Legal
Privacy Policy
Ares Realm Studios builds local-first products with optional account and connected services. This policy explains what stays on your device, what we handle only when necessary or requested, and how you remain in control. Effective July 19, 2026.
Our Privacy Principle
Privacy does not mean that accounts can never exist. It means local features work without an account whenever possible, connected features have a clear purpose, and your information never becomes ours simply because you used our software.
- We do not sell personal information or use it to build advertising profiles.
- We do not use account information, prompts, conversations, files, or backups to train or fine-tune AI models.
- Our local-first applications do not include advertising SDKs or hidden behavioral telemetry.
- We collect and retain only what is needed to provide a feature you chose, secure the service, or meet a legal obligation.
Local App Data
- Projects, libraries, local model conversations, companion memory, configurations, and other app data remain on your device unless you deliberately use a connected feature.
- Local data can be removed using the application's controls, by clearing its storage, or by uninstalling it.
- Files you export are saved to a location you choose and remain under your control.
- Downloads such as AI models, books, voice packs, or assets may come directly from third-party hosts, which receive the network information required to fulfill that request.
Optional Accounts
Core local functionality does not require an Ares Realm Studios account wherever a product says so. You may choose an account to organize license or program keys, use backups, connect devices, manage entitlements, or access Ares Realm Studios-hosted AI models.
- Account records include your email address, an optional username, a protected password verifier, account status, creation date, and last-login time.
- We store the entitlements, product rights, license redemptions, and key records needed to provide access you own or have been granted.
- Session and member API credentials are stored as protected hashes rather than reusable plaintext secrets.
- We use a sign-in session cookie for account access. We do not use advertising or cross-site tracking cookies.
- Security and rate-limiting records may include an IP address, time, requested operation, and success or failure so we can prevent abuse and investigate threats.
Information You Choose to Store
- App backups are uploaded only when you activate a backup or sync feature. They are tied to your account and can be replaced or deleted through supported controls.
- L.U.C.Y. conversation-history backups are encrypted in your browser before upload. The server stores ciphertext and does not receive the decryption key.
- Ares Secrets Vault labels and values are encrypted in the Android or desktop app before upload. We store account-scoped ciphertext and a recovery-wrapped key envelope, but we never receive the recovery key, local passphrase, or plaintext secret.
- Notes are separate from the Secrets Vault. Notes MCP keys can access account notes but cannot list, read, copy, or change vault ciphertext or secrets.
- Other optional app backups, including EV3RLY Library backups, may be stored as account-scoped JSON and are not end-to-end encrypted unless that product explicitly says otherwise.
- If you enable account-linked device connection, we store the device identifier, display name, connection details, presence time, and an encrypted connection token needed to find your device.
- We do not inspect optional backups for advertising or AI training.
License Activation
When you activate licensed software, we may store the license key and edition, product identifier, a machine-generated fingerprint, activation and last-validation times, expiration, and activation limit. We use this information to provide the license, prevent unauthorized duplication, and troubleshoot legitimate device changes—not for advertising.
AI Model Access
- Prompts sent to Ares Realm Studios-hosted models are processed to generate your response. Our application layer does not log or retain the conversation content as chat history unless you enable encrypted history backup.
- Some hosted AI interfaces may automatically analyze the latest prompt for safety or abuse before inference. This check does not create a stored conversation history.
- If you connect a third-party AI provider such as OpenAI, Anthropic, Google, OpenRouter, or another service, the information needed for that request is sent to that provider and is governed by its terms and privacy policy.
- Your conversations and account information are not added to Ares Realm Studios training datasets.
Service Providers
- Cloudflare hosts our website, APIs, account database, security controls, and connections to our model backends.
- Google/Gmail delivers account verification, password-reset, and other service messages.
- These providers receive only the information needed to perform the connected service and process it under their own terms and privacy policies.
Support Through Ko-fi
If you support us through Ko-fi, Ko-fi may send us your display name, email, contribution amount and currency, message, contribution or membership type, tier, and transaction identifiers. We do not receive full payment-card details. If Ko-fi marks a contribution public, our website may display the public supporter name and amount.
Your Control
- You can use supported local features without creating an account.
- You decide whether to enable backups, connect devices, use hosted models, or configure a third-party provider.
- You can delete eligible backups, revoke keys, and end sessions through the available product and account controls.
- You can download an account archive from the account page. It includes your profile, entitlements, licenses and activation records, optional backup data, encrypted Secrets Vault ciphertext, encrypted chat-history ciphertext, connected-device metadata, and hosted-chat usage. It does not include vault recovery or local device keys.
- You can close a non-administrator account through the account page after confirming your password. Closure deletes profile identifiers, password verifier, sessions, API keys, hosted backups, connected-device records, hosted-chat usage, entitlements, and rights.
- After closure, we retain only an anonymous disabled account identifier and license, redemption, and machine-activation records needed to prevent duplicate redemption and license fraud. Service-wide security/rate-limit logs and independent support transactions follow their separate retention requirements.
- You may request correction or ask questions about records outside the self-service controls by contacting us.
Security and Retention
- Passwords are not stored in plaintext. Account passwords use a unique salt and a computationally expensive password hash.
- Encrypted backups and Secrets Vault contents remain unreadable to us without the key held by you. If that key is lost along with every usable local device key, we cannot recover the data.
- Account and service records are retained while needed to provide the service, protect accounts and licenses, resolve disputes, and meet legal obligations.
- No system can promise absolute security, but we design around data minimization, user consent, least privilege, and local ownership.
Changes to This Policy
If we make material changes to this privacy policy, we will update the effective date and provide notice through the website, account service, or applicable application when appropriate.