Privacy policy

This English text is a translation for your convenience. If there is any discrepancy, the Dutch version prevails.

Version 2.4 · last updated: 25 September 2026.
Applicable to all services of Mistress Lounge ("the Platform").

1. Data controller

Mistress Lounge is responsible for the processing of personal data.

  • Trade name: Mistress Lounge
  • Legal form and Chamber of Commerce (KvK) number: registration has been applied for; these details will be stated here once the registration is completed.
  • Business address: will be stated once the registration is completed.
  • Email: info@mistresslounge.nl

We have not appointed a data protection officer (DPO). This is not legally required for a platform of this size, but we will reassess this as soon as the number of users or the scale of the processing grows substantially. Questions about privacy arrive at the email address above and are handled within 30 days. Put "privacy" in the subject line and your message will be recognised as a privacy request.

2. Which data do we process?

Account data: username, email address, password (stored only encrypted as a bcrypt hash, never readable), role on the platform, approval status, confirmation that you are 18 or older, and the confirmation that you have read that not every profile is a real person and that messages may be generated automatically.

Profile data:a self-chosen display name, an optional avatar, images you upload, an optional short description ("about me") and your online status. Every member has a profile page that other logged-in users(members, Mistresses and staff) can view: your display name, avatar, description, online status and the date you joined. You can change this at any time in your account settings: also make your profile visible to visitors without an account (search engines do not index it), hide your profile completely from other members ("Only me"), or hide just your photo (in the members directory and on your profile page — your photo still shows next to comments you post). What you enter or upload there is your own choice; do not enter information you do not want to share with others.

Public comments:comments you post under a profile photo or on another member's profile are visible to other logged-in users and are shown with your display name. You can delete your own comments; they are erased when you delete your account.

Conversations and messages: the content of your chat messages, photos sent, timestamps, read/unread status and which profile a conversation is linked to.

Payment data:subscriptions, transactions (subscription payments, tips and payment requests), payment status and the payment provider's transaction number. We do not receive or store card numbers or other payment instruments: the payment itself takes place entirely with the payment provider.

Technical data: IP address, session data (an encrypted session token and the expiry time), time of your last activity, rate-limiting data against abuse, and technical error reports from the server.

Notification data (only if you turn on notifications):if you enable push notifications on a device, we store the subscription created by your browser — a unique endpoint URL at your browser's push service, two public keys with which the notification is encrypted, and the browser description (user agent). This allows us to send you an alert for a new chat or a new message. You can switch this off again per device; we then delete the subscription.

Administration data: internal notes by staff about a conversation or account, and a non-erasable log of the moments when an administrator temporarily looked along in an account (see section 8).

3. Special categories of personal data and your explicit consent

This is a platform for erotically tinged roleplay. The messages you write here, the profiles you look up and the photos you send can therefore reveal information about your sexual behaviour and sexual orientation. These are special categories of personal data within the meaning of article 9 GDPR, and in principle we may not process them.

We base this processing on the exception of article 9(2)(a) GDPR: your explicit consent. By creating an account and using the chat function you give that consent to the processing of the content of your conversations and the images you upload, insofar as they contain information about your sex life. Without that consent the chat function cannot work — after all, the message has to be stored and delivered.

You may withdraw that consent at any time. You can withdraw it by having your conversations deleted or your account closed via info@mistresslounge.nl. Withdrawal works going forward: processing that took place before the withdrawal remains lawful. Because the chat function cannot exist without this processing, in practice withdrawal means that use of the chat stops. After withdrawal we may still retain the data that we must or may retain on another basis, such as payment data for the tax administration (section 6).

We do not ask for, and have no need of, data about your health, religious belief, political preference, race or ethnic origin. Do not put that information in your profile or messages.

4. Why do we process this data, and on what basis?

PurposeBasis (art. 6 GDPR)
Creating and maintaining an account, and giving you access to the platformPerformance of the contract (para. 1 b)
Delivering, storing and displaying messages and photos in your conversationsPerformance of the contract (para. 1 b), plus your explicit consent for the special categories of data contained therein (art. 9(2)(a) — see section 3)
Selling subscriptions and handling paymentsPerformance of the contract (para. 1 b)
Confirming your email address and enabling password recoveryPerformance of the contract (para. 1 b)
Verifying that you are 18 or olderLegal obligation (para. 1 c) and legitimate interest (para. 1 f)
Security, combating abuse, rate limiting, fraud prevention and investigating malfunctionsLegitimate interest in a secure, working platform (para. 1 f)
Customer service and handling complaints and privacy requestsPerformance of the contract (para. 1 b) and legal obligation (para. 1 c)
Financial administration and retaining invoicesLegal obligation (para. 1 c)
Non-necessary cookies and any statisticsConsent (para. 1 a) — see the Cookie policy
Sending push notifications to devices on which you have enabled notificationsConsent (para. 1 a); can be withdrawn by switching notifications off again

5. Who reads and answers your messages

Creator profiles. Some of the profiles are managed by a real, verified creator. If you chat with such a profile, the creator behind that profile can read your messages, photos sent and your display name in order to be able to answer you. Creators are bound by our terms and may not use or share conversation content outside the platform. The platform indicates which profiles are managed by a real creator.

Staff. Staff of Mistress Lounge can respond on behalf of a profile and view conversations for moderation and customer service (see section 8).

Artificial intelligence. For profiles where this is enabled, a message may be answered automatically by artificial intelligence instead of by a creator or staff member. For this we use Gemini from Google Ireland Limited / Google LLC. The text of at most the last 20 messages of that one conversation is sent, together with a persona description of the profile. No name, email address, IP address, account ID or payment data is sent along. On the platform it is visible to staff and the creator which messages were generated by AI; for the member themselves this distinction is deliberately not visible.

