Noctelle Privacy Policy
Version 2026-06-27
Effective date: June 27, 2026 Last updated: June 27, 2026
This Privacy Policy explains how Odyssey Digital Technologies LLC, d/b/a Noctelle ("Noctelle," "we," "us," or "the Company"), a California limited liability company, collects, uses, shares, and protects information in connection with the Noctelle website (noctelle.xyz) and application (collectively, the "Service").
Noctelle is a subscription-based, adults-only (18+) AI-companion service. Users chat with AI personas, and the Service generates AI text, AI images, and AI voice. All companion content is wholly AI-generated and does not depict any real, identifiable human being; there are no real performers or models.
This Policy is a sensitive-data context. Because of the nature of the Service, the conversational and behavioral data we process — and inferences we may derive from it — can reveal or suggest information that is treated as sensitive personal information under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), and as special category data under the EU/UK General Data Protection Regulation ("GDPR"), including information that may relate to or imply a person's sex life or sexual orientation. We handle this information accordingly, as described in this Policy.
1. Scope and who we are
This Policy applies to personal information we process about visitors, account holders, and subscribers of the Service. It does not apply to third-party websites, products, or services that we do not control, even if they link to or from the Service.
For privacy matters, the data controller (GDPR) and business (CCPA/CPRA) is Odyssey Digital Technologies LLC, d/b/a Noctelle, a California limited liability company. Our contact details are in Section 17.
2. Eligibility — adults only (18+); we do not knowingly collect data from minors
The Service is strictly for adults aged 18 or older (or the age of majority in your jurisdiction, if higher).
Age and geographic gating. Access is controlled by (a) a self-attestation age gate that you must pass to enter, and (b) geographic blocking. Noctelle blocks the entire site — no signup and no use — for visitors located in (i) any U.S. state that mandates age verification for sites offering sexual material harmful to minors, and (ii) the European Union and the United Kingdom. Where the site is blocked, no account can be created and the Service is not offered. Noctelle does not currently use a third-party age-verification vendor; our age controls are the geoblock and self-attestation age gate described here.
We do not knowingly collect, use, or store personal information from anyone under 18. The Service is not directed to minors, and minors are prohibited from using it. If we learn that we have collected information from a person under 18, we will delete it promptly, subject only to information we are legally required to preserve (for example, evidence that must be preserved and reported in connection with suspected child sexual abuse material — see Sections 6 and 8). If you believe a minor has provided us information, contact us immediately at the address in Section 17.
Suspected sexualization of minors (CSAM) is strictly prohibited and hard-blocked by our content-policy system; suspected CSAM is preserved and reported to the National Center for Missing & Exploited Children (NCMEC) as described in Section 6.
3. Information we collect
We collect the following categories of information.
3.1 Account and identity information
Information you provide to create and manage an account, such as your email address, username or display name, password (stored in hashed form), and account settings and preferences.
3.2 Age-gate and geo-eligibility records
Records sufficient to evidence that access controls were applied — for example, that you passed the self-attestation age gate and that your access was permitted from a non-blocked location. We retain a minimal pass/fail eligibility token/record rather than government-ID images; Noctelle does not operate a third-party identity-verification step. (Noctelle geoblocks U.S. states that mandate government-ID age verification for adult sites, as well as the EU and UK.)
3.3 Conversations and derived memory
The content of your chats with AI personas (messages you send and AI-generated responses), and "memory" derived from those conversations — summaries, preferences, and persona/relationship state we generate so the companion can maintain context across sessions. This content and the inferences derived from it may constitute sensitive personal information / special category data as described above.
Chat history is retained on a rolling basis: for each companion, only the 5 most-recent conversations are kept. When you start a new conversation beyond that limit, the oldest conversation and its messages are permanently deleted. Derived memory, generated media, and the compliance/audit trail are preserved separately and are not deleted by this rolling process (see Section 7).
3.4 Uploaded and AI-generated media
Media you upload (for example, images you provide) and media the Service generates for you (AI images and AI voice/audio). Every media asset is hashed (sha256) at intake, and the digest is stored with the asset for integrity, deduplication, abuse-prevention, and takedown-matching purposes (see Sections 6 and 7).
3.5 Voice and call data
If you use realtime voice calls, the Service captures your microphone audio during the call and streams it transiently to our voice sub-processors to run the call: Deepgram for speech-to-text and Hume (and/or Cartesia) for text-to-speech. See Section 8.1 for how this data is handled, including our affirmative statement that we do not create or store a voiceprint or biometric template.
3.6 Usage and analytics information
Information about how you interact with the Service, such as features used, messages and media generated, quota and subscription usage, session activity, and event logs we use for reliability, security, abuse-prevention, and product analytics.
