TWINii Privacy Policy
Twin Inc Ltd (Company No. 16656477)
Registered in England & Wales. Registered office: 20 Wenlock Road, London N1 7GU, United Kingdom.
Last Updated: 11 May 2026
TWINii Privacy Policy (Global + Regional Disclosures)
0. Summary
We collect only the data needed for TWINii to work: to run the service, personalise your experience, attribute purchases, pay Experts, protect our community, and improve the product. We are transparent about how AI, affiliate links and partners like Kindred are used. You control your data rights. We do not train public models on your private conversations with TWINiis without your consent.
1. Who We Are and How to Contact Us
Twin Inc Ltd ("TWINii", "we", "us") is the data controller for personal data used in our consumer services. If you have questions about your data or this policy, you can contact us at [email protected]. When an Expert or brand uses TWINii under a commercial agreement and instructs us how to handle personal data, we act as their data processor under a Data Processing Addendum (DPA).
2. Data We Collect
2.1 Account & contact data: Information you provide such as your name or handle, email, age band or date of birth, country, language, and device identifiers.
2.2 Usage & content data: Activity from your time on TWINii, including chats with TWINiis, prompts, posts, likes, follows, search queries, session telemetry, crash logs, and moderation flags.
2.3 Technical data: Information used to deliver and secure the service, such as IP address, device/OS/browser details, app version, referrer, and cookie or SDK identifiers.
2.4 Commerce & affiliate data: Click-throughs on product links, cart and purchase events, pseudonymous order IDs, and store receipts or tokens used to issue rewards or pay Experts.
2.5 Subscription & in-app purchase data: When you subscribe to TWINii or purchase a Boost or other in-app product, Apple or Google process your payment and share with us limited transaction data, such as a pseudonymous transaction ID, receipt or token, product identifier, country, and renewal status. We do not receive your card details, full billing address or Apple/Google account credentials.
2.6 Expert assets: For Experts, the likeness, voice, name, branding, prompts and instructions you provide so we can operate your verified TWINii.
2.7 Optional or sensitive data: Facial imagery and skin metrics for virtual try-on, and any health-related concerns you choose to share in chats. We only process this with your explicit consent where required by law, and you may withdraw consent at any time.
2.8 Voice & conversational data: When you choose to speak with a TWINii, we capture your voice audio on-device and transmit it to our voice AI provider for real-time speech-to-text transcription. Voice audio is not stored after transcription. Transcribed text and conversation context are transmitted to our LLM provider to generate the TWINii's response.
2.9 Inferences: Interest segments, predicted preferences and other insights we generate from your activity to personalise recommendations.
3. Purposes and Legal Bases
3.1 Provide and secure the Services (contract; legitimate interests). Examples: create your account; authenticate; safeguard; prevent fraud; debug.
3.2 Personalisation and recommendations (legitimate interests; consent where required for cookies/ads). Example: ranking product suggestions.
3.3 Affiliate attribution and payouts (contract/legitimate interests). Example: sending pseudonymous click/purchase events to Partner Networks such as Kindred.
3.4 Subscription and in-app purchases (contract). Example: confirming your subscription is active, applying Boost purchases to your account, monitoring fair usage limits.
3.5 Communications (consent; legitimate interests for service emails). Example: send service announcements; obtain feedback.
3.6 Marketing (consent in the EEA/UK; soft opt-in for existing customers where allowed). Example: email newsletters you subscribe to; you may opt out at any time.
3.7 Safety and integrity (legal obligation; legitimate interests). Example: detect harmful content; respond to rights requests; comply with law.
3.8 Research and product improvement (legitimate interests). We may use de-identified or aggregated data to improve features.
3.9 AI training and evaluation. We may use de-identified or aggregated data to improve our models. We do not train public models on your private one-to-one conversations with TWINiis without your consent.
4. Sharing of Personal Data
4.1 Service providers (processors): Hosting, storage, analytics, messaging, payment, age-assurance, fraud prevention, content moderation and customer support providers acting under our instructions.
4.2 Partner Networks and retailers: We share pseudonymous identifiers and event data to attribute sales and calculate commissions (e.g., Kindred). We do not share raw chat content for this purpose.
4.3 Platforms and APIs: If you choose to sign in with another platform (for example, an identity provider offering single sign-on), that provider processes your data under its own terms and policies.
4.4 Apple and Google: When you subscribe or make an in-app purchase through Apple or Google, those platforms process your payment and share with us limited transaction data as set out in Section 2.5. Their handling of your data is governed by Apple's and Google's own privacy policies.
4.5 Business transfers: If TWINii undergoes a reorganisation, merger or sale, your data may transfer to the successor entity subject to this Policy.
4.6 Legal and safety: We may disclose data to authorities or others where necessary to comply with law or protect individuals.
4.7 Public or shared content: Content you publish publicly may be visible to others; please consider this before sharing.
4.8 Third-party AI service providers: To deliver the conversational TWINii experience, we share limited user data with third-party AI service providers acting as our processors. These fall into two categories:
(a) Large language model (LLM) providers receive the text of your messages and relevant conversation context in order to generate the TWINii's response. They do not receive your name, email or other directly identifying account data.
(b) Voice AI providers receive voice audio when you speak with a TWINii, for the sole purpose of real-time speech-to-text transcription and, where applicable, voice synthesis of the TWINii's reply. Voice audio is not retained after transcription.
We only work with AI providers that operate under enterprise data-processing agreements which (i) prohibit the use of your data to train their public models, (ii) require encryption in transit, (iii) restrict data retention to what is necessary to deliver the service, and (iv) provide data-protection standards equivalent to our own. You may request further information about the specific providers we use at any time by emailing [email protected].
