Kinky Zone
Privacy Policy
Last updated 19 September 2026
This Privacy Policy explains what Kinky Zone collects, why, who can see it, and what you can do about it. It goes with the Terms of Service. We do not sell your personal data.
1. Who we are
Kinky Zone is an adult social service operated at kinky.zone. If you have a privacy request (access, export, correction, deletion), use Settings on the site, or contact us through the channels listed at the end of this policy.
2. What we collect
Depending on how you use the Service, we may store:
- Account. Email, password hash (we do not store your raw password), date of birth, handle, display name, bio, links, optional country, avatar and cover images, locale and theme, privacy flags (for example a private account), Premium and verification status, and timestamps such as created-at and last login.
- Auth extras. Email verification and password-reset tokens, two-factor secrets if you enable them, OAuth identifiers if you connect Google or GitHub, session cookies, and CSRF tokens.
- Posts and media. Text you post or reply with, attached photos/GIFs/video we accept, edit history metadata, reply privacy, optional place labels and coordinates, community association, likes (including golden likes), regenerations/reposts, bookmarks, pins, and view counts we use for ranking and analytics.
- Social graph. Follows and follow requests, blocks, mutes, lists, community memberships, and reports you file.
- Messages. Direct message content and related metadata so the conversation can be delivered and shown to the people in it.
- Notifications. In-site notification records. If you enable browser push, we store the push subscription endpoint and keys your browser gives us, plus your preference flags (likes, replies, follows, mentions, regenerations, DMs, push).
- Invites. Invite codes you create or redeem, and which account they are tied to.
- Developer API. Names of API apps you create and hashed app passwords (the secret is shown once).
- Technical logs. IP address, user agent, and similar request data as needed for security, rate limits, mail delivery logs, and abuse investigation. We keep rate-limit windows and some mail logs for a limited time.
- Payments. If you buy Premium, our payment processor (Stripe where configured) handles card data. We store the subscription/customer references we need to know that you paid — not your full card number.
We do not require you to use your legal name. Date of birth is collected to enforce age rules and is not shown on your profile.
3. Why we use it
- to create and secure your account, and to keep you signed in;
- to show feeds, profiles, communities, search, and messages;
- to enforce 18+ rules, consent rules, and the rest of the Terms;
- to send email we owe you (verification, password reset, optional digests);
- to send in-site and, if you opted in, browser push notifications;
- to process Premium payments and developer API access;
- to rate-limit abuse, debug outages, and improve the product;
- to honour export and deletion requests you make in Settings.
Legal bases, where a privacy law asks for them, are typically: performing the contract (running the account you asked for), legitimate interests (security, moderation, keeping an adult space adult), and consent (optional push, optional place tags, optional OAuth, marketing-like digests if we offer them and you turn them on).
4. Who can see what
Public or logged-out views are limited. Adult post bodies and media are meant to stay behind authentication. Shareable pages (for example a profile or post URL hit by a crawler) may still expose a title, description, and a brand image — not your private media.
Other members see what your privacy settings allow: public posts go to people who can use the Service; a private account requires approval; reply privacy can limit who answers. Community posts may show a community origin on your profile or in other timelines.
People you message see those messages. We do not offer end-to-end encryption: operators with server access could technically read stored DMs. Do not put secrets in DMs that you cannot afford anyone ever seeing.
Staff and moderators can access reports, account flags, and content as needed to run and moderate the Service.
We do not sell personal data to data brokers. We do not run an advertising network on the backs of your kinks.
5. Processors and other services
We use infrastructure and vendors to operate Kinky Zone. That typically includes:
- hosting and database storage for the site;
- transactional email (SMTP) to send verification and reset mail;
- Stripe, if you pay for Premium;
- Google or GitHub, if you choose OAuth login — they then see that you authenticated to us;
- your browser’s push service (for example FCM/Mozilla/Apple push) if you enable push;
- a password-breach check (HIBP-style) that hashes a prefix of your password so we can reject known-pwned passwords — we do not send your full password to them.
Those parties process data under their own terms. We only send them what that feature needs.
6. Cookies and similar tech
We use a session cookie to keep you logged in, a CSRF token, and a theme cookie so the site can remember dark/light if you are not logged in. These are needed for the Service to work. We do not use third-party ad cookies. If we add optional analytics later, we will say so here.
7. How long we keep it
- Active account data lasts for as long as the account exists.
- Unverified signups may be purged after about 7 days.
- Soft-deleted posts are typically hard-deleted after 30 days.
- After you delete your account, we mark it deleted; after about 90 days we scrub the email so it cannot keep colliding with a new signup. Backups may lag behind live deletion.
- Rate-limit rows and similar operational data are pruned on a short cycle (days).
- Mail logs are pruned on a longer cycle (about 90 days).
- Legal holds, unpaid chargebacks, or ongoing abuse investigations may require us to keep a subset longer.
8. Your choices
- Profile and privacy. Private account, reply privacy, notification toggles, push on or off, theme and language.
- Place tags. Optional. Do not add them if you do not want a location on the post.
- Export. Settings → Data lets you download a JSON archive of profile, posts, likes, bookmarks, and connections (subject to rate limits).
- Correction. Edit profile, email (with verification), password, and handle in Settings.
- Deletion. Deactivate or delete the account in Settings → Danger zone. Deletion is meant to be permanent for your public presence.
- Appeals. Appeal a restriction if you think we got moderation wrong.
If a privacy law (for example GDPR or similar) gives you extra rights — access, portability, objection, restriction, complaint to a regulator — you can exercise them by contacting us. We will ask you to prove you control the account first.
9. Children
Kinky Zone is not for anyone under 18. We do not knowingly collect data from children. If we learn that we have, we will delete the account and associated personal data.
10. Security
We hash passwords, use HTTPS, and limit what is exposed to logged-out visitors. No adult site is unhackable. You can reduce risk with a unique password, 2FA, and care about what you post. If you believe there is a security issue, contact us rather than posting an exploit.
11. International users
Servers may be in a different country from you. By using Kinky Zone you understand that your data may be processed where we host. Adult content is illegal or heavily restricted in some places; you are responsible for following the laws where you are.
12. Changes
We may update this policy. The “Last updated” date will change. Material changes should be obvious here; continued use after an update means you accept the new policy.
13. Contact
Privacy questions and requests: Settings on Kinky Zone, /appeal for account restrictions, or email the address we publish for kinky.zone (typically the site’s from-address). Tell us which account and what you want us to do.