3.7 Device, connection, and IP information
Technical information automatically collected when you use the Service, such as IP address, browser and device type, operating system, language, and similar diagnostic and log data, including a tamper-evident policy/audit event trail for compliance-relevant actions.
3.8 Payment information — handled by the payment processor
Paid subscriptions are billed by a third-party payment processor acting as the merchant/biller of record: a third-party payment processor. Noctelle does not collect or store full payment card numbers. Our processor handles card data; we receive limited billing-related information such as subscription tier, transaction status, billing reference, and renewal/cancellation events.
4. How we use information
We use personal information to:
- Provide and operate the Service — create and authenticate your account, run the age gate and geographic controls, generate AI text/image/voice companion content, and maintain conversational memory and persona state;
- Process subscriptions — manage paid tiers, recurring monthly billing, renewals, and cancellations (via our payment processor);
- Maintain safety, security, and compliance — enforce our content policy and Terms, detect and prevent fraud and abuse, operate the abuse-reporting and takedown pipeline, hash and match media, preserve and report suspected CSAM to NCMEC, and respond to legal obligations;
- Verify age and eligibility — confirm you attest to being 18+ and apply geographic restrictions;
- Analyze and maintain the Service — measure reliability, diagnose problems, and understand usage in aggregate;
- Communicate with you — send service, security, billing, and support messages, and (where permitted) product updates;
- Comply with law — meet record-keeping, tax, and regulatory obligations and respond to lawful requests.
No AI model training on your content. Noctelle does not use members' conversations, voice, or images to train or fine-tune AI models. Your content is used only to operate and secure the Service for you, and is shared only with the named sub-processors listed in Section 6.1 that perform those functions on our behalf.
We do not use preserved CSAM-related material for any purpose other than preservation and reporting to NCMEC/law enforcement; it is never used for model training, testing, or any other purpose.
5. Legal bases for processing (GDPR)
Noctelle is not offered in the EU or UK (those regions are geoblocked; see Sections 2, 9.1, and 17). This section is provided as a courtesy and for the limited circumstances in which GDPR-style legal bases may otherwise be relevant. Where applicable, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing the Service you request; processing your subscription | Performance of a contract (Art. 6(1)(b)) |
| Security, fraud/abuse prevention, and operating the Service | Legitimate interests (Art. 6(1)(f)), balanced against your rights |
| Age/eligibility controls, CSAM preservation/reporting, record-keeping, responding to lawful requests | Legal obligation (Art. 6(1)(c)) and, where applicable, substantial public interest |
| Marketing communications and any non-essential cookies/analytics | Consent (Art. 6(1)(a)), withdrawable at any time |
| Processing of special category data (e.g., data implying sex life/sexual orientation) inherent in companion conversations | Your explicit consent (Art. 9(2)(a)); and, for CSAM reporting, substantial public interest / legal claims (Art. 9(2)(g)/(f)) |
6. How we share information
We do not sell your personal information (see Section 9). We share information only as described below.
6.1 Service providers and sub-processors
We use vetted vendors to operate the Service. They process information only on our instructions and under contract, are not permitted to use it for their own purposes, and are not used to train or fine-tune their models on your content. Our current sub-processors are:
| Sub-processor | Data category | Role |
|---|---|---|
| OpenRouter | Chat messages and prompts (text) | LLM inference for AI text/companion responses |
| Hume | Conversation text → synthesized speech | Voice text-to-speech (TTS) for calls |
| Cartesia | Conversation text → synthesized speech | Voice text-to-speech (TTS) for calls |
| Deepgram | Live microphone/call audio (transient) | Speech-to-text (STT) for calls |
| RunPod | Image-generation prompts and outputs | AI image generation |
| Resend | Email address, message content | Transactional/service email delivery |
| Hetzner (cloud hosting) and Cloudflare (CDN, edge, and DDoS protection) | Infrastructure, storage, request/log data | Hosting, storage, and content delivery |
| Cloudflare (visitor geolocation for regional access control) | IP/location signal, pass/fail token | Geographic blocking and age-gate enforcement |
We do not authorize any of these sub-processors to use your content for their own purposes, including model training.
6.2 Payment processor
Our third-party payment processor — a third-party payment processor — processes your payment as merchant/biller of record. Your card details are handled under the processor's own privacy policy; we do not store full card numbers.
6.3 Law enforcement, legal process, and NCMEC
We may disclose information when we believe in good faith it is necessary to comply with law, valid legal process, or a lawful government request; to enforce our Terms; or to protect the rights, safety, and property of users, the public, or the Company. In particular:
- Suspected CSAM is removed from serving, preserved in a restricted-access legal hold (the asset, hashes, relevant uploader account data, and audit events), and reported to NCMEC via the CyberTipline as required of providers under 18 U.S.C. § 2258A, with the data law enforcement needs. As required by § 2258A(h), reported material is preserved for at least 90 days (and longer where law or legal process requires). This material is never redistributed and is used only for preservation and reporting.
