Skip to text
Yurimashi logo Yurimashi AI companion
Memory Moments Access Trust FAQ privacy policy terms of use
privacy policy

privacy policy

This privacy policy describes how Yurimashi processes personal data in web pages, clients, account processes, relational memory, vector retrieval, conversation context, real-name and age verification, auditing, certificate depositing, and related support operations.

last updated May 2, 2026
Return to home page Read the terms of use Contact Legal Get started with Yurimashi

Scope and service boundaries

This policy covers personal data processed by Yurimashi when you visit a public website, open or use a console, authenticate through a first-party identity process, request support, or otherwise interact with official Yurimashi services.

This policy does not apply to third-party websites, payment processors, game publishers, community servers or platform operators, which have their own privacy statements, terms of service and security controls.

If you access the service from mainland China, Hong Kong, Singapore or other regions, local mandatory legal requirements may apply in parallel with this policy; Yurimashi will supplement processing or limit relevant capabilities in accordance with local rules to the extent applicable.

Data we collect

Yurimashi only collects data categories that are reasonably necessary to operate, protect, comply with and improve services, and try to avoid processing beyond the scope and purpose.

  • Account and Identity Data. Account identifier, username, role, benefit status, and email, public profile information, or other necessary identifiers returned by the authentication process you choose to use.
  • Real name, age, guardianship and emergency contact data. When required by law, protection of minors, risk management or account security, it may include name, ID number, age determination results, guardian information, emergency contact information, verification results, failure reasons and corresponding disposal records. This type of information is usually sensitive or high-risk personal information, and we will only process it to the extent necessary and adopt stricter controls as a priority.
  • Session and security data. Session identifiers, CSRF status, cookie metadata, token lifecycle events, login timestamps, IP addresses, user agent data, and anti-abuse signals needed to protect accounts and authenticate across subdomains.
  • Device and network data. Browser type, operating system, approximate region, request headers, latency, error codes, and other technical events used for delivery, troubleshooting, compatibility determination, and service hardening.
  • Service activity data. Console operations, configuration changes, audit events, release channel interactions, download events, model invocation events, context stitching results, and product-side events necessary to provide the functionality you use.
  • Relational memory, vectors and contextual data. When the service provides relational memory, long-term preferences, or context continuation capabilities, it may process your actively entered text, tagged summaries, structured memory entries, retrieval hints, embedding vectors, PgVector similarity retrieval results, and context fragments spliced ​​together to send requests to LLM.
  • Support, Complaints and Enforcement Data. Messages, attachments, logs, screenshots, screen recordings, work order information, and case histories that you submit when requesting support, reporting abuse, applying for an appeal, or cooperating with a compliance investigation.
  • Evidence storage and dispute handling data. In the scenarios of complaint reporting, serious violation handling, judicial assistance, rights protection or risk control audit, it may include necessary chat fragments, operation logs, timestamps, account identifications, equipment clues, disposal conclusions and evidence package metadata.

Sensitive personal information and high-risk data

Certain information may be sensitive personal information or high-risk data, such as ID numbers, age determinations, guardianship relationships, emergency contacts, minor-related information, precise disputed materials, CSAM or serious illegal clues, account security incidents, payment disputed materials, and conversation fragments that may reflect personal preferences, emotional states, or the context of intimate relationships.

Yurimashi will only process such information when there is a clear purpose, sufficient necessity, applicable legal basis or your consent, and will adopt stricter access control, encryption, auditing, retention period and post isolation measures.

If a function requires the processing of sensitive personal information, the page, account process or service description may prompt the purpose, necessity, impact and your choices of processing. Refusal to provide certain necessary information may result in the corresponding functions not being provided, the need to switch to protection mode, or the verification being unable to be completed.

  • minimum necessary. We will try to process only the data fields required to achieve real-name verification, age protection, risk handling, evidence preservation, account security or legal obligations.
  • extra protection. For information such as ID numbers, minor protection records, clues to serious violations, and evidence of disputes, stricter keys, permissions, traces, and internal approval controls will be prioritized.
  • Impact Tips. Certain sensitive processing may affect account access, benefit use, content visibility, manual review, law enforcement collaboration, or dispute handling results; we will remain transparent where applicable.

