Privacy Policy
How we collect, use and protect your personal data (GDPR).
Last updated 22 July 2026 · Provisional while under legal review.
1. Controller
Eradore AB (under formation), Sweden, is the data controller for personal data processed in the Service. Contact: via the Support function in the Service.
2. What we collect
Account data: email address, password (stored as a salted hash), date of birth, display name and the profile information you choose to add (photos, bio, preferences).
Review and verification status: whether your account has been reviewed/approved and any related timestamps. If we enable a third-party age or identity verification provider, identity documents are processed on that provider's side — we never receive or store copies of your ID documents.
Usage data: content you upload, messages you send (stored to deliver the chat), transactions in the credit ledger, moderation events, and technical logs (IP address, device type) kept for security.
Private messages are not routinely read by staff. They may be reviewed only in response to a report, a flag from our safety systems, or a legal obligation — and every such access is recorded in an internal audit log with the reviewer's identity, reason and timestamp.
3. Why we process it (legal bases)
To provide the Service you signed up for — contract (Art. 6(1)(b) GDPR).
Safety, moderation and fraud prevention, and age/identity checks where applicable — legal obligation and legitimate interest (Art. 6(1)(c) and (f)); this processing is necessary for compliance with content-platform obligations.
Payments and bookkeeping — contract and legal obligation.
We do not sell personal data and we do not use third-party advertising trackers.
4. Sharing
We share data only with processors needed to run the Service: our hosting provider (EU data centre, Netherlands) and our payment provider (which processes payment data under its own responsibility). If we later enable a third-party age/identity verification or content-scanning provider, it will be added here. All processors are bound by data processing agreements.
We disclose data to authorities only where required by law, including mandatory reporting of suspected child sexual abuse material.
5. Retention
Account data is kept while your account exists and deleted or anonymised within 90 days of account deletion, except: transaction records (kept per bookkeeping law, 7 years), moderation and abuse records needed for platform safety (up to 5 years), and content subject to legal hold.
6. Your rights
You have the right to access, rectify, erase, restrict and port your data, and to object to processing based on legitimate interest. Use Support to exercise these rights. You can complain to the Swedish Authority for Privacy Protection (IMY) or your local supervisory authority.
7. Security
Traffic is encrypted (TLS), passwords are hashed, sessions are stored server-side, locked media is never delivered to browsers without entitlement, and access to production systems is restricted and logged. Nightly backups are kept encrypted at rest.