Effective September 2, 2026 · Nonchalant is operated by Premade, LLC, a Florida limited liability company ("Nonchalant," "we," "us") · Privacy contact: privacy@staynonchalant.com · Mailing address: Premade, LLC — 6344 Autumn Berry Cir, Jacksonville, FL 32258-8415
You share a conversation; we turn it into reply suggestions; we don't keep the conversation. Screenshots, pasted text, and any optional situation choice you send with a read are sent over an encrypted connection to our servers and to our AI provider (Anthropic) to generate your suggestions, then deleted from our systems (Anthropic deletes its copies within 30 days — §6 has the details) — nothing you upload is stored long-term, sold, shared for advertising, or used to train AI models. What we do keep is the minimum needed to run your account: your email, your subscription and credit balance, a content-free technical summary of each read, the reply options we generated for you, any optional onboarding or survey answers you choose to give, an optional self-persona writing-style profile, an optional list of short About-me facts you type about yourself, an optional Game Plan objective and preferences (fixed-choice only), any product feedback you choose to send, content-free Practice Trainer control records if you use that feature, and the anti-abuse and age-confirmation records described below. Everything here is AI — no human reads your conversations in the normal course of the service (the single exception: content our automated safety systems flag for legally required review, §9) — and every suggestion you see is AI-generated.
Nonchalant is an AI texting coach. You choose a conversation you are part of and share it with the app as a screenshot or pasted text. The app does not and cannot log into, connect to, monitor, or automatically read Instagram, Tinder, iMessage, or any other platform; it has no access to your accounts on other services; it never sends messages. The only conversation content it ever sees is what you hand it, when you hand it.
| Data | What it is | Kept how long |
|---|---|---|
| Account | email address, password (hashed by our authentication provider), sign-in records | until you delete your account — deleting it erases your account and every sign-in record our own database holds for it (§8; backups purge within 35 days). Our authentication provider also keeps its own service security logs of account activity in its infrastructure, on its own retention schedule (§6, §8). |
| Uploaded conversations | screenshots / pasted text and any optional fixed situation choice you submit for a read, and screenshots you choose to submit to teach your optional "Sounds like me" style profile | not stored: processed, then discarded; the extracted text lives in an encrypted, non-user-readable cache that expires after 1 hour — expired content is never read, and the underlying record is cleared by our scheduled purge. Style-teach uploads skip even that cache: extracted once, distilled into the content-free traits below, then discarded immediately |
| Read results | stage, timing features, verdict — a technical summary that contains no message content | until you delete your account; your readable history is stored on your device only and clears if you delete the app |
| Our suggested replies | the reply options Nonchalant generated for you on paid reads, kept so we can later measure which of our own advice works. Before storing, each line passes the same scrub as the coach's notes: any line echoing the other person's words is dropped entirely, and any detected name or handle is removed. The AI's reasoning prose is never stored. On free-trial reads we keep no reply text at all — server-side storage of our generated replies happens only on paid reads, as described here. | until you delete your account |
| Coaching memory ("coach's notes") | a short, de-identified per-contact summary (stage, patterns, what's been tried) — never messages, screenshots, or the other person's name/handle/photos; deletable per contact in the app. The other person's handle is stored only as a salted one-way hash so repeat contacts are recognized without storing identity; same-name contacts never merge without your confirmation. When you analyze a conversation with a contact the app recognizes (or you confirm), the stored coach's notes for that contact — the same short, de-identified summary described here — and the label you gave that contact are sent along with that read to our AI provider so the advice can build on where things stand; they are covered by the same no-training terms and the provider's deletion window (§6), and the notes never include messages, screenshots, or the other person's name or handle. The label on each saved contact is text you type yourself — many people use a first name. It's your choice; it's shown in your app, it travels with a recognized contact's read as just described (that continuity is what the coach's notes are for), and it's deleted with the contact — the one name a read can carry is the label you typed yourself. | until you delete it — per-contact hard delete anytime |
| 18+ confirmation | the time you confirmed, and which wording you confirmed | life of the account |
| Payments | handled by Stripe (web) and Google Play / RevenueCat (mobile); we receive subscription status, credit grants, wallet balances, credit holds and bucket allocations, debit and settlement records, transaction identifiers, and—while your account exists—which account a provider event belongs to — never your card number | account-linked records remain until you delete your account; content-free provider webhook identifiers can remain for billing bookkeeping without an application-account link; provider-side records follow the provider's own legal and bookkeeping requirements |
