Sign in

Privacy Policy

This Privacy Policy explains how VireliaVault collects, uses, shares, and protects your personal data, and the rights you have. It is written to comply with the EU General Data Protection Regulation (GDPR / RODO) and applicable Polish, EU, UK, and U.S. data-protection rules. VireliaVault is an 18+, non-nudity creator platform; we do not knowingly collect data from anyone under 18.

Last updated: [DATE].

1. Who is responsible for your data (Controller)

The data controller is [OPERATOR LEGAL NAME], a sole proprietorship registered in Poland, NIP [NIP], REGON [REGON], registered address [BUSINESS ADDRESS] (the "Operator", "we", "us").

Data-protection contact: privacy@vireliavault.com. We have not appointed a Data Protection Officer; if we do, we will publish the contact here.

2. What personal data we collect

2.1 Data you give us

  • Account data: email address, password (stored only as a secure hash), and optional display name and avatar.
  • Age confirmation: your statement that you are 18 or older.
  • Creator data: profile details, links, and information needed for payouts (identity and bank verification is performed by Stripe, not stored by us).
  • Content and communications: the content you upload, comments, messages, support tickets, and reports.

2.2 Data we collect automatically

  • Technical and usage data: IP address, approximate location derived from your IP, device and browser information, pages viewed, and actions taken.
  • Cookies and similar technologies (see Section 4).

2.3 Payment data

Payments are processed by Stripe. We do not receive or store your full card number. We receive limited transaction data (for example, that a payment succeeded, amounts, and identifiers) needed to grant access and keep records.

3. Why we use your data and our legal bases

  • To provide the Platform and your account, process purchases, and deliver Content — performance of a contract (Art. 6(1)(b) GDPR).
  • To process payments and pay Creators — performance of a contract and legal obligation (Art. 6(1)(b) and (c)).
  • To keep the Platform secure, prevent fraud and abuse, moderate content, and enforce our Terms — legitimate interests (Art. 6(1)(f)).
  • To review content and communications, including direct messages and their attachments (such as pay-per-view media), to detect illegal content, keep users safe, moderate the Platform, and enforce our Terms — legitimate interests and legal obligation (Art. 6(1)(f) and (c)).
  • To log sign-ins with IP address for security and abuse-prevention — legitimate interests (Art. 6(1)(f)).
  • To restrict access from certain regions — legitimate interests and legal compliance (Art. 6(1)(f) and (c)).
  • To comply with legal obligations, including tax, accounting, and reporting duties for platforms — legal obligation (Art. 6(1)(c)).
  • To send service messages and, where you agree, other communications — contract and consent (Art. 6(1)(b) and (a)).

4. Cookies and similar technologies

We use strictly necessary cookies to keep you signed in, remember preferences, and operate core features (for example, an age-confirmation cookie and a region cookie). These are required for the Platform to work. We aim to keep non-essential tracking to a minimum; where we use any optional cookies, we will ask for your consent.

5. Who we share your data with

We do not sell your personal data. We share it only with service providers ("processors") and where required by law:

  • Stripe — payment processing and Creator payouts. Stripe acts as an independent controller and/or processor under its own privacy policy.
  • Hosting and infrastructure — our server/hosting provider that runs the Platform.
  • Geolocation — we send visitor IP addresses to a third-party IP-geolocation service (currently ipwho.is) to determine country/region for regional access rules. We may move this function to an offline database in future.
  • Email/communications providers — to send service messages, where applicable.
  • Authorities and advisers — where necessary to comply with the law, respond to lawful requests, or establish, exercise, or defend legal claims.

6. International transfers

Some providers (for example Stripe and IP-geolocation) may process data outside the European Economic Area, including in the United States. Where this happens, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and/or an adequacy mechanism (such as the EU-U.S. Data Privacy Framework, where the provider is certified). You can request more information at privacy@vireliavault.com.

7. How long we keep your data

  • Account data — for as long as your account exists, and for a reasonable period afterwards to handle disputes and legal obligations.
  • Sign-in logs (IP and device) — up to 12 months, then deleted.
  • Payment and accounting records — for the period required by tax and accounting law (in Poland, generally 5 years).
  • Content — until you or the Creator delete it, subject to retention needed to comply with law or resolve disputes.

When you ask us to delete your account, a 30-day grace period begins. During that time your profile and your content are hidden from other users, and you can stop the deletion at any moment by signing in and choosing to keep your account.

After 30 days the account is permanently anonymised: your email address, name, avatar, biography, messages, comments, likes and sign-in logs (including IP addresses) are erased and cannot be restored.

Two things deliberately survive that anonymisation. Records of completed payments are retained in a form that no longer identifies you, for as long as accounting and tax law requires (currently 5 years in Poland) — we are legally obliged to keep them. And content that other users have already paid for stays available to those buyers, so that they do not lose access to something they purchased.

If you need your data erased sooner than 30 days, contact us at privacy@vireliavault.com and we will handle it individually.

8. Your rights

Subject to conditions in the GDPR and applicable law, you have the right to:

  • Access your personal data and receive a copy.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten") in certain circumstances.
  • Restrict or object to certain processing, including processing based on our legitimate interests.
  • Data portability for data you provided, where processing is based on consent or contract and is automated.
  • Withdraw consent at any time, where processing is based on consent, without affecting prior processing.

To exercise your rights, email privacy@vireliavault.com. We may need to verify your identity. We respond within the timeframes required by law (generally one month).

9. Complaints

If you believe we have handled your data unlawfully, you can lodge a complaint with your local data-protection authority. In Poland, this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warszawa. We would appreciate the chance to address your concerns first.

10. How we protect your data

We use appropriate technical and organisational measures, including hashing of passwords, encrypted connections (HTTPS in production), access controls, and gated delivery of paid media. No system is completely secure; we cannot guarantee absolute security, but we work to protect your data and will notify you and the authorities of a breach where the law requires.

11. Children

VireliaVault is strictly for adults (18+). We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, contact privacy@vireliavault.com and we will delete it.

12. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Automated tools may assist moderation and fraud prevention, but material decisions involve human review or are subject to appeal via support.

13. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, take reasonable steps to notify you.

14. Contact

Data-protection questions and requests: privacy@vireliavault.com. Controller: [OPERATOR LEGAL NAME], [BUSINESS ADDRESS], NIP [NIP], REGON [REGON].