Privacy Policy for SmileBloom Platform

Last updated: September 15, 2026

This Privacy Policy explains how SmileBloom AI LLC, a Delaware limited liability company, with place of business at 100 Illinois St. Suite 200 Saint Charles, IL 60174, United States of America (collectively, “Company,” “we,” “us,” or “our”), collects, uses, shares, and safeguards personal information in connection with your access to and use of SmileBloom Platform, our mobile applications, websites, products, services, and features (collectively, the “Services”). By using the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please discontinue use of the Services.

Scope and Applicability

This Privacy Policy applies to personal information processed by us in the course of operating the Services. It also applies to personal information we collect from individuals who do not have accounts but interact with the Services (for example, by viewing content, receiving invitations, or contacting us). This Privacy Policy does not apply to information processed by third parties acting independently of us or to information collected in the context of employment or job applications, which may be governed by separate notices.

Information We Collect

When you accept our Terms of Service and Privacy Policy, we record the date and time of acceptance, your IP address, and device/browser information, and retain this record as evidence of your agreement.

We collect information you provide when you create or update an account or profile, such as name, username, handle, display name, email address, phone number, date of birth or age range, profile photo, biography, language, interests, and any other information you choose to include in your profile. An adult account holder may also create a child profile, in which case we collect the child’s name, age, optional phone number, avatar photo, theme, and relationship to the account holder.

Content You Create and Provide

We collect content you post, upload, or otherwise provide through the Services, including text, prompts, stories, images, videos, audio, live streams, voice samples, Stories, captions, comments, messages, drafts, hashtags, tags, mentions, and metadata associated with such content (such as the date, time, and device or app version used to create or upload content).

Direct Messages and Communications

We process messages, chats, comments, and other communications between users, and between you and us, including their content, recipients, timestamps, attachments, reactions, and delivery/read status, as necessary to operate messaging and community features and to enforce our Terms.

Connections and Invitations

If you choose to connect with someone or invite them, you may manually provide that person’s information, including an email address, as described in Data of Non-Users.

Usage and Engagement Data

We collect information about your activity on the Services, such as the accounts and content you view, create, like, save, share, follow, report, or otherwise engage with; the features you use; the time, frequency, and duration of your activities; and inferred interests and preferences based on your interactions.

Device, Log, and Network Data

We automatically collect technical information from and about the devices you use to access the Services, such as IP address, user agent, operating system, browser and app version, device settings, language settings, device and session identifiers, and necessary security, authentication, and diagnostic logs.

Location Information

We approximate general location from your IP address only for security, service operations, and jurisdictional compliance.

Cookies and Similar Technologies

We use only cookies and similar technologies necessary to operate and secure the Services, remember your preferences, and maintain your session. These include the sb_session cookie on the .smilebloom.ai domain with a 30-day sliding expiration, a JWT mirror cookie used by the platform identity service, appearance and locale cookies retained for one year, and other necessary operational cookies. We do not use nonessential measurement or session-replay technologies.

Information from Third Parties

We may receive information about you from other users, including tags, relationship labels, invitations, or content they share; from service providers acting on our behalf; and from anti-abuse or anti-fraud providers.

Payment and Transaction Information

If you make purchases, subscribe to a paid plan, purchase credits or virtual goods, or otherwise engage in a paid transaction, we collect information necessary to process payments, such as name, contact details, payment instrument type (tokenized), transaction amount, currency, timestamps, and limited billing information. We use payment processors, including Stripe, who handle your full payment card details.

Sensitive Categories of Data

We do not solicit sensitive personal information in profiles, prompts, uploads, or chats, and you should not provide it unless it is necessary and lawful for a feature you choose to use. If sensitive information is included in content or otherwise provided, we process it only as necessary to provide, secure, moderate, or comply with law in connection with the Services, and with consent where required. Biometric and voice data are addressed separately below.

How We Use Information

Provide and Improve the Services

We use information to operate, maintain, and improve the Services; create and manage accounts; provide social features and messaging; moderate content; personalize feeds and recommendations; provide customer support; and develop new features.

Safety, Security, and Integrity

We use information to detect, prevent, and respond to spam, abuse, fraud, illegal content or activity, intellectual property violations, and security incidents; to protect users and our Services; and to enforce our Terms and other policies.

