1. Scope
This Privacy Policy explains how Real Fake Girls handles personal data when you browse the site, create an account, log in, follow tags, save posts, comment, report content, earn or use credits, enter premium access, submit prompts, use image-edit features, or contact us.
2. Data we collect
- Account data such as email address, password hash, login provider identifiers, session records, username, display name, account role, and account status.
- Account and adult-access records such as Terms acceptance, Privacy Notice acknowledgment, accepted policy version, 18+ confirmation, adult-content acceptance, and Premium-entry timestamps. Adult-access records are collected when a member asks to unlock Premium, not during ordinary sign-in.
- Product activity such as votes, saves, comments, comment votes, reports, followed tags, viewed pages, opened lightboxes, searches, premium unlocks, and private messages.
- Credit and historical payment records such as wallet ledger entries, mission rewards, top-up status, payment provider references, idempotency keys, refund notes, and fraud-prevention metadata. New purchases are disabled during the free beta.
- Optional credit-purchase interest such as whether you want FIAT and/or crypto availability updates, where you made the request, when you made it, and the account connected to the request.
- Optional YouPay and direct crypto support is not linked to your product benefits. External providers and public blockchains process those transactions under their own privacy practices.
- AI feature data such as source post IDs, prompts, moderation results, blocked prompt records, generation jobs, provider responses, and private generated outputs.
- Contact and support data such as name, email, message, business inquiries, legal requests, DMCA notices, and removal requests.
- Measurement data such as pseudonymous visitor, 30-minute session, and seven-day acquisition-journey identifiers; landing path and variant; referrer domain; campaign, creative, and device category; experiment exposure; and conversion events such as prompt submission, authentication, edit completion, result viewing, checkout, and payment.
- Operational data such as IP-derived request metadata, rate-limit buckets, security logs, import metadata, source/license metadata, storage references, browser/device diagnostics, and error logs.
3. Why we use data
We use data to run accounts, verify access, protect NSFW and private media, process credits and payments, personalize followed-tag feeds, moderate abuse, troubleshoot imports and generation jobs, prevent fraud, respond to support and legal requests, enforce our terms, comply with applicable law, and improve the product.
If you ask to hear when credit purchases become available, we use that preference to understand demand and to send availability updates only for the payment options you selected. Signing up does not purchase credits or trigger a payment.
We also use data to keep NSFW content gated, prevent direct app-route leakage of protected media, detect duplicate uploads, review reports, manage banned tags, and preserve audit trails for abuse prevention.
4. Cookies, analytics, and advertising measurement
We use essential cookies and similar storage for login, security, age/access checks, premium gating, saved preferences, CSRF-style safety, and account sessions. These are necessary for the service.
We use Plausible for privacy-friendly, aggregate analytics such as page views, feature use, referrers, and device categories. Plausible runs without analytics cookies or persistent identifiers and is not used to build advertising profiles. It operates independently from the optional Google Ads measurement choice.
We use a random, signed first-party browser identifier for authoritative product measurement. It may last for up to 90 days. On our server, we keep only a keyed one-way protected version of that identifier and use it to create 30-minute activity sessions and seven-day acquisition journeys. This lets us distinguish, for example, a completed edit from a result that was actually visible, preserve campaign attribution through login, deduplicate reloads, and measure return use. Clearing site storage or using another browser normally separates browser measurement; when you log in, a journey may be linked to your account so authentication and cross-device completion can be measured accurately.
Measurement records may include sanitized source, medium, campaign, creative, referrer domain, landing type and path, landing-page variant, broad device category, prompt source, and experiment assignment or exposure. We do not copy raw prompts into analytics records. Advertising click identifiers are retained only when the applicable advertising measurement consent permits it. PostgreSQL conversion records are our internal source of truth; Plausible and Google Ads are secondary measurement destinations.
The Google Ads tag uses advanced Consent Mode with analytics storage, advertising storage, advertising user data, and advertising personalization denied by default. Before consent, or after rejection, Google may receive cookieless consent and measurement pings with limited page and request context for aggregate measurement and modeling, without permission to read or write advertising or analytics cookies.
