twinAI
Privacy Policy
Last updated: September 10, 2026
This policy explains how twinAI handles information about owners (people who build
a career twin) and visitors (people who interact with one). An owner chooses whether
to publish a profile. The original uploaded PDF is not shown to visitors, but text
extracted from it is processed by AI providers to build the profile. We do not sell
personal information or use it for third-party advertising.
1. Who is responsible for your data
twinAI is operated by Samir Tannoury, an individual sole trader
based in Lebanon. For account, service, security, support, and billing operations,
the operator decides why and how personal information is processed. Contact:
info@mytwinai.me.
When an owner publishes a twin, receives visitor conversations or location data,
and decides how to use that information, the owner may also have duties as a separate
or joint controller under local law. Visitors may contact twinAI first; we will route
a request to the owner where that is necessary.
twinAI is funded by paid subscriptions and one-off top-up packs. It has no
advertising business.
2. Information we collect from owners
- Account and sign-in — name, email, account id, session data,
and the sign-in method supplied through Clerk — an email code, or Google or Apple if
you sign in with one of those.
- Documents and profile — the résumé or LinkedIn PDF you upload,
its extracted text, your photo, profile fields, edits, publication state, suggested
questions, share link, and avatar presentation.
- Configuration and credentials — AI model, voice, and avatar
choices and any provider credential you supply. Provider keys are stored encrypted
and are not displayed again in full after submission; the service retains and shows
their last four characters so the owner can recognize a saved key.
- Billing — plan, provider, customer and subscription references,
RevenueCat identifiers, billing status and event times, and transaction records such
as transaction id, product description, currency, gross amount, an estimated net
amount, and a webhook-recorded timestamp. We do not receive or store your full card
number.
- Usage — text, voice, and avatar units; call duration; input,
output, and audio token counts; top-ups; and plan periods. Unit counters are used to
apply limits. Internal bundle-value estimates are derived for administrative display,
not as a measurement of provider cost or as the limit itself.
- Support — help questions, replies, ticket history, account and
plan context needed to investigate a request, and AI-generated support suggestions.
- Technical and security data — application and access events,
errors, IP-related rate-limit and abuse records, and log metadata generated by the
infrastructure and logging features enabled in the live service.
An account identifier and the minimum profile information needed to build a twin are
required for the owner service. We collect an email and name when the enabled sign-in
provider supplies them. A photo, voice/avatar feature, owner-supplied provider key, and
support request are optional. Without required account/profile information we cannot
create or operate the twin; declining an optional item affects only that feature.
3. Information we collect from visitors
- Conversations — typed questions and generated answers. On plans
that record conversations, the transcript is stored and made available to the owner.
- Session and security data — a temporary session id, IP address,
rate-limit records, and browser/device signals used by Cloudflare Turnstile to check
for bots and abuse.
- IP and approximate location — on eligible paid plans, IPinfo
converts an IP into an approximate record. The response we currently retain can
include the IP, hostname, city, region, country, approximate coordinates, postal
area, timezone, network/ASN, and related network fields. It is not GPS or a precise
street address. The owner-accessible session record can contain this information,
although the interface is designed to emphasize city, region, country, and network.
- Voice and avatar calls — microphone audio is streamed to the AI
service to run the call. twinAI does not deliberately save the raw audio as its own
recording. Spoken questions and answers are transcribed; on recorded plans the text
transcript is stored and shown to the owner. Providers may process or retain audio
or traces under their own service terms.
- Call records and feedback — session and call references, call
type, timing, reserved/used duration, provider call or avatar identifiers, quota
information, status, and an optional thumbs-up/down rating. A rate-limit key can
contain the visitor IP.
For visitors, a question and temporary session/security data are required for typed
chat. Microphone audio is required only for a voice or avatar call, and feedback is
optional. Without the data required for a feature, that feature cannot run.
4. Why we use information and our legal grounds
We use the information above to create and publish twins, answer visitor questions,
provide text/voice/avatar features, share recorded interactions with the owner,
administer plans and payments, prevent abuse, operate and improve the product, answer
support requests, and meet legal obligations.
Where EU, UK, or similar law applies, the ground depends on the person and purpose:
- Contract — to provide an owner account, build and publish the
requested twin, deliver purchased features, administer the owner relationship, and
process the transaction.