| Practice Trainer controls | content-free records needed to run a drill safely and charge it correctly: random session, retry, turn, admission, and reservation identifiers; selected mode and difficulty; authored practice-item identifiers; turn limit and number; deadlines; completion or failure labels; accepted-price, credit-reservation, and settlement fields; provider-start and processing-cost receipts; and timestamps. These records are linked to your account while linked and are service-only. We do not store what you type in a drill, the visible practice thread, prompts, generated replies or grades, a transcript, the other person's identity, or a content digest. | Session, attempt, and reservation rows are deleted with your account and otherwise at or after 24 hours on the next scheduled purge (normally within about five minutes). Short-lived admission and rate-limit rows lose their account link when the account is deleted and are removed on their shorter schedule. Content-free processing-cost records also lose their account link on deletion and are covered by the 90-day Service telemetry row below |
| Referral attribution | if you sign up through a partner's referral link or code: the code you used and which partner referred you, kept for commission bookkeeping | until you delete your account; any commission amounts still owed to the partner survive deletion with the link to you removed (§8) |
| Onboarding answers | optional answers you choose about where you heard about us, what you want help with, how you rate your texting experience, and which built-in coaching voice you prefer (including the resulting default voice order), used to personalize your experience and understand how users find us. These are fixed-choice answers, except for the optional short creator name you may provide after choosing YouTuber/creator. | until you delete your account |
| Cancellation / paywall survey answers | the optional fixed-choice reason you select when canceling or closing a paywall, used to understand why users cancel or decline an offer | until you delete your account |
| Self-persona style profile | an optional "Sounds like me" profile built only from your side of chats: six content-free style traits (typical message length, casing, vocabulary register, slang frequency, punctuation style, and emoji frequency); the cumulative number of your own messages summarized; content-free per-category tallies used to keep those traits representative across eligible reads and any style-teach uploads you choose to submit; your auto-incorporation opt-in status (off unless you turn it on); and, if you use teaching, a content-free daily count of your teach attempts (numbers and dates only, kept 30 days). It never contains vocabulary tokens, screenshots, message text, or the other person's words. | until you delete the profile in the app, which you can do anytime, or until you delete your account |
| About-me profile | an optional list of short facts you type about yourself ("I like video games"), each under a category you pick (work, interests, lifestyle, humor, personality, basics), plus your include-in-suggestions opt-in status (off unless you turn it on). Used only to make your reply suggestions fit your actual life; when About-me is on, your saved facts are sent to our AI provider with each read they apply to (§6). Facts are only ever typed by you — we never infer, import, or extract them from your conversations. We screen every fact and refuse ones that look like contact details, links, phone numbers, or @handles, or that mention health, sexual orientation, religion, politics, or immigration status; the screen is automated and best-effort, so please also keep other people's names and details out of your facts. | until you edit or delete them in the app, which you can do anytime, or until you delete your account; copies sent to our AI provider with a read leave its systems on the §6 schedule (normally within 30 days) |
| Game Plan profile | an optional Player-plan feature: your chosen dating objective and a short set of fixed-choice preferences you tap about yourself (such as the pacing you prefer and the skills you want to practice), used only to calibrate your reply suggestions and the explanations beside them to what you are trying to achieve. Every answer is chosen from options we show you — there is nothing to type, and we never infer, import, or extract any of it from your conversations. When Game Plan is on, your objective and preferences are sent to our AI provider with each read they apply to (§6). | until you edit or delete them in the app, which you can do anytime, even if your plan lapses, or until you delete your account; copies sent to our AI provider with a read leave its systems on the §6 schedule (normally within 30 days) |
| Anti-abuse | a one-way hashed device identifier used to stop free-trial cycling; it is not designed to be reversible into your device identity | life of the account system, independent of your account |
| Feedback | thumbs up/down you give a suggestion, reports you file on a suggestion, and — if you choose to send it — product feedback you write about how the app is working. You can type feedback or speak it using your keyboard's built-in voice typing; either way we receive only the final text, never an audio recording (the app itself has no microphone access). If we grant a small credit thank-you for feedback, we keep a record of that grant with your account. And, if you report an app problem, the fixed problem category you picked and which app (mobile, web, or desktop) you reported it from — never a description you typed, because the bug-report control has no text field. | until you delete your account |
| Service telemetry | per-request processing cost and error logs (reads, style-teach uploads, and Practice Trainer requests) — no message or practice content | rolling 90-day operational window |
| Effectiveness analytics | a content-free record of how our own suggestions performed (see §12 — not yet active) | until you delete your account |
What we never collect: your contacts, your photo library (you pick individual images), your location beyond coarse network-level region used for the access controls in §7, any advertising identifier. There are no advertising networks, no data brokers, and no third-party analytics SDKs in the app. Our product analytics are first-party only — with one disclosed exception: purchase records reach our subscription processor's revenue dashboards (see the processor list, §6): the optional account answers described above and the content-free effectiveness records described in §12 (currently off). Onboarding, cancellation, paywall, style-profile, About-me, Game Plan, feedback, and Practice Trainer control data are stored only in our own Supabase account records, never in a third-party analytics service.
