Version 1.1 — September 30th, 2026. This version applies when made available and accepted where acceptance is required; it does not retrospectively reduce rights under an earlier contract.
1. Who is responsible#
Unstatic Labs, a French single-member simplified joint-stock company (SASU à capital variable), share capital €1,000, minimum capital €100; RCS Paris 983 982 950; registered office 60 rue François Ier, 75008 Paris, France; VAT FR48 983 982 950.
Unstatic Labs is the controller for the Kinkverse account, profile, subscription, QR and game processing described here. Any change to the entity deciding purposes and means will be explained before the new arrangement operates.
Contact for support, complaints, withdrawal and privacy requests: hello@kinkverse.org.
You may use that contact for the privacy function without being a paying member. This policy covers visitors, members, game participants and people whose data reaches us in reports. The Boutique Privacy Policy covers orders and fulfillment; Telegram and external sign-in services have their own policies for their services.
2. The choices that matter#
Kink and sexual-life information can be sensitive personal data. We do process it when you choose relevant features. Even a relationship, game entry, badge or association with this community may reveal sensitive information. Pseudonyms and internal identifiers remain personal data when they can be linked to someone.
You control optional disclosures. We do not sell personal data or share it for other parties’ behavioural advertising. We do not use your intimate profile, private content or game evidence for general-purpose AI training or unrelated research. Optional publication, recommendation, analytics, research and marketing purposes require their own appropriate choice rather than being silently included in accepting the terms.
We protect data in the systems we operate, but this is a centrally operated service, not a promise of end-to-end encryption or decentralized custody. Authorized service providers and limited authorized staff can process information needed for their role. A public page is visible beyond the community. Telegram messages and other recipients’ copies have separate limitations.
3. The data involved#
| Category | Examples and source |
|---|---|
| Account and sign-in | Email or linked authentication identifier, sign-in events, language, account identifiers and the limited identity information supplied by the sign-in method you choose. |
| Profile and self-description | Chosen name, pseudonym, avatar, bio, links, appearance, stickers, optional age information, city and other fields you enter. |
| Sensitive self-description | Kinks, sexual preferences, orientation, roles, boundaries, answers to the wizard, scores, inferred suggestions and sensitive claims or relationship information. Gender information is treated sensitively in context; it is not automatically Article 9 data in every case. |
| Relationships and disclosure | Smashes, accepted relationships, blocks, chosen audiences, consents, publication choices and permitted auto-connection events. |
| Location | A city or location you select; technical IP-derived location may assist a location search or security. Precise location is not made public merely because you select a city. We do not require continuous location tracking. |
| Locktober | Linked Telegram identifier, eligibility, entry date, chosen challenge settings, check-ins, submitted evidence, assigned reviewers, reviews, progress, freezes, missions, opt-in ranking, badges and moderation records. |
| Stars and Treats | Purchases and their origin, balance movements, gifts, allocations, conversions, rewards, reversals, redemption and account-linking identifiers. We retain enough transaction history to explain balances and prevent double use, not a copy of every intimate submission forever. |
| Purchases | Contact and billing details required by the transaction, customer and provider references, tax information, subscription state, invoices, refunds and disputes. Payment providers receive payment-instrument details; our ordinary systems do not need your full card number or security code. |
| Support and reports | Messages you send, evidence necessary to investigate a report, decisions and appeals. Reports may include information supplied by another person. Private note content is covered where such a feature is lawfully provided; it is not exempt from privacy rights because it is called private. |
| Technical operation | IP address, device/browser information, request and security logs, crash and performance diagnostics, preferences and necessary session information. Optional usage analytics concern interactions and performance, not the text of intimate answers. |
We receive data from you, your chosen linked services, the people interacting with you, payment and fulfillment systems, and technical operation of the service. We do not purchase profiles from data brokers. We do not require a public legal name or a public link between separate personas. Legal billing information is kept separate from public profile content.
4. Purposes and legal bases#
| Purpose | GDPR basis |
|---|---|
| Account access and functions you request | Article 6(1)(b), performance of the contract, for data objectively necessary to provide them. |
| Optional intimate self-description, wizard interpretation, storage and audience disclosure | Article 6(1)(a) and explicit consent under Article 9(2)(a). The choice identifies the processing and the audience. |
| A chosen game, sensitive evidence review and necessary sensitive game records | Article 6(1)(b) for the requested programme and explicit Article 9(2)(a) consent for the specified sensitive processing. Publication of ranking or badges is a separate choice. |
| Optional sensitive-data recommendations, matching or AI assistance | Article 6(1)(a) and, where applicable, Article 9(2)(a), for the disclosed optional purpose. |
| Payments, orders, balances and servicing a transaction | Article 6(1)(b); Article 6(1)(c) for required accounting, tax and regulatory evidence. Sensitive context is minimized and any Article 9 exception must separately apply. |
| Security, abuse prevention, proportionate moderation and defending rights | Article 6(1)(f), legitimate interests in a secure and lawful service; Article 6(1)(c) where a specific legal obligation applies. These bases do not override Article 9: sensitive material is processed under an applicable exception, such as the member’s specific consent or Article 9(2)(f) where actually necessary for legal claims. |
| Optional analytics, non-essential device tracking and marketing | Consent under Article 6(1)(a), and the applicable device-tracking rules. Strictly necessary technical functions and limited security diagnostics use the relevant contract, legal-duty or legitimate-interest basis. |
| Responding to rights requests and valid authority requests | Article 6(1)(c), with any additional sensitive-data condition that the particular request requires. |
Where we rely on legitimate interests you may object. We assess necessity, proportionality and your rights. There is no general “legitimate interest” exception permitting unrestricted processing of sexual-life data. Data being visible online does not authorize us to reuse it for any purpose.
