POLYMORPH AWAKE Privacy Policy
1. Scope
This Privacy Policy explains how personal data may be processed when using the POLYMORPH AWAKE desktop client, the associated POLYMORPH AWAKE online service, and the POLYMORPH AWAKE documentation and privacy pages.
POLYMORPH AWAKE is designed for Second Life and works primarily with Second Life identities rather than real-world identities.
2. Data Controller
POLYMORPH AWAKE is provided under the POLYMORPH brand by Enzo Calcagni, acting as an individual data controller in Italy.
Privacy contact: privacy@polymorphsl.com
3. Avatar-first identity
POLYMORPH AWAKE does not require people interacting with a companion to disclose their real-world identity and does not attempt to determine the real-world identity behind a Second Life avatar.
Users and other people encountered in Second Life are normally identified within AWAKE through Second Life identifiers such as avatar names and avatar UUIDs. These identifiers are treated as pseudonymous identifiers, not as anonymous data.
POLYMORPH does not require a companion to collect a person's real name, postal address, telephone number or other real-world identity information in order to provide normal AWAKE functionality.
If a person voluntarily discloses real-world information during a conversation, AWAKE may process that information as part of the conversation or an applicable memory function. POLYMORPH does not use such disclosures to try to identify the person behind the avatar.
4. Information AWAKE may process
Depending on the features that are enabled and used, AWAKE may process the following categories of information:
- POLYMORPH account identifiers, authentication/session information and entitlement status needed to authorize and operate the service.
- A device identifier, client/version information and limited operational or security metadata needed to authenticate devices, enforce service limits, protect accounts and operate the service.
- The Second Life name and UUID of the companion avatar and of other avatars involved in supported interactions.
- Second Life relationship or access context, such as owner, friend or unknown-avatar status, when required by an enabled feature.
- In-world context required by enabled functions, which may include region or place information, nearby avatar or object information, outfit or AO information, landmarks and other Second Life state.
- Conversation content sent to or generated by AWAKE, including eligible instant messages and public-chat context, is processed transiently when needed to produce a response. Raw conversation transcripts are not retained in the POLYMORPH application database.
- Conversation continuity may use a bounded recent-history cache held only in the running AWAKE desktop client. Separately, structured memories deliberately created by AWAKE may be stored server-side and may include personal facts voluntarily provided by an avatar, relationship context, preferences, identity declarations and place-related memories.
- Account-level companion-owner settings, including an optional Owner Gender value, where configured by the account holder to support consistent owner-specific conversation behavior.
- Ephemeral observations derived from current Second Life avatar state. Where available, AWAKE may use the current body-shape sex marker of a non-owner avatar as a low-confidence fallback for conversational addressing when no explicit gender declaration or stored gender memory is available. This observation is not treated as a self-declared identity and is not stored as a durable personal fact merely because it was observed.
- Persona and companion configuration data selected by the companion owner.
- For Escort Mode, temporary public Second Life profile information associated with unknown avatars. Recent private conversation context is processed transiently and kept in the running desktop client's volatile memory rather than stored as a server-side transcript.
5. Sensitive or special-category information
AWAKE does not require people to disclose information about their race or ethnicity, political opinions, religion, health, sex life, sexual orientation or other special-category information.
A Second Life statement may describe a fictional avatar persona, roleplay, or the real person controlling the avatar. POLYMORPH does not attempt to determine which is the case.
If information voluntarily provided by a user concerns the real person behind the avatar and falls within a special category of personal data, POLYMORPH treats it as sensitive information. Persistent storage of such information is intended only for an optional function requested or deliberately used by the user, such as a memory or identity-continuity function. Where the GDPR requires an Article 9 condition, POLYMORPH relies on the user's explicit consent for that requested storage and use.
A user may withdraw that consent by using available memory-deletion controls or by contacting privacy@polymorphsl.com. Withdrawal does not affect processing that was lawful before the withdrawal.
6. Why information is processed
AWAKE processes information only for purposes connected with providing and protecting the service, including:
- authenticating the POLYMORPH account and authorized device;
- connecting and controlling the Second Life companion;
- providing conversation and AI-generated responses;
- maintaining requested conversational continuity and memory;
- providing enabled movement, appearance, travel, Persona, Adult, Escort and other AWAKE functions;
- providing optional web-grounded answers when current external information is required;
- enforcing product entitlements, active-companion limits and service quotas;
- protecting accounts and the service against unauthorized use, token misuse, abuse and technical failures;
- responding to privacy, support or security requests.
