Back to Hidden Horny Smile

Legal · Hidden Horny Smile

Privacy Notice

This Notice explains what Hidden Horny Smile collects, why it is used, who receives it, how long it is kept and the choices available to you.

Effective
2 August 2026
Version
1.1
Applies to
Website and private account services

1. Scope and controller

This Notice applies to the Hidden Horny Smile website, account area, private content library, messages, custom requests, purchases and related support. The operator of Hidden Horny Smile determines how personal data is processed for these services and acts as the data controller where that concept applies.

Third-party platforms linked from the landing page process data under their own privacy notices. Visiting those platforms is separate from using Hidden Horny Smile.

2. Data we collect

  • Account data: pseudonym, role, account status, creation time and last sign-in time.
  • Passkey data: public credential identifiers, public keys, authenticator metadata and last-use time. We do not receive your device PIN, fingerprint or facial template.
  • Age-assurance data: an over-18 result, provider name, opaque provider reference, issue time and expiry. Hidden Horny Smile is designed not to retain identity-document images.
  • Purchase data: order identifiers, provider references, amount, currency, status, credit ledger entries and fraud-prevention metadata. Full payment-card details stay with the hosted payment provider.
  • Service data: purchased entitlements, content access, encrypted message bodies, encrypted custom-request briefs and delivery status.
  • Optional notification data: an application-encrypted email address, verification status, consent version, language, consent time and withdrawal time when you choose new-content emails. Social profile names and avatars are not retained for this purpose.
  • Technical and security data: session identifiers, CSRF tokens, timestamps, redacted request information, hashed IP indicators, device or browser signals and audit events needed to protect the service.
  • Support and report data: information you choose to submit when requesting help, privacy action or content removal.

3. Where data comes from

Most data comes directly from you when you acknowledge the safety gate, create an account, sign in, purchase access, send a message or make a request. Age-assurance and payment providers return limited status and reference data. Security data is generated when your device communicates with the service.

4. Purposes and legal bases

  • Contract: create and secure your account, deliver purchased content, maintain credits, process messages and fulfil accepted custom requests.
  • Legal obligation: meet accounting, tax, consumer-protection, age-assurance, lawful-request and record-keeping duties that apply to the operator.
  • Legitimate interests: prevent fraud and abuse, protect creator safety and rights, secure the service, keep audit evidence and improve reliability, balanced against your rights.
  • Consent: send optional new-content emails and use behavioural advertising or other non-essential persistent storage only after a valid, separate choice. Notification consent can be withdrawn in the account area at any time.
  • Vital or public interests: respond to an immediate safety threat or a valid request from a competent authority where the law permits or requires it.

5. Providers and disclosures

We share only the data needed for a provider’s role and enable integrations only after configuration and review. Depending on the feature used, recipients may include:

  • Age-assurance providers, to determine whether protected access may be granted.
  • Hosted payment providers, to process payment, refunds, fraud checks and chargebacks.
  • Private media delivery and storage providers, to upload, encode, store and deliver protected content through short-lived links.
  • Infrastructure, database, backup and security providers that operate the service under access restrictions.
  • An email delivery provider receives the destination address and neutral notification text only after double opt-in. Emails do not include content titles, previews, purchases, message bodies, custom briefs or payment credentials.
  • Professional advisers, payment partners, regulators, courts or law enforcement where disclosure is necessary, lawful and proportionate.
  • A successor operator in a merger, sale or reorganisation, subject to confidentiality and applicable notice requirements.

6. International transfers

Some providers may process data outside your country. Where transfer restrictions apply, we use an available lawful mechanism such as an adequacy decision, approved contractual safeguards or another permitted basis, and apply technical and organisational protections appropriate to the data.

7. Retention

  • The essential signed-in session expires after 30 minutes of inactivity unless renewed by activity or ended sooner.
  • The local 18+ confirmation remains on your device until you clear site data. It records a self-attestation and is not independent proof of age.
  • A temporary self-attested age grant is kept in the server session until its recorded expiry. A future age-assurance result may be retained longer only when needed for a dispute, fraud-prevention or legal obligation.
  • Account, entitlement, message and custom-order data is kept while the account or relevant service is active, then deleted or de-identified subject to safety, dispute and legal requirements.
  • Payment references and ledger records are kept for the period required for reconciliation, chargebacks, fraud prevention, accounting, tax and legal claims.
  • An unconfirmed email token expires after 24 hours. Withdrawing notification consent immediately cancels queued messages; minimal consent and withdrawal evidence may be retained for compliance and abuse prevention.
  • Security logs and audit records are kept only for the period reasonably needed to investigate abuse, protect the service and meet legal duties.
  • When no fixed period applies, we use the purpose, sensitivity, risk, contractual need and applicable limitation periods to set the retention period.

8. Cookies and device storage

  • HHS_SESSION: a strictly necessary, HTTP-only session cookie used to keep a signed-in session secure; configured for a 30-minute inactivity timeout.
  • XSRF-TOKEN: a strictly necessary security token used to prevent cross-site request forgery.
  • hhs_safety_ack_v1: first-party local storage that remembers the landing-page acknowledgement until you clear it.
  • First-party aggregate analytics uses a random identifier held only in the memory of the open browser tab. It records normalized page paths, event categories, time and a coarse referral category; it does not store IP addresses, user-agent strings, cookies, persistent device identifiers or fingerprints.
  • The current build does not set analytics or behavioural-advertising cookies. Behavioural tracking or persistent analytics storage must remain off until a required consent choice is made.

9. Security

The service uses passkeys, encrypted message and custom-request storage, access controls, short-lived media links, audit records and hosted payment handling. Sensitive provider credentials are kept out of browser code. No system is completely secure, and screenshots or external recording cannot be prevented with certainty.

10. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, obtain a portable copy, withdraw consent, and complain to a data-protection authority. You may also have rights relating to automated decisions and targeted advertising.

  • Submit a request through secure account support and describe the account or transaction concerned without sending identity documents unless a secure verification method is specifically provided.
  • We may ask for proportionate verification before acting on a request and may retain a minimal record of the request and outcome.
  • Some data cannot be deleted immediately when retention is required for payment, fraud, legal claims, safety or another lawful obligation.
  • You can clear the landing-page acknowledgement through your browser’s site-data controls and can end a signed-in session by signing out.

11. Age assurance and automated access decisions

During the temporary launch phase, your explicit 18+ self-attestation allows protected features for the browser session. Strong age assurance is planned for a later stage; when enabled, Hidden Horny Smile is designed to receive an over-18 result and an opaque reference rather than the identity document itself.

12. Adults only

The service is not directed to anyone under 18. If we learn that an underage person supplied account data, we will restrict access and delete or preserve information as required for safety and legal compliance. Report suspected underage access through the Content Removal and reporting route.

13. Changes to this Notice

We may update this Notice when the service, providers or legal requirements change. The current version and effective date appear at the top of the page. Material changes will be communicated in the service when required.

14. Contact and complaints

Use secure account support for privacy requests and questions. Use the Content Removal page for unlawful, non-consensual or rights-infringing material. You may also complain directly to the data-protection or consumer authority available in your country.

Secure routes

Need help or want to make a request?

Do not send identity documents, card details or sensitive media through ordinary messages.