Privacy Policy
What we collect, why, who we share it with, and your rights.
Effective September 1, 2026 · Operated by [Legal entity — to be completed] ("DuoText", "we", "us").
1. Controller
The data controller for DuoText is [Legal entity — to be completed]. Privacy questions: support@duotext.com.
2. What we collect
- Account data: email, password hash, date of birth and your 18+ attestation, display name, verified phone number.
- Creator verification: government ID and liveness data, processed for identity (KYC) and tax onboarding. Tax forms (e.g. W-9/W-8BEN) where payouts require them.
- Payment data: handled by our payment processor — we store payment tokens, receipts, and ledger records, never full card numbers.
- Content and messages you upload or send, including media safety-scan results and content hashes.
- Usage and device data: IP address, browser, pages, and security events (rate-limit and fraud signals).
- Profile-view counts: when you are signed in and open a creator profile, we keep a per viewer–creator view count with the time of the last view (used to prevent abuse of creator collaborations and for aggregate analytics; creators never see who viewed them).
3. Why we process it
- To run the service: accounts, messaging, purchases, subscriptions, payouts.
- Safety and legal compliance: age assurance, participant-consent verification, scanning for child sexual abuse material (including hash-matching against industry databases), fraud and abuse prevention, records required by 18 U.S.C. §2257 and financial regulation.
- To improve the service (aggregate analytics). We do not sell personal data and we do not use your content to train AI models.
4. Who we share it with
- Processors that run parts of the service under contract: payment processing, phone/SMS verification and masked calling, live video infrastructure, cloud hosting and storage, content-safety vendors.
- NCMEC and law enforcement, where the law requires or permits reports (CSAM is always reported).
- Authorities and courts responding to valid legal process.
- A successor entity if the service is acquired — under this same policy.
5. Retention
Account data is kept while the account exists. Per-viewer profile-view counts are deleted after 24 months without a new view for that viewer–creator pair, and with the account on deletion. Financial and tax records, §2257 records, and safety evidence are kept for their statutory periods even after deletion. Content you delete stops being served immediately and is purged from storage after the safety-hold window, except where an evidence hold applies.
6. Your rights
Depending on where you live (GDPR, CCPA, and similar), you can request access, a copy, correction, deletion, or restriction of your personal data, and you can object to certain processing. Write to support@duotext.com — we answer within 30 days. You can also complain to your data-protection authority.
7. Cookies
We use strictly-necessary and preference cookies only: session authentication, CSRF protection, and interface preferences (language, theme, persona view). There are no third-party advertising or tracking cookies.
8. Security
Content is stored in access-controlled buckets and served through short-lived signed URLs; paid media may carry visible watermarks; transport is encrypted in transit (TLS). No system is perfectly secure — report vulnerabilities to support@duotext.com.
9. International transfers
Data may be processed in countries other than yours; where required we rely on adequacy decisions or standard contractual clauses.
10. Changes
Material changes to this policy are announced in the service before they take effect. The binding text is the English version.
Questions about this page: support@duotext.com