7. Legal bases
Depending on the processing activity, POLYMORPH may rely on:
- performance of a contract where processing is necessary to provide the AWAKE service requested by the account holder;
- legitimate interests where necessary to secure the service, prevent abuse, enforce reasonable service limits, maintain reliability and protect accounts, provided those interests are not overridden by the rights and interests of the person concerned;
- consent where an optional feature or requested memory requires consent;
- explicit consent where Article 9 GDPR applies to special-category personal data voluntarily provided for an optional requested feature;
- legal obligation where processing is required by applicable law.
8. AI processing, web grounding and service providers
When a message requires AI generation, conversation content and the context necessary to produce a reply may be transmitted through POLYMORPH servers to third-party AI inference providers used by AWAKE.
Depending on the active conversation mode and service routing, current providers may include OpenAI and OpenRouter, including models made available through OpenRouter. POLYMORPH may change providers when necessary to operate or improve the service; this policy will be updated if that materially changes how personal data is processed.
When AWAKE determines that a question requires current external information, a query derived from the user's message may be sent to an external web-grounding service. The current implementation may use OpenAI web-search capabilities for that purpose. Grounded information may then be supplied as context to the model generating the final conversational reply.
Requests routed to the OpenAI API by the current AWAKE service are configured with store:false. Processing by third-party providers is also subject to the technical configuration and applicable terms of those providers.
Some service providers may process data outside the European Economic Area. Where EU data-transfer rules apply, POLYMORPH will use applicable transfer safeguards available for the relevant service.
9. Second Life credentials
POLYMORPH servers do not receive or store the companion avatar's Second Life login password or other Second Life authentication secrets.
The AWAKE desktop client stores the companion avatar's Second Life password only on the user's Windows computer using Windows Credential Manager and uses it to authenticate directly with Linden Lab/Second Life. The password is not stored in the normal AWAKE settings file, is not uploaded to POLYMORPH, and is not made available to POLYMORPH servers.
This design is intended to remain consistent with Second Life requirements applicable to third-party viewers and applications concerning the handling of Second Life login credentials.
10. Conversation transcripts and server storage
POLYMORPH servers do not retain raw conversation transcripts.
For a private conversation, the current message and a bounded amount of recent context may be transmitted to the POLYMORPH service and the selected AI provider only for the purpose of generating the current response. Recent conversational continuity is kept in volatile memory by the running AWAKE desktop client and is discarded when that client process ends.
The POLYMORPH database may retain non-content operational metadata about conversation requests, such as request identifiers, timestamps, status, provider/model identifiers, token counts, reply-length metrics and policy/version information. These records do not contain the raw user message or raw assistant reply.
This does not prevent AWAKE from storing separate structured memories when a memory feature is used. Stored memories are data extracted or deliberately saved for continuity, such as a preference, identity declaration, relationship fact, place memory or privacy-preserving episode/topic record; they are not a copy of the raw conversation transcript.
Public-chat and ambient-chat context may be processed transiently when required for an enabled feature, but AWAKE does not store those raw chat lines as private conversation transcripts in the POLYMORPH database.
11. Conversation filtering and Second Life service notices
AWAKE applies routing rules before conversational AI processing. Second Life offline-delivery and service-notice traffic covered by the current service-notice guard is not sent for AI generation, is not written to AWAKE transcript or memory by that path, and does not generate a conversational outbound reply.
12. Retention
Different categories of information are retained for different periods according to their purpose.
- Account, authentication, entitlement and security information is retained for as long as necessary to operate and protect the account and service, and as otherwise required by applicable law.
- Account-level settings such as Owner Gender remain associated with the account until changed, removed through an available account control, or deleted with the relevant account data.
- Conversation request records may be retained for a limited operational period for idempotency, usage accounting, abuse prevention, diagnostics and reliability. These records contain metadata only and do not retain the raw user or assistant message text.
- The AWAKE Windows client keeps local diagnostic activity logs on the user's own computer for troubleshooting, reliability and technical diagnostics. These logs may contain operational metadata such as Second Life avatar names or UUIDs, request identifiers, feature or activity status, message-length metrics, provider or model identifiers, token counts and technical error information. They do not intentionally store the raw text of private conversations or AI replies. Local diagnostic log files are rotated at approximately 10 MB per file and are automatically retained for up to 14 days.
