1. Who is responsible for your data
The controller of the personal data described in this policy โ the "organisation" for the purposes of the Singapore Personal Data Protection Act 2012 (PDPA) and the "controller" for the purposes of the EU and UK General Data Protection Regulation (GDPR) โ is:
Culturetek Pte. Ltd.
UEN 202411392W
6 Raffles Quay #14-02
Singapore 048580
Email: hello@linanoa.com
This policy explains what personal data we collect when you use linanoa.com, the members area at /app/ and the real-time voice and chat experience at api.linanoa.com/lab/ (together, the "Service"), why we collect it, on what legal basis, who we share it with, how long we keep it, and what rights you have.
No Data Protection Officer is appointed at the date of this policy, and whether one must be appointed for this Service is under review with our advisers โ we would rather tell you that than claim an exemption we have not confirmed. Until one is named here, you can raise any data protection matter, including any of the rights in section 11, directly with us at hello@linanoa.com, and we will handle it ourselves and within the statutory deadlines. The same applies to our representatives in the EU under GDPR Art. 27 and in the UK under UK GDPR Art. 27: their appointment is in progress, and their names and addresses will be published here as soon as they are in place. In the meantime, addressing a request to the email above has exactly the same effect.
2. What data we collect
a) Account data
Your email address, your password (stored only as a salted cryptographic hash โ we never see or store it in readable form), your display name or chosen nickname if you provide one, your account status, subscription plan and settings, and the date you registered.
b) Payment data
Your subscription and payment history, plan, renewal date, currency and amounts, the country you gave for billing and tax purposes, and a payment reference or token supplied by Stripe. Full card numbers, CVC codes and bank credentials are entered directly into Stripe's own systems and never reach us. We receive only limited information such as the card brand, the last four digits, the expiry date and the outcome of the transaction. See section 5.
c) Conversation content
The chat messages you write, the messages generated by the AI in reply, requests you make for voice or video messages, and the resulting generated audio and video. Because Lina is a companionship product, conversations may contain information about your feelings, relationships, health, beliefs or intimate life. Depending on what you choose to write, that may amount to special category data under GDPR Art. 9 (for example data concerning health, sex life or sexual orientation, religious or philosophical beliefs). See section 4 for how we handle this.
d) Memory and personalisation data
Summaries, facts and preferences derived from your conversations, which the Service stores so that Lina can refer back to earlier exchanges, remember what matters to you and personalise the daily check-in. You can view and delete this memory as described in section 11.
e) Microphone audio (live experience)
If you use the real-time voice and chat experience, your browser will ask for permission to access your microphone. While a live session is running, the audio captured by your microphone is streamed to our servers and to the AI providers that generate the real-time response, and is transcribed to text so the system can reply. Your browser shows a recording indicator while this is active, and you can end the session or revoke the permission at any time in your browser settings. Live microphone audio is processed transiently and is not stored. The audio is held in memory only for as long as it takes to transcribe it and generate a reply, and is then discarded โ we do not keep raw audio recordings of your live sessions, and neither our AI providers nor we build a voice profile from them. The text transcript is treated exactly like the rest of your conversation content and is covered by section 9.
f) Usage and technical data
Your IP address, approximate location derived from it at country level, device and browser type, operating system, language setting, referring page, the pages and features you use, timestamps, error and diagnostic logs, and the identifiers stored in cookies or similar technologies. Our servers create access logs automatically as an inherent part of delivering a website.
g) Correspondence
Messages you send to hello@linanoa.com or through any contact or support form, and our replies.
h) Cookies and analytics
See section 8.
3. Why we use your data and on what legal basis
Where the GDPR applies, we rely on the legal bases in Article 6(1) set out below. Where the Singapore PDPA applies, we rely on your consent or on the exceptions permitted under the PDPA, including performance of a contract with you and legitimate interests under the First Schedule.