- Legitimate interests — to provide an interaction requested by a
visitor; secure and administer the service; prevent fraud and abuse; apply limits;
understand engagement with a published twin; generate and share eligible transcripts,
approximate-location records, and feedback with the owner; provide support, including
the limited cross-account support context described below; diagnose model calls; and
improve reliability. We must balance each interest against the person's rights and
stop or change the processing where those rights override it.
- Consent — only where an applicable law requires consent and we
obtain it through a valid choice, for example for a non-essential storage technology
or a voice/transcription activity in a jurisdiction that requires consent. A browser
or device microphone permission is a technical access control and is not, by itself,
consent for data-protection purposes. Ending a call stops future microphone processing
but does not undo completed processing or automatically delete a transcript.
- Legal obligation — for records or actions required by tax,
payment, consumer, security, or other applicable law.
CVs, photos, chats, and support messages can reveal specially protected information
or information about other people. Do not submit health, ethnicity, religion, politics,
trade-union membership, sexuality, referee, or other sensitive or third-party personal
information unless twinAI has first confirmed in writing that the feature is appropriate
and the required lawful condition, permissions, and safeguards are in place. Merely
warning us that the information is sensitive does not create a lawful basis. The current
upload, chat, and support paths do not automatically filter all such information before
provider processing, so this rule is not a technical safeguard or a substitute for the
required legal condition.
5. AI processing
- Profile creation — text extracted from the uploaded PDF is sent
to the configured AI model to produce a draft profile. The owner must review it.
- Visitor answers — for an ordinary typed question, the published
profile, system instructions, and current question are sent to the configured provider,
normally Anthropic or OpenAI; earlier typed turns are not sent as conversation context.
A live realtime session can carry the context created during that session. Gold owners
can use their own provider account and key, so that provider's settings and terms also
apply.
- Voice and avatar — OpenAI provides realtime AI/voice processing;
Simli or HeyGen's LiveAvatar product renders the selected avatar.
- Support — account/plan context, usage, the current ticket,
previous tickets, and recent answered support questions can be sent to the AI model
to suggest a reply. Recent answered question/answer pairs are also reused as support
context across accounts until they rotate out. Do not put secrets or unnecessary
personal information in a support ticket.
- Diagnostics — some model calls use the OpenAI Agents SDK, whose
tracing is enabled by default. The current application code does not disable that
default; unless the live deployment overrides it, traces send model inputs and outputs,
including profile, conversation, and support context, to OpenAI even when Anthropic
generated the answer.
twinAI does not train its own AI model on this content and does not intentionally
opt customer content into provider model training. Business/API providers generally
apply no-training defaults, but their endpoint-specific security retention, legal
exceptions, and an owner's separately controlled provider settings still apply. See
OpenAI data controls
and Anthropic retention information.
A twin is an AI system and can be inaccurate. Visitors are told they are interacting
with AI, not the owner. Important statements and hiring decisions must be confirmed
with the real person.
twinAI generates content and engagement records for human review. It does not itself
make a solely automated decision that produces legal or similarly significant effects
about an owner or visitor.
6. Service providers and recipients
Providers change as the product develops. The following list describes the material
services identified for the current product; a provider can act as our processor for
one purpose and as an independent controller for fraud, tax, identity, transaction,
or legal-compliance purposes.
- Amazon Web Services — application hosting, database, logs, and
file storage. The deployment configuration reviewed for this notice targets primarily
US East (N. Virginia), United States; a differently configured live environment may
use another region.
- Clerk, and the Google and Apple
identity services — sign-in, identity, and account sessions. Sign-in is by email code,
Google, or Apple.
- Anthropic — profile drafting, generated answers, and support
suggestions, depending on the selected model and feature.
- OpenAI — profile drafting, generated answers, support suggestions,
diagnostic tracing, and realtime voice, depending on the feature and configuration.
- Simli and HeyGen/LiveAvatar — receive the
credential used to authenticate the owner's enabled integration, avatar/persona and
session identifiers, generated audio or avatar media, and connection metadata needed
to render an avatar session. The visitor's browser establishes the live session
transport with the selected service.
- RevenueCat, Apple, and Google
— all purchases (paid plans and top-ups are sold only in the mobile app), entitlement
status, receipts, and store-account management.
- Cloudflare — DNS and Turnstile bot/security processing.
- IPinfo — IP and approximate location/network enrichment on
eligible paid plans.
- Expo — mobile update delivery and related technical processing
if EAS Update is enabled in the production build.
Ask info@mytwinai.me for the current legal
entity, role, location, and privacy terms for a particular provider.