5. Consent, visibility and withdrawal#
Consent must be specific, informed, affirmative and recorded. It is not inferred merely from account creation, payment, accepting terms or inactivity. Refusing optional sensitive fields, analytics or marketing does not prevent basic non-sensitive functions that can operate without them. A feature genuinely dependent on sensitive data cannot continue processing that data after its required consent is withdrawn, but unrelated access and legal rights remain.
You can withdraw an optional consent through the relevant privacy control or by contacting us, without a fee. Withdrawal stops the future processing covered by it; it does not retroactively invalidate processing that was lawful. We stop dependent sharing and remove or restrict related data unless a separate lawful retention obligation applies. A visibility change is not a substitute for withdrawing consent to a different purpose. There is no retroactive consent for previously unconsented processing.
Before publishing a sensitive field or using game evidence, the interface explains what will be processed and who can see it. Public sharing, private storage, assigned peer review, recommendation and research are not treated as one undifferentiated consent. Relations involving another person require that person’s authorization where needed.
6. Who can see information#
Your chosen audience. Public profiles can be seen by anyone with access to the page. Restricted content is provided according to applicable permissions, not merely because someone scanned a code or expressed interest. Auto-Smash can create an owner-authorized ordinary relationship with an authenticated scanner, as described in the Terms. Anonymous scan statistics are not a named history of visitors supplied to the profile owner.
Game reviewers. Evidence submitted for peer review is shared with assigned reviewers and authorized safety staff, not automatically with the public or every player. Assignment does not create permanent access to other restricted profile information. Reviewers must not copy, redistribute or use evidence for another purpose. Those rules reduce misuse but cannot make copying technically impossible on an independent device.
Staff and delegated operators. Access is limited to support, security, moderation, technical operations and legal duties, with confidentiality and appropriate authorization. Private or restricted does not mean “invisible to the operator.” Access to particularly sensitive content must be justified and auditable, not unrestricted browsing. Reports about you may be assessed subject to protection of other people’s rights and confidentiality.
Service providers. We use providers by category: hosting and infrastructure, database and authentication, email delivery, customer support, optional audience measurement, error diagnostics and payment (including Stripe where offered). Telegram is involved for the game and sign-in. Each receives only what its function requires. A provider can be our processor for one activity and an independent controller for another; payment fraud, regulated payment processing and external sign-in are not all controlled exclusively by us.
Telegram. Choosing the Telegram game sends relevant account-linking information, messages and submitted media through Telegram and our bot integration. Telegram operates its own platform and payment system. Bot/cloud conversations are not represented as end-to-end encrypted. Your Telegram settings and participation in a group may expose information to other group members. Do not post private evidence in a public group.
Good Boys Club. When you choose to link accounts, redeem Treats, unlock a collection or personalize a QR item, the Boutique receives necessary linking identifiers, the selected public identity/QR destination, reward transactions and eligibility. It does not need your private kink answers or raw game images to fulfill an order. Linking does not authorize exposing a billing identity, merging separate personas or subscribing you to another brand’s marketing. We do not duplicate a spendable balance across systems.
Authorities and successors. We disclose what a valid legal requirement or necessary legal claim justifies. A business transfer is subject to applicable transparency, purpose and transfer safeguards, not a general permission to sell a member database for unrelated use.
7. International processing#
Some providers, support operations and network locations are outside the European Economic Area. Public content may be distributed through a global network. EU storage does not necessarily mean all access occurs in the EU. We do not promise that all processing is EU-only.
For transfers requiring a safeguard, we use the applicable lawful mechanism, such as an adequacy decision or the European Commission’s standard contractual clauses together with necessary supplementary safeguards. A provider’s participation in an adequacy framework must cover the relevant recipient and activity; its mere brand or an EU ingestion address is not sufficient. You can ask for information about recipients, relevant locations and the safeguards, and a copy subject to justified redactions. A voluntary click on a link is not used as a blanket transfer consent.
8. Cookies, analytics and automated processing#
Necessary storage supports authentication, security, shopping or service functions you request and remembering your choices. Optional analytics and non-essential trackers wait for an appropriate opt-in. Accepting and refusing optional tracking are comparably accessible; you can change the choice later. We do not require advertising consent to use the service.
Our privacy baseline excludes session replay of member or administrative screens. Diagnostics must minimize and redact identifiers, content, tokens and sensitive URLs. Optional analytics must not include intimate free text, proof images, raw questionnaire answers or unnecessary direct identifiers.