When TWINii integrates with third-party platforms (for example, identity providers for single sign-on, analytics providers, or affiliate networks such as Kindred), data is processed solely within the scope of those partners' Platform Terms and Developer Policies. TWINii does not store or reuse partner data beyond the permitted purposes.
5. International Data Transfers
Where we transfer personal data outside the UK or EEA, we rely on the EU Standard Contractual Clauses (2021/914) and/or the UK International Data Transfer Addendum, and apply supplementary measures where appropriate, including encryption in transit, access controls and vendor due diligence.
6. Retention
We retain data only as long as necessary for the purposes described.
6.1 Account and profile data: Life of account plus up to 24 months.
6.2 Chats and content logs: 12 months by default unless you delete them sooner or we need to retain them for safety or legal reasons.
6.3 Commerce and affiliate events: Up to 7 years for tax and audit requirements.
6.4 Subscription and in-app purchase records: Up to 7 years for tax and audit requirements.
6.5 Expert assets: As specified in the Expert Agreement or until access is revoked, with archival copies kept only for legal holds.
6.6 Security logs and breach records: Retained as required by law and industry practice.
6.7 Voice audio: Not retained after real-time transcription. Only the resulting text transcript is stored as part of your conversation history.
7. Your Rights
Your privacy rights depend on where you live.
7.1 UK/EEA rights: You have the right to access, rectify, erase, restrict processing, object, request data portability, and withdraw consent at any time. You may also object to profiling or automated decision-making that has legal or similarly significant effects.
7.2 US state rights (CPRA/Colorado/Connecticut/Virginia): You have the right to know, access, delete, correct, and opt out of the sale or sharing of personal data and of targeted advertising. We provide a "Do Not Sell or Share My Personal Information" mechanism for applicable users.
7.3 Appeals: If we deny a request, you may appeal and we will explain the outcome.
7.4 Regulators: You can complain to the UK ICO or your local data protection authority.
8. Children
8.1 The Services are not intended for children under 18.
8.2 We may apply age-assurance measures and limit features for accounts believed to be under the applicable age, and we will delete children's data on verified parental requests.
8.3 We may use face-scan or age-assurance technology to help confirm eligibility and apply youth-safety measures. Verification is triggered only when risk or legal thresholds require it, and no raw facial imagery is retained.
9. Cookies and Similar Technologies
9.1 We use cookies and SDKs for functionality, analytics, fraud prevention and ads measurement.
9.2 In the EEA/UK we obtain consent through a consent-management platform (CMP) aligned with the IAB TCF, and you can change your preferences at any time.
9.3 Some features may not function without certain cookies or SDKs.
10. Security of Personal Data
10.1 We implement appropriate technical and organisational measures, including TLS encryption in transit, access controls, secret management, least-privilege permissions, event logging, regular reviews, short-lived authentication tokens and vulnerability management.
10.2 No system is 100% secure, but we work to protect your data and limit risk through layered safeguards.
10A. Security Incidents and Breach Notification
10A.1 If we become aware of a personal-data breach that is likely to result in risk to individuals, we will notify the relevant supervisory authority within 72 hours where required by law.
10A.2 We will notify affected users without undue delay when the breach is likely to result in a high risk to their rights or freedoms.
10A.3 We maintain incident and breach logs for audit, security monitoring and legal compliance.
11. AI Transparency
11.1 TWINii is an AI-powered service. Conversations with TWINiis are generated by third-party large language model (LLM) providers, and voice interactions are processed by third-party voice AI providers (for speech-to-text transcription and voice synthesis). Before your first conversation, we present an in-app disclosure explaining what data is sent, to which categories of providers, and ask for your explicit consent to proceed.
11.2 Data we share with third-party AI providers is limited to what is necessary to generate the TWINii's response: the text of your messages, relevant conversation context, and (when you speak) voice audio for transcription. We do not share your name, email, payment details or other directly identifying account data with these AI providers.
11.3 We label AI-generated or AI-manipulated media where feasible and may use cryptographic watermarks or metadata to signal provenance.
11.4 We disclose when content is sponsored or includes affiliate links.
12. Affiliate & Partner Network Disclosure (Kindred)
12.1 We partner with networks such as Kindred; some offers may carry affiliate status or result in commission to us and/or you.
12.2 We do not endorse the underlying products or services. Always review the product's instructions, safety labels and Terms & Conditions before purchase.
12.3 Data shared for attribution is pseudonymous and limited in scope.
13. Exercising Your Rights; Contact
13.1 You can submit rights requests by emailing [email protected].
13.2 We may need to verify your identity before completing your request, and you may appoint an authorised agent where permitted by law.
13.3 We will respond within the applicable statutory timeframe.
13.4 EU/UK representative and DPO details will be published here when appointed.
14. Region-Specific Disclosures
14.1 California (CPRA): We disclose categories of personal information collected, the purposes of use and sharing in this Policy. You may opt out of sale/share and targeted advertising, and you will not be discriminated against for exercising your rights. An appeal process is available.
14.2 Colorado, Connecticut, Virginia and Utah: Similar rights apply in these states, and we honour them as required.
14.3 EEA/UK: Our lawful bases are set out in Section 3. You may lodge a complaint with the UK ICO (ico.org.uk) or your local supervisory authority.
15. Changes to this Policy
15.1 We may update this Policy from time to time. We will post updates on this page and provide reasonable notice of material changes before they take effect.
15.2 Continued use of the Services after the effective date of an updated Policy constitutes acceptance of the changes.
15.3 The effective date will be shown at the end of this document.
Effective Date: 11 May 2026