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Creating and administering your account; authenticating you | Account data, technical data | Art. 6(1)(b) โ performance of a contract |
| Delivering the Service: generating chat, voice and video responses, the memory feature and the daily check-in | Conversation content, memory data, account data | Art. 6(1)(b) โ performance of a contract |
| Running the real-time voice experience | Microphone audio, transcripts | Art. 6(1)(b) โ performance of a contract; browser microphone permission is obtained separately |
| Processing payments, renewals, refunds and chargebacks | Payment data, account data | Art. 6(1)(b) โ performance of a contract; Art. 6(1)(c) โ legal obligation (accounting, tax) |
| Keeping accounting and tax records | Payment data | Art. 6(1)(c) โ legal obligation |
| Handling your support enquiries | Correspondence, account data | Art. 6(1)(b) and Art. 6(1)(f) โ legitimate interest in responding to users |
| Safety, moderation, age assurance, fraud and abuse prevention, enforcing our Terms | Conversation content, technical data, account data | Art. 6(1)(f) โ legitimate interest in a safe and lawful service; Art. 6(1)(c) where legally required |
| Securing and maintaining our systems; diagnosing faults | Technical data, logs | Art. 6(1)(f) โ legitimate interest in network and information security |
| Measuring and improving the Service; analytics | Usage data, cookie identifiers | Art. 6(1)(a) โ consent, where analytics cookies are used; otherwise Art. 6(1)(f) |
| Sending service messages about your subscription, renewals and changes to these documents | Account data | Art. 6(1)(b) and Art. 6(1)(c) |
| Sending marketing email about the Service | Account data | Art. 6(1)(a) โ consent; you can withdraw at any time |
| Establishing, exercising or defending legal claims | As relevant | Art. 6(1)(f) โ legitimate interest in legal protection |
4. Sensitive information in your conversations
Because of the nature of the Service, you may choose to tell Lina things that are highly personal. Please share only what you are comfortable having processed by an AI system and stored on our infrastructure.
Where you voluntarily provide information that constitutes special category data under GDPR Art. 9 โ for example about your health, your sex life or sexual orientation, or your religious or philosophical beliefs โ we process it on the basis of your explicit consent under Art. 9(2)(a), given by choosing to enter that information into a companionship service whose purpose is to discuss personal matters, or, where relevant, on the basis of Art. 9(2)(f) for legal claims. You can withdraw that consent at any time by deleting the relevant content and your memory data, or by closing your account.
Under the Singapore PDPA, we handle such content with a correspondingly higher standard of care and access restriction.
We do not use conversation content to build advertising profiles, we do not sell it, and we do not disclose it to third parties other than the processors listed in section 6 and where required by law.
Your conversations are not routinely read by anyone at Culturetek. No human being monitors your chats, and we do not read them for curiosity, quality-scoring, marketing or training. A very small number of authorised staff can access conversation content only where it is strictly necessary in a specific case โ to investigate a credible safety risk or a report of abuse, to fix a fault you have reported to us, or to comply with a binding legal order. Every such access is limited to what is actually needed, is logged, and is subject to confidentiality obligations. Our AI providers process the content only to generate your reply and are contractually prohibited from reading or using it for their own purposes.
5. Payments โ Stripe
Payments are processed by Stripe (Stripe, Inc. and its group companies, including Stripe Payments Europe, Ltd. for customers in Europe).
When you pay, your card or bank details are collected directly by Stripe through its own hosted payment interface. Culturetek never receives, sees or stores your full card number, CVC or bank credentials. Stripe acts as an independent controller in respect of the payment data it collects for fraud prevention, regulatory and anti-money-laundering purposes, and as our processor in respect of the subscription data it manages on our behalf.
We receive from Stripe only what we need to run the subscription: a customer and subscription identifier, the plan, amount and currency, the payment status, the card brand and last four digits, the expiry date, the billing country, and refund or dispute status.
Stripe's own privacy notice explains how it handles your data: stripe.com/privacy.
6. Service providers and sub-processors
We use a small number of specialist providers to run the Service. They act as our processors, may only process personal data on our documented instructions, are bound by written data processing agreements including the confidentiality and security obligations required by GDPR Art. 28, and may not use your data for their own purposes.
