vVelvet Stories
Stories Blog FAQ
on this page
1. Who we are 2. Data we collect 3. How your stories are generated 4. Legal bases (EEA / UK) 5. Who processes data for us 6. International transfers 7. How long we keep data 8. Deleting your account 9. Your rights 10. Security 11. Changes to this policy 12. Contact

Privacy Policy

Velvet Stories · Last updated 7 August 2026

Velvet Stories (“the app”) is an adults-only application that generates personalised romance fiction with AI. This policy explains what personal data we collect, why we collect it, who processes it on our behalf, and how you can exercise your rights over it.

Velvet Stories is strictly for adults aged 18 and over. The app is not directed at children, and we do not knowingly collect personal data from anyone under 18. If we learn that we hold data from a minor, we delete the account and its content.

1. Who we are

The data controller is Pedro Manfredi (Clutch Developer), Pau Alsina 64, bloque A, 3, 1, Barcelona 08024, Spain — the developer and operator of Velvet Stories. As the controller is established in Spain, within the EEA, no separate EU representative is required. You can reach us at info@clutchdeveloper.com for any privacy question, request or complaint.

2. Data we collect

CategoryWhat it includesWhy we process it
Account data Email address, display name or first name, an internal account identifier, and the sign-in method you used (email and password, Google, Apple or Facebook). Apple’s “Hide My Email” relay address is stored as-is if you choose it. Creating and securing your account, signing you in, and contacting you about the service.
Content you create Story prompts and settings, generated stories, characters you create (name, traits, description, uploaded or generated portrait), content boundaries and intensity preferences, favourites, and reading progress. Generating stories, saving your library, and applying the boundaries you set.
Purchase data Subscription and token-pack status, product identifier, purchase and expiry dates, and the store transaction identifier. Unlocking what you paid for, restoring purchases, and preventing duplicate delivery. We never receive or store your card or bank details — payment is handled entirely by Apple or Google.
Diagnostics Crash reports and stack traces, performance traces, device model, operating-system version, app version, and language. Finding and fixing crashes, and keeping the app fast and stable.
Usage analytics Aggregated in-app events such as screens opened, stories created, and purchases completed, tied to a pseudonymous app instance identifier. Understanding which features are used so we can improve them.
Website analytics After you opt in on this website, Google Analytics receives a page view with query details removed and may set analytics cookies. It uses a persistent pseudonymous identifier; we do not send form contents, names, email addresses, or search terms. Understanding which pages are useful. You can reject or later revoke website analytics from Cookie settings.
Notifications A push notification token, only if you allow notifications. Telling you when a story is ready and sending the reminders you enabled.
Link attribution Referral and deep-link data when you open the app from a shared link. Sending you to the right screen and measuring how people find the app.

What we do not collect

  • The app shows no ads. There is no advertising SDK in the app, we collect no advertising identifiers, we never present the App Tracking Transparency prompt, and we do not read Apple’s IDFA or Android’s advertising ID. Advertiser-ID collection and automatic event logging in the Facebook SDK remain explicitly disabled — that SDK is present only so you can sign in with Facebook. If we ever introduce advertising, it will be non-personalized and we will update this policy before any ad is shown.
  • We do not track you across other companies’ apps or websites, we do not sell your personal information, and we build no advertising profile from your activity.
  • We do not ask for your precise location, contacts, or health data.

3. How your stories are generated

To create a story, a character or narration audio, the app sends your prompt, your character details and your boundary settings to our servers, which pass them to the AI providers listed in section 5. Photos you pick for a character are uploaded only so a portrait can be generated and stored in your library. Your stories are private to your account unless you explicitly choose to publish a character or story, in which case it is reviewed before it becomes visible to others.

4. Legal bases (EEA / UK)

  • Performance of a contract — running your account, generating and storing your stories, and delivering purchases.
  • Legitimate interests — keeping the service secure, preventing abuse and fraud, and diagnosing crashes.
  • Consent — push notifications, website analytics, and optional app analytics where consent is required in your country. You can withdraw website consent at any time from Cookie settings and app consent from your device or app settings.
  • Legal obligation — keeping transaction records and responding to lawful requests.

5. Who processes data for us

We use the following processors. They act on our instructions and may not use your data for their own purposes.

  • Google — Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Cloud Messaging, Remote Config, Google Analytics for Firebase, website Google Analytics after consent, Crashlytics and Performance Monitoring (hosting, accounts, diagnostics); and Google Gemini and Google Cloud Text-to-Speech (story, character and narration generation).
  • Leonardo.Ai — generating character portraits from the description you provide.
  • Branch Metrics — deep links and install attribution.
  • Meta Platforms — Facebook Login, only if you choose to sign in with Facebook.
  • Apple and Google Play — processing in-app purchases and subscriptions under their own privacy policies.

We also disclose data where we are legally required to, or to protect the rights and safety of our users and of Velvet Stories.

6. International transfers

Our processors operate globally, so your data may be processed outside the European Economic Area, including in the United States. Those transfers rely on the European Commission’s Standard Contractual Clauses and the data-processing terms of each provider, together with technical safeguards such as encryption in transit and at rest.

7. How long we keep data

  • Account data and your content — for as long as your account exists. Deleting your account removes them.
  • Crash and performance data — retained by Firebase for up to 90 days.
  • Analytics events — app and website analytics are retained for up to 14 months, in pseudonymous form.
  • Purchase records — kept for as long as accounting and tax rules require, even after account deletion.
  • Residual copies in encrypted backups are purged on our providers’ normal backup rotation, within 90 days at the latest.

8. Deleting your account

You can delete your account and all of its content from inside the app: Account → Account details → Delete account. This removes your profile, stories, characters, favourites and preferences from our systems, signs you out on the device, and clears locally cached data. Deletion is permanent and cannot be undone. An active subscription is managed by the App Store or Google Play — cancel it there so you are not billed again. If you cannot access the app, email info@clutchdeveloper.com from your account address and we will delete it for you.

9. Your rights

If you are in the EEA or the UK, you have the right to access your data, to have it corrected, to have it erased, to restrict or object to processing, to data portability, and to withdraw consent at any time. You may also lodge a complaint with your national data-protection authority.

If you are a California resident, you have the right to know what personal information we collect and disclose, to request its deletion or correction, to opt out of sale or sharing (we do not sell or share your personal information — the app shows no ads, so nothing is disclosed for cross-context behavioural advertising), to limit the use of sensitive personal information, and not to be discriminated against for exercising any of these rights.

To exercise any right, email info@clutchdeveloper.com. We answer within 30 days and may ask you to confirm the email address on the account before we act.

10. Security

Traffic between the app and our servers is encrypted with TLS, and data at rest is encrypted by our cloud providers. Authentication tokens are stored in the iOS Keychain or the Android Keystore, never in plain preferences. Access to production data is restricted to the people who need it. No system is perfectly secure, so please use a strong, unique password and tell us immediately if you suspect your account has been compromised.

11. Changes to this policy

We will update this page when our practices change and revise the date at the top. If a change materially affects you, we will tell you in the app before it takes effect.

12. Contact

Privacy questions, requests and complaints: info@clutchdeveloper.com, or by post: Pedro Manfredi (Clutch Developer), Pau Alsina 64, bloque A, 3, 1, Barcelona 08024, Spain.

vVelvet Stories Explicit interactive fiction for adults. Consensual scenarios only. Your heat ceiling stays on your device.
18+ adults only
Read
StoriesBlogLatest article
Support
FAQContact usContent rules
Legal
Terms of servicePrivacy policyCookie settings
© 2026 Clutch Developercustom-velvet-stories.com