Privacy Notice
Version 2.1.0 · effective 2026-09-02
Note. This notice was prepared with AI assistance and published on the operator's own review; independent legal counsel review is planned. Operator details render from live configuration.
Controller: Richard Gyor ("we", "us", "the operator"), established in the Netherlands at Gispkruidweg 52, 1313CV, Almere. Business register (KvK) number: not yet registered. Contact for privacy matters: info@projectdigo.com.
The Service is currently operated by a natural person; if operation is later transferred to a company owned by the same operator, the controller identity shown above will be updated, you will be notified in the app, and this notice will be re-issued — the Service, the purposes and your rights do not change with that step.
This notice explains what personal data ProjectDigo collects, why, on what legal basis, who we share it with, how long we keep it, and the rights you have under the EU General Data Protection Regulation (GDPR).
1. What we collect
| Data | When | Why |
|---|---|---|
| Email address | Registration, waitlist | Account identity, login, verification, transactional email |
| Spoken/UI language | Registration, waitlist | Localisation |
| Date of birth | Registration (mandatory), or the one-time confirmation step for older accounts | Age assurance — the Service is 18+ only (see §9) |
| Country of residence you declare | Registration (mandatory), Settings | Deciding whether we may serve you and whether adult content is available where you are (see §2) |
| Approximate country derived from your IP address | Every request, while you use the Service | The same jurisdiction decision (see §2) |
| Nationality | Registration, waitlist | Age of majority in your country; VAT country for billing |
| Password (hashed) | Registration | Authentication — stored only as a salted hash, never in clear text |
| Bot-protection check | Registration | Cloudflare Turnstile verifies the request comes from a person (see §7) |
| Consent records | Registration, waitlist, settings | Proof of the consents you gave, with timestamps |
| Age-assurance records | Registration; certified verification if you start one | Proof that we checked your age (see §3) |
| Generated images/videos and the prompts you write | When you use the generator / play a story | Providing the service; the prompts you type are stored with the result |
| Roleplay sessions, stories, characters | When you play / create | Providing the roleplay feature |
| Content reports you file | When you report content | Handling the report and telling you the outcome (Digital Services Act) |
| In-app notifications | When the Service has something to tell you | The notification feed in the app |
| Billing details (name, address, country), invoices, payments | If you purchase (no purchases are offered during the free beta) | Legal accounting/tax obligations |
| Technical data: hashed IP address, user agent, approximate country | On certain actions | Security, fraud/abuse prevention, audit trail |
We do not sell your personal data, and we do not use your location for advertising, profiling or tracking. The app itself contains no analytics or tracking scripts. The separate marketing site uses analytics only with your consent (see §7).
2. Where you are: geolocation and regional availability
Laws on adult content and on the minimum age for online services differ from country to country, and some countries prohibit us from offering this Service at all unless we meet requirements we cannot currently meet. To respect those laws we have to know, at minimum, which country you are connecting from.
How we determine it. We look your IP address up in a GeoLite2 country database that we download and store on our own server. The lookup happens locally, inside our own infrastructure: your IP address is never sent to MaxMind or to any other third party for this purpose, and no request leaves our servers when we geolocate you. The database gives a country only — not a city, street, or precise position.
What we do with it. We combine the country from your IP with the country of residence you declared and apply whichever of the two is more restrictive. That decides (a) whether the Service is available to you at all, and (b) whether adult content is available to you. If we cannot determine your country, we treat the request as ineligible.
What we keep. Your IP address is used transiently, in memory, and is never stored in its raw form. When a decision has to be evidenced (for example, a refusal), we record only: a one-way cryptographic hash of the IP (SHA-256 with a secret key — it cannot be reversed back into your address), the country code, the build date of the geolocation database, the timestamp, and the reason for the decision. That record exists so we can demonstrate to a regulator that we applied the law correctly.
Legal basis. Compliance with legal obligations (GDPR Art. 6(1)(c)) — the age and content laws of the countries we serve — and our legitimate interests (Art. 6(1)(f)) in operating the Service lawfully and preventing circumvention of those rules, balanced against your rights.
Attribution. This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.
3. Age assurance
The Service is for adults only. We establish your age in one of two ways:
- Self-declaration. You give your date of birth at registration; we check it against the age of majority of your country and record that we did (the record holds the declared date, a coarse birth year, the outcome and the timestamp).
- Certified verification. Where the law of your country requires more than a declaration before adult content may be shown, adult content stays unavailable there until a certified verification is possible. When it becomes available we will use the European age-verification solution, which works by zero-knowledge proof: your national wallet or the EU age-verification app proves to us only the single fact that you are over 18. Your identity, your date of birth, your document and any other attribute stay with you — they are never disclosed to us. We store only an opaque transaction reference, the outcome, and its validity period (12 months).
We never ask for, receive, or store images of identity documents.
4. Special-category and adult data
Adult ("18+") content is optional and off by default. If you opt in, that preference is a record of a choice you made and is treated as sensitive: your stories and preferences are never used for advertising or profiling and are shared only as needed to generate your content (§6). Where adult content is unavailable in your jurisdiction, the opt-in has no effect. Character and reference images are created only by accounts with creator permissions, not by general users.
5. Legal bases
- Contract (GDPR Art. 6(1)(b)) — operating your account and providing the service.