Automated systems may suggest tags, assess submitted content, route reviews, calculate documented game progression or detect anomalies. Suggestions can be wrong and are not diagnoses. If a feature sends your input to an external AI provider, its notice identifies that provider and processing before use. It is not authorization for the provider’s unrelated training. You can seek human review of a significant moderation, reward or account decision; we do not treat a fraud flag as conclusive evidence. Any legally significant solely automated decision requires its own lawful basis and safeguards.
Operational notifications are separate from marketing. We minimize intimate content in notifications and provide controls for optional messages. A shared device, lock screen or email account may nevertheless reveal that an interaction occurred.
9. Retention schedule#
| Record | Normal retention limit or criterion |
|---|---|
| Account and chosen profile | While actively used. Free inactive accounts are reviewed after 24 months, with advance notice before deletion. Active paid rights and unresolved purchased balances are not silently destroyed as inactivity. |
| Deleted operational content | Withdrawn from normal serving without undue delay; operational erasure completed within 30 days unless a documented legal exception applies. |
| Rolling backups | 30 days. Data pending expiry is isolated from ordinary use; restoration must reapply deletions. |
| Game evidence media | No longer than 30 days after its review and any timely appeal are resolved; a specific safety/legal hold may preserve only necessary evidence. |
| Detailed game, review and mission events | Up to 90 days after the season ends; thereafter only necessary badge, balance, dispute or aggregate records. |
| Badge record | While retained in your account or required to verify a badge you choose to maintain; raw proof is not retained for the badge’s entire life. |
| Optional identifiable analytics | 90 days. |
| Redacted diagnostic events | 30 days. No session replay. |
| Ordinary security and access audit logs | Six months, unless a specific applicable law or a documented incident requires a different period. |
| Closed support and moderation cases | 12 months, unless necessary for an actual dispute, safeguarding duty or other documented legal requirement. |
| Individual QR events | 30 days. Operational token counts may persist while the token is used; longer statistical reporting must be genuinely anonymized. |
| Minimal consent and contract evidence | While needed to operate the choice/contract, then generally five years in restricted legal archives; a longer mandatory contract-archive period applies where required. This is not retention of all underlying intimate content. |
| Invoices and statutory accounting evidence | Ten years from the end of the relevant financial year; other tax evidence follows its applicable statutory period. |
| Wallet and redemption accounting | While rights remain outstanding, then the applicable dispute or accounting period. Keep transaction evidence separate from intimate game media. |
| Age assurance | Minimum method, threshold result, date and evidence reference necessary to substantiate the check; no routine identity-document image in our member database. |
A legal hold is documented, access-restricted, reviewed and ended when no longer needed. We do not retain a complete intimate profile merely because an invoice must remain. Proper anonymization is different from replacing a name with an identifier.
10. Deletion, offline devices and separate systems#
Deletion stops ordinary serving and triggers removal across relevant operational stores, media, indexes, derived suggestions and caches. Necessary restricted legal records can remain as explained above. Relevant recipients are informed of correction, restriction or erasure where required.
An installed application can have a previously authorized offline copy for up to seven days. An offline device cannot immediately receive a new block, deletion or privacy change. Restricted intimate offline access requires a clear choice and must not be extended without a fresh permission check. Revocation takes effect at the next enforceable check or expiry; the system must not renew access from a stale local copy. Signing out clears that account’s local cache controlled by the application.
We cannot guarantee retrieval of screenshots, downloads or independently retained third-party copies. We act on known misuse and make deletion requests where appropriate. Deleting in Kinkverse does not automatically erase independent Telegram history, an already engraved physical item or the Boutique’s statutory invoice. The account-linking and deletion interface explains which systems are affected.
11. Your rights#
You may request access and a copy, correction, erasure, restriction, applicable portability, and objection to legitimate-interest processing. You can withdraw consent at any time and object to direct marketing. Privacy controls, export and deletion must remain accessible without Plus; support is an alternative, not a way to pressure you to stay.
We respond without undue delay and normally within one month. Where legally permitted, a complex or numerous request may take up to two additional months; we explain this within the first month. We ask only for proportionate identity assurance where there is reasonable doubt, not a routine government ID to reveal a pseudonymous account. Requests are normally free, subject only to lawful exceptions. We explain any refusal and your remedies.
You can complain directly to CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, through cnil.fr, or to the competent supervisory authority where you live or work. You do not have to complain to us first.
12. Security, incidents and changes#
We use measures appropriate to the sensitivity and risks, including access restrictions, protected transmission, authorization checks, data minimization and operational oversight. No online service can guarantee perfect security. Where legally required after a breach, we notify the supervisory authority and affected people; we do not delay a required warning merely because the full investigation is unfinished.
Material policy changes are brought to your attention. A policy update cannot itself authorize a new incompatible purpose, new sensitive-data use or wider audience. We obtain a new consent where required and preserve evidence of the choices actually made.
Changes in version 1.1#
Hosting and service-provider information simplified.