sign-in does not grant access to your Gmail emails or Google Drive files. Email sign-in remains available.
- providing chat, memory, media, purchases and support: performance of the contract;
- preventing fraud, securing the service and handling reports: legitimate interests and legal obligations;
- keeping accounting and payment records: legal obligation;
- reviewing conversation excerpts to improve quality: only with your optional consent or when a report needs to be handled.
4. Service providers
Depending on the feature used, strictly necessary data may be processed by Supabase, Vercel, OpenAI, Venice.ai, PostHog EU, Resend for sending emails, OVHcloud and Google Gmail for support email, and Didit when age verification is used. Events sent to PostHog are limited to general metrics, without messages, prompts, characters or moderation categories. A tool-specific pseudonym replaces the account identifier; events related to adult contexts are excluded from these exports. AI providers receive the context necessary for the requested reply or generation.
Didit may request a selfie and, if necessary, an identity document. These are provided to Didit. Talyni’s server receives the relevant results, including age or its estimate during the check, then retains a decision and technical references. Talyni does not retain your selfie, identity document or date of birth. No conversation or generated image is sent to Didit for this check.
Before continuing with verification, read the Didit verification privacy notice and its verification terms. Its notice describes security uses and secondary uses of anonymized or pseudonymized data, as well as options to object.
5. International transfers
Some providers are established outside the European Economic Area. Talyni selects appropriate contractual mechanisms and privacy settings where required by applicable regulations. Provider-specific safeguards are described in their documentation and privacy policies.
6. Retention
Conversations and memories are retained to provide continuity while your account is active. Forgetting a memory removes it from active memory; it does not automatically delete the messages it came from. Some actions can be undone from your space. You can request more complete erasure through support. Media stays private and is retained for 90 days by default, with an expiry date shown in delivery data, unless deleted earlier or retained as necessary for a dispute. Withdrawal declarations, timestamps, the declared name and acknowledgement email address are retained with contractual evidence, separately from conversations, to handle the request and document its follow-up. Retention may continue after account deletion for applicable obligations and dispute handling, with limited access. Invoices and accounting records are retained for ten years from the close of the relevant financial year. Other contractual evidence follows the retention periods applicable to its nature. Closed ordinary support requests and declarations not linked to an order are reviewed after twelve months to remove data that is no longer needed. Technical logs are reviewed and purged after ninety days, except in the event of an incident or documented justification. Only evidence necessary for a dispute may be archived separately, with limited access and review of its retention period.
The Didit workflow used by Talyni is configured to retain data at Didit for one month and delete biometric templates with the session. Talyni access rights have their own duration, shown in your space, and may expire earlier. Provider backups and logs follow the terms described in its notice.
7. Your choices and rights
Use “Memory” in your space to view, edit or forget memories, and “Preferences” to manage memory, consented follow-ups and optional quality review. You may request access, rectification, erasure, restriction, objection or portability of your data by contacting support. You may also complain to the CNIL if you believe your rights have not been respected.
You can submit a deletion request through “Help and safety” or by email. After verification of the request, access is closed and renewal cancellation is processed. Erasure covers usage data, private files and sign-in identity; required provider-side steps are tracked separately. Financial references subject to retention requirements are kept with limited access. A contact address may be retained while the request is handled, then erased when it is closed. Linking accounts does not automatically delete the other account.
A response to your rights request is provided within one month. If an extension permitted by applicable regulations is necessary, its reasons will be communicated within that period. You can lodge a complaint with the CNIL.
8. Security and privacy
A cookie stores the interface language (English) for up to one year from its last update. It keeps that language during your visits and contains no conversations or memories.
Session cookies secure sign-in. Follow-ups require explicit consent and respect your chosen frequency, time zone, quiet hours and pauses. Email and push follow-up channels are separate and disabled. Linking accounts does not merge their data and can be revoked.
Generated media is stored privately and delivered through temporary links. Technical keys stay on the server. Human access to conversations is limited to reports and users who have optionally consented to quality review.