AskMe trust
Privacy notice
How AskMe handles account, Profile, conversation, source, voice, support, billing, and operational data.
Published versions: 2026-09-03.01 · Last updated September 2, 2026
Who is responsible
AskMe is the controller for account, billing, product-support, security, and platform analytics data. A Profile owner or sponsoring Brand may be the controller for content they upload and for interactions with their Profile; AskMe processes that data to provide the service. The applicable Brand privacy notice remains available on the Brand host.
Data we process
We process account identity, Profile and source content, conversations and approved member memory, source-connection metadata, voice samples and generated-voice identifiers, support records, billing and credit history, privacy choices, and content-free security and reliability events.
- OAuth access and refresh tokens are encrypted and excluded from exports.
- Anonymous visitor profiling and cross-site advertising profiles are disabled for Founder Beta.
- Optional product analytics is off until an authenticated user opts in.
Why and on what basis
We use data to perform the requested service, secure and operate it, support customers, administer billing, meet legal obligations, and—with opt-in where applicable—understand product usage. Specific legal bases depend on the customer’s location and must be confirmed by qualified counsel before production approval.
Processors and transfers
Hosting/database, authentication, AI model, vector, observability, email, payment, source-provider, and voice providers may process the minimum data required for their service. The final subprocessor list, transfer mechanism, regional hosting commitments, and processor agreements remain a launch sign-off item.
Retention and deletion
A deletion request starts a 30-day recovery window. The affected Profile is unpublished, subscriptions are scheduled to cancel, and recovery can restore the recorded state before the deadline. After the deadline, an operator-run retry-safe workflow revokes provider tokens; deletes voice and storage objects; removes tenant content, source text, embeddings, conversations, memory, support content, and analytics; then deletes the login identity for account deletion.
- Pseudonymous billing, tax, accounting, dispute, fraud-defense, and fulfillment proof may be kept up to seven years.
- Content-free support/security audit may be kept up to two years and operational logs up to 90 days.
- Encrypted disaster-recovery copies expire on a 30-day rolling schedule and are not restored for ordinary product use.
Your choices and rights
Authenticated users can export account or managed-Profile data, change optional analytics and eligible member-memory choices, request access or correction, schedule deletion, and recover it during the 30-day window. If you cannot sign in, contact support; identity must be verified before disclosure or deletion. Depending on local law, additional rights may apply, including objection, restriction, portability, appeal, or a complaint to a regulator.
Children, family, and sensitive stories
AskMe is not directed to children and account creation is intended for adults or users legally able to consent. Family, memorial, legacy, health-adjacent, biometric/voice, and third-party stories can be sensitive. Uploaders must have authority and should avoid unnecessary information about other people. The precise age threshold and regional guardian-consent requirements require counsel review.
Security and contact
AskMe uses tenant/Profile authorization boundaries, encryption in transit, encrypted source tokens, private storage for sensitive uploads, audit events, and content-minimizing logs. No system is risk-free. Report privacy or security concerns through AskMe support; a final controller address, privacy contact, and regulator-specific disclosures must be added before production approval.