Personalization and Recommendations

We use your activity, connections, and device data to personalize your experience, including recommended content, accounts, and topics, and to rank, organize, and surface content in feeds and search results.

Service Communications and Marketing

We use your information to send transactional and service-related communications, such as verification, password-reset, invitation, support, subscription, and safety messages. With your consent where required by law, we may send limited marketing communications about SmileBloom. You may withdraw marketing consent or opt out at any time; we will continue to send communications necessary to provide the Services or complete a transaction.

Product Operations and Quality

We use information to understand use of the Services, monitor service health through necessary operational logs, improve features, and conduct internal quality and safety work. We do not use member data to train third-party AI models.

AI Data Processing

SmileBloom uses third-party artificial intelligence services to provide creative, conversational, moderation, transcription, and media-generation features. Depending on the feature, member inputs—including prompts, photos, voice samples, stories, character descriptions, and chat conversations—are sent to third-party AI providers. When a child profile is active, relevant child-profile information, including the child’s age, prompts, conversations, photos, and generated-story inputs, may be processed through these services as described in Children’s Privacy.

The provider categories are: (a) text generation and chat—OpenAI, including AI character chat and story, screenplay, idea, transcription, and related language features; (b) image generation and avatar creation from photos—Google Gemini/Imagen and fal.ai-hosted image models; (c) voice synthesis and cloning—ElevenLabs; (d) content moderation for child safety—xAI Grok, for moderation of AI replies shown to child profiles; and (e) video generation—fal.ai-hosted video models.

These providers process inputs and outputs under their own terms and privacy practices, subject to SmileBloom’s API agreements and instructions. SmileBloom uses provider APIs and does not use member data to train third-party AI models. SmileBloom’s own use of member inputs and outputs is limited to providing, securing, moderating, and improving the requested Services.

Biometric and Voice Data

With your prior written consent, SmileBloom may collect and process biometric information derived from your creative inputs. When you upload a photo for a 3D avatar or cartoon character, we may derive facial geometry from that photo. When you submit a voice recording for a custom voice, we may derive and process a voiceprint to create a synthetic voice through ElevenLabs. For child profiles, these features may be used only through the controlling adult account and with the consents required by applicable law.

We use facial geometry and voiceprints only to create, operate, and deliver the member’s own creative works on the Services, including avatars, characters, narration, and dialogue. We do not sell or otherwise disclose this information to any third party except the AI processing providers identified in AI Data Processing, solely to provide the requested feature.

Before collection, SmileBloom will provide written notice of the specific purpose and length of time for which facial geometry or a voiceprint will be collected, used, and stored, and will obtain a written release. By selecting the applicable consent box or signing the feature consent form, you provide the written consent and release required for this collection and use. We retain biometric and voice data only until account deletion or your deletion request and will destroy it within three years after your last interaction with the applicable feature, or sooner upon request, subject to limited residual copies securely deleted through our backup processes. You may withdraw consent by contacting us or using applicable feature controls; withdrawal does not affect processing already completed.

Legal Compliance

We use information as required by applicable laws, regulations, legal processes, or enforceable governmental requests, and to establish, exercise, or defend legal claims.

Legal Bases for Processing (EEA/UK/Switzerland)

For individuals in the European Economic Area, the United Kingdom, and Switzerland, we process personal data under the following legal bases, as applicable: (a) contract performance, to create and administer accounts, authenticate members, provide the Services and requested features, process transactions, and respond to support requests; (b) legitimate interests, to protect users, moderate content, prevent abuse and fraud, secure and maintain the Services, enforce our Terms, and perform necessary internal service operations, where those interests are not overridden by your rights; (c) consent, for biometric and voice data, optional marketing communications, non-essential cookies or similar optional processing, and any other processing for which consent is required; and (d) compliance with legal obligations, including responding to lawful requests and maintaining required records. Where consent is withdrawn, we will stop the relevant optional processing unless another lawful basis applies. Processing involving EU children is addressed in Children’s Privacy and GDPR-K provisions below.

How We Share Information

With Other Users

Your profile information, posts, comments, likes, followers, following, and other activity may be viewable by others based on your settings and the nature of the content or feature you use. Direct messages are shared with intended recipients; we do not disclose their contents except as necessary to operate the Services, comply with law, or with your consent. Relationship labels selected by one user about another person are personal information and may be shared with that person in an invitation email and within the Services, including in pending connection or circle flows.