How we use personal data

  • provide services. Create and maintain accounts, authorize access, deliver client and console functionality, and keep your service status consistent across supported interfaces.
  • Operational certification. Run login, logout, session renewal, account recovery, CSRF protection, and other identity processes required to keep access secure.
  • Real name, age and guardianship relationship verification. When the service needs to determine the real-name status, age classification, guardian consent, emergency contact validity or risk handling conditions, perform necessary verification and minimize additional exposure or repeated processing.
  • Prevent abuse. Detect credential abuse, limit malicious traffic, investigate violations, identify dependency risks or red flags in anthropomorphic interactions, and retain logs needed for incident response.
  • User support. Respond to work orders, reproduce issues based on submitted diagnostic information, and communicate important service, account, verification, or security notifications.
  • Improve reliability. Monitor uptime, diagnose regressions, understand failure modes, and make compatibility, performance, and security improvements based on aggregated operational data.
  • Running memory and contextual capabilities. To reduce your burden of repeating context, generate, store, retrieve, and update relational memory summaries, preference fragments, tagged context, or other necessary structured information, and recall them as least necessary in subsequent conversations.
  • Quality, Safety and Audit. In order to discover violations of laws and regulations, risks for minors, risks of self-harm, abnormal dependence, abuse, or improper model output, Yurimashi may conduct automated rule checks, sampling quality inspection, or transfer manual review to the necessary extent on part of the text, vectorization results, search hit fragments, prompt context, or model output.
  • fulfill legal obligations. Comply with lawful requests, retain records when required, handle privacy and consumer requests, and enforce terms of use or other binding policies.
  • Evidence fixation and dispute resolution. Fix, preserve, inspect and issue necessary electronic evidence materials in cases of suspected serious violations of laws and regulations, recharge disputes, infringement complaints, judicial assistance or rights protection.
  • Jurisdictional Compliance. Access, correction, deletion, restriction, withdrawal of consent, data breach response, protection of minors and cross-border transfer matters shall be handled in accordance with the applicable rules of mainland China, Hong Kong, Singapore or other regions.

Automated processing, models and memory boundaries

Yurimashi may use automated rules, risk models, text embeddings, similarity retrieval, LLM inference, classifiers or moderation assistance systems to provide dialogue, memory continuation, content security, account protection, quality improvement and dispute handling capabilities.

Automated processing may affect context recall, risk reminders, functional restrictions, minor protection mode, abnormal login blocking, abuse processing priority, or whether to transfer to manual review. For disposals that will have a significant impact, we will provide channels for appeals, manual review or supplementary explanations to the extent permitted by applicable laws and product capabilities.

Unless otherwise explicitly stated or necessary authorization has been obtained, Yurimashi will not sell your personal conversation content as a public advertising targeting portrait, nor will it share personal data for independent marketing purposes of unrelated third parties.

  • memory boundaries. Relationship Memory is intended to reduce repetitive interpretations, is not a complete record of all conversations, and should not be construed as a formal evaluation of your personality, health, creditworthiness, legal status, or real-life relationships.
  • model context. To generate a response, the service may combine the current input, necessary memory summaries, retrieval hit fragments, system rules, and security prompts and send them to the relevant model or infrastructure for processing.
  • manual review. Authorized personnel will review relevant materials to the extent necessary only when reasonably necessary for safety, quality, support, complaints, violation investigations, protection of minors, legal obligations, or dispute resolution.

Cookies, local storage and authentication status

Yurimashi uses first-party cookies and similar browser storage when necessary to keep sessions secure, persist language or interface preferences, coordinate login status across subdomains, and protect against request forgery, replay, and abuse.

Security-sensitive session handling uses only necessary first-party controls. If the service relies on cookies between related subdomains, these cookies will remain HttpOnly, Secure, and purpose-limited, and will not be used for broad tracking.

After clearing browser cookies, some server-side sessions, device risk signals, account security status, or compliance flags may remain in the background for a necessary period of time. Therefore, clearing cookies does not necessarily equate to deleting your account, withdrawing all consent, or removing all security and legal records.

