POLYMORPH AWAKE Privacy Policy

Last updated: 16 September 2026

1. Scope

This Privacy Policy explains how personal data may be processed when using the POLYMORPH AWAKE desktop client, the associated POLYMORPH AWAKE online service, and the POLYMORPH AWAKE documentation and privacy pages.

POLYMORPH AWAKE is designed for Second Life and works primarily with Second Life identities rather than real-world identities.

2. Data Controller

POLYMORPH AWAKE is provided under the POLYMORPH brand by Enzo Calcagni, acting as an individual data controller in Italy.

Privacy contact: privacy@polymorphsl.com

3. Avatar-first identity

POLYMORPH AWAKE does not require people interacting with a companion to disclose their real-world identity and does not attempt to determine the real-world identity behind a Second Life avatar.

Users and other people encountered in Second Life are normally identified within AWAKE through Second Life identifiers such as avatar names and avatar UUIDs. These identifiers are treated as pseudonymous identifiers, not as anonymous data.

POLYMORPH does not require a companion to collect a person's real name, postal address, telephone number or other real-world identity information in order to provide normal AWAKE functionality.

If a person voluntarily discloses real-world information during a conversation, AWAKE may process that information as part of the conversation or an applicable memory function. POLYMORPH does not use such disclosures to try to identify the person behind the avatar.

4. Information AWAKE may process

Depending on the features that are enabled and used, AWAKE may process the following categories of information:

5. Sensitive or special-category information

AWAKE does not require people to disclose information about their race or ethnicity, political opinions, religion, health, sex life, sexual orientation or other special-category information.

A Second Life statement may describe a fictional avatar persona, roleplay, or the real person controlling the avatar. POLYMORPH does not attempt to determine which is the case.

If information voluntarily provided by a user concerns the real person behind the avatar and falls within a special category of personal data, POLYMORPH treats it as sensitive information. Persistent storage of such information is intended only for an optional function requested or deliberately used by the user, such as a memory or identity-continuity function. Where the GDPR requires an Article 9 condition, POLYMORPH relies on the user's explicit consent for that requested storage and use.

A user may withdraw that consent by using available memory-deletion controls or by contacting privacy@polymorphsl.com. Withdrawal does not affect processing that was lawful before the withdrawal.

6. Why information is processed

AWAKE processes information only for purposes connected with providing and protecting the service, including:

7. Legal bases

Depending on the processing activity, POLYMORPH may rely on:

8. AI processing, web grounding and service providers

When a message requires AI generation, conversation content and the context necessary to produce a reply may be transmitted through POLYMORPH servers to third-party AI inference providers used by AWAKE.

Depending on the active conversation mode and service routing, current providers may include OpenAI and OpenRouter, including models made available through OpenRouter. POLYMORPH may change providers when necessary to operate or improve the service; this policy will be updated if that materially changes how personal data is processed.

When AWAKE determines that a question requires current external information, a query derived from the user's message may be sent to an external web-grounding service. The current implementation may use OpenAI web-search capabilities for that purpose. Grounded information may then be supplied as context to the model generating the final conversational reply.

Requests routed to the OpenAI API by the current AWAKE service are configured with store:false. Processing by third-party providers is also subject to the technical configuration and applicable terms of those providers.

Some service providers may process data outside the European Economic Area. Where EU data-transfer rules apply, POLYMORPH will use applicable transfer safeguards available for the relevant service.

9. Second Life credentials

POLYMORPH servers do not receive or store the companion avatar's Second Life login password or other Second Life authentication secrets.

The AWAKE desktop client stores the companion avatar's Second Life password only on the user's Windows computer using Windows Credential Manager and uses it to authenticate directly with Linden Lab/Second Life. The password is not stored in the normal AWAKE settings file, is not uploaded to POLYMORPH, and is not made available to POLYMORPH servers.

This design is intended to remain consistent with Second Life requirements applicable to third-party viewers and applications concerning the handling of Second Life login credentials.

10. Conversation transcripts and server storage

POLYMORPH servers do not retain raw conversation transcripts.