With Service Providers

We share information with vendors and service providers who perform services on our behalf, such as hosting, storage, streaming, security, payment processing, customer support, email delivery, content moderation, and AI processing and generation. These parties are bound by contractual obligations to protect personal information and process it only as instructed, subject to the provider terms and API agreements described in AI Data Processing.

For Safety, Legal, and Compliance

We share information with law enforcement, regulators, government authorities, or other third parties if we believe disclosure is reasonably necessary to comply with law or legal process; to protect our, your, or others’ rights, property, or safety; to investigate or prevent suspected wrongdoing; or to enforce our Terms or policies.

Corporate Transactions

We may disclose or transfer information in connection with any merger, sale, financing, acquisition, reorganization, bankruptcy, or similar event. In such cases, we will take steps to ensure the confidentiality and continued protection of personal information.

With Your Consent or at Your Direction

We share information consistent with your instructions, settings, or when you otherwise consent to or direct us to do so.

International Data Transfers

We operate globally.

Your information may be transferred to, stored in, and processed in countries other than where you live, including the United States, by SmileBloom and service providers such as cloud, payment, email, streaming, and AI-processing providers. Where required, we implement appropriate safeguards for cross-border transfers, including Standard Contractual Clauses, transfer assessments, and other legally recognized mechanisms, and take steps to ensure an adequate level of protection. You may contact us for information about the safeguards applicable to a particular transfer.

Retention

We retain personal information for the following periods, subject to legal holds and other legal obligations: server logs generally for 7 to 30 days, including application logs, platform-event logs, scheduler logs, and access logs; user content, including posts, messages, stories, books, films, and other creative works, until you delete it or your account is purged; media and uploads until deletion or account purge; live-stream recordings for as long as the associated content remains retained, with recordings moved to archival storage after 7 days; legal-acceptance records indefinitely, with personal identifiers anonymized after account deletion; Stripe customer, subscription, and billing records according to Stripe’s policies; and RDS backups on a 7-day rolling basis. We may retain properly anonymized or aggregated information indefinitely.

Your Choices

Account Settings

You can access and update certain personal information through your account settings, including profile details, privacy preferences, and communications choices.

Account Deletion

SmileBloom does not currently offer self-service account deletion. To request deletion, contact us through support or at privacy@smilebloom.ai; we may verify your identity and authority before acting. Staff will process a full account purge, including deletion of content, profiles, child profiles, messages, posts, contacts, groups, TV history, engagement data, journeys, support requests, avatars, credit and usage records, circle memberships, invitations, sessions, device tokens, and associated media, subject to the exceptions below.

After a purge, anonymized legal-acceptance records remain indefinitely, Stripe customer, subscription, and billing records remain subject to Stripe’s retention policies, and server logs remain only within the retention window described above. Rolling backups may retain residual copies for up to seven days, after which they are overwritten in the ordinary course.

Device and Browser Controls

You can manage cookies and permissions for camera, microphone, notifications, and other device features through your device and browser settings.

Marketing Communications

You can opt out of marketing emails by following the unsubscribe link or changing your preferences in settings. We may still send you transactional or service-related communications.

Cookies and Tracking

We use only the cookies and similar technologies described in Information We Collect: the sb_session cookie on the .smilebloom.ai domain with a 30-day sliding expiration, a JWT mirror cookie used for authentication, appearance and locale cookies retained for one year, and necessary operational cookies. These technologies support authentication, security, session continuity, appearance, locale, and core feature operation. We do not use nonessential measurement or session-replay technologies, and disabling necessary cookies may prevent the Services from functioning properly.

Do Not Track and Global Privacy Control

Because our cookies are limited to authentication, security, appearance, locale, and necessary operations, Do Not Track and Global Privacy Control signals do not change our cookie practices.

User Rights

Depending on your location and applicable law, you may have rights regarding your personal information. Under the GDPR, UK GDPR, and similar European laws, these may include access, correction, deletion, restriction, objection, portability, withdrawal of consent, and the right to complain to a supervisory authority. Under the LGPD, these may include confirmation, access, correction, anonymization, blocking or deletion where applicable, portability, information about sharing, and review of certain automated decisions. Under the CCPA/CPRA, these may include the rights to know or access, delete, correct, opt out of sale or sharing, and limit use of sensitive personal information. Other applicable laws, including Canadian, Australian, and Indian laws, may provide access, correction, complaint, consent-withdrawal, or other rights. To exercise your rights, please contact us as described in Contact Us. We will verify your request consistent with applicable law and respond within the time period required by law.

