Privacy Policy

Last updated: April 20, 2026

Cuffplay's business depends on member trust. This Privacy Policy explains, in plain language, what data we collect, why we collect it, how we protect it, and what choices you have.

Many of our members are closeted or otherwise have significant reasons to keep their Cuffplay activity private. We've designed our data collection around that reality.

1. What we collect

Account data

  • Email address — for password recovery and account alerts. Never shown to other members.
  • Nickname — visible to other members. You choose it; it need not reflect your real identity.
  • Date of birth — collected once at signup, used to verify age. Never shown to other members.
  • Password hash — we store only a hashed version of your password (PBKDF2 with per-user salt). We cannot recover your plaintext password.

Content and activity

  • Messages you post in public rooms and private DMs.
  • Your profile content (bio, role, interests).
  • Moderation reports you file or that are filed about you.
  • Block / favorite lists.

Technical data

  • IP address — collected for anti-abuse (spam prevention, ban evasion detection). Retained for up to 30 days, then purged.
  • Browser and device information — user-agent, screen size, approximate location derived from IP. Used to debug issues and detect abuse.
  • Session cookies — required for login.

What we do NOT collect

  • Your real name (never requested, never optional-to-add).
  • Government ID (beyond age verification at signup).
  • Phone number.
  • Precise location (we derive approximate region from IP only).
  • Payment card numbers (our payment processor handles these).

2. How we use your data

  • To operate the Service (authenticate, deliver messages, moderate).
  • To prevent abuse (spam, harassment, underage accounts).
  • To improve the product (aggregated usage patterns, never tied to individuals).
  • To communicate account-related information (password resets, policy changes).

We do not sell your data. We do not share data with advertisers. We do not run behavioral advertising.

3. Who we share data with

  • Service providers — Cloudflare (hosting), Stream Chat (chat infrastructure), and our payment processor. Each receives only the minimum data needed for its function.
  • Moderators — our own team, bound by confidentiality. They see reports and account context relevant to moderation decisions.
  • Law enforcement — only in response to valid legal process (subpoena, court order). We will challenge overbroad requests where feasible.

4. Your rights

Depending on where you live, you may have the following rights:

  • Access — request a copy of the data we hold about you.
  • Correction — update inaccurate data via account settings or by contacting us.
  • Deletion — delete your account at any time; we purge personal data within 30 days of deletion, except where law requires retention.
  • Portability — request an export of your data in a machine-readable format.
  • Objection — object to specific processing activities.
  • Restriction — request we limit how we use your data.

To exercise any of these rights, email privacy@cuffplay.com. We respond within 30 days.

GDPR (EU / UK residents)

Our legal bases for processing are: (a) contract necessity (delivering the Service), (b) legitimate interests (anti-abuse, moderation, product improvement), and (c) consent (where specifically requested). You have the right to lodge a complaint with your local data protection authority.

CCPA (California residents)

We do not sell personal information as defined under the CCPA. You have the right to know what we collect, delete what we hold, and not be discriminated against for exercising your rights.

5. Security

We encrypt data in transit (TLS 1.3) and at rest. Access to production data is limited to the operators who need it, logged, and periodically audited. We use modern password hashing (PBKDF2, 210k iterations, per-user salt). No system is perfectly secure; we disclose material breaches to affected members promptly.

6. Children

Cuffplay is exclusively for adults 18 and older. We do not knowingly collect data from anyone under 18. If we learn an account belongs to a minor, we terminate the account and purge its data.

7. International data transfers

Cuffplay is operated from the United States. Data you submit may be transferred to and processed in the US or in any country where our service providers operate. By using the Service, you consent to these transfers.

8. Changes to this Policy

We may update this Policy. Material changes are announced in-product and by updating the “Last updated” date above.

9. Contact

Privacy questions or rights requests: privacy@cuffplay.com.