1. Data Controller & Applicable Law
The data controller responsible for your personal data is specified in our Impressum.
Afterdark is operated from Switzerland. This privacy policy complies with:
- Swiss DSG (Datenschutzgesetz) - applicable to all users
- EU GDPR - additionally applicable to users in the European Economic Area
2. Information We Collect
Account Information
When you create an account, we collect:
- Email address (for login and communication)
- Password (encrypted with bcrypt, never stored in plain text)
- Account creation date
Subscription Data
When you subscribe to creators:
- Subscription status and dates
- PayPal subscription ID (for recurring payments)
Messages & Chat
Messages you send to or receive from creators are stored to provide the messaging service.
Chat messages are processed by OpenAI (via their API) to generate AI responses. When you send a message:
- Your message content is sent to OpenAI for processing
- Recent conversation history (up to 20 messages) may be included for context
- OpenAI processes this data according to their Privacy Policy
We do not send your email, name, or other personal identifiers to OpenAI - only the message content.
Payment Information
Payment processing is handled entirely by PayPal. We do not store credit card numbers, bank account details, or other financial information.
Tips / Donations
When you send a tip (with or without an account):
- Tip amount and recipient creator
- PayPal order ID (for payment verification)
- Payment status and timestamp
- User ID (if logged in) or "anonymous" marker
For anonymous tips, we do not store your email, name, or PayPal account details - only the transaction reference. PayPal processes your payment data according to their Privacy Policy.
3. Legal Basis for Processing (GDPR Art. 6)
- Contract Performance: Processing account and subscription data to provide our services
- Legitimate Interest: Platform security, fraud prevention, service improvement
- Consent: Where explicitly requested (e.g., optional features)
4. Data Retention
- Account Data: Retained until you delete your account
- Subscription Data: Retained for 7 years after end of subscription (tax/legal requirements)
- Messages: Deleted when you delete your account
- Support Tickets: Deleted when you delete your account
You can delete your account at any time via Account > Delete Account.
5. Third-Party Processors
We share data with:
- PayPal (Europe): Payment processing for subscriptions and tips. Subject to PayPal Privacy Policy
- OpenAI (USA): AI chat processing. Message content only (no personal identifiers). Subject to OpenAI Privacy Policy. Data transfer to USA based on Standard Contractual Clauses (Art. 46 GDPR).
We do not sell your personal information to third parties.
6. Cookies
We use only essential cookies:
- Authentication Cookie: Keeps you logged in (session-based JWT token)
We do not use tracking, analytics, or advertising cookies.
7. Your Rights (GDPR Art. 15-22)
You have the right to:
- Access (Art. 15): Request a copy of your personal data
- Rectification (Art. 16): Correct inaccurate data (via Account > Profile)
- Erasure (Art. 17): Delete your account and all data (via Account > Delete Account)
- Data Portability (Art. 20): Export your data in machine-readable format (via Account > Profile > Download My Data)
- Restriction (Art. 18): Request restriction of processing
- Objection (Art. 21): Object to processing based on legitimate interest
8. Right to Complain
You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated:
- Switzerland: EDÖB (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter)
- EU/EEA: Your local data protection authority (e.g., in Germany: Landesdatenschutzbeauftragte)
9. Contact
For privacy questions or to exercise your rights, contact us via our Impressum or submit a Support Ticket.