California Privacy Notice

This section supplements the Privacy Policy for California residents and describes how we collect, use, and disclose personal information subject to the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA).

Categories of Personal Information

In the preceding 12 months, we may have collected identifiers (such as name, email address, IP address, and account identifiers), customer records, commercial information, internet or other network activity, IP-derived approximate geolocation, audio and visual content, biometric information such as facial geometry and voiceprints when you use those features, inferences, and sensitive personal information only if voluntarily provided or processed for a feature described in this Privacy Policy. We collect these categories from you, your devices, other users, service providers, and processors for the purposes described in this Privacy Policy.

Disclosures for Business Purposes

We disclose personal information to service providers for business purposes such as hosting, storage, streaming, security, AI processing and generation, content moderation, customer support, email delivery, and payment processing.

Sales and Sharing

We do not sell or share personal information for cross-context behavioral advertising.

Sensitive Personal Information

We do not solicit sensitive personal information. If sensitive personal information is included in content or provided for a feature, including biometric or voice data, we use and disclose it only for purposes permitted by the CCPA/CPRA, applicable law, or your consent.

Rights of California Residents

Subject to certain exceptions, you have the right to request access, deletion, correction, to opt out of sales or sharing, and to limit the use and disclosure of sensitive personal information. We will not discriminate against you for exercising your rights.

Children’s Privacy

SmileBloom supports child profiles for children under 13, but a child profile is not an independent account. A child profile may be created only by a logged-in adult account holder through a parent or guardian’s account, with step-up authentication, and the parent or guardian controls the profile and all activity conducted through it. The child profile cannot sign in independently and cannot access the public social feed, publish books publicly, follow or subscribe to creators, invite users, manage billing, or act as a circle administrator.

For a child profile, we may collect and use the child’s name, age, optional phone number, avatar photo, theme, relationship to the parent or guardian, AI chat prompts and conversations, generated stories, family-scoped posts and messages, and TV preferences and blocks. The child may use the parent’s session to chat with AI characters, create non-public Studio works, save generated stories, post or message within the permitted family or friends scope, and read or watch child-labeled content. Relevant child-profile data may be sent to the applicable AI providers identified in AI Data Processing to provide the requested feature; for child AI chat, conversation inputs may be sent to OpenAI and AI reply outputs may be sent to xAI Grok for child-safety moderation.

The parent or guardian can use the available controls to manage child-profile TV content categories, block videos, creators, or categories, set quiet-time hours for AI-toy speech, control whether the member’s stories may appear on TV, and apply age-based audience gating. We will not condition a child’s participation on providing more personal information than is reasonably necessary for the activity, and we will use child information only to provide, secure, moderate, and support the child-profile features or as otherwise permitted by law.

Where required by the Children’s Online Privacy Protection Act (COPPA), SmileBloom will obtain verifiable parental consent before collecting personal information from a child under 13, maintain that consent, and provide the parent or guardian with notice of the collection and use. A parent or guardian may contact us to review the child’s personal information, request a copy, correct it, withdraw consent, or request deletion. We may verify the requester’s identity and parental authority using information reasonably necessary for that purpose, and we will not require the parent or guardian to disclose more information than is reasonably necessary to verify authority.

For children in the European Union, where processing is based on consent in connection with an information-society service offered directly to a child, SmileBloom will apply the parental-consent requirements of GDPR Article 8. The applicable age threshold is 16 unless the relevant Member State has set a lower age, which may not be below 13. Where the child is below the applicable threshold, we will make reasonable efforts to verify consent or authorization by the holder of parental responsibility, as required by law. Parents and children may exercise applicable data-subject rights, and consent may be withdrawn at any time.

We do not make child profiles publicly searchable, use child-profile personal information for promotional targeting, or disclose it except as necessary to provide the child-profile features, protect safety, comply with law, or as directed by the parent or guardian. Child-profile data is deleted at the parent’s request or when the associated account is purged, subject to the legal-retention provisions described in Retention.

