twinAI

Privacy Policy

Last updated: September 10, 2026

This policy explains how twinAI handles information about owners (people who build a career twin) and visitors (people who interact with one). An owner chooses whether to publish a profile. The original uploaded PDF is not shown to visitors, but text extracted from it is processed by AI providers to build the profile. We do not sell personal information or use it for third-party advertising.

1. Who is responsible for your data

twinAI is operated by Samir Tannoury, an individual sole trader based in Lebanon. For account, service, security, support, and billing operations, the operator decides why and how personal information is processed. Contact: info@mytwinai.me.

When an owner publishes a twin, receives visitor conversations or location data, and decides how to use that information, the owner may also have duties as a separate or joint controller under local law. Visitors may contact twinAI first; we will route a request to the owner where that is necessary.

twinAI is funded by paid subscriptions and one-off top-up packs. It has no advertising business.

2. Information we collect from owners

An account identifier and the minimum profile information needed to build a twin are required for the owner service. We collect an email and name when the enabled sign-in provider supplies them. A photo, voice/avatar feature, owner-supplied provider key, and support request are optional. Without required account/profile information we cannot create or operate the twin; declining an optional item affects only that feature.

3. Information we collect from visitors

For visitors, a question and temporary session/security data are required for typed chat. Microphone audio is required only for a voice or avatar call, and feedback is optional. Without the data required for a feature, that feature cannot run.

4. Why we use information and our legal grounds

We use the information above to create and publish twins, answer visitor questions, provide text/voice/avatar features, share recorded interactions with the owner, administer plans and payments, prevent abuse, operate and improve the product, answer support requests, and meet legal obligations.

Where EU, UK, or similar law applies, the ground depends on the person and purpose:

CVs, photos, chats, and support messages can reveal specially protected information or information about other people. Do not submit health, ethnicity, religion, politics, trade-union membership, sexuality, referee, or other sensitive or third-party personal information unless twinAI has first confirmed in writing that the feature is appropriate and the required lawful condition, permissions, and safeguards are in place. Merely warning us that the information is sensitive does not create a lawful basis. The current upload, chat, and support paths do not automatically filter all such information before provider processing, so this rule is not a technical safeguard or a substitute for the required legal condition.

5. AI processing

twinAI does not train its own AI model on this content and does not intentionally opt customer content into provider model training. Business/API providers generally apply no-training defaults, but their endpoint-specific security retention, legal exceptions, and an owner's separately controlled provider settings still apply. See OpenAI data controls and Anthropic retention information.

A twin is an AI system and can be inaccurate. Visitors are told they are interacting with AI, not the owner. Important statements and hiring decisions must be confirmed with the real person.

twinAI generates content and engagement records for human review. It does not itself make a solely automated decision that produces legal or similarly significant effects about an owner or visitor.

6. Service providers and recipients

Providers change as the product develops. The following list describes the material services identified for the current product; a provider can act as our processor for one purpose and as an independent controller for fraud, tax, identity, transaction, or legal-compliance purposes.

Ask info@mytwinai.me for the current legal entity, role, location, and privacy terms for a particular provider.

7. International transfers

twinAI is operated from Lebanon, the reviewed hosting configuration targets the United States, and providers can process information in other countries. Personal information may therefore leave the country where the owner or visitor is located, including for countries that local law does not consider equivalent. The live hosting region and each provider's contracting entity must be confirmed for the actual service.

Where a transfer safeguard is legally required, the applicable arrangement may include controller/processor terms, EU Standard Contractual Clauses, the UK Addendum or IDTA, an adequacy decision or Data Privacy Framework certification, or another valid mechanism. A provider merely offering one of these safeguards is not enough; the mechanism must cover the actual entity and data flow. Contact us for the mechanism currently relied on and how to obtain a copy. If an EU or UK representative is required for the markets twinAI targets, its contact details will be added to this notice.

