Atween AI Service Statement (Overseas)
Not submittable yet. This page states what the AI can and cannot do, who confirms, and how to exit. Real provider contracts, accuracy-boundary report, redline cases, deletion-propagation evidence and raw-free audit samples must be added before release. Sandbox logs never stand in for real model capability.
1. AI is not a person (AI Act Art. 50 transparency)
Atween clearly discloses: AI-organised, not a human. You are interacting with an AI system unless we state otherwise. The AI helps organise facts, rhythm, a sayable sentence and safety reminders; it does not judge who is right or make major decisions for you. Atween is not a medical, psychological, legal, financial or relationship-arbitration service.
2. How the AI reads your input
The AI must understand text, images, video, voice and voice rhythm/emotion. The concrete strategy (single multimodal model, combination or cascade) may be replaced later, but the capability floor cannot drop. All modalities enter RawSource/MediaSource boundaries first; the AI Gateway / Context Capsule assembles only the minimum material needed for the current purpose, still authorised and not deleted. Routing logs record only necessary audit fields, never originals, full transcripts, media URLs, full prompt/output or reversible source refs.
3. On-device voice understanding
After your first explicit confirmation, an on-device model (whisper-class / SenseVoice-class or functional equivalent) produces a transcript plus structured cues (pace, pauses, energy, pitch trend, event-level emotion candidates, confidence, time window, model and version). These are model candidates, not facts, not personality conclusions, not medical or psychological diagnoses. Minimised transcripts and cues may be passed to a backend text model for context, rhythm and safety; internal emotion labels are not shown to you, not given to the other person, and not used for scoring, profiling, advertising, differential pricing or significant automated decisions.
4. How results are used and shown
- Images/video describe only visible facts, action order and safety boundaries; no automatic inference of motive, personality or relationship conclusions.
- Voice cues only adjust understanding and rhythm; internal labels ("angry", "anxious") are not attached to you.
- Text organisation distinguishes fact, guess, request, boundary and deliverable version.
- Low-confidence, conflicting or out-of-window candidates are down-weighted, confirmed, or not used.
- Anything prepared for the other person must be previewed and confirmed by you; internal analysis, emotion candidates and unconfirmed originals are never delivered.
5. Save, this-session-only and deletion
If you choose "this session only", voice cues do not enter long-term understanding and are deleted after processing or a short cache expiry. If you save, cues are bound to the source record with model/version, confidence, window, authorisation, your corrections and deletion watermark. Deleting the original voice or record propagates to transcripts, cues, emotion candidates, long-term understanding, indexes, caches, queues, provider retries and future Context Capsules, with verifiable status or receipt.
6. Third-party models and data boundaries
On-device models, or self-hosted processing that does not leave our control, are not a third-party transfer. If production passes structured cues or emotion candidates to an external model API (AWS Bedrock / Azure AI Foundry candidates), the Sub-processor List names the real processor, fields, purpose, retention, region and your opt-out, and a ProviderAdapter restricts scope. We do not use your intimate content, voice, cues, long-term understanding or AI output to train base models unless you separately consent with a withdrawal and deletion path.
7. Your choices
On first voice use, a one-time confirmation explains purpose, data types, scope and exit; the same scope does not re-prompt on every recording. You can switch off "voice cues for AI understanding" in Settings; basic transcription and text input still work. Where law requires separate consent, we obtain it.
8. Safety redlines, exit and reminders
For self-harm, harm-to-others, threat, domestic violence, control, addiction or major property risk, safety takes priority over mediation, delivery, charging or retention. You can exit by button, keyword or voice. Continuous anthropomorphic interaction beyond 2 hours triggers a usage reminder. We do not obstruct exit with emotional retention or follow-up questions.
9. Accuracy and release boundary
AI output and voice candidates may be inaccurate, incomplete or mismatched to your true feeling. Before external release we must add real provider-adapter output, real on-device and backend benchmarks, an accuracy-boundary report, redline cases, deletion-propagation evidence and a raw-free audit sample.