This notice explains how Content Protect processes personal information when adult creators create an account, verify eligibility, upload reference media, search for suspected copies, manage takedown cases, contact support or purchase a subscription. We use data minimisation, encryption and human review. We do not sell personal information or use private media for advertising or model training.
| Purpose | UK GDPR basis |
|---|---|
| Create, secure and provide the service | Contract; legitimate interests in security, fraud prevention and service integrity. |
| Verify adult eligibility and authority | Contract and legitimate interests in preventing abuse and protecting creators and third parties. |
| Process submitted media and locate suspected copies | Contract. Where submitted media reveals special-category information, including information about sex life or sexual orientation, explicit consent is requested at upload under Article 9(2)(a). |
| Prepare, review and deliver notices; handle disputes | Contract, legitimate interests in protecting and defending rights, and legal claims where applicable. |
| Billing, tax and accounting | Contract and legal obligation; legitimate interests in payment fraud prevention. |
| Respond to safety incidents or lawful requests | Legal obligation, legitimate interests and, in a genuine emergency, vital interests where applicable. |
Where we rely on legitimate interests, the interests are operating a secure rights-protection service, preventing misuse, preserving evidence and managing legal claims. We balance these interests against the rights and reasonable expectations of affected people.
You decide whether to upload content that may contain special-category information, including a page capture used as case evidence. A separate confirmation is requested before each page-capture upload. You may withdraw consent for future processing by deleting the relevant asset or your account, or by contacting us. Withdrawal does not make earlier lawful processing unlawful. A legal hold may preserve narrowly defined case or financial records where required.
We disclose only the minimum necessary to providers used for an enabled feature: Render (application and PostgreSQL hosting), Cloudflare R2 or equivalent private object storage, Yoti (age assurance), TinEye and any separately identified video-matching provider, Stripe (billing), and Resend (transactional and takedown email). A provider that is not activated does not receive data for that feature. Approved takedown information may be disclosed to the relevant platform, host, search engine, registrar, legal adviser or authority. Private reference files are not attached to routine notices.
Providers may process information in the UK, EEA or other countries. Before production data is transferred outside the UK without UK adequacy regulations, we require an appropriate safeguard such as the UK International Data Transfer Agreement or UK Addendum and assess supplementary measures. Provider locations and subprocessors can change; material changes will be reflected in this notice.
| Record | Typical retention |
|---|---|
| Unverified account | 30 days |
| Account/profile and successful verification result | Account life plus up to 30 days |
| Encrypted reference media | Until deletion or account closure |
| Failed/abandoned verification metadata | 90 days |
| Match evidence without a legal case | 12 months after last review |
| Encrypted creator-supplied page capture | Same as the associated match/case evidence, unless legal hold |
| Takedown communications and dispute records | Up to 6 years after case closure |
| Security/audit logs | 12 months |
| Billing and tax records | 6 years after the relevant financial year |
| Support conversations | 24 months after closure |
Encrypted backups are targeted to expire within 35 days. Legal holds suspend deletion only for affected records and are documented.
Controls include encrypted media storage, TLS, password hashing, secure cookies, least-privilege provider credentials, rate limits, integrity hashes, tenant isolation, audit trails and human approval before notice delivery. No service can guarantee absolute security. Please report suspected security issues without attaching intimate content.
The service is for adults aged 18 or over. Our age provider may offer document checks or facial age estimation. Content Protect is designed to receive the outcome rather than raw documents or images. Match scores and age-provider results support decisions but do not by themselves create a legal takedown or similarly significant decision; creator and operator review are required.
Depending on the circumstances, you may request access, correction, deletion, restriction, portability or object to processing. You may withdraw consent and complain about automated processing. We normally respond within one month after verifying identity. Reported parties may use our dispute channel. You may complain to the Information Commissioner's Office.
We currently use only essential authentication and security cookies. See the Cookie Notice.
Material changes will be dated and, where appropriate, communicated in the service. Contact white.eagles.dm@gmail.com for privacy requests.