How data may be shared

Yurimashi may disclose Personal Data to service providers and sub-processors that help deliver the Services, but only to the extent that they have a legitimate operational role and are contractually or operationally bound to protect the data they process.

Yurimashi does not disclose personal data to unrelated third parties for their independent advertising or marketing use.

  • Infrastructure and delivery providers. Provider offering hosting, content distribution, DNS, bot mitigation, and edge security capabilities.
  • Model, vector database and audit related providers. A vendor or underlying capability provider used to host LLM inference, text embedding, PgVector retrieval, risk identification, audit assistance, or quality assessment. In these scenarios, only the text fragments, summaries, vectors, prompt context, risk labels, or event metadata necessary to complete the corresponding processing are shared.
  • Identity and access provider. Provider for running account, login, recovery, session workflows, and necessary identity verification. For example, when two-factor verification of name and ID number is required, Yurimashi may access Alibaba Cloud's relevant capabilities to complete consistency verification, and try to share only the data fields necessary to complete this purpose.
  • Operational tools. Logging, observability, storage, database, caching and customer support systems used to operate the platform.
  • Trusted evidence storage and judicial collaboration provider. In dispute handling, violation evidence fixation, rights protection or judicial assistance scenarios, Yurimashi may use Baidu Smart Cloud Super Chain's trusted evidence storage or judicial evidence storage capabilities to the extent necessary to submit evidence summaries, timestamps, evidence package metadata or necessary documents and materials.
  • Legal and Safety Disclosure. Necessary disclosures to authorities, courts, arbitration institutions, platform partners or other authorized recipients when required by law, major security incidents, protection of minors, anti-fraud, rights relief or public safety.
  • corporate events. If Yurimashi is involved in a financing, merger, acquisition, reorganization or asset transfer, necessary information may be disclosed to a buyer, investor or successor entity, subject to appropriate confidentiality measures.

Keep and delete

Yurimashi retains personal data only as long as reasonably necessary to provide services, keep accounts secure, resolve disputes, comply with legal obligations, and maintain accurate business and security records.

Retention periods depend on the type of record, sensitivity of the data, context of collection, jurisdictional requirements, and whether the record is needed for fraud prevention, auditability, protection of minors, dispute resolution, or legal defense.

  • Account records. Retained while the account or benefit remains active, and for a limited period thereafter as needed for recovery, dispute resolution, consumer complaints, or recordkeeping.
  • security log. Retained only for as long as reasonably necessary to investigate abuse, verify incidents, maintain audit trails, and enforce service protection.
  • Real-name verification and evidence preservation records. Real-name or age verification results, violation handling records, certificate summaries and related evidence materials will be retained for a longer period of time in accordance with legal obligations, dispute resolution, minor protection and risk control.
  • Support records. Retained for continuity, quality control and follow-up, unless legal, regulatory requirements or reasonable requests require earlier erasure or restriction of processing.
  • Memories, Vectors and Audit Records. Relational memory summaries, embedding vectors, search indexes, contextual splicing records, and audit conclusions will be retained for as long as reasonably necessary to achieve corresponding functions, risk control, dispute resolution, or legal compliance, and will be deleted, de-identified, or removed from the online index when no longer necessary.
  • backup. May last for a limited period before being overwritten to comply with disaster recovery, integrity verification, and safe rollback requirements.

security measures

Yurimashi uses layered technical and organizational controls appropriate to the nature of the service, including transport security, scoped access controls, logging, rate limiting, monitoring, least privilege, job isolation, and operational review of account and session events.

No system can guarantee absolute security. Users also play a role by maintaining the confidentiality of credentials, using a supported browser or client, and promptly reporting suspected account abuse.

  • Sensitive identity information protection. Sensitive personal information such as ID numbers will be protected through strict envelope encryption, key isolation and rotation, minimum privilege access, environment-specific isolation and audit traces.
  • Certificate storage and log protection. Evidence packages, timestamps, verification results, risk control logs and judicial collaboration materials will be subject to strict access control based on positions and scenarios, and will be managed hierarchically with regular business data.
  • Memory and audit access control. Access to texts, summaries, vectors, and risk tags used for relational memory, PgVector retrieval, prompt splicing, and review will be restricted in accordance with the principle of least privilege, and unnecessary exposure will be reduced as much as possible through hierarchical storage, key isolation, audit logs, and job separation.
  • Incident response and notification. When a data security incident occurs or is suspected, Yurimashi will identify, triage, contain, investigate, and remediate; and, if required by applicable law, notify or report to affected individuals, regulators, or other authorized recipients.

Additional information on applicable jurisdictions and regions

This policy is based on the laws and regulations of mainland China, and also supplements applicable privacy and data protection requirements for Hong Kong, Singapore and other cross-border processing scenarios.

If applicable law requires us to publish local representatives, data protection contacts, complaint channels, or additional regional information in the future, Yurimashi will update it through first-party websites, support interfaces, or other official channels. Legal, privacy, or compliance questions can also be sent to [email protected].

  • Chinese mainland. Taking the laws and regulations of mainland China as the main axis, it focuses on the protection of personal information, protection of minors, generative artificial intelligence and anthropomorphic interactive service governance requirements.We will handle sensitive or high-risk information such as ID number, age, guardianship relationship, emergency contact, verification results, evidence materials, etc. in accordance with the principles of legality, legitimacy, necessity, integrity, minimum necessity, and openness and transparency.
  • Hongkong. For relevant users or processing scenarios in Hong Kong, we will refer to the Personal Data (Privacy) Ordinance and the guidelines of the Office of the Privacy Commissioner to implement requirements such as collection purpose, use restrictions, security, disclosure, and access and correction.For cross-border scenarios, we will refer to the PCPD’s guidance on cross-border transfers and referral contract clauses to take appropriate contractual and security measures, and will not express the requirements of section 33 that have not yet fully entered into force as established obligations.
  • Singapore. For Singapore-related users or processing scenarios, reference will be made to PDPA’s obligations such as notice, consent, purpose limitation, protection, retention restrictions, cross-border comparable protection, access correction and notifiable data breaches.We will not write a data portability mechanism that has not yet taken effect into a natural right, but will only respond to relevant requests when applicable law gives you this right and the corresponding mechanism has taken effect.
  • International and other regions. For cross-border or international processing scenarios, "international law" is not regarded as a single source of law, but transparency, minimum necessity, safety guarantees, user rights and local mandatory laws are prioritized as the baseline.We may refer to GDPR/EEA style drafting processes for transparency and cross-border safeguards practices, but will not thereby imply that services will of course be fully GDPR compliant.

international transfer

Because infrastructure, delivery, security, identity and support services may operate in multiple regions, personal data may be processed, accessed, backed up or stored outside of your location of residence.

When relational memory, embedding generation, PgVector retrieval, LLM inference, risk identification, or audit assistance is enabled, related text fragments, summaries, vectors, context, or output content may also be processed in regions and vendor environments that support these capabilities.

When it comes to the cross-border provision of personal information from mainland China, if required by applicable law, Yurimashi will supplement consent, impact assessment, contract, certification or other compliance arrangements as required, and will continue to follow the minimum necessary principle.

When it comes to cross-border processing of user data in Hong Kong or Singapore, Yurimashi will refer to the PCPD cross-border transfer guidelines, recommended contract clauses, and Singapore's comparable protection requirements, and combine contract, encryption, access control, and supplier governance measures to reduce risks.

For other international processing situations, Yurimashi will adhere to the principles of transparency, purpose limitation, data minimization, security guarantees and the primacy of local mandatory laws.

Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, restrict, object to or obtain a copy of the personal data held. You may also have the right to withdraw consent where processing relies on consent, without affecting lawful processing before the withdrawal.

Requests should be submitted through the first-party account or support channel provided in the Yurimashi service you use. For formal privacy communication, contact [email protected]. Yurimashi may request additional information when reasonably necessary to verify identity before processing a privacy request.

To the extent permitted by applicable law and product capabilities, you may also request deletion or correction of certain relationship memory entries, preference summaries, or contextual information that you no longer wish to be referenced in subsequent conversations; however, there may be exceptions for records required for security, auditing, evidence preservation, dispute resolution, or legal obligations.

  • Access and Correction. Request a copy of relevant data, understand the underlying circumstances of a use or disclosure, or request that inaccurate account information be corrected.
  • Removal and restriction. Request deletion, cessation of processing or restriction of processing where applicable, subject to security, evidence preservation, protection of minors, legal and contractual exceptions.
  • Objections, withdrawal of consent and portability. Object to certain processing, withdraw consent where permitted by law, or request the export or transfer of data where applicable law gives you this right and the relevant mechanisms are in force.
  • regulatory complaints. If you feel that your rights have not been properly addressed, you may contact the supervisory authority in your jurisdiction or make a further complaint to Yurimashi through official channels.

Children and age sensitive use

Yurimashi is not intended for use by children under the age of independent consent in relevant jurisdictions, nor should it violate local age rules. If Yurimashi learns that personal data from children has been collected in a manner that requires deletion under applicable law, it will take appropriate steps to delete, restrict processing, switch protection modes, or implement other necessary protections.

In accordance with applicable laws and the "Interim Measures for the Management of Artificial Intelligence Anthropomorphic Interactive Services" that will be implemented from July 15, 2026, Yurimashi does not provide virtual relatives, virtual partners and other virtual intimacy services to minors; when necessary, we will take effective measures to identify minors, require guardian consent, switch minors mode, carry out over-dependence reminders, emotional boundary guidance, or take other protective measures.

Complaints, Contact and Formal Privacy Requests

If you have questions about this privacy policy, personal data processing, cross-border transfers, sensitive personal information, protection of minors, automated processing, or rights request results, you may contact [email protected].

Please try to explain your identity, contact information, related account numbers, request type, involved data or functions, factual background and necessary supporting materials. To protect you and other users, Yurimashi may require you to confirm your identity through a first-party account, email verification, or other reasonable means.

For abuse reports, infringement notifications, CSAM, real personal danger or ongoing emergency risks, please use the dedicated reporting portal provided on the page or contact local law enforcement agencies; the privacy mailbox is mainly used for legal, privacy and compliance communications.

  • processing time. We will respond to verifiable requests within the deadlines required by applicable law; requests that are complex, repetitive, overly broad, or require additional material may take longer.
  • Request limits. Certain access, deletion or disclosure requests may be restricted when necessary for security, protection of minors, anti-fraud, dispute resolution, evidence preservation, legal obligations, rights of others, or protection of trade secrets.

Policy updates

Yurimashi may update this Privacy Policy when services, laws, or processing models change. The current version is effective when posted on the official website, unless a later effective date is noted.

Major changes may also be highlighted through first-party service notifications, account messages or other appropriate channels; if local instructions are required due to legal changes in mainland China, Hong Kong, Singapore or other regions, we may also release regional supplementary content simultaneously.

AI companion Yurimashi

Start chatting on WeChat first, and you can connect naturally next time

Browse
Chat memory companionship scene Use the entrance FAQ
law
privacy policy terms of use
Report abuse
Cloudflare official website badge protection Hosted on Cloudflare Pages™ and secured by Cloudflare

© 2026 Yurimashi Development, all rights reserved

Yurimashi is a companion AI and does not constitute legal, medical, psychological crisis intervention, financial or other professional advice

AI answers may be wrong or inappropriate for your specific situation, please do not rely on them as the sole basis for high-stakes decisions

It can currently be used on WeChat, and more entrances will be opened as they are ready.

Do not use Yurimashi to generate, distribute, solicit or facilitate content that is illegal, harmful or infringing upon others

In case of serious violation of the rules, Yurimashi may limit or stop services and retain necessary records as required by law.

To protect accounts and security, some scenarios may require additional confirmation, and relevant information will be processed in accordance with the privacy policy

Use by minors or other high-risk scenarios may be restricted or require guardian consent and additional protective measures.

Third-party brands, trademarks, model names and badges are for identification or capability description only and do not represent their endorsement, authorization or guarantee of Yurimashi

Cloudflare related trademarks and badges belong to the original brands