Conversations you upload contain messages written by someone who is not our user. How we handle that is the core of this policy:
We use a small number of service providers, each processing data only on our instructions:
We do not "share" data with third parties in the advertising sense, and transfers to these processors are service-provider transfers under our instructions — which is exactly how they are declared on the Google Play Data safety form.
Nonchalant is offered to United States residents, 18 or older, and served from US infrastructure. Access from the EU/EEA, UK, and sanctioned regions is blocked at the network edge; we do not market to or serve those regions, pricing is USD-only, and this policy is not drafted for GDPR.
California note (CalOPPA): this policy is our conspicuous privacy policy for all users including Californians; material changes are announced per §13; and because we do not track users across third-party sites or services over time, we do not respond to browser "Do Not Track" or opt-out preference signals — there is no cross-site tracking to opt out of.
Cookies and our website: the app contains no advertising or analytics SDKs (§3). Our website (staynonchalant.com) uses only strictly-necessary first-party cookies (sign-in sessions, security, checkout) and similar strictly-necessary first-party browser storage — including a random device identifier that helps prevent free-trial abuse (it identifies the browser profile, never you, and never leaves our systems). If you arrive through a referral link, the referral code is kept briefly in your browser's session storage so sign-up can credit the referrer; it identifies the code, not you, and it is cleared when sign-up completes or after about thirty minutes, whichever comes first. The site runs no session-replay tools, no keystroke or chat capture, no third-party trackers, and no advertising pixels.
We give every user the same controls, regardless of state:
Our deletion promises in §3 and §8 describe our own systems, with the exceptions §8 discloses; this section covers the one that involves the law: retention required by law. Separately, our service providers keep their own copies on their own schedules — our AI provider deletes its copies within 30 days (longer for safety-flagged content, §6), and our authentication provider keeps its own service security logs of account activity — sign-ins, and a record of the deletion itself — in its infrastructure (§6, §8). No provider's schedule is affected by anything you delete here. If we are legally required to preserve specific content — for example, United States law requires providers who obtain actual knowledge of apparent child sexual exploitation to report it to the National Center for Missing & Exploited Children and preserve the reported material for one year — that specific content is moved to a segregated, access-restricted legal hold instead of being deleted, for as long as the law requires, and no longer. Our automated safety screening exists to enforce our own content rules — it is not a program of searching your conversations for reportable material. This preservation duty arises only when that screening, or a user's report, puts specific unlawful content in front of us.
Encrypted transport everywhere; encryption at rest; row-level security so each account can only ever read its own rows; the analysis pipeline runs server-side with least-privilege keys; secrets live in managed vaults, never in the app; payment card numbers never touch our servers. If a breach affects your unencrypted personal information, we will notify you as required by applicable state breach-notification laws (for Florida residents, within 30 days under Fla. Stat. §501.171; other states' timelines as applicable).
Nonchalant is for adults 18+ only. We do not knowingly serve anyone under 18, we do not knowingly collect any child's data (COPPA does not apply to a service that is neither directed to nor knowingly collecting from under-13s — and our floor is 18), and the product refuses analyses involving suspected minors regardless of what anyone confirms. Where an app store provides an age signal under state app-store laws (e.g., Texas), we use it only to enforce the 18+ restriction and for legal compliance — never for advertising or profiling — and we do not retain it beyond that check.
Not yet active: this program is currently switched off, and no effectiveness data is being collected. If we turn it on, it will work exactly as described in this section, and collection will never be retroactive.
We want to know which of our own suggestions actually help, so the coaching gets better. To do that without keeping your conversations, we record a small, content-free summary when you re-read a conversation you previously analyzed:
We'll post changes here with a new effective date. For material changes, we'll notify you in-app or by email before they take effect, and where a change materially expands what we collect or how we use it, we will ask for fresh consent rather than rely on continued use. We do not begin collecting a newly disclosed stored category before the amended policy takes effect.