Privacy Policy
What Tenderkind collects, how we use it, and the rights you keep.
Tenderkind Privacy Policy — what we collect, how we use it, who processes it, and the rights you have over your data on our subscription platform.
1. What we collect
We collect the minimum we need to run Tenderkind and to keep it safe. That includes:
- Account information. Your email address, the username and display name you choose, your password (stored as a one-way hash), and the date you joined.
- Identity & age-verification data. For creators, the documents we are required to collect under 18 U.S.C. § 2257 (and equivalent rules in other jurisdictions) to confirm every performer is an adult. These records are kept in a restricted-access store, separate from public profile data.
- Payment information. Stripe handles card details and billing on our behalf; we keep the last four digits, card brand, expiry, billing country, and a Stripe customer identifier for receipting, refunds, and tax records. We never see or store full card numbers.
- Content you upload. The posts, images, videos, and files you publish, plus the metadata those uploads carry (file size, format, upload time, and the captions and tags you attach).
- Usage and device data. IP address, user-agent, approximate geolocation (country / region), pages viewed, and feature interactions. This is used to keep the service working, to detect abuse, and — only after we enable it — for analytics.
- Support and safety correspondence. Anything you send us by email, the tickets you open, and the reports you file about other users or content.
2. How we use it
We use the data above to:
- Run your account. Authenticate you, sync your profile across devices, deliver the content you’ve subscribed to, and remember your preferences (theme, language, notification settings).
- Process payments. Charge subscriptions and one-time purchases, pay creators, issue refunds, and keep the financial records we’re required to keep.
- Deliver and protect content. Store uploads, serve them to the audiences you’ve chosen, scan for known child-sexual-abuse material, enforce takedowns, and respond to lawful law-enforcement and DMCA requests.
- Keep the platform safe. Detect spam, scrape attempts, credential stuffing, and fraudulent payments; suspend or remove accounts that breach our Terms; cooperate with authorities on credible reports of illegal activity.
- Improve the product. Understand which features work and which confuse people, fix broken flows, and prioritise the next thing we build. Where analytics is enabled, IP addresses are anonymised at the earliest possible step and never tied back to a specific user.
- Communicate with you. Send transactional email (receipts, security alerts, takedown notices) and the notifications you’ve opted into. We don’t sell your email and we don’t rent it to third parties.
3. Third-party processors
We share data only with sub-processors we’ve vetted, and only the slice they need to do their job. The current list is:
- Stripe. Payment processing, fraud screening, and creator payouts. Card data never touches our servers; we receive only the tokenised identifiers Stripe returns. Privacy: stripe.com/privacy.
- Object storage provider. Encrypted upload storage and CDN delivery for the content creators publish. File objects are private by default and served via short-lived, origin-checked URLs.
- Better-Auth. Identity and session management — the library that signs sessions, handles password resets, and enforces per-user authorisation on every API request.
- Hosting & infrastructure. The platform and database run on Polsia-managed infrastructure; database snapshots are encrypted at rest and access is limited to on-call engineers.
- Analytics (when enabled). Google Analytics 4 with IP-anonymisation enabled at the property level. See §4 for what that means in practice.
We update this list when we add or replace a processor. The current sub-processor list is always reachable from this page.
4. Cookies & analytics
Tenderkind uses a small number of cookies. We keep this section current with what the site actually sets.
- Essential session cookies. These keep you signed in, protect against cross-site request forgery, and remember your in-progress form entries. They cannot be disabled without breaking sign-in.
- Preference cookies. A small store for theme, language, and notification-dismissal state. Disabling these resets those preferences to defaults.
- Analytics cookies (future). We may enable Google Analytics 4 to understand aggregate product usage. If we do, GA4 will run with IP anonymisation enabled, advertising features turned off, and no advertising cookies will be set. We will not use analytics for any automated decision that produces legal effects on you.
We don’t use advertising or cross-site tracking cookies. We don’t sell behavioural data to data brokers, and we don’t let third parties set advertising cookies on Tenderkind.
5. Your rights
You stay in control of the data you’ve given us. The rights below apply to everyone, with the specific extra protections required for users in the EEA, the UK, and California described in §7.
- Access. Request a copy of the personal data we hold about you.
- Export. Download your posts, messages, and profile data in a portable format.
- Correction. Fix anything in your profile or account metadata that’s wrong.
- Deletion / account removal. Close your account from Settings → Account, or ask us in writing. Account deletion cancels future charges, revokes active sessions, and triggers deletion of your content and personal data within thirty (30) days, except for the records we’re required to keep (§6).
- Withdraw consent. Turn off optional notifications and marketing email at any time; transactional email remains unavoidable while you hold an account.
- Object or restrict. Ask us to restrict processing where you believe it’s unlawful, and object to processing based on our legitimate interests.
To exercise any of these, email tenderkind@polsia.app from the address on your account. We respond within thirty (30) days; if your request is complex we’ll tell you in advance and explain why it’s taking longer.
6. Data retention
We hold data only for as long as we have a reason to. Concretely:
- Account & profile data. Kept while your account is active and for up to thirty (30) days after deletion to honour the undo window and routine backups.
- Financial records. Subscription receipts, payout history, and tax statements are kept for at least seven (7) years to satisfy tax, accounting, and consumer-protection law in our operating jurisdictions. Creator 2257 records are kept for the period required by 28 C.F.R. § 75.2.
- Backup window. Encrypted database snapshots are retained for up to thirty (30) days; user-initiated deletion propagates to backups as they roll forward.
- Safety-incident logs. Account suspensions, takedowns, and law-enforcement disclosures are retained for the period needed to defend against re-abuse and to comply with reporting rules.
7. International transfers & GDPR
Tenderkind is operated from the United States. When you use the service from the EEA, the UK, or another jurisdiction with its own data-protection rules, your personal data is transferred to and processed in the U.S. on the legal bases below.
- Performance of a contract. Article 6(1)(b) GDPR — to deliver the service you signed up for.
- Legitimate interests. Article 6(1)(f) GDPR — to keep the platform secure, prevent fraud, and enforce our Terms, balanced against your rights.
- Legal obligation. Article 6(1)(c) GDPR — keeping tax, financial, age-verification, and law-enforcement records we’re required to retain.
- Consent. Article 6(1)(a) GDPR — for anything optional, like analytics or non-essential notifications. You can withdraw consent at any time without affecting the rest of our processing.
For transfers from the EEA / UK to the U.S., we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum, where applicable) with our sub-processors. California residents have equivalent rights under the CCPA / CPRA, including the right to know, delete, correct, and opt out of any “sale” of personal information — we don’t sell personal information.
8. Children’s data
Tenderkind is an adults-only platform, and the underlying activity it hosts is for adult audiences. We do not knowingly collect personal data from anyone under 18. The minimum age to create an account matches the higher of 18 or the age of majority in your jurisdiction. If you believe we have collected data from a minor, email tenderkind@polsia.app and we will delete the record.
9. Contact
Questions about this policy, requests to exercise your rights, and any concern about how your data is handled all go to tenderkind@polsia.app. A real person reads it. The data controller is the legal entity referenced in our Terms of Service; correspondence can be addressed to that entity at the same inbox.
Effective date: 2026-08-15. Last updated: 2026-08-15.