Privacy Notice
What we collect, why, who sees it, how long we keep it, and what you can make us do about it.
Version 2026-08-04
1. Who is responsible for your information
The responsible party is [Registered entity name — not yet published by this deployment], of [Physical address — not yet published by this deployment].
- Information Officer
- [Appointed Information Officer — not yet published by this deployment]
- Contact
- [Information Officer email — not yet published by this deployment]
- Regulator registration
- [Information Regulator registration reference — not yet published by this deployment]
2. What we collect, and why
We collect only what a particular feature needs — POPIA calls this minimality, and it is why, for example, we hash your IP address rather than storing it whole.
Account and identity
- Email address, username, display name, password. To create and secure your account. The password is stored only as a bcrypt hash — we cannot read it.
- Your confirmation that you are 18 or older, and when you gave it. Required by the Films and Publications Act before adult content may be shown to you.
- Which version of these documents you accepted, and when. This is the record of your consent.
- Profile content you choose to add — bio, avatar, cover image, social links.
Security and session records
- A one-way hash of your IP address, a masked form of that address, browser user-agent, and sign-in times. Used to show you your active sessions, to alert you to unfamiliar sign-ins and to rate-limit abuse. The unmasked address is not stored.
- Two-factor secrets and backup codes, if you turn 2FA on.
Content you publish
- Posts, images, video, captions, comments, messages, reactions. Images are re-encoded on upload, which strips embedded camera metadata — including GPS coordinates — before the file is ever stored.
- The age classification you give each post, and your attestation that everyone depicted is an adult who consented.
Creator verification (creators only)
- Legal name, South African ID number, a photograph of your identity document, and bank account details. Collected only when you apply to be paid out, to verify that we are paying the right person and to meet financial record-keeping obligations. Your ID number is special personal information under POPIA and is never shown in the app, never included in exports of other people's data, and served only to you and to a reviewing administrator over an access-controlled route.
Payments
- Wallet balance, ledger entries, payment records, payout requests. Card numbers never reach us — the payment gateway handles the card and returns only a result.
Access register for explicit content
- A record that a given account was granted access to a given X18-classified post on a given day. The 2022 Films and Publications Regulations require an online distributor to keep this register and retain it for one year. It records one entry per account, per post, per day — deliberately not a click-by-click history — and is purged automatically after twelve months.
3. Is providing it optional?
Email address, username, password and the 18+ confirmation are mandatory: without them we cannot lawfully or technically give you an account. Everything else is voluntary, but a feature that depends on information you withhold will not work — you cannot be paid out without verification, for example. We tell you at the point of collection which is which.
4. Our lawful basis
- Performance of our contract with you (POPIA s11(1)(b)) — running your account, delivering content you paid for, settling payments.
- Legal obligation (s11(1)(c)) — the age confirmation and access register under the Films and Publications Act; identity verification and financial records under the Financial Intelligence Centre Act and tax law; responding to takedown notices under the ECT Act.
- Legitimate interests (s11(1)(f)) — security, fraud and abuse prevention, and keeping the platform working.
- Your consent (s11(1)(a)) — marketing email, and browser push notifications. Both are opt-in and you can withdraw either at any time in Settings without affecting anything else.
5. Who we share it with
We share personal information only with:
- Other users, as you direct. Your profile and public posts are visible to anyone signed in; subscriber-only content goes only to subscribers you approved. You control this per post.
- Our operators (processors) — the hosting provider, the database and object-storage providers, the email sender, the push-notification service and the payment gateway. Each is bound by a written contract requiring POPIA-grade security and barring them from using the information for their own purposes.
- Law enforcement and regulators where we are legally obliged, or where content depicts a child. We do not hand over user data on an informal request; we require lawful process.
We do not sell personal information, and we do not share it with advertisers or data brokers.
6. Where it is stored, and cross-border transfers
- Database
- [Declared database location — not yet published by this deployment]
- Uploaded media
- [Declared media storage location — not yet published by this deployment]
- Transferred outside South Africa
- No routine transfer outside South Africa is declared for this deployment.
Section 72 of POPIA restricts sending personal information out of South Africa. Where a transfer does happen, it is covered by a contract binding the recipient to substantially the same protection POPIA requires.
7. How long we keep it
- Account and profile — until you close the account, then erased.
- Posts and media — until you delete them or close the account. Deleted files are removed from storage, not merely hidden.
- Financial records (payments, wallet ledger, payouts, verification) — five years from the end of the tax year they relate to, as required by the Tax Administration Act and the Financial Intelligence Centre Act. These survive account closure, reduced to what the obligation actually needs.
- Explicit-content access register — twelve months, then purged automatically.
- Moderation and takedown records — kept while needed to defend a legal claim or show a regulator how a complaint was handled.
- Expired sessions and one-time tokens — purged on a scheduled sweep.
8. Your rights
POPIA gives you the right to:
- Know what we hold and get a copy (s23). Download everything we hold about you, as a JSON file, from Settings → Privacy & your data — no request form, no waiting period.
- Correct or delete inaccurate information (s24). Most of it you can edit directly in Settings.
- Have your information deleted (s24). Closing your account from the same screen erases your personal information and content, keeping only records under a statutory retention duty.
- Object to processing (s11(3)) and to withdraw consent for anything based on consent.
- Not be subject to direct marketing you did not ask for (s69). We only send marketing email if you opted in, and every such email carries an unsubscribe link.
- Complain to the Information Regulator. Details in section 11 below.
Every access and deletion request is logged with its outcome, so we can show that requests are answered.
9. Security
Passwords are bcrypt-hashed; sessions are signed, HTTP-only and server-revocable; two-factor authentication is available; uploads are validated by file content rather than by what the browser claims; subscriber-only media is served through an authorisation check on every request and watermarked with the viewer's handle. The full technical posture is documented in the project's security policy.
10. If something goes wrong
Section 22 of POPIA requires us to notify the Information Regulator and every affected person as soon as reasonably possible after discovering that personal information has been accessed or acquired by an unauthorised person. We will tell you what happened, what information was involved, what we are doing about it and what you should do — in the app and by email to the address on your account.
11. Complaints
Speak to the Information Officer first: [Information Officer email — not yet published by this deployment]. If you are not satisfied, you may complain to:
The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Complaints: POPIAComplaints@inforegulator.org.za
General enquiries: enquiries@inforegulator.org.za
inforegulator.org.za
This document may be updated. Material changes are announced in the app and take effect only after you have had a chance to read them.