- Legal obligation (Art. 6(1)(c)) — keeping invoices/accounting records; age assurance and the jurisdiction gate (§2, §3); handling content reports under the Digital Services Act.
- Consent (Art. 6(1)(a)) — optional marketing email, the optional adult-content opt-in (explicit consent, Art. 9(2)(a)), and analytics cookies on the marketing site. You may withdraw consent at any time (Settings in the app; the cookie banner on the marketing site).
- Legitimate interests (Art. 6(1)(f)) — security, abuse prevention and keeping our service working lawfully, balanced against your rights.
6. AI processing
Text and image/video generation is performed via our AI provider, Atlas Cloud AI Inc. (United States) — see the Sub-processor list. The prompts you write and, for image editing, the images you provide are sent to that provider to produce a result. According to its published policies, the provider retains submitted content for up to seven days and does not use it to train its models unless a customer authorises that in writing (we have not). The provider routes requests onward to third-party model providers (at the time of writing: OpenAI, Google, BytePlus, Alibaba Cloud, xAI), whose own retention practices may apply to the content they process. We do not use your content to train our own models. See the AI Transparency Statement.
7. Who we share data with (sub-processors and third parties)
We use a small number of processors that handle data on our behalf — AI generation, hosting, email delivery. The current list, including where each one processes data and under which safeguard, is published and kept up to date at https://my.projectdigo.com/legal/subprocessors. Two call-outs:
- Cloudflare Turnstile (bot protection at registration). When you register, a verification widget from Cloudflare, Inc. (USA) runs in your browser and we verify its token server-side; Cloudflare receives your IP address and browser characteristics for this single purpose. This protects the registration flow against automated abuse (legitimate interest, Art. 6(1)(f)). Cloudflare participates in the EU–US Data Privacy Framework.
- Google Analytics on the marketing site only. Our public marketing site (the landing pages) can use Google Analytics 4 — only after you accept analytics cookies in the banner there, with IP anonymisation and all advertising features disabled. Nothing loads before you consent, declining is one click, and you can withdraw at any time via "Cookie settings". The app you are reading this in uses no analytics at all.
The geolocation database (§2) is not a sub-processor: it is a data file we host ourselves, and no personal data of yours is sent to its publisher.
Where a provider processes data outside the EEA, transfers rest on an adequacy decision (e.g. the EU–US Data Privacy Framework) or Standard Contractual Clauses; the sub-processor list states the mechanism per provider.
Known gap, stated plainly: with the AI provider (Atlas Cloud AI Inc., United States) we do not yet have a data-processing agreement or an EU transfer mechanism in place. The operator intends to conclude both as part of its planned move to a corporate legal form; until then this is a disclosed, time-bounded gap. Because story text in the adult tier can reveal information about your sex life, the adult-content opt-in asks for your explicit consent to this transfer after this notice of the missing safeguards (GDPR Art. 49(1)(a)); you may decline and still use the non-adult service, whose prompts are far less sensitive. The provider does not receive your name, email address or account identity — only the text and images needed to produce your result.
8. How long we keep data
- Account data: while your account exists, then deleted (see §10).
- Content sent to the AI provider: up to seven days on the provider's side (its published policy), independent of what we keep.
- Raw IP addresses: never stored. Only the irreversible hash described in §2; the IP captured with a payment as tax evidence is deleted after 90 days.
- Security event log (failed logins, throttles): 180 days.
- Payment-provider webhook payloads: 90 days (the deduplication skeleton is kept).
- In-app notifications: 180 days.
- Technical telemetry (model latency samples): 90 days.
- Compliance/audit records (age assurance, consent, jurisdiction decisions, content-report decisions): kept while the account exists and afterwards for as long as needed to demonstrate compliance and to establish or defend legal claims — they are the evidence that we applied the law at the time.
- Invoices and accounting records: retained for the statutory period (in the Netherlands generally 7 years) even after account deletion, but stripped of directly-identifying details (name/address/email replaced). During the free beta no payments are processed and no invoices are issued.
- Waitlist entries and unused invitations: invitation data is deleted 30 days after the invitation expires.
9. Security
Passwords are stored only as salted hashes. Secrets are encrypted at rest. Access to generated media is authenticated. IP addresses in logs are hashed, masked or redacted. We apply technical and organisational measures appropriate to the risk (GDPR Art. 32).
10. Your rights
You have the right to access, rectify, erase ("right to be forgotten"), restrict, port, and object to the processing of your data (GDPR Art. 15–21). You can exercise the main ones yourself:
- Export — download a copy of your data from Settings → My data.
- Delete — request account deletion from Settings; it is disabled immediately and permanently erased after a 30-day grace period (invoices are kept anonymised as the law requires).
Your date of birth cannot be edited by yourself once given, because it is the basis of the age gate; contact us if it needs correcting and we will rectify it.
You also have the right to lodge a complaint with a supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl); you may also complain to the authority of your own country of residence.
11. Children
The Service is 18+ only and is not directed at children. A date of birth is required to register, and an account that declares an age below the age of majority of its country is deactivated. This is not limited to adult content: no part of the Service is offered to minors.
12. Changes
We may update this notice. Material changes will be notified and, where required, will ask for renewed acceptance. The effective date is shown above.
13. Contact
Questions or requests: info@projectdigo.com.