8. What is public

At a published share link, visitors can directly see the owner's name, headline, photo, suggested questions, and share URL; an enabled avatar can be presented during an avatar call. The broader published profile is used as hidden grounding for answers even where each field is not directly displayed. A generated answer is shown to the visitor who asked and, on recorded plans, to the owner; it is not automatically published to every visitor.

The original PDF, owner email, credentials, billing details, unpublished edits, and private account screens are not intended to be public. A published link can be forwarded, so published information should not be treated as confidential.

9. Retention and deletion

These are the current application rules. Some are event-driven rather than fixed deletion dates, and provider copies follow separate policies:

Deleting an account does not itself cancel an Apple or Google subscription; see the Terms of Use. For a complete deletion check, including data that cannot be found through the account screen, email us.

10. Cookies, device storage, and bot protection

The website uses browser storage for Clerk sign-in, language, chat/microphone preferences, and a visitor session id. The mobile app stores the sign-in session, language, theme, and related preferences on the device. Cloudflare Turnstile also processes browser/device signals to detect bots. We do not use advertising cookies or cross-site advertising trackers.

Signing out clears or invalidates authentication state but does not necessarily remove language, theme, chat, or microphone preferences. Clear the site's data in your browser or the app's storage through your device settings to remove those values. The absence of advertising does not by itself make every storage technology exempt from consent, so we review the deployed Clerk, Turnstile, payment, Expo, browser, and mobile storage by market. The current product has no general cookie-preference tool. An optional technology that requires consent must not be used in that market until a valid prior choice is available.

11. Security

We use HTTPS for user-facing connections, encryption at rest for stored files and database records, encryption for owner-supplied provider keys, access controls designed to separate owners, rate limiting, bot protection, and restricted administrative access. Transport inside the hosting environment depends on the deployed network path, so we do not promise end-to-end TLS on every internal hop.

No service can guarantee perfect security. If a personal-data breach requires notice, we will notify affected people and the relevant authority within the applicable period.

12. Your rights

Depending on the law that applies, you may ask us to:

You may also object to processing based on legitimate interests, including location/engagement analysis, subject to any compelling lawful grounds we are permitted to rely on.

Email info@mytwinai.me. A visitor should include the twin/share link, approximate date and time, and session id if still available; do not send more identity information than needed. We may verify identity, ask for details needed to locate a record, or deny/charge for a request only where law permits.

For requests governed by Lebanese Law 81/2018, we will complete a valid access, correction, completion, update, or erasure request within 10 calendar days. Under that law, you may apply to the competent Lebanese courts, including the Magistrate of Summary Justice, to enforce access and correction rights. EU/UK requests are generally due within one month, subject to a lawful extension notified within that month; where applicable, you may complain to the supervisory authority where you live or work.

13. Owner responsibilities

Owners must have the right to upload and publish their content. Visitor questions, transcripts, and location/network data concern a real person. Use them only for the stated engagement purpose, keep them secure, respect valid rights requests, and do not use them to identify, contact, track, rank, profile, or discriminate against a visitor unlawfully. Do not make a hiring decision solely from a twin's output; verify important information with the real person. Depending on the use, an owner may need their own privacy notice and lawful basis.

14. Children

twinAI is not directed to children. You must be at least 16 to create an account or use a public twin. If you are under the age at which you can enter the relevant contract or make a paid purchase where you live, a parent or guardian must authorize it. This rule is separate from any jurisdiction-specific age for privacy consent. The current service does not provide a server-side age check for public twins or a guardian-consent workflow, so a person who needs guardian authorization must not use the service unless and until twinAI provides a valid process. If you believe a child has provided information contrary to this section, email us for deletion.

15. Changes and contact

We may update this notice when the product, providers, or law changes. The date above identifies the current version. We will give any advance and durable notice required when a material change affects rights or introduces a materially different use. A Privacy Policy is a notice, not a request to consent to every use.

This notice is currently available only in English, even though parts of the product interface support other languages. A translated interface does not translate this notice. The English version controls only to the extent local law permits. Questions, rights requests, or complaints: the Help tab or info@mytwinai.me.

See also the Terms of Use.