Privacy Policy
Last updated: August 25, 2026
How ShikuAI collects, uses, and protects your personal data, and the rights you have over it under the GDPR.
1. Introduction
This Privacy Policy explains what personal data Thomas Piazzalunga ("ShikuAI," "we," "us," or "our") collects when you use the ShikuAI website, apps, and related services (the "Platform"), why we collect it, who we share it with, and the rights you have over it under the EU General Data Protection Regulation (GDPR) and applicable Italian law.
This Policy should be read together with our Terms of Service, which governs your use of the Platform more broadly.
2. Data Controller
The data controller responsible for your personal data is Thomas Piazzalunga, operating ShikuAI. For any question about this Policy or to exercise your rights, contact [email protected].
3. Personal Data We Collect
3.1 Account data. Email address, username, a bcrypt-hashed password (we never store your actual password, only a one-way hash of it), and your date of birth, which we collect solely to confirm you meet the Platform's 18+ age requirement — see Section 11.
3.2 Profile and social content. Anything you choose to add to your profile — avatar, bio, custom profile CSS, guestbook entries — plus the follows, blocks, favorites, and comments you make on the Platform.
3.3 Characters and chat content. Any character you create (name, personality, scenario, tags, avatar image) and the messages you exchange with characters in chat. Chat messages are the most sensitive data category on the Platform — see Section 5 for how they're processed.
3.4 Payment data. When you buy credits or subscribe to Shiku+, payment is handled entirely by Stripe, our payment processor. We never receive or store your full card number — only a transaction record (amount, date, credit/subscription granted) and the Stripe identifiers needed to manage your subscription.
3.5 Your own connected API key (BYOK). If you connect your own OpenRouter API key to use a custom AI model, it's encrypted at rest before storage and only decrypted server-side at the moment a request is made with it.
3.6 Technical data. Your IP address is processed transiently for rate limiting and abuse prevention (for example, capping how many accounts can be created from one network per day) — see Section 8. Your session is maintained through an authentication cookie.
4. How We Use Your Data
We process your personal data on these legal bases:
4.1 Performance of a contract — to create and maintain your account, generate AI chat replies, process payments, and provide the features you've enabled (e.g. Shiku+ perks).
4.2 Legitimate interest — to prevent fraud and abuse (rate limiting, the age check, our content-safety systems), to secure the Platform, and to enforce our Terms and Content Guidelines.
4.3 Consent — for optional features you actively opt into, such as connecting your own OpenRouter API key.
4.4 Legal obligation — where we need to retain records (e.g. payment records) to comply with tax or accounting law.
5. AI Processing and Third-Party AI Providers
When you send a message to a character, that message — together with the character's definition and recent chat history — is sent to OpenRouter, our AI inference provider, to generate a reply. This is core to how the Platform works and can't be disabled while keeping the chat feature functional.
If you connect your own API key (BYOK), your messages are instead sent using your own OpenRouter account and billed to it directly, rather than through our shared platform key.
We don't use your chat content to train our own models, and we select AI models and providers with reasonable data-handling practices, but once a message is sent for generation it is, by the nature of the feature, processed by that third-party provider under its own terms.
6. Automated Content Safety Systems
Character images are automatically screened by a local image classifier before being stored, and character definitions are checked by an automated text safeguard that blocks explicit content for any character whose own description indicates they're under 18 — regardless of how the character is otherwise configured. Both checks run on our own infrastructure, not through a third party. See our Safety page for how this fits together with human review.
8. International Data Transfers
Some of our service providers (including OpenRouter, Stripe, and Resend) may process data outside the European Economic Area, including in the United States. Where this happens, we rely on the provider's own GDPR-compliant transfer mechanisms, such as Standard Contractual Clauses, to ensure your data remains protected to a standard equivalent to EU law.
10. Data Retention
We keep your personal data for as long as your account is active. If you delete your account, your personal data is deleted immediately, except: payment/transaction records we're legally required to retain for accounting purposes, and any character you published that other users may be chatting with — that character survives with its authorship anonymized (it's no longer linked to you) rather than being deleted, so it doesn't erase other users' chat history with it.
11. Your Rights
Under the GDPR, you have the right to:
Access and portability — download a full export of your personal data at any time from Settings → Data & Account.
Erasure — permanently delete your account and personal data from Settings → Data & Account. This cancels any active Shiku+ subscription before deleting your account.
Rectification — correct inaccurate account or profile data at any time from Settings.
Restriction and objection — ask us to limit or stop specific processing by contacting [email protected].
You also have the right to lodge a complaint with your local data protection authority — in Italy, the Garante per la protezione dei dati personali.
12. Age Requirement and Children's Privacy
The Platform is restricted to users who are at least 18 years old, verified by a self-declared date of birth at registration that is checked server-side. We do not knowingly collect personal data from anyone under 18. If we become aware that an account belongs to someone under 18, we will suspend it and delete the associated personal data.
13. Security
Passwords are stored only as bcrypt hashes, connected API keys are encrypted at rest, and password-reset tokens are single-use, short-lived, and stored only as a hash — never in plain text. No system is perfectly secure, but we design account-sensitive features around these principles rather than storing sensitive values in recoverable form.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date at the top of this page; continuing to use the Platform after a change means you accept the updated Policy.
15. Contact
Questions about this Privacy Policy or how your data is handled? Reach us at [email protected].