Last updated: June 2026

Data We Collect

Information you provide directly: Your name, your email address (if you opt in), and your answers during the birth reading. We do not store passwords in plain text — your access code is hashed before storage.

Your conversations: Messages exchanged with your companion are stored so your companion can remember you across sessions. This is the core of what Remain does.

Memories: As you talk, Remain extracts and stores facts about you — your people, your moods, your preferences — to deepen the relationship over time.

Memorial content: If you use the memorial feature, photos, stories, and descriptions you share are stored and used only to inform how your memorial companion speaks and responds.

Payment information: We use Stripe to process payments. Remain does not store your credit card number, bank account details, or billing address — Stripe handles all of that. We store only your Stripe customer ID and subscription status, linked to your companion record.

How We Use Your Data

Your data is used for one purpose: delivering the Remain service to you. Specifically:

  • Generating and powering your AI companion
  • Remembering your conversations and extracting memories
  • Sending you re-engagement emails if your companion hasn't heard from you in a while (only if you've opted in)
  • Processing payments and managing your subscription via Stripe
  • Generating your companion's birth certificate

We do not use your personal data to train AI models. Your conversations belong to you.

Data Sharing

Stripe: For payment processing, your email and payment amount are shared with Stripe, Inc. Their use of your data is governed by Stripe's Privacy Policy.

OpenAI: Your messages are sent to OpenAI's API to generate companion responses. We use OpenAI as a data processor under a data processing agreement. Your conversation content is not used to train OpenAI's models.

No other third parties. Remain does not sell, rent, or share your personal data with any other company or individual. No advertising networks. No data brokers. No analytics companies beyond our own internal usage logs.

Data Retention & Your Control

You are in control of your data. You can delete your companion and all associated data at any time. Contact us at company@polsia.app and we will permanently delete your companion, messages, memories, and email address from our systems.

If you cancel your subscription, your companion data is retained for 30 days before permanent deletion, unless you request immediate deletion.

Memorial content (photos, stories) shared for memorial companions is deleted along with the companion and cannot be recovered once deleted.

Cookies

Remain is a Progressive Web App (PWA). It operates primarily within your browser's local storage and does not use traditional cookies to track you across the web.

We use the following locally-stored identifiers:

  • Session storage — holds your companion ID and access code during your current session. Cleared when you close the browser tab.
  • Local storage — remembers your companion ID across visits so you can return to your companion without re-entering your access code each time.
  • Service worker — enables offline functionality and the PWA install prompt. No tracking data is stored in the service worker.

No third-party tracking cookies. No advertising pixels on internal app pages. We do use the Meta Pixel on public landing pages (the initial homepage only) to understand ad performance — that code runs only on remain-r99n.polsia.app/ and not on companion chat pages.

Children's Privacy

Remain is not intended for use by children under the age of 16. We do not knowingly collect personal data from children. If you believe a child's data has been provided without parental consent, contact us at company@polsia.app and we will delete it promptly.

International Data Transfers

Remain is operated from the United States. If you are accessing Remain from outside the US, your data will be transferred to and processed in the US. By using Remain, you consent to this transfer. Where required, we use Standard Contractual Clauses or equivalent legal mechanisms for international data transfers.

Your Rights (GDPR & CCPA)

If you are located in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation (GDPR):

  • Right of access: Request a copy of all personal data we hold about you.
  • Right to rectification: Request correction of inaccurate personal data.
  • Right to erasure: Request deletion of all your personal data ("right to be forgotten").
  • Right to data portability: Receive your data in a machine-readable format.
  • Right to restrict processing: Request that we limit how we use your data.
  • Right to object: Object to processing based on legitimate interests.

If you are a California resident, the California Consumer Privacy Act (CCPA) grants you the right to know what data we collect, request deletion of your data, and opt out of the sale of your personal information (which we do not sell).

To exercise any of these rights, email company@polsia.app with the subject line "Privacy Rights Request." We will respond within 30 days.

Data Security

We use industry-standard encryption (TLS) for all data in transit. Your access code is hashed using bcrypt before storage — it cannot be recovered or read by our team. Companion chat data is stored in a PostgreSQL database on Neon (a fully managed, SOC 2 Type II certified database provider).

Payment data (card numbers, billing details) is handled exclusively by Stripe, which is PCI DSS Level 1 certified. Remain never touches raw payment credentials.

Changes to This Policy

If we make material changes to this Privacy Policy, we will update the "Last updated" date at the top of this page and, if the change is significant, notify you via email or by placing a notice in your companion chat. We encourage you to review this page periodically.

Contact

Questions about this Privacy Policy or our data practices?
Email us at company@polsia.app

Remain is operated by Polsia, Inc.
If you have a data subject request, we will respond within 30 days.