AI + Frnds · Back to the event

Privacy Policy

Last updated: 24 September 2026

This policy explains how AI + Frnds handles information in our event-building app, including the live office, Merlin assistant, storybook, Wall of Love and awards. For privacy questions or requests, contact the event organizer at sid@aiplusfriends.com.

Your Merlin conversation and email are not shown on the public wall. Your submitted app details are shared with other participants, and the photo you confirm for your storybook is public. You can ask us to remove your information.

Information we collect

How we use it

We use this information to run the event, help you develop an idea with Merlin, save and restore your progress, create your storybook, display submitted work, administer awards, prevent duplicate or unauthorized votes, troubleshoot problems and respond to support or privacy requests. Google account information is used for sign-in, account recovery and securing your participation; it is not used for advertising.

What other people can see

People watching the live office can see the names and appearances of visible characters, their movements and seating. When you submit a live app URL, your chosen name, character, idea, app link and shipping information may appear in event app listings, voting screens and award results. If event announcements are enabled, your name, idea and app link may also be posted to the event's Discord community.

When you confirm your storybook photo, your name, role, photo, idea and app link appear on the public Wall of Love and storybook. These can be viewed, downloaded or shared by others. Your email, private Merlin transcript and individual ballot are not included in public listings. Event operators can access stored records to administer and support the event.

Only upload photos you have permission to share. Do not put passwords, payment details or confidential information into Merlin or public submissions. We cannot retrieve copies that other people have already downloaded or independently shared.

Providers and external services

We use Render for application hosting and Supabase for database storage, authentication and photo storage. Merlin's model requests send your ideation messages and relevant conversation context to Anthropic to generate responses. These providers process information to supply their services, under their applicable terms and privacy policies. Email verification messages are delivered through the configured authentication email service.

Google handles Google sign-in if you choose it. Opening an app preview or external link connects your browser to that app's host, which may receive technical information and have its own privacy practices. Our interface loads fonts from Google Fonts. Build prompts may include an AI + Frnds badge hosted on Vercel; if included in your published app, loading it connects visitors to that badge service. Choosing Clicky, Replit, Discord or social sharing also involves those services' own policies. We do not control independently built participant apps.

Providers may process data in countries other than your own. We do not sell personal information. We may disclose information when required by law or when necessary to address abuse, protect users or secure the service.

Cookies and browser storage

An essential signed session cookie lets you resume your guest or verified journey; its configured lifetime is 30 days. Browser storage also retains character preferences, authentication sessions and pending request identifiers so retries can be handled safely. Clearing browser storage can remove access to an unverified guest journey. Verifying an account lets you recover that account's journey on another device.

Retention and security

Journey, conversation, account, storybook and voting records are saved so people can return after the event. These records currently have no automatic deletion date; they remain stored until removed through an organizer's retention review or an applicable deletion request. Expiry of a browser cookie does not delete the database record. Technical logs and any provider backups follow the applicable provider's retention arrangements.

We use authenticated access, server-side access checks and encrypted network connections in production. No service can guarantee absolute security. Public photos and app information are intentionally available without signing in.

Your choices and requests

You can participate and vote as a guest after shipping your app, or choose Google sign-in to recover progress across devices. Guest access depends on your browser session; clearing browser data or losing that session can lose access, even though the records remain saved. Email-code sign-in is not currently offered. You can avoid uploading a photo and stop using the service at any time.

To request access, correction, deletion or removal from the public wall, email sid@aiplusfriends.com. Include the event and the email or name you used; do not send passwords or verification codes. We may ask for information to verify that the records belong to you. We will review your request and explain any information that must be retained for legal or security reasons. Removing Google access alone does not delete your existing event records; contact us for deletion.

Your privacy rights depend on the laws that apply to you. This policy does not limit those rights. If a child has submitted information and you are their parent or guardian, contact us for help reviewing or removing it.

Changes to this policy

We will update this page and its date when our practices change. Material changes to how we use information will be communicated through the app or another appropriate channel.