The following list is complete as at our last review on 18 July 2026. We compiled it by auditing the external calls the website, the API and the live experience actually make, rather than by listing categories we assume we might one day use. These are the external services the Service calls as at that date. We review the list whenever a provider is added or removed, and we update this policy when it changes โ so if you are reading this long after that date, ask us and we will confirm the current position.
| Provider | Purpose | Primary region |
|---|---|---|
| Stripe | Payment processing, subscription billing, fraud prevention | United States / Ireland (EU) |
| Hostinger | Website and server hosting; outbound email (smtp.hostinger.com) | European Union (Lithuania) |
| OpenAI | Language model powering Lina's chat replies | United States |
| ElevenLabs | Speech synthesis โ Lina's voice | United States |
| Anam | Real-time interactive avatar in the live experience (api.linanoa.com/lab/) | United States |
| HeyGen | Avatar video generation | United States |
| fal.ai | AI video generation | United States |
| GeoJS | IP-to-country lookup for the automatic language redirect | United States |
| esm.sh | Content delivery network โ delivers the Anam avatar software to your browser in the live experience | United States |
GeoJS receives your IP address before any consent โ we would rather say so plainly. Every page of the public website requests get.geojs.io as it loads, so that we can offer the site in your language. Because that request is made by your browser, your IP address reaches GeoJS on your very first page view, before you have interacted with the site and before any consent could be obtained. GeoJS returns only a country code. No cookie is set, no identifier is stored, and the result is not used to profile you or to recognise you again. Our legal basis is our legitimate interest in serving the site in the right language (GDPR Art. 6(1)(f)); you may object at any time under section 11, and the site works normally if the lookup fails.
esm.sh applies only to the live voice and avatar experience. When you open that experience, your browser loads the Anam avatar software from esm.sh, a content delivery network. Ordinary pages never contact it. As with any request your browser makes to any server, esm.sh necessarily receives your IP address in order to return the software โ but it is a code-delivery network, not a tracking service: no cookie is set, no identifier is stored, and nothing about you is profiled. We rely on the same legitimate interest as above, in delivering the software the experience needs to run.
So that this list can be checked rather than taken on trust, these are the endpoints involved: the public website calls GeoJS and nothing else; the application server calls Stripe, OpenAI, ElevenLabs, HeyGen, fal.ai and the Hostinger mail server; and the live interactive avatar calls Anam, OpenAI, ElevenLabs and esm.sh. No other external service is called by the Service.
The seven providers we hold a contract with โ Stripe, Hostinger, OpenAI, ElevenLabs, Anam, HeyGen and fal.ai โ are each bound by a written data processing agreement and are contractually prohibited from using your conversations or your content to train their own models. GeoJS and esm.sh are different: they are free, public endpoints that your browser contacts directly, and we hold no contract with either. That is precisely why we set out above exactly what each of them receives and why. No third-party analytics, advertising or tracking provider appears in this table, because we use none.
A per-provider list of processing locations is available on request at hello@linanoa.com.
We may also disclose data to professional advisers, auditors, or to public authorities and courts where we are legally obliged to do so, and to a purchaser or successor in the event of a merger, acquisition or transfer of the business โ in which case we will notify you and this policy will continue to apply until replaced.
We do not sell your personal data and we do not share it with advertising networks or data brokers.
7. International transfers
We are established in Singapore, and our providers operate in a number of countries. Your personal data will therefore be transferred to, stored in and processed in countries outside your own โ which, for users in the European Economic Area or the United Kingdom, means outside the EEA/UK.
Where we transfer personal data out of the EEA or the UK to a country that has not been recognised by the European Commission or the UK government as providing an adequate level of protection, we rely on appropriate safeguards under GDPR Chapter V โ principally the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), together with the UK International Data Transfer Addendum where the UK GDPR applies, and, where a transfer risk assessment shows it to be necessary, supplementary technical and organisational measures.
Where the Singapore PDPA applies, we comply with the Transfer Limitation Obligation in section 26 of the PDPA and Regulation 10 of the Personal Data Protection Regulations 2021 by taking appropriate steps to ensure that overseas recipients are bound to a comparable standard of protection.
You may request a copy of the safeguards we rely on by writing to hello@linanoa.com.
Because we are established in Singapore and use providers established elsewhere, your data is processed outside the EEA and the UK. We can confirm that processing takes place in Singapore (Culturetek itself), in the European Union and other regions used by our hosting provider, and in the countries in which our payment and AI providers operate, which include the United States. Where data leaves the EEA or the UK we rely on the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, and on an adequacy decision where one covers the provider in question. Section 6 sets out our sub-processors by name; a per-provider list of processing locations is available on request at hello@linanoa.com.
