1. Scope and controller
This Notice applies to the Hidden Horny Smile website, account area, private content library, messages, custom requests, purchases and related support. The operator of Hidden Horny Smile determines how personal data is processed for these services and acts as the data controller where that concept applies.
Third-party platforms linked from the landing page process data under their own privacy notices. Visiting those platforms is separate from using Hidden Horny Smile.
2. Data we collect
- Account data: pseudonym, role, account status, creation time and last sign-in time.
- Passkey data: public credential identifiers, public keys, authenticator metadata and last-use time. We do not receive your device PIN, fingerprint or facial template.
- Age-assurance data: an over-18 result, provider name, opaque provider reference, issue time and expiry. Hidden Horny Smile is designed not to retain identity-document images.
- Purchase data: order identifiers, provider references, amount, currency, status, credit ledger entries and fraud-prevention metadata. Full payment-card details stay with the hosted payment provider.
- Service data: purchased entitlements, content access, encrypted message bodies, encrypted custom-request briefs and delivery status.
- Optional notification data: an application-encrypted email address, verification status, consent version, language, consent time and withdrawal time when you choose new-content emails. Social profile names and avatars are not retained for this purpose.
- Technical and security data: session identifiers, CSRF tokens, timestamps, redacted request information, hashed IP indicators, device or browser signals and audit events needed to protect the service.
- Support and report data: information you choose to submit when requesting help, privacy action or content removal.
3. Where data comes from
Most data comes directly from you when you acknowledge the safety gate, create an account, sign in, purchase access, send a message or make a request. Age-assurance and payment providers return limited status and reference data. Security data is generated when your device communicates with the service.
4. Purposes and legal bases
- Contract: create and secure your account, deliver purchased content, maintain credits, process messages and fulfil accepted custom requests.
- Legal obligation: meet accounting, tax, consumer-protection, age-assurance, lawful-request and record-keeping duties that apply to the operator.
- Legitimate interests: prevent fraud and abuse, protect creator safety and rights, secure the service, keep audit evidence and improve reliability, balanced against your rights.
- Consent: send optional new-content emails and use behavioural advertising or other non-essential persistent storage only after a valid, separate choice. Notification consent can be withdrawn in the account area at any time.
- Vital or public interests: respond to an immediate safety threat or a valid request from a competent authority where the law permits or requires it.
6. International transfers
Some providers may process data outside your country. Where transfer restrictions apply, we use an available lawful mechanism such as an adequacy decision, approved contractual safeguards or another permitted basis, and apply technical and organisational protections appropriate to the data.
7. Retention
- The essential signed-in session expires after 30 minutes of inactivity unless renewed by activity or ended sooner.
- The local 18+ confirmation remains on your device until you clear site data. It records a self-attestation and is not independent proof of age.
- A temporary self-attested age grant is kept in the server session until its recorded expiry. A future age-assurance result may be retained longer only when needed for a dispute, fraud-prevention or legal obligation.
- Account, entitlement, message and custom-order data is kept while the account or relevant service is active, then deleted or de-identified subject to safety, dispute and legal requirements.
- Payment references and ledger records are kept for the period required for reconciliation, chargebacks, fraud prevention, accounting, tax and legal claims.
- An unconfirmed email token expires after 24 hours. Withdrawing notification consent immediately cancels queued messages; minimal consent and withdrawal evidence may be retained for compliance and abuse prevention.
- Security logs and audit records are kept only for the period reasonably needed to investigate abuse, protect the service and meet legal duties.
- When no fixed period applies, we use the purpose, sensitivity, risk, contractual need and applicable limitation periods to set the retention period.
9. Security
The service uses passkeys, encrypted message and custom-request storage, access controls, short-lived media links, audit records and hosted payment handling. Sensitive provider credentials are kept out of browser code. No system is completely secure, and screenshots or external recording cannot be prevented with certainty.
10. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, obtain a portable copy, withdraw consent, and complain to a data-protection authority. You may also have rights relating to automated decisions and targeted advertising.
- Submit a request through secure account support and describe the account or transaction concerned without sending identity documents unless a secure verification method is specifically provided.
- We may ask for proportionate verification before acting on a request and may retain a minimal record of the request and outcome.
- Some data cannot be deleted immediately when retention is required for payment, fraud, legal claims, safety or another lawful obligation.
- You can clear the landing-page acknowledgement through your browser’s site-data controls and can end a signed-in session by signing out.
11. Age assurance and automated access decisions
During the temporary launch phase, your explicit 18+ self-attestation allows protected features for the browser session. Strong age assurance is planned for a later stage; when enabled, Hidden Horny Smile is designed to receive an over-18 result and an opaque reference rather than the identity document itself.
12. Adults only
The service is not directed to anyone under 18. If we learn that an underage person supplied account data, we will restrict access and delete or preserve information as required for safety and legal compliance. Report suspected underage access through the Content Removal and reporting route.
13. Changes to this Notice
We may update this Notice when the service, providers or legal requirements change. The current version and effective date appear at the top of the page. Material changes will be communicated in the service when required.
14. Contact and complaints
Use secure account support for privacy requests and questions. Use the Content Removal page for unlawful, non-consensual or rights-infringing material. You may also complain directly to the data-protection or consumer authority available in your country.
Secure routes
Need help or want to make a request?
Do not send identity documents, card details or sensitive media through ordinary messages.