For a private conversation, the current message and a bounded amount of recent context may be transmitted to the POLYMORPH service and the selected AI provider only for the purpose of generating the current response. Recent conversational continuity is kept in volatile memory by the running AWAKE desktop client and is discarded when that client process ends.

The POLYMORPH database may retain non-content operational metadata about conversation requests, such as request identifiers, timestamps, status, provider/model identifiers, token counts, reply-length metrics and policy/version information. These records do not contain the raw user message or raw assistant reply.

This does not prevent AWAKE from storing separate structured memories when a memory feature is used. Stored memories are data extracted or deliberately saved for continuity, such as a preference, identity declaration, relationship fact, place memory or privacy-preserving episode/topic record; they are not a copy of the raw conversation transcript.

Public-chat and ambient-chat context may be processed transiently when required for an enabled feature, but AWAKE does not store those raw chat lines as private conversation transcripts in the POLYMORPH database.

11. Conversation filtering and Second Life service notices

AWAKE applies routing rules before conversational AI processing. Second Life offline-delivery and service-notice traffic covered by the current service-notice guard is not sent for AI generation, is not written to AWAKE transcript or memory by that path, and does not generate a conversational outbound reply.

12. Retention

Different categories of information are retained for different periods according to their purpose.

POLYMORPH may retain limited information for longer where necessary to establish, exercise or defend legal claims, meet a legal obligation, investigate security abuse, or resolve an active dispute.

13. Website analytics and tracking

POLYMORPH does not use Google Analytics or other analytics, advertising or profiling services on the POLYMORPH AWAKE documentation and privacy pages at this time.

POLYMORPH does not maintain or have access to website visitor access logs through its current hosting service. The hosting provider may nevertheless process limited technical information, such as network request information, as necessary to provide, secure or maintain its hosting infrastructure.

POLYMORPH does not use website visits to create advertising profiles of AWAKE users.

14. Sharing of information

POLYMORPH does not sell personal data.

Information may be disclosed only where necessary to provide or protect AWAKE, including to infrastructure, hosting or AI service providers acting in connection with the service, or where disclosure is required by law.

Second Life itself is a separate third-party service. Information sent to or obtained from Second Life is also subject to the policies and terms applicable to Second Life.

15. Security

POLYMORPH uses technical and organizational measures intended to reduce unauthorized access, disclosure or misuse of AWAKE data. The current service keeps POLYMORPH provider/API secrets server-side, uses HTTPS for the official service endpoint, keeps authentication and entitlement checks server-authoritative, and does not distribute provider API keys in the normal client package. This does not include the companion avatar's Second Life password, which remains local to the user's Windows computer.

No security measure can provide an absolute guarantee of security.

16. Your privacy rights

Subject to the conditions and limits provided by applicable law, a person may have the right to request access to personal data concerning them, correction of inaccurate data, deletion, restriction of processing, data portability, or objection to certain processing.

Where processing is based on consent, consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.

Because AWAKE is designed around pseudonymous Second Life identities and does not seek real-world identification, POLYMORPH may need information sufficient to identify the relevant Second Life avatar, account or stored record before acting on a request. POLYMORPH will not request additional real-world identity information solely for the purpose of identifying a person where that is not necessary.

Privacy requests may be sent to privacy@polymorphsl.com.

Individuals in the European Union also have the right to lodge a complaint with a competent data protection supervisory authority. For a controller established in Italy, this includes the Garante per la protezione dei dati personali.

17. Companion owners and other Second Life users

AWAKE companions may interact with people other than the POLYMORPH account holder. Companion owners choose whether to enable certain functions, including features that may use volatile recent conversation context or create structured memories. Depending on how a companion is used, its owner may have separate obligations under applicable privacy or data-protection law.

This Privacy Policy describes processing performed through the POLYMORPH AWAKE service. It does not replace any privacy notice that a companion owner may independently be required to provide for their own use of AWAKE.

18. Changes to this policy

This policy may be updated when AWAKE functionality, service providers, retention rules or legal requirements change. The current server-hosted copy linked from the AWAKE Help menu should be treated as the current version.