Privacy Policy
You tell Lady Soraya things you would not tell most people. This page sets out exactly what happens to that, in language you can actually check us against.
The four things most people want to know
We do not sell your data. Not to advertisers, not to data brokers, not to anyone.
We do not publish your conversations.
You can delete everything from your account settings, at any time.
We never see your full card number. It goes straight to the payment processor.
1. Who controls your data
Ad Management Services LLC, of 30 N Gould St #23552, Sheridan, WY 82801, United States, is the data controller for the personal data described here.
For any privacy question, contact [email protected].
2. What we collect
| Category | What it is | Why we have it |
|---|---|---|
| Account data | Email address, password (hashed), display name, account settings | To create and secure your account, and to contact you about your membership |
| Conversation data | What you write or say to Lady Soraya, and her responses | To generate replies and to give her memory of your situation between sessions |
| Voice audio | Recordings of voice messages, where you use voice | To transcribe what you said so it can be answered |
| Billing data | Card brand, last four digits, expiry, billing country, transaction history | To take payment, issue receipts, process refunds and meet tax obligations |
| Consent records | Timestamp, IP address, and the version of the terms shown when you subscribed | To prove you were properly informed before being billed - a legal requirement |
| Technical data | IP address, browser and device type, pages viewed, timestamps, error logs | To keep the service running, prevent fraud and abuse, and diagnose faults |
| Support data | Emails, call notes and tickets | To answer you and keep a record of what was agreed |
What we never collect: your full card number or CVV (these go directly to our payment processor), and any government identity document. We do not ask for any of it and could not use it if we had it.
3. Sensitive topics in conversation
You may talk to Lady Soraya about health, relationships, beliefs, sexuality or other deeply personal matters. In some jurisdictions that content is treated as a special category of personal data attracting extra protection.
We handle it accordingly: it is used only to answer you and to maintain your conversation context, it is not used to build advertising profiles, it is not shared for marketing, and it is deleted when you delete it. We ask you not to send us information about other identifiable people that they would not want shared, and never to send payment card numbers, passwords or identity documents inside a conversation.
4. Our legal bases
- Performance of a contract — providing the Service you have paid for: your account, your conversations, your billing.
- Legal obligation — tax and accounting records, consent records required by consumer-protection law, and responses to lawful requests.
- Legitimate interests — keeping the Service secure, preventing fraud and abuse, and improving reliability. We balance these against your rights and use the least intrusive option available.
- Consent — for optional analytics and for marketing email. You can withdraw it at any time without affecting your membership.
5. How your conversations are used by the AI
Your messages are sent to the AI model that generates Lady Soraya’s replies, and stored so that she can refer back to your situation in later sessions.
We do not use your conversations to train foundation models, and we contractually require our AI providers not to train on data we send them. If that ever changes it would be an opt-in choice presented to you separately, never a silent default.
A small number of authorised staff can access conversation data where it is strictly necessary — investigating a bug you have reported, responding to a safety or legal issue, or acting on your own support request. Such access is logged.
6. Who we share it with
We share data only with service providers who need it to run the Service, under contracts that limit them to our instructions:
- Cloud hosting and storage — to run the application and hold your data.
- AI model providers — to generate responses, under no-training terms.
- Payment processing — a PCI DSS Level 1 processor that handles card data on our behalf. They receive your card details directly; we do not.
- Email delivery — to send receipts, notices and support replies.
- Fraud and abuse prevention — to detect stolen cards and automated abuse.
- Professional advisers and authorities — where we are legally required, or to establish or defend legal claims.
We do not sell personal data, and we do not share it for cross-context behavioural advertising. If we are ever involved in a merger or acquisition, your data may transfer to the acquirer under the same commitments, and we will tell you before it happens.
7. International transfers
Our providers may process data outside your country. Where data leaves a jurisdiction with data-transfer restrictions, we rely on an approved safeguard — an adequacy decision, or Standard Contractual Clauses with supplementary measures. You can request details of the safeguard used at [email protected].
8. How long we keep it
| Data | Kept for |
|---|---|
| Conversation history | Until you delete it, or 30 days after you close your account |
| Voice recordings | Deleted after transcription; transcripts follow conversation history |
| Account data | Life of the account, then 30 days |
| Billing and tax records | As required by tax law in United States, typically 7 years |
| Consent records | At least 3 years, or 1 year after cancellation, whichever is longer |
| Security and fraud logs | Up to 12 months |
| Support correspondence | 3 years from the last contact |
Where we must keep billing records for tax purposes, we keep only what the law requires — the transaction, not your conversations.
9. Your rights
Depending on where you live, you have some or all of the following rights. We honour all of them for every user, wherever you are, because operating two standards is a worse way to run a service.
- Access — get a copy of what we hold about you.
- Correction — fix anything inaccurate.
- Deletion — have it erased, subject only to records we are legally required to keep.
- Portability — receive your data in a machine-readable format.
- Restriction and objection — limit or object to certain processing.
- Withdraw consent — at any time, for anything based on consent.
- Non-discrimination — we will never degrade your service or change your price because you exercised a privacy right.
Most of this is self-service in Account → Privacy. Otherwise email [email protected]. We respond within 30 days and will tell you if we need longer. We do not charge for this.
If you are unhappy with how we handled a request, you can complain to your local data-protection authority. We would appreciate the chance to put it right first.
10. Security
- All traffic is encrypted in transit with TLS; data is encrypted at rest.
- Passwords are stored using a modern one-way hashing algorithm and are never recoverable in plain text.
- Staff access is role-based, granted on a need-to-know basis, and logged.
- Card data never touches our infrastructure.
- We keep audit logs and monitor for unusual access patterns.
No system is perfectly secure. If a breach affects your personal data and creates a risk to you, we will notify you and the relevant regulator within the timeframes the law requires, and tell you plainly what happened and what to do.
11. Children
Soraya Live is for adults. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, contact [email protected] and we will close it, delete the data and refund any charges.
12. Cookies
We use a small number of cookies, described in the Cookie Policy. Only strictly necessary cookies are set without your consent.
13. Changes to this policy
If we make a material change we will email you and update the date at the top of this page before it takes effect. Previous versions are available on request.
14. Contact
- Data controller
- Ad Management Services LLC
- Privacy contact
- [email protected]
- Postal address
- 30 N Gould St #23552Sheridan, WY 82801, United States