Trust Center
Last Updated: May 26, 2025
Last Updated: May 26, 2025
At Nomi, trust is foundational to everything we build. This page summarizes how we approach security, data protection, AI safety, and our commitments to users.
Data Security
We use industry-standard security measures to protect your personal information from unauthorized access, loss, alteration, or disclosure. Our practices include:
Encryption. Data transmitted between your device and our servers is encrypted using TLS (Transport Layer Security). Sensitive data at rest is encrypted using AES-256 or equivalent standards.
Access Controls. Access to user data is restricted to authorized personnel on a need-to-know basis. We use role-based access control and log access to sensitive systems.
Infrastructure Security. Our services are hosted on reputable cloud infrastructure providers that maintain SOC 2 and ISO 27001 certifications. We apply regular security patches and updates.
Monitoring. We continuously monitor our systems for unusual activity, potential threats, and unauthorized access attempts.
No method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.
AI Safety and Content Moderation
Nomi's AI companion features are built with safety in mind.
Content Policies. All AI companions operate under defined content policies that prohibit the generation of harmful, illegal, or exploitative content — regardless of how a request is framed. Certain prohibitions, such as content that sexualizes minors, are absolute and cannot be overridden by any user setting or input.
Safety Filters. We apply automated content filtering and monitoring to detect and prevent policy violations. These systems are reviewed and updated on an ongoing basis.
Human Review. We may review conversations that are flagged by our automated systems to improve safety and product quality. Reviewed conversations are handled in accordance with our Privacy Policy.
AI Limitations. Our AI systems are powerful but imperfect. They may occasionally produce inaccurate, outdated, or inappropriate responses. We are continuously working to improve quality and safety. If you encounter a response that you believe is harmful or inappropriate, please report it to compliance@nomifriend.com.
Privacy by Design
Privacy is built into our product from the ground up, not added as an afterthought.
Data Minimization. We collect only the data necessary to provide the Services. We do not collect sensitive information we don't need.
Retention Limits. We retain personal data only as long as necessary to provide the Services or comply with legal obligations. Users may request deletion of their data at any time.
Third-Party AI Providers. Conversation data processed by third-party AI model providers is governed by data processing agreements that include appropriate data protection obligations. We do not authorize these providers to use your data to train their models without appropriate safeguards.
No Sale of Sensitive Data. We do not sell conversation content or AI interaction data to data brokers or advertisers.
Responsible AI Disclosure
We are committed to transparency about how our AI systems work.
- Nomi's companion characters are AI-generated personas, not real people
- AI-generated messages, including proactive outreach notifications, are produced by machine learning models trained on large datasets
- Companion characters are designed and maintained by our team; their personalities, backstories, and behaviors are intentional product decisions
- We do not use your conversations to train our AI models without your explicit consent
Compliance
Nomi is committed to compliance with applicable privacy and data protection laws, including:
- California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
- Children's Online Privacy Protection Act (COPPA) — we do not knowingly collect data from users under 17
- CAN-SPAM Act for email communications
- App Store and Google Play guidelines for mobile applications
Vulnerability Disclosure
If you discover a security vulnerability in our Services, we ask that you report it to us responsibly before disclosing it publicly. Please contact us at compliance@nomifriend.com with a description of the vulnerability and steps to reproduce it. We will acknowledge receipt within 5 business days and work to address confirmed issues promptly.
We ask that you:
- Give us reasonable time to investigate and remediate before public disclosure
- Avoid accessing, modifying, or deleting user data in the course of your research
- Not perform denial-of-service attacks or other disruptive testing
We appreciate the security research community's efforts to help keep Nomi safe.
Contact
For security or trust-related inquiries:
Email: compliance@nomifriend.com Address: [Company Address]
Copyright © 2025 Life Agents, LLC