Legal · draft for review

Privacy Policy.
Draft, not counsel-approved.

What Vantly collects, how it is used, who it is shared with, how long it is kept, and the rights you have over your data. This is a first-pass draft — not final, counsel-approved text.

Draft banner.

This page is a draft produced for the operator to review before general access. It is not legal advice, not counsel-approved text, and not a substitute for review by qualified counsel familiar with the data-protection laws in the jurisdictions where Vantly operates.

01

What we collect.

Vantly collects the minimum data needed to operate an adult creator marketplace, verify eligibility, process payments, comply with recordkeeping obligations, and prevent fraud. The categories below describe every class of data we ask for.

Account data: the information you provide at signup (legal name or a verified alias, email address, contact details, password or single-sign-on identity). Creators provide additional profile information visible on their public creator page.

Identity and age verification: documentation collected at onboarding through a verification vendor configured to satisfy 18 U.S.C. 2257. We retain the verification result and the supporting evidence our custodian obligations require.

Payment metadata: information needed to process payouts and refunds — payout routing details (held by our payment processor, not by us), transaction history, chargeback history, and tax forms.

Device and log data: basic technical data necessary to operate the service — IP address, user-agent, approximate geographic region, timestamps of access, and security-event logs.

02

How we use it.

Data is used for the operational purposes below. We do not sell personal information, we do not use it for advertising, and we do not share it with third parties for their own marketing purposes.

Provide the service: account creation, sign-in, content delivery to paying subscribers, payment processing, payouts, customer support, and platform notifications.

Verify eligibility: identity and age verification at onboarding and at intervals thereafter, content labeling for age-restricted jurisdictions, and detection of patterns that suggest verification should be re-run.

Process payments: payout routing through adult-friendly payment processors, fraud screening on transactions, and the tax forms required by the jurisdictions in which we operate.

Comply with recordkeeping obligations: retention of the records we are required to keep under 18 U.S.C. 2257 and other applicable recordkeeping rules, available for inspection by authorized persons on proper request.

Prevent fraud and protect the community: detection of fraud patterns, enforcement of the platform’s prohibited-content policy, and response to lawful disclosure requests.

03

How long we keep it.

Retention follows three windows: compliance records for the statutory period, financial records for the tax window, and everything else for as long as you have an active account or until you ask us to delete what we are permitted to delete.

Compliance records (identity verification, age verification, 2257 custodian records, takedown history) are retained for the periods required by law. The current period is at least several years from the last depiction produced; the exact period is set by the prevailing federal rules.

Financial records (transaction logs, payouts, chargebacks, refunds, tax forms) are retained for the period required by tax law in the relevant jurisdictions.

Marketing data (newsletter subscriptions, optional preference settings) is retained until you withdraw consent or close your account, whichever comes first.

Account data and content beyond what retention requires are deleted on the published closure timeline after you close your account, unless we are required to retain them for a longer period.

04

Who we share it with.

We share data with the third parties who help us operate the platform — processors, a verification vendor, and counsel where required. We do not sell personal information. We do not share it with third parties for their own marketing purposes.

Payment processors in the adult-friendly processor stack we use for payouts and refunds. Routing details are held by the processor, not by us; transaction metadata flows through both systems for settlement.

Identity and age verification vendor, which performs the checks we use to satisfy 2257 custodian obligations and to confirm age and identity at onboarding.

Hosting and infrastructure providers, which store platform data on our behalf under contractual obligations that restrict their use of the data to providing the service to us.

Counsel and law enforcement, on receipt of lawful disclosure requests submitted through the proper legal channel. Preservation requests are acknowledged and production is handled through counsel.

05

Cross-border transfers.

Vantly is operated by a team distributed across multiple jurisdictions. Data may be processed in countries other than the one you live in. The safeguards we apply to those transfers are described in this section.

We rely on the lawful transfer mechanisms available in the jurisdictions where our users live — standard contractual clauses for transfers out of the European Economic Area and the United Kingdom, equivalent mechanisms for transfers out of other jurisdictions with cross-border-transfer rules.

Our infrastructure providers operate in regions selected for the legal protections they apply to data and for the operational reliability they offer. The processor stack is documented in the platform’s published security statement.

