¿Tienes volumen, una audiencia o construyes herramientas para creadores? Crezcamos juntos. CONVIÉRTETE EN PARTNER DE DROPP

Privacy Policy

Version 2.0 · Effective date: 18/08/2026

Replaces the Privacy Policy of 30 December 2025 (archived)

Changelog: adds biometric verification, named processors, automated-moderation disclosure, legacy-AI data, CNIL, DPO position

1. Who we are and how to contact us

DROPP SAS ("DROPP", "we", "us"), société par actions simplifiée, 930 948 997 RCS Paris, operates the DROPP platform and website at www.dropp.fans. Address: 9 rue des Colonnes, 75002 Paris, France. Contact for anything in this policy: contact@dropp.fans.

DROPP is the controller of the personal data described in this policy. For personal data contained inside the Files creators upload, DROPP acts as processor on the creator's behalf (see Section 2.d).

Data protection officer: we have appointed a Data Protection Officer, reachable at contact@dropp.fans.

2. What data we collect, by audience

a) Creators and Agencies: name and surname, date of birth, postal address, email, phone number, account credentials, a valid identity document and proof of residence (collected for verification, Section 3), banking details (IBAN), payment and invoice data, profile and account settings, uploaded content and its moderation data (Section 4).

b) Fans: email address, purchase history, payment amount and date (never full card details, which go directly to the payment processor), age-verification status (Section 3), device and access data (below).

c) Website visitors: IP address, device information (browser, OS), activity logs (pages visited, clicks, errors), cookie data per the Cookies Policy (Section 13).

d) Persons appearing in creator content: Files may contain images, likenesses or other personal data of depicted persons. For this data DROPP acts as processor for the creator, who is responsible for consent and releases (Content & Acceptable Use Policy §4). DROPP processes Files as controller for one purpose only: the safety screening described in Section 4.

3. Age and identity verification (biometric data)

To verify age and identity we use Ondato, a certified identity-verification provider, to check an identity document together with an active-liveness (3D) check. The liveness check processes biometric data for the purpose of uniquely identifying a person, which is special-category data under Article 9 GDPR. We process it on the basis of your explicit consent (Article 9(2)(a)), requested at the start of the verification flow; if you decline, verification, and the purchase of adult content, is not possible.

This applies to both sides of the platform:

  • Buyers: before purchasing adult content, the buyer completes the Ondato check. What we receive and store server-side is the verification result; a successful verification is valid for twelve (12) months on the device used, via a token described in the Cookies Policy. The control fails closed (no completed verification, no checkout) and an under-18 result is terminal for that device.
  • Creators: identity and date-of-birth verification is required per the Terms of Service §7, using the same provider and the same categories of data.

Retention of verification records: creator verification records are kept for the duration of the account plus five (5) years after closure (aligned with anti-money-laundering retention and card-network retrievability requirements); buyer verification results are kept for five (5) years from the check, with the device token expiring after twelve (12) months. Failed or abandoned verification attempts are deleted within thirty (30) days; an under-18 result retains only a device-level block flag, with no identity data, for twelve (12) months.

Legacy records: before Ondato we used KYCAID for identity verification. Legacy KYCAID verification records belonging to active accounts are retained under the same rule as current verification records (account duration + 5 years; basis: legal obligation and legitimate interest); records not linked to an active account are deleted within ninety (90) days of this policy's effective date.

4. Automated content moderation

Every File uploaded for sale is analysed by automated classification systems, including OpenAI's Moderation API, before it can be sold and again when content is reported. The system assigns content categories, a severity score and a confidence score. These outputs, together with the model's stored rationale, are attached to the content record and are used in decisions about content availability and account-level action (removal, strikes, suspension, termination).

What this means for you, as required by GDPR Article 13(2)(f): automated analysis is involved in content decisions, but no account-level enforcement is taken without human review. No alert is closed without a named reviewer, and every enforcement decision can be appealed (Content & Acceptable Use Policy §9).

Moderation records, including the stored rationale and confidence scores attached to reviewed content, are retained for the life of the account plus five (5) years, on the basis of our legitimate interest in platform safety and the defence of legal claims. Records connected to a report to authorities follow the statutory preservation windows instead (Section 9).