- Non-consensual intimate imagery (NCII), including AI "digital forgeries" of identifiable real people, is handled under the notice-and-removal process described in Section 6.4 and may be reported as required.
6.4 Non-consensual intimate imagery (NCII) — notice and removal
Consistent with the federal TAKE IT DOWN Act, Noctelle maintains a notice-and-removal process for non-consensual intimate imagery, including AI-generated "digital forgeries" depicting identifiable real people.
Removal commitment. Upon receipt of a valid request, Noctelle will remove the reported NCII — and make reasonable efforts to remove identical copies — within 48 hours. (Suspected CSAM is removed immediately on detection, separately from this process.)
How to report. A clear and conspicuous reporting channel is available at our email and in-app abuse/NCII reporting channels and via the contact in Section 17. A valid request should include:
- a physical or electronic signature of the depicted individual (or an authorized representative);
- identification of, and information reasonably sufficient to locate, the NCII at issue (e.g., URL or in-Service location);
- a good-faith statement that the intimate imagery was published without the depicted individual's consent; and
- the requester's contact information (name, address, email or telephone) so we can respond.
Re-upload prevention. When content is removed, we retain its sha256 hash (a one-way digest) and use exact-match (sha256) hash-blocking to prevent re-upload of identical files. Perceptual/near-duplicate matching (for example, PhotoDNA or StopNCII-style hashing) is on our roadmap and is not currently in production.
6.5 Corporate transactions
If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to this Policy or a successor policy with equivalent protections.
7. Data retention
We retain personal information for as long as needed to provide the Service and for the purposes described in this Policy, then delete or de-identify it, except where a longer period is required or permitted by law. The periods below are proposed operational defaults that the operator may adjust to align with applicable law and business needs.
- Account and subscription/billing data: retained while your account is active, then for a proposed wind-down period of 24 months afterward for legal, tax, accounting, and dispute-resolution purposes.
- Conversations and derived memory: Conversations are retained on a rolling basis — only the 5 most-recent conversations per companion are kept. Starting a new conversation beyond that limit permanently deletes the oldest conversation and its messages. Derived memory (summaries/preferences/persona state) persists while your account is active and is removed on account deletion as described in Section 11, subject to legal holds.
- Uploaded and AI-generated media: retained while associated with your account; on deletion, removed within a proposed purge window of 30 days, with backups overwritten on a proposed rolling cycle of 35 days, subject to legal holds.
- Age-gate and geo-eligibility records: a minimal pass/fail eligibility token/record retained only as needed to evidence that access controls were applied (proposed 24 months); no government-ID images are retained.
- CSAM/NCII legal-hold material: preserved as required by law. Material reported to NCMEC is preserved for at least 90 days under 18 U.S.C. § 2258A(h), and longer where law or legal process requires; it is not subject to ordinary deletion routines.
- Usage, device/IP, and audit logs: the policy/audit event trail is append-only and is the system of record for compliance and law-enforcement response; it is retained for a proposed 7 years. Other operational logs are retained for a proposed 90 days.
Hash retained after deletion (legal-hold / takedown matching). Even after content is deleted, we may retain the content's sha256 hash (a one-way digest, not the content itself) so that prohibited material that has been removed can be matched and blocked on re-upload, and to satisfy legal-hold and takedown obligations. The retained hash does not reconstruct the original content. Only exact-match (sha256) hashing is used; perceptual hashing is not currently in use. Material under a CSAM/NCII legal hold is preserved as required by law and is not subject to ordinary deletion routines.
8. Security
We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, hashed storage of passwords, hashing (sha256) of media at intake, access controls and role-gating for administrative tooling, an append-only audit trail of compliance-relevant actions, and restricted-access handling of preserved legal-hold material.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential.
8.1 Voice and biometric data
If you use realtime voice calls, the Service captures your microphone audio for the duration of the call and streams it transiently to our voice sub-processors solely to run the call:
- Deepgram converts your live call audio to text (speech-to-text); and
- Hume and/or Cartesia convert the companion's text into synthesized speech (text-to-speech).
No voiceprint or biometric template. Noctelle does not create, derive, or store a voiceprint, faceprint, or other biometric identifier or biometric-information template from your voice, and does not use your voice for biometric identification. We do not retain raw call audio beyond what is necessary to process the live turn; raw audio is processed transiently and is not stored as a persistent recording by Noctelle. The transcribed text of the call may be processed for the conversation, for safety screening, and to maintain conversational memory, consistent with this Policy.