- Limited license-claim and transaction-integrity records may be retained after companion-data deletion or account deletion where necessary to prevent duplicate or replayed activations and transactions, reconcile commercial purchases and Escort payments, refunds or settlements, handle disputes, and meet applicable legal or accounting obligations. These records may include pseudonymous Second Life avatar UUIDs, transaction or payment identifiers, product or action codes, amounts, timestamps and final processing status. They are not retained as conversation transcripts and are not used to keep a deleted account active.
- Companion Persona, memories, place memories and related companion state may remain associated with that companion's Second Life UUID until deleted or otherwise removed under an applicable service rule. Switching the account's active companion does not by itself delete the previous companion's stored Persona, memories or place information.
- Explicit personal identity declarations stored as contact memory remain subject to the applicable memory and deletion controls. An ephemeral body-shape observation is not, by itself, stored as a durable personal fact.
- Raw owner/friend conversation transcripts are not retained server-side. Recent conversational continuity exists only in the running desktop client's volatile memory, while separately stored structured memories follow their applicable memory and deletion rules.
- Escort Mode does not store a raw private-chat transcript on POLYMORPH servers. Its recent conversational continuity is likewise client-local and volatile. Separate temporary Escort contact/profile data and operational request metadata expire after 36 hours without contact. The client also provides a Delete Escort history control to remove the applicable temporary Escort server data and clear the local Escort conversation cache.
POLYMORPH may retain limited information for longer where necessary to establish, exercise or defend legal claims, meet a legal obligation, investigate security abuse, or resolve an active dispute.
13. Website analytics and tracking
POLYMORPH does not use Google Analytics or other analytics, advertising or profiling services on the POLYMORPH AWAKE documentation and privacy pages at this time.
POLYMORPH does not maintain or have access to website visitor access logs through its current hosting service. The hosting provider may nevertheless process limited technical information, such as network request information, as necessary to provide, secure or maintain its hosting infrastructure.
POLYMORPH does not use website visits to create advertising profiles of AWAKE users.
14. Sharing of information
POLYMORPH does not sell personal data.
Information may be disclosed only where necessary to provide or protect AWAKE, including to infrastructure, hosting or AI service providers acting in connection with the service, or where disclosure is required by law.
Second Life itself is a separate third-party service. Information sent to or obtained from Second Life is also subject to the policies and terms applicable to Second Life.
15. Security
POLYMORPH uses technical and organizational measures intended to reduce unauthorized access, disclosure or misuse of AWAKE data. The current service keeps POLYMORPH provider/API secrets server-side, uses HTTPS for the official service endpoint, keeps authentication and entitlement checks server-authoritative, and does not distribute provider API keys in the normal client package. This does not include the companion avatar's Second Life password, which remains local to the user's Windows computer.
No security measure can provide an absolute guarantee of security.
16. Your privacy rights
Subject to the conditions and limits provided by applicable law, a person may have the right to request access to personal data concerning them, correction of inaccurate data, deletion, restriction of processing, data portability, or objection to certain processing.
Where processing is based on consent, consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
Because AWAKE is designed around pseudonymous Second Life identities and does not seek real-world identification, POLYMORPH may need information sufficient to identify the relevant Second Life avatar, account or stored record before acting on a request. POLYMORPH will not request additional real-world identity information solely for the purpose of identifying a person where that is not necessary.
Privacy requests may be sent to privacy@polymorphsl.com.
Individuals in the European Union also have the right to lodge a complaint with a competent data protection supervisory authority. For a controller established in Italy, this includes the Garante per la protezione dei dati personali.
17. Companion owners and other Second Life users
AWAKE companions may interact with people other than the POLYMORPH account holder. Companion owners choose whether to enable certain functions, including features that may use volatile recent conversation context or create structured memories. Depending on how a companion is used, its owner may have separate obligations under applicable privacy or data-protection law.
This Privacy Policy describes processing performed through the POLYMORPH AWAKE service. It does not replace any privacy notice that a companion owner may independently be required to provide for their own use of AWAKE.
18. Changes to this policy
This policy may be updated when AWAKE functionality, service providers, retention rules or legal requirements change. The current server-hosted copy linked from the AWAKE Help menu should be treated as the current version.