7. International transfers
twinAI is operated from Lebanon, the reviewed hosting configuration targets the
United States, and providers can process information in other countries. Personal
information may therefore leave the country where the owner or visitor is located,
including for countries that local law does not consider equivalent. The live hosting
region and each provider's contracting entity must be confirmed for the actual service.
Where a transfer safeguard is legally required, the applicable arrangement may
include controller/processor terms, EU Standard Contractual Clauses, the UK Addendum
or IDTA, an adequacy decision or Data Privacy Framework certification, or another
valid mechanism. A provider merely offering one of these safeguards is not enough;
the mechanism must cover the actual entity and data flow. Contact us for the mechanism
currently relied on and how to obtain a copy. If an EU or UK representative is required
for the markets twinAI targets, its contact details will be added to this notice.
8. What is public
At a published share link, visitors can directly see the owner's name, headline,
photo, suggested questions, and share URL; an enabled avatar can be presented during
an avatar call. The broader
published profile is used as hidden grounding for answers even where each field is
not directly displayed. A generated answer is shown to the visitor who asked and,
on recorded plans, to the owner; it is not automatically published to every visitor.
The original PDF, owner email, credentials, billing details, unpublished edits,
and private account screens are not intended to be public. A published link can be
forwarded, so published information should not be treated as confidential.
9. Retention and deletion
These are the current application rules. Some are event-driven rather than fixed
deletion dates, and provider copies follow separate policies:
- Account and profile — kept while the account is active. Where a
twin/profile record exists, account deletion removes its owner-partition records and
current/versioned profile files. The current deletion path can skip owner-partition
cleanup if no twin/profile exists. If the account has support data but no twin, ask us
to remove that residual data before deleting the identity; afterward, the
support partition may no longer be identifiable from the email address alone.
- Free accounts — the free tier is a trial. An account that has
never moved to a paid plan may be closed and its data deleted once the free period has
passed: currently 30 days, counted from when the trial began. While the account is
free, the date that applies to it is shown in the account dashboard. Moving to a paid
plan removes the account from this schedule. An account that has ever held a paid plan
is not closed under this rule at all: if the subscription ends, the account and its
twin remain on the free tier indefinitely, without a free allowance. Deletion under
this rule removes the same data, with the same limitations, as any other account
deletion described here.
- Record kept after deletion (one trial per person) — the trial is
offered once per person rather than once per registration, so that deleting an account
does not simply restore it. When an account is deleted, whether by you or under the
rule above, we keep a single record containing a one-way cryptographic fingerprint of
the email address, the date the trial started, the free voice time already used, and
whether the account had ever been paid. We do not keep the address itself, the name,
or any other content: the fingerprint lets us recognise a repeat trial without our
being able to read who it belonged to. It is used for no other purpose, is never used
to contact anyone, and is not disclosed. Registering later with the same address
resumes that trial; registering with a different address does not. Our lawful basis is
our legitimate interest in preventing repeated use of a free trial.
- Recorded conversations — the service aims to retain the ten most
recent sessions per owner. Pruning occurs when certain owner account/history actions
run, so more than ten may exist until that happens. The retained ten have no separate
time expiry while the account remains active.
- Visitor session id — the server-side temporary session is treated
as expired after 24 hours. Clearing the browser value does not delete a server-side
conversation.
- IP/location — application code treats a shared raw-IPinfo cache
item as unavailable after 30 days. Where database TTL is enabled in the live stack,
DynamoDB later deletes the expired item asynchronously. A reviewed infrastructure
variant does not enable that TTL, and older rows created without an expiry field can
remain until migrated or manually removed. A copy attached to a conversation lasts
with that conversation.
- Call records and feedback — call/quota/provider metadata and a
rating can remain in the owner's account partition until account deletion. Pruning a
conversation does not currently remove its associated call row.
- Support — the owner account view is pruned to the ten most recent
tickets when the pruning action runs. A shared corpus of the thirty most recent
answered question/answer pairs remains until older entries rotate out and can outlive
deletion of the source account. Corpus entries do not currently retain owner provenance,
so twinAI cannot reliably locate a particular person's pair for deletion; rotation can
also be indefinite if fewer than thirty newer answered questions arrive.
- Payment and tax — transaction records may be retained for the
period required for accounting, tax, fraud, chargeback, or legal claims. Globally
keyed mobile-purchase records can remain after profile deletion and have no automatic
application expiry.