8. Cookies, similar technologies and analytics
We keep this deliberately simple: the Service uses only strictly necessary first-party browser storage. We do not use analytics, advertising or cross-site tracking technologies at all.
- Strictly necessary storage โ we use your browser's local and session storage to keep you signed in to the members area, to remember your language choice, to remember your saved practice preferences, and to avoid repeating the same welcome message in one visit. These are set by us, are required for the Service to work, and are not used to profile you or to follow you across other websites.
- No analytics, no advertising, no tracking โ we do not use Google Analytics or any comparable analytics or error-monitoring product, we do not use advertising or retargeting pixels, we do not embed social network tracking, and we do not sell or share any data for advertising. Our servers keep ordinary access logs, described in section 2(f), retained as set out in section 9.
Because we set only strictly necessary storage, no cookie consent banner is legally required under the ePrivacy Directive as implemented in the EU and the UK, and we do not show one. We would rather state that plainly than imply a consent mechanism we do not have. If we ever introduce analytics or any other non-essential technology, we will update this policy and put a compliant consent mechanism in place before switching it on.
Third-party requests you should know about. The public website asks a third-party IP geolocation service, geojs.io, for your approximate country so that it can offer you the site in your language. That request discloses your IP address to that service. It happens on the public pages only โ not inside the members area. Separately, when you go through checkout, Stripe sets its own cookies for payment processing and fraud prevention; see Stripe's own privacy policy and section 5 of this policy.
You can clear or block browser storage at any time in your browser settings, though blocking strictly necessary storage will stop you from staying signed in.
9. How long we keep your data
We keep personal data only for as long as necessary for the purposes described above, and then delete or irreversibly anonymise it.
| Data | Retention |
|---|---|
| Account data | For as long as your account is open. If you ask us to delete your account, it is deleted within 90 days of that request |
| Conversation content and memory data | Until you delete it, or until 12 months after your subscription ends โ whichever comes first. If you close your account, it is deleted within 90 days |
| Generated voice and video messages | Deleted together with the conversation they belong to, or as soon as you delete them, and in any event within 90 days of account closure |
| Live microphone audio | Not retained. Processed transiently in memory and discarded โ see section 2(e) |
| Live session transcripts | Treated as conversation content, on the same basis as the row above |
| Payment and invoice records | Retained for the statutory accounting and tax period โ in Singapore generally five years under the Income Tax Act and the GST Act; longer where another applicable tax law requires it |
| Server and security logs | 30 days |
| Support correspondence | 24 months |
| Records needed for legal claims, or of accounts terminated for serious breach | Until the relevant limitation period expires |
Backups are rotated and overwritten on a 30-day cycle. Deleted data can therefore still exist in backup media for up to 30 days after it disappears from the live system, and is permanently gone at the end of that cycle.
10. Automated processing and AI
Lina's replies are produced by automated AI systems without human intervention. This is the core function of the Service rather than a decision about you, and it does not produce legal effects concerning you or similarly significantly affect you within the meaning of GDPR Art. 22.
We use automated filters to detect prohibited content, abuse and attempts to circumvent age or safety restrictions. If such a filter contributes to a decision to restrict or terminate an account, you can ask for the decision to be reviewed by a person, express your point of view and contest the outcome, by writing to hello@linanoa.com.
We do not use your data to train AI models. Your conversations, your memory data and your generated voice and video content are not used to train, fine-tune or evaluate any AI model โ neither ours nor any provider's โ and our agreements with our AI providers prohibit them from using the data we send for their own training. If we ever wished to use conversation data for model training, we would ask for your explicit opt-in consent first, and you would be free to refuse without losing access to the Service.
11. Your rights
Subject to the conditions and exceptions in the applicable law, you have the following rights.
Under the GDPR (EU / UK users):
- Access (Art. 15) โ to be told whether we process your data and to receive a copy of it.
- Rectification (Art. 16) โ to have inaccurate data corrected and incomplete data completed.
- Erasure (Art. 17) โ to have your data deleted, for example when it is no longer needed or you withdraw consent.
- Restriction (Art. 18) โ to have processing limited in certain circumstances.
- Portability (Art. 20) โ to receive the data you provided in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible.
- Objection (Art. 21) โ to object at any time to processing based on legitimate interests, and absolutely to any processing for direct marketing.