User-Generated Content and Public Information

Content you post may be public depending on your settings and the nature of the feature you use. Public content may be indexed by search engines and accessible by others on and off the Services. You should not post personal information you do not wish to be publicly available. Copies of content may persist in backup copies, cached versions, or may be re-shared by others. Removing a post does not guarantee complete removal from the internet.

Community Safety and Moderation

We use automated systems and human review to moderate content and detect, prevent, and address violations of our Terms and policies. We may remove or restrict content or features, suspend or terminate accounts, and notify law enforcement as appropriate. We also allow users to report content or behavior that may violate our policies.

Automated Decision-Making and Profiling

We may use automated systems, including machine learning models, to help provide and personalize the Services, recommend content, detect spam and abuse, rank and organize feeds and search results, generate content at your direction, and support content moderation, including additional moderation for AI replies shown to child profiles. Where required, we will provide information about the logic involved and the significance and consequences of such processing, as well as your rights to request human review.

Third-Party Links and Services

The Services may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing them your information.

Security

We implement technical, organizational, and administrative measures designed to protect personal information against unauthorized access, destruction, loss, alteration, and misuse. No security measures are perfect or impenetrable, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for all activities under your account.

Data of Non-Users

We may process information about non-users that is provided by our users, including a name, relationship label, or email address entered to send an invitation, or information included in content shared by a user. Members may cause SmileBloom to send invitation emails to email addresses they provide, including addresses belonging to non-members, and we store the invitation recipient’s email address to send and manage the invitation. A relationship label selected by the member may appear in the invitation email and within the Services. If you believe we hold information about you and you do not use the Services, you may contact us at privacy@smilebloom.ai to request access or deletion where applicable.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we do, we will revise the “Last Updated” date and take additional steps as required by law, which may include notifying you through the Services or by other means. Your continued use of the Services after an update signifies your acceptance of the updated Privacy Policy.

Contact Us

If you have questions about this Privacy Policy or our privacy practices, or if you wish to exercise your rights, please contact us at:

SmileBloom AI LLC

Attn: Privacy Office

100 Illinois St. Suite 200

Saint Charles, IL 60174, United States of America

Email: privacy@smilebloom.ai

Jurisdiction-Specific Disclosures

EEA/UK Representative and DPO

SmileBloom intends to appoint a Data Protection Officer and EU and UK representatives when required by applicable law. We will publish their names and contact details in this Privacy Policy or through the Contact Us section once appointed.

Brazil (LGPD)

Individuals in Brazil may have rights under the LGPD, including confirmation of processing, access, correction, anonymization, blocking or elimination of unnecessary or excessive data, portability, information about public and private entities with which data is shared, information about the possibility of refusing consent and the consequences of refusal, revocation of consent, review of automated decisions, and petitioning the National Data Protection Authority (ANPD). Our applicable legal bases may include contract performance, compliance with legal obligations, legitimate interests, and consent for optional processing, including biometric and voice data and marketing where required. You may contact us to exercise these rights.

Canada (PIPEDA and provincial laws)

Individuals in Canada have rights to access and correct personal information and to file complaints with the Office of the Privacy Commissioner of Canada or their provincial authority.

Australia

Individuals in Australia may contact us to access or correct personal information and may lodge complaints with the Office of the Australian Information Commissioner. Where consent is required, we will obtain it expressly or impliedly as permitted by law.

India

We process personal data in accordance with applicable Indian data protection requirements. Where consent is required, we will obtain it and provide mechanisms to withdraw consent.

Additional Platform-Specific Features

Live Streams

If you participate in live streams, your participation, including your profile, voice, video, and interactions, may be publicly visible and recorded by us or other participants. We may use automated and human moderation for safety and integrity.

Virtual Goods and In-App Purchases

Purchases of virtual goods are generally non-refundable except as required by law or as otherwise disclosed. We may display purchase history and balances in your account.

Your Responsibilities

You are responsible for the content you post and for complying with our Terms and community guidelines. Do not post personal information of others without their consent. Respect intellectual property and legal rights of others. Use available privacy controls and report concerns to us.

Effective Date

This Privacy Policy is effective as of the date stated at the top. It supersedes all prior versions. If there is any conflict between this Privacy Policy and any supplemental terms, the supplemental terms will control to the extent of the conflict for the subject matter they address.

Last updated: September 16, 2026