If advertising measurement is accepted, Google Ads may also process campaign, referrer, browser, device, page, and interaction data and may store or read measurement cookies so we can understand campaign visits and conversions. Advertising personalization remains disabled.
5. Legal bases and legitimate interests
Depending on your location, we process data based on contract performance, consent, legitimate interests, legal obligations, and safety/compliance needs. Our legitimate interests include operating an adult synthetic-content service, preventing abuse, protecting gated media, processing payments, improving the product, enforcing terms, responding to legal requests, and keeping security records.
6. Service providers
The app may use providers for hosting, DNS/security, email delivery, media storage/CDN, payments, analytics, OAuth login, and AI generation. Examples include Render, Cloudflare, Bunny, Resend, NOWPayments, Plausible, Google Ads, Google Workspace, and configured OAuth or AI providers. Providers process data only as needed to deliver, secure, monitor, and support the service.
If image-edit features are connected to third-party AI providers, prompts, source-image references, and moderation metadata may be sent to those providers to process the request.
7. Adult-content privacy
We store whether an account confirmed adult-content access because it is required to gate NSFW areas. Do not use the service if you do not want this type of account record stored. We may also store whether you accepted adult-content rules, unlocked premium access, used credits, or attempted blocked requests.
8. Public and private activity
Comments, usernames, profile pages, and some social activity may be visible to other users. Saves, private gallery items, account email, wallet records, private prompts, and generated outputs are intended to remain private unless you choose to share them or a legal/safety need requires review.
9. Retention
We keep account, wallet, moderation, and audit records as long as reasonably needed for security, legal, accounting, abuse-prevention, and product operations. You can request deletion, but some records may be retained where required, where needed to resolve disputes, where needed for chargeback/fraud/legal records, or where needed to protect the service.
Public comments or reports may be deleted, anonymized, or retained depending on moderation needs. Removed content may remain in backups or logs for a limited period.
Credit-purchase interest remains connected to your account while the alert is active. Removing yourself from the alert on Wallet deletes the preference, and deleting the account also deletes it.
Raw conversion events and their supporting pseudonymous visitor, session, journey, identity-link, and experiment-assignment records are normally retained for 90 days after the relevant activity. Before they are removed, we create aggregated daily funnel records that may be retained for up to 25 months. Aggregates do not contain raw prompts or direct account identifiers. When an account is deleted, we remove its analytics identity links and account experiment assignments and remove the account-linked actor key from raw measurement rows that remain during their retention period. For active accounts, we retain the first qualifying result-view timestamp and generation-job reference with the account so a later edit is not incorrectly counted as a new first activation; account deletion clears that milestone. Operational payment, security, fraud, and legal records may follow different retention rules described above.
10. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or export certain personal data. You can also stop using the service, log out, or request account deletion.
You can manage your account settings where available. For privacy requests, include the email connected to your account and enough detail for us to verify and process the request.
You can review, grant, or withdraw optional advertising measurement consent at any time.
You can withdraw a credit-purchase availability request at any time using “Remove me from this alert” on Wallet.
11. Children and minors
The service is not for minors. We do not knowingly allow users under 18 to create accounts or access adult content. If you believe a minor used the site or content appears to depict a minor or minor-coded character, contact us immediately.
12. International users
Your data may be processed in countries other than your own because our service providers may operate across multiple regions. Those countries may have different data protection laws. We use service providers and operational controls intended to protect data during processing.
13. Security
We use access checks, protected media routes, rate limits, signed URLs where configured, and admin audit trails. We limit access to operational systems where possible. No online service can guarantee perfect security, and you use the service at your own risk.
14. Legal and removal requests
For copyright, privacy, likeness, safety, or removal requests, see the DMCA and Removal Policy. We may ask for identifying information, ownership details, URLs, screenshots, statements of good faith, or other information needed to evaluate the request.
15. Contact
Privacy requests can be sent to contact@realfakegirls.com.