- Withdrawal of consent (Art. 7(3)) โ to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
- Not to be subject to automated decision-making (Art. 22) โ see section 10.
Under the Singapore PDPA: you have the right to request access to personal data we hold about you and information about how it has been used or disclosed in the past year (s. 21), the right to request correction (s. 22), and the right to withdraw consent to the collection, use or disclosure of your personal data (s. 16) โ noting that withdrawing consent necessary to provide the Service will mean we can no longer provide it.
How to exercise your rights
Many actions are available directly in the members area at /app/ โ you can edit your account details, view and delete memory entries, delete conversations, and close your account.
For anything else, email hello@linanoa.com from the address registered to your account, stating clearly what you are asking for. We will respond within one month as required by GDPR Art. 12(3) (extendable by two further months for complex requests, in which case we will tell you), and within 30 days as required by the PDPA. We may need to verify your identity before acting, and we will not charge a fee unless a request is manifestly unfounded or excessive.
Complaints
If you believe we have handled your personal data unlawfully, please contact us first โ we would like the chance to put it right. You also have the right to complain to a supervisory authority:
- EU users: the data protection supervisory authority of the EU member state where you live, work, or where you believe the infringement took place (GDPR Art. 77). A list is published by the European Data Protection Board at edpb.europa.eu.
- UK users: the Information Commissioner's Office, ico.org.uk.
- Singapore: the Personal Data Protection Commission, pdpc.gov.sg.
12. Children
The Service is for adults aged 18 and over only. It is not directed at children, and we do not knowingly collect personal data from anyone under 18.
If we learn that we hold personal data relating to a person under 18, we will delete it without undue delay and close the associated account. If you are a parent or guardian and believe a minor has provided us with personal data, contact us at hello@linanoa.com and we will act promptly.
At sign-up you must confirm that you are 18 or over, and the requirement is set out in the Terms. We treat a successful adult payment method as a further signal. We do not currently operate third-party age verification, and we are not going to imply otherwise. We do not knowingly allow anyone under 18 to use the Service: where we become aware of, or have reasonable grounds to suspect, an under-18 account, we suspend it immediately, delete the associated conversation data, and refund any unused part of the subscription. If you believe a minor is using the Service, tell us at hello@linanoa.com and we will act on it. Where a market we sell into requires stronger age assurance than self-declaration, we will put that in place before continuing to sell there.
13. Security
We take appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, loss and destruction, as required by GDPR Art. 32 and the PDPA Protection Obligation. These include:
- encryption of data in transit using TLS/HTTPS across the website, the members area and the live experience;
- storage of passwords only as salted cryptographic hashes;
- encryption of data at rest at the infrastructure level;
- access control on a least-privilege basis, restricted to personnel who need access to operate the Service;
- contractual security obligations imposed on our processors;
- logging, monitoring and regular application of security updates.
No system can be guaranteed completely secure, and you send data to us over the internet at your own risk. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours where GDPR Art. 33 requires it, notify the Personal Data Protection Commission and affected individuals as required by the PDPA data breach notification obligation, and inform you directly where the risk is high.
To be precise about what we can confirm today: all traffic between your browser and the Service is encrypted in transit using TLS; passwords are stored only as salted cryptographic hashes and are never readable by us; card data never reaches our systems, because it is entered directly into Stripe; access to production systems and to conversation content is restricted to a small number of authorised people and is logged; and data is held on managed infrastructure that provides encryption at rest. Multi-factor authentication is not currently offered on member accounts โ we are working on it, and until it is available we recommend you use a unique, strong password. No system can be guaranteed completely secure, and we do not claim otherwise.
14. Changes to this policy
We may update this Privacy Policy to reflect changes to the Service, our providers, or legal requirements. The current version is always published at linanoa.com/privacy/ with the date of last update at the top.
If a change is material โ for example a new purpose of processing, a new category of recipient, or a change of legal basis โ we will notify you by email or in the members area in advance, and where the change requires your consent we will ask for it before it takes effect.
15. Contact
Culturetek Pte. Ltd.
UEN 202411392W
6 Raffles Quay #14-02
Singapore 048580
Privacy enquiries and data subject requests: hello@linanoa.com
See also our Terms of Service.