This means a transfer of personal data outside the European Economic Area (to the United States), on the basis of the EU-US Data Privacy Framework and the standard contractual clauses from the Google terms. The Google project to which our access is linked is a paid project: Google does not use the submitted content to train or improve its services.

If the service we use for this changes, or if we start sending more data than described here, we will update this policy before it is put into use and actively inform you of such a material change (see section 14).

No automated decision-making with legal effects for you is made based on your messages or photos.

6. Retention periods

DataRetention period
Account data and profileAs long as your account exists. After a deletion request, deleted or irreversibly anonymised within 30 days at the latest.
Chat messages and uploaded photosAs long as your account exists, and after that at most 30 days.
Inactive accounts (no activity at all)We may delete an account that has not been used for 24 months. We announce this at least 30 days in advance by email, so that you can log in to keep it.
SessionsAutomatically when the session expires or when you log out.
Confirmation and password-reset tokensUntil the token is used or expired; deleted afterwards.
Payment and invoice data, transactions7 years, because of the statutory tax retention obligation (art. 52 General Tax Act (Algemene wet inzake rijksbelastingen)). This period also applies if your account was deleted earlier.
Technical error reports and security logsAt most 12 months.
Rate-limiting dataA few hours to days; cleaned up automatically.
Log of administrators looking along24 months. This log is deliberately not erasable while it is retained, because it exists precisely to make oversight possible.
Correspondence with customer service24 months after handling.
Push notification subscriptionsUntil you switch notifications off on that device, your account is deleted, or the subscription is declared invalid by the push service; deleted immediately afterwards.

7. With whom do we share data?

We never sell personal data and do not use it for third-party advertising. We engage the following processors and service providers:

PartyRoleDataLocation
IONOS SEHosting of the server and databaseAll platform dataEU (IONOS Cloud, France)
Cheese HostingDomain name, DNS and outgoing emailEmail address and the content of service emailsEU
PayPal (Europe) S.à r.l. et Cie, S.C.A.Payment provider — independent controller for the payment itselfAmount, order number, email address and payment detailsEU (Luxembourg)
Google Ireland Limited / Google LLCAI replies to chat messages (Gemini) — only for profiles with AI onText of at most the last 20 messages of that conversation, plus the persona description of the profile. No name, email address, IP address, account ID or payment data.EU + United States, on the basis of the EU-US Data Privacy Framework and standard contractual clauses. Paid Google project: no use for training.
Push services of browser vendors (incl. Apple, Google, Mozilla, Microsoft)Delivering push notifications to your device — only if you have enabled notificationsThe endpoint URL of your notification subscription and the encrypted notification (title plus a short text such as "New message")Depends on your browser; may be outside the EEA (e.g. United States). The notification text never contains the content of a conversation.
Competent authoritiesOnly in case of a legal obligation or court orderWhat is legally demandedNetherlands / EU

Which push service is used is determined by the browser you choose, not by Mistress Lounge. We only send a notification if you have asked for it yourself, and the notification deliberately contains no conversation content. If you do not want any transfer via such a service, do not turn on notifications (or turn them off again).

We conclude data processing agreements with processors. We keep an internal register of processing activities as referred to in article 30 GDPR; you can enquire about it via the email address in section 1.

8. Access by staff and looking along in accounts

Administrators and staff can view conversations insofar as necessary for moderation, customer service or resolving malfunctions. In exceptional cases a developer can temporarily look along in an account to reproduce a problem. Every time this happens, it is recorded who did so, in whose account, why, and when it started and ended. That log cannot be erased or modified, not even by the developer concerned.

9. Security

We take appropriate technical and organisational measures, including: traffic only via HTTPS, passwords stored as a bcrypt hash, session tokens that are stored only encrypted in the database, secure cookies, protection against cross-site request forgery on all actions that change data, rate limiting on login and message actions, a database that is only reachable from the server itself, a firewall that only allows web and administration traffic, and re-encoding of uploaded images so that hidden metadata (including GPS locations from your camera) and disguised files are removed.

In the event of a data breach posing a risk to your rights and freedoms, we report it within 72 hours to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and we inform you if that risk is high.

10. Data protection impact assessment (DPIA)

Because we process special categories of personal data about sex life on a large scale, a data protection impact assessment (DPIA, article 35 GDPR) may be mandatory. We have recognised this obligation and are preparing a DPIA; we will incorporate its outcomes into this policy and into our measures. Until then we apply the principle of data minimisation: we do not ask for more data than necessary, do not use an AI service for the chat and limit internal access to what is necessary.

11. Cookies

We currently place strictly necessary cookies only: one for your logged-in session, one to protect forms against cross-site request forgery, one to remember that you confirmed the 18+ notice and one to remember your language choice. No consent is required for these. We do not place analytical or marketing cookies; should that change, we will first ask for your consent. More information is in the Cookie policy.

12. Your rights

Under the GDPR you have the right to:

  • access to the data we process about you;
  • correction of incorrect data;
  • erasure of your data ("right to be forgotten");
  • restriction of processing;
  • portability of the data you provided yourself;
  • object to processing on the basis of legitimate interest;
  • withdraw your consent, including the explicit consent from section 3 — at no cost to you and without us disadvantaging you for it;
  • not be subject to solely automated decision-making with legal effects; this does not take place with us.

Submit your request via info@mistresslounge.nl. We respond within one month. To prevent us from providing data to the wrong person, we may ask you to send the request from the email address of your account.

13. Complaints

If you disagree with how we handle your data, please let us know first. You also always have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), Postbus 93374, 2509 AJ The Hague.

14. Changes

This privacy policy may be changed. The most recent version is always on this page, with the version number and date at the top. In case of material changes we will actively inform you, for example by email or via a notice on the platform.