5. Purposes and legal bases

PurposeDataLegal basisRetention
Provide the platform, accounts, downloadsaccount, transaction, device dataContract (Art 6(1)(b))account life + 5 years
Payments and payoutsbanking, transaction dataContract + legal obligation10 years (tax/commercial code)
Buyer age verificationverification result, DOB/over-18 flag, device tokenLegal obligation (Art 6(1)(c)) + Art 9(2)(a) for biometrics5 years (device token 12 months)
Creator identity verification (KYC)ID document data, verification resultLegal obligation (AML/card-network) + Art 9(2)(a)5 years after account closure
Content safety screeningFiles, moderation outputsLegitimate interest (platform safety); legal obligation for CSAM handling (Art 6(1)(c) + Art 10)see §4
Reports to authoritiescontent, account, transaction dataLegal obligationstatutory preservation windows
Fraud preventiontransaction, device, log dataLegitimate interest + legal obligation5 years
Support and service communicationscontact data, correspondenceContract / legitimate interest3 years after last contact
Marketing (optional)emailConsent, unsubscribe any timeuntil withdrawal

We do not sell personal data.

6. Legacy AI features

Until 17 June 2026, DROPP offered AI features including an AI chat agent. These features have been removed. All conversation data generated by the chat agent was deleted on 17 June 2026.

We do not use your content, your uploaded files, your messages or any other personal data to train or fine-tune AI models. Where this policy refers to automated moderation (Section 4), that means analysis of content for safety (monitoring, configuration and evaluation of those systems), not training on your data. Content submitted to the Moderation API is processed under OpenAI's API data-usage terms, which do not use API-submitted business data to train models.

7. Who we share data with

Processors (under Article 28 agreements):

  • Ondato: identity and age verification (Section 3)
  • KYCAID: identity verification, legacy records only
  • Payaut: payout onboarding and processing
  • Shift4: payment processing
  • Nuvei: payment processing
  • Crédit Agricole: payment processing
  • MassPay: payout solution
  • Tally: complaint and deletion request intake forms
  • Google Workspace: internal communications and support
  • OpenAI: automated content classification (Moderation API, Section 4)
  • Vercel: website hosting

We update this list before engaging a new processor; material changes follow the notice commitment in the Terms of Service §4.

Payment partners as independent controllers: payment processing partners may process your data under their own privacy policies for their own regulatory obligations.

Authorities: we disclose data where required by law or court order, and we report illegal content as described in the Content & Acceptable Use Policy §8, including mandatory reporting and evidence preservation for child sexual abuse material.

8. International transfers

Data is primarily hosted in the European Economic Area. Where a processor involves transfers outside the EEA (including US-based providers on the list above), we rely on Standard Contractual Clauses or another Article 46 mechanism, recorded per processor in our Article 30 register.

9. Data retention

  • Account data: while the account is active; on closure, see next line.
  • On account deletion or termination: content is removed from public access immediately; data and content are retained only as required by law (tax and accounting, up to 10 years; evidence preservation for reported illegal content; pending disputes) and then deleted (Terms of Service §5.4/§14.4).
  • Verification records: Section 3 periods.
  • Moderation records: Section 4 period.
  • Security and connection logs: twelve (12) months. Backups: rolling ninety (90) day cycle. Both retained for security and legal reasons.

When no longer required, data is deleted or anonymized.

10. Your rights

You may: access your data; correct it; request deletion; restrict or object to processing; withdraw consent; request portability; define post-death instructions (France); and complain to a supervisory authority.

Exercise rights at contact@dropp.fans or through the account deletion form. We may ask for proof of identity. We respond within one month of receiving your request (extendable by two months for complex requests, with notice, per Art 12(3)).

Two scope notes: (i) deletion requests do not override legal retention duties, including tax retention and preservation of reported illegal content (Section 9); (ii) if you appear in a creator's content and want it removed, the fastest route is the non-consensual content or likeness report described in the Complaints & Removal Policy, available whether or not you have an account.

11. Minors

DROPP is an 18+ service. We do not knowingly collect data from minors; the age controls in Section 3 exist to prevent it. If you believe we hold a minor's data, contact us; it will be deleted and, where content is involved, handled under the Content & Acceptable Use Policy §3.1/§8.

12. Security

We apply technical and organizational measures including encryption of data in transit and at rest, access controls and logging on moderation and verification systems, and audit trails on safety-critical settings. No online system is completely secure; if a breach is likely to affect your rights, we will notify you and the authorities as required by Articles 33/34.

13. Cookies

Cookies and similar technologies, including the 12-month age-verification token, are described in our Cookies Policy.

14. Supervisory authority, changes, contact

Our lead supervisory authority is the CNIL, Commission Nationale de l'Informatique et des Libertés, 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France (www.cnil.fr). You may also complain to the authority of your habitual residence.

Changes to this policy follow the version-and-notice rules in the Terms of Service §4; the version block above carries the changelog, and prior versions remain available at stable URLs.

Contact: contact@dropp.fans · DROPP SAS, 9 rue des Colonnes, 75002 Paris, France.