- Application logs — a reviewed container-log configuration uses a
30-day retention period. Other reviewed application/Lambda logs have no explicit
retention setting and can remain until the deployed logging service or an operator
deletes them.
- Backups — deployment templates can enable database point-in-time
recovery, whose recovery points can remain for up to 35 days. The current application
has no deletion ledger or automated process to reapply completed erasures after a
restore, so restored data could reappear until manually reconciled.
- Providers — AI, identity, payment, hosting, and other providers
keep their own security, legal, transaction, and backup records under their terms.
Deleting an account does not itself cancel an Apple or Google subscription; see the
Terms of Use. For a complete deletion check, including data
that cannot be found through the account screen, email us.
10. Cookies, device storage, and bot protection
The website uses browser storage for Clerk sign-in, language, chat/microphone
preferences, and a visitor session id. The mobile app stores the sign-in session,
language, theme, and related preferences on the device. Cloudflare Turnstile also
processes browser/device signals to detect bots. We do not use advertising cookies
or cross-site advertising trackers.
Signing out clears or invalidates authentication state but does not necessarily
remove language, theme, chat, or microphone preferences. Clear the site's data in your
browser or the app's storage through your device settings to remove those values. The
absence of advertising does not by itself make every storage technology exempt from
consent, so we review the deployed Clerk, Turnstile, payment, Expo, browser, and mobile
storage by market. The current product has no general cookie-preference tool. An optional
technology that requires consent must not be used in that market until a valid prior
choice is available.
11. Security
We use HTTPS for user-facing connections, encryption at rest for stored files and
database records, encryption for owner-supplied provider keys, access controls designed
to separate owners, rate limiting, bot protection, and restricted administrative
access. Transport inside the hosting environment depends on the deployed network path,
so we do not promise end-to-end TLS on every internal hop.
No service can guarantee perfect security. If a personal-data breach requires notice,
we will notify affected people and the relevant authority within the applicable period.
12. Your rights
Depending on the law that applies, you may ask us to:
- give you access to and a copy of your personal information;
- correct inaccurate or incomplete information;
- delete information or restrict how it is used;
- provide eligible information in a portable format;
- withdraw consent, without affecting processing already lawfully completed; and
- review any decision that applicable law says must not be made solely by automated means.
You may also object to processing based on legitimate interests,
including location/engagement analysis, subject to any compelling lawful grounds we
are permitted to rely on.
Email info@mytwinai.me. A visitor should include
the twin/share link, approximate date and time, and session id if still available; do
not send more identity information than needed. We may verify identity, ask for details
needed to locate a record, or deny/charge for a request only where law permits.
For requests governed by Lebanese Law 81/2018, we will complete a valid access,
correction, completion, update, or erasure request within 10 calendar days. Under that
law, you may apply to the competent Lebanese courts, including the Magistrate of Summary
Justice, to enforce access and correction rights. EU/UK requests are generally due
within one month, subject to a lawful extension notified within that month; where
applicable, you may complain to the supervisory authority where you live or work.
13. Owner responsibilities
Owners must have the right to upload and publish their content. Visitor questions,
transcripts, and location/network data concern a real person. Use them only for the
stated engagement purpose, keep them secure, respect valid rights requests, and do not
use them to identify, contact, track, rank, profile, or discriminate against a visitor
unlawfully. Do not make a hiring decision solely from a twin's output; verify important
information with the real person. Depending on the use, an owner may need their own
privacy notice and lawful basis.
14. Children
twinAI is not directed to children. You must be at least 16 to create an account or
use a public twin. If you are under the age at which you can enter the relevant contract
or make a paid purchase where you live, a parent or guardian must authorize it. This
rule is separate from any jurisdiction-specific age for privacy consent. The current
service does not provide a server-side age check for public twins or a guardian-consent
workflow, so a person who needs guardian authorization must not use the service unless
and until twinAI provides a valid process. If you believe a child has provided
information contrary to this section, email us for deletion.
15. Changes and contact
We may update this notice when the product, providers, or law changes. The date above
identifies the current version. We will give any advance and durable notice required
when a material change affects rights or introduces a materially different use. A
Privacy Policy is a notice, not a request to consent to every use.
This notice is currently available only in English, even though parts of the product
interface support other languages. A translated interface does not translate this
notice. The English version controls only to the extent local law permits. Questions,
rights requests, or complaints: the Help tab or
info@mytwinai.me.