If you live in a jurisdiction with specific data-residency requirements, the relevant choices are surfaced to you at signup and can be reviewed in the platform’s published transfer disclosure.

06

Your rights.

You can request access to, correction of, or deletion of the personal information we hold about you, within the limits of our retention obligations. The mechanism for exercising those rights is described below.

Access: you can request a copy of the personal information we hold about you, within the limits of our retention obligations. The request is processed in line with the law of your jurisdiction.

Correction: you can ask us to correct information that is wrong or incomplete. Account information can also be updated directly from your dashboard for fields we expose in the UI.

Deletion: you can ask us to delete personal information beyond what retention requires. Compliance records and financial records are retained for the periods set out in the retention section above and cannot be deleted on request during those windows.

Withdraw consent: where processing is based on consent, you can withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.

07

Security.

We apply security measures designed for the categories of data we hold, with heightened controls on identity verification records and on financial routing data. The exact measures are documented in the platform’s published security statement.

Encryption in transit (TLS) and at rest (provider-managed disk encryption with key-management separation), access controls scoped to the role required to do the work, and audit logging on access to high-sensitivity records.

Vendor due diligence on the processors and sub-processors in the data plane, with contractual obligations that restrict their use of the data to providing the service to us.

Incident response with breach notification in line with the law of your jurisdiction. If an incident affects your personal information, we notify you (and, where applicable, the relevant regulator) within the timeframes set by law.

08

Children's privacy.

Vantly is an adults-only service. We do not knowingly collect personal information from anyone under 18 years of age, and we do not knowingly operate the service in a way that would place us in receipt of information from a minor.

Identity verification at onboarding is designed to keep accounts out of the hands of minors. If we discover that an account belongs to, was used by, or depicts a minor, the account is closed and the relevant authorities are notified.

If you believe we have collected information from a minor in error, contact us at the inbox at the bottom of this page and we will delete the information immediately.

09

Cookies.

Vantly uses cookies and similar technologies for the purposes set out in the Cookie Policy. The summary is provided here; the full disclosure is at the page linked below.

Essential cookies for session and authentication where a module sets them, plus the technical cookies required to operate the platform.

Analytics cookies where the deploy has configured the platform analytics slug. These fire only when the slug is set and only after the relevant disclosures have been surfaced.

No marketing cookies on a fresh deploy. If marketing cookies are introduced in the future, they will be disclosed in the Cookie Policy and surfaced through the consent flow before they are set.

Full disclosure at the Cookie Policy.

10

Recordkeeping.

Identity and age verification records are retained under the custodian obligations published in the 2257 compliance statement. The full custodian statement, including the designated custodian contact for inspection requests, is on the linked page.

Vantly is custodian of the records required by 18 U.S.C. 2257 for content hosted on the platform. The categories of records and the retention period are described in detail on the 2257 compliance page.

Each creator is custodian of performer-side records, including records of any third-party performers who appear in the creator’s work. Vantly cannot delete platform-held records on a creator’s request during the statutory retention period.

Full custodian statement at the 2257 compliance page.

11

Changes to this policy.

We may update this policy as the platform matures. Material changes are flagged prominently inside the platform and communicated by email to the address on file. The current version is always the one published at this URL.

Non-material changes (clarifications, contact details) do not trigger a separate notification. Material changes (new categories of data, new processing purposes, changes to retention windows) are communicated before the effective date.

The previous versions of this policy are available on request to the contact inbox at the bottom of this page, so the evolution of the policy is auditable.

12

Contact.

For privacy requests and questions about this policy, write to the inbox below. Mark the subject line clearly so the message is routed to the privacy contact on the team.

Privacy requests: trovewell-we9yit@polsia.app. Mark the subject line clearly with the type of request (access, correction, deletion, withdrawal of consent, or general question).

For recordkeeping inspection requests, see the 2257 compliance page. For takedown notices, see the DMCA section of the FAQ.

trovewell-we9yit@polsia.app

This document is published in good faith as a first-pass draft. Specific clauses should be reviewed and adapted by qualified counsel before the platform is opened to general access.

See also the Terms of Service, the 2257 compliance statement, and the Cookie Policy.