Lady Soraya online 24/7 Email support Mon-Fri [email protected] Cancel online anytime
Soraya Live
Legal

Privacy Policy

Effective 25 August 2026 Last updated 25 August 2026 Controller: Ad Management Services LLC

You tell Lady Soraya things you would not tell most people. This page sets out exactly what happens to that, in language you can actually check us against.

The four things most people want to know

We do not sell your data. Not to advertisers, not to data brokers, not to anyone.
We do not publish your conversations.
You can delete everything from your account settings, at any time.
We never see your full card number. It goes straight to the payment processor.

1. Who controls your data

Ad Management Services LLC, of 30 N Gould St #23552, Sheridan, WY 82801, United States, is the data controller for the personal data described here.

For any privacy question, contact [email protected].

2. What we collect

CategoryWhat it isWhy we have it
Account dataEmail address, password (hashed), display name, account settingsTo create and secure your account, and to contact you about your membership
Conversation dataWhat you write or say to Lady Soraya, and her responsesTo generate replies and to give her memory of your situation between sessions
Voice audioRecordings of voice messages, where you use voiceTo transcribe what you said so it can be answered
Billing dataCard brand, last four digits, expiry, billing country, transaction historyTo take payment, issue receipts, process refunds and meet tax obligations
Consent recordsTimestamp, IP address, and the version of the terms shown when you subscribedTo prove you were properly informed before being billed - a legal requirement
Technical dataIP address, browser and device type, pages viewed, timestamps, error logsTo keep the service running, prevent fraud and abuse, and diagnose faults
Support dataEmails, call notes and ticketsTo answer you and keep a record of what was agreed

What we never collect: your full card number or CVV (these go directly to our payment processor), and any government identity document. We do not ask for any of it and could not use it if we had it.

3. Sensitive topics in conversation

You may talk to Lady Soraya about health, relationships, beliefs, sexuality or other deeply personal matters. In some jurisdictions that content is treated as a special category of personal data attracting extra protection.

We handle it accordingly: it is used only to answer you and to maintain your conversation context, it is not used to build advertising profiles, it is not shared for marketing, and it is deleted when you delete it. We ask you not to send us information about other identifiable people that they would not want shared, and never to send payment card numbers, passwords or identity documents inside a conversation.

4. Our legal bases

  • Performance of a contract — providing the Service you have paid for: your account, your conversations, your billing.
  • Legal obligation — tax and accounting records, consent records required by consumer-protection law, and responses to lawful requests.
  • Legitimate interests — keeping the Service secure, preventing fraud and abuse, and improving reliability. We balance these against your rights and use the least intrusive option available.
  • Consent — for optional analytics and for marketing email. You can withdraw it at any time without affecting your membership.

5. How your conversations are used by the AI

Your messages are sent to the AI model that generates Lady Soraya’s replies, and stored so that she can refer back to your situation in later sessions.

We do not use your conversations to train foundation models, and we contractually require our AI providers not to train on data we send them. If that ever changes it would be an opt-in choice presented to you separately, never a silent default.

A small number of authorised staff can access conversation data where it is strictly necessary — investigating a bug you have reported, responding to a safety or legal issue, or acting on your own support request. Such access is logged.

6. Who we share it with

We share data only with service providers who need it to run the Service, under contracts that limit them to our instructions:

  • Cloud hosting and storage — to run the application and hold your data.
  • AI model providers — to generate responses, under no-training terms.
  • Payment processing — a PCI DSS Level 1 processor that handles card data on our behalf. They receive your card details directly; we do not.
  • Email delivery — to send receipts, notices and support replies.
  • Fraud and abuse prevention — to detect stolen cards and automated abuse.
  • Professional advisers and authorities — where we are legally required, or to establish or defend legal claims.

We do not sell personal data, and we do not share it for cross-context behavioural advertising. If we are ever involved in a merger or acquisition, your data may transfer to the acquirer under the same commitments, and we will tell you before it happens.

7. International transfers

Our providers may process data outside your country. Where data leaves a jurisdiction with data-transfer restrictions, we rely on an approved safeguard — an adequacy decision, or Standard Contractual Clauses with supplementary measures. You can request details of the safeguard used at [email protected].

8. How long we keep it

DataKept for
Conversation historyUntil you delete it, or 30 days after you close your account
Voice recordingsDeleted after transcription; transcripts follow conversation history
Account dataLife of the account, then 30 days
Billing and tax recordsAs required by tax law in United States, typically 7 years
Consent recordsAt least 3 years, or 1 year after cancellation, whichever is longer
Security and fraud logsUp to 12 months
Support correspondence3 years from the last contact

Where we must keep billing records for tax purposes, we keep only what the law requires — the transaction, not your conversations.

9. Your rights

Depending on where you live, you have some or all of the following rights. We honour all of them for every user, wherever you are, because operating two standards is a worse way to run a service.

  • Access — get a copy of what we hold about you.
  • Correction — fix anything inaccurate.
  • Deletion — have it erased, subject only to records we are legally required to keep.
  • Portability — receive your data in a machine-readable format.
  • Restriction and objection — limit or object to certain processing.
  • Withdraw consent — at any time, for anything based on consent.
  • Non-discrimination — we will never degrade your service or change your price because you exercised a privacy right.

Most of this is self-service in Account → Privacy. Otherwise email [email protected]. We respond within 30 days and will tell you if we need longer. We do not charge for this.

If you are unhappy with how we handled a request, you can complain to your local data-protection authority. We would appreciate the chance to put it right first.

10. Security

  • All traffic is encrypted in transit with TLS; data is encrypted at rest.
  • Passwords are stored using a modern one-way hashing algorithm and are never recoverable in plain text.
  • Staff access is role-based, granted on a need-to-know basis, and logged.
  • Card data never touches our infrastructure.
  • We keep audit logs and monitor for unusual access patterns.

No system is perfectly secure. If a breach affects your personal data and creates a risk to you, we will notify you and the relevant regulator within the timeframes the law requires, and tell you plainly what happened and what to do.

11. Children

Soraya Live is for adults. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, contact [email protected] and we will close it, delete the data and refund any charges.

12. Cookies

We use a small number of cookies, described in the Cookie Policy. Only strictly necessary cookies are set without your consent.

13. Changes to this policy

If we make a material change we will email you and update the date at the top of this page before it takes effect. Previous versions are available on request.

14. Contact

Data controller
Ad Management Services LLC
Privacy contact
[email protected]
Postal address
30 N Gould St #23552Sheridan, WY 82801, United States