This disclosure is provided with biometric-privacy laws (such as the Illinois Biometric Information Privacy Act, "BIPA") in mind. Because we do not collect, capture, or store biometric identifiers or biometric information as those terms are defined under such laws, no biometric retention schedule applies; the underlying call audio is handled transiently as described above.
9. Your privacy rights
9.1 EU/UK users — service not offered
Noctelle is not available in the European Union or the United Kingdom; those regions are geoblocked and the Service is not offered there. Accordingly, Noctelle does not appoint a representative under GDPR Article 27. This Policy nonetheless describes GDPR-style protections as a courtesy. To the extent any mandatory local data-protection or consumer rights apply to you despite the geoblock, we will honor those rights where they apply by law, including any right to lodge a complaint with your local supervisory authority.
9.2 California rights (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know / Access — request the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties to whom we disclose it;
- Delete — request deletion of personal information we collected from you, subject to legal exceptions;
- Correct — request correction of inaccurate personal information;
- Opt out of "sale" or "sharing" of personal information (see below);
- Limit the use and disclosure of sensitive personal information — direct us to limit our use of sensitive personal information to what is necessary to provide the Service.
You will not be discriminated against for exercising these rights.
Sensitive personal information. Given the nature of the Service, some information we process (and inferences we may derive) constitutes sensitive personal information under the CCPA/CPRA, including information that may relate to or imply sex life or sexual orientation. We use sensitive personal information only as necessary to provide the Service you request and for permitted purposes (such as security, abuse-prevention, and legal compliance), and not to infer characteristics about you for advertising. We do not use it for purposes that would trigger a mandatory "Limit the Use of My Sensitive Personal Information" right beyond those permitted uses.
We do not sell your personal information. We do not sell personal information for money, and we do not "share" personal information for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. Because we do not sell or share, there is nothing to opt out of in that respect; we nonetheless honor opt-out preference signals (such as Global Privacy Control) where applicable.
10. How to exercise your rights
You can exercise many rights directly in the Service:
- In-app data export — request a copy of your data;
- In-app account deletion — delete your account and associated content (subject to legal holds and the sha256/legal-hold retention described in Section 7).
You may also contact us at the email address in Section 17. We will verify your identity before acting on a request and will respond within the timeframes required by applicable law. Authorized agents may submit CCPA/CPRA requests on your behalf with proper authorization.
11. Account deletion and what happens to your data
When you delete your account, we delete or archive your account data and associated conversations, derived memory, and media, except where we must retain information for legal, security, or compliance reasons. As described in Section 7, we may retain content hashes (sha256) and any material under a legal hold (including preserved CSAM/NCII evidence) after deletion. Note that conversation history is also subject to ongoing rolling deletion during normal use (only the 5 most-recent conversations per companion are kept; see Sections 3.3 and 7).
12. Cookies and tracking technologies
We use cookies and similar technologies that are strictly necessary to operate the Service (for example, authentication and session management). We may use limited analytics to understand and improve the Service. We do not use cookies for cross-context behavioral advertising. Where required, we will obtain consent for non-essential cookies and provide controls to manage them; you can also control cookies through your browser settings.
13. International data transfers
We are based in the United States, and we and our service providers may process your information in the United States and other countries. Because the Service is not offered in the EU or UK (see Section 9.1), Noctelle does not direct the Service to those regions; where any cross-border transfer safeguards nonetheless apply to information we process, we rely on appropriate safeguards, such as the Standard Contractual Clauses (SCCs), where applicable.
14. Data-breach notification
We maintain procedures to detect, investigate, and respond to security incidents. If a breach affects your personal information, we will notify affected individuals and applicable regulators as and when required by law (for example, within the timeframes set by applicable U.S. state breach-notification laws).
15. Children's privacy
See Section 2. The Service is for adults only; we do not knowingly collect personal information from anyone under 18, and we report suspected child sexual abuse material to NCMEC as described in Section 6.
16. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date and version, and, where required, provide additional notice (for example, by email or an in-Service notice). Your continued use of the Service after an update takes effect constitutes acceptance of the revised Policy, to the extent permitted by law.
17. Contact us
Odyssey Digital Technologies LLC, d/b/a Noctelle (a California limited liability company)
Privacy / data-rights contact: [email protected]
Custodian of Records: Mohmad Arab, 1011 El Cajon Blvd, Unit 9, El Cajon, CA 92020, USA.
For CSAM, NCII/takedown, or other abuse reports, see Sections 6.3 and 6.4 and use the reporting channel referenced there.
EU/UK: Noctelle is not offered in the EU or UK and does not appoint a representative under GDPR Article 27 (see Section 9.1).
This Policy is governed by the laws of the State of California, USA, and any disputes are subject to the venue provisions in our Terms of Service.