Data processed
NarraMesh processes account identifiers, profile details, adult-eligibility confirmation, interests, conversations, uploaded media, posts, comments, reports, blocks, purchase entitlements, advertising consent, notification tokens, and limited diagnostics required to operate and secure the service.
Service providers
Firebase provides authentication, database, messaging, analytics, crash reporting, performance monitoring, remote configuration, and app attestation. Vercel hosts the authenticated API. Cloudflare R2 stores uploaded media, and Transloadit processes uploads. OpenRouter and independently configured model providers process prompts and recent chat context. RevenueCat and Google Play process purchases. Google Mobile Ads processes ads and consent choices. Sentry receives privacy-filtered diagnostics.
Controls and retention
Users can report content and AI output, block users, manage ad privacy choices and notifications, and request deletion. Account and content data remains while the account is active and is removed through the deletion workflow, except for narrowly retained safety, fraud-prevention, transaction, legal-claim, or legally required records. Product analytics is retained for no longer than 14 months; crash and API telemetry uses the shortest practical retention configured with each provider. Disappearing-image capture prevention is best effort.
Child safety
NarraMesh is adults-only and prohibits CSAE and CSAM. In-app reports involving children are prioritized for urgent review. NarraMesh complies with applicable child-safety laws and reports apparent CSAM or imminent danger as required